What the heck?!

Author Message

Noicokuna Niemoge

Wednesday 18 March 2009 1:20:42 am

Hi;

I have just received an information from my engine that a new user has been registered...

It wouldn't be strange if <b>all user information</b> were just... BLANK.

o_O O_O! How is that possible? How can I investigate this?

Shiki soku ze ku...

André R.

Wednesday 18 March 2009 1:41:47 am

Is the mail empty or the user object?
What version are you running? There where some security bugs fixed in 4.0.1 that might relate to this if you are still on 4.0.0.

eZ Online Editor 5: http://projects.ez.no/ezoe || eZJSCore (Ajax): http://projects.ez.no/ezjscore || eZ Publish EE http://ez.no/eZPublish/eZ-Publish-Enterprise-Subscription
@: http://twitter.com/andrerom

Piotrek Karaś

Wednesday 18 March 2009 2:54:14 am

Using ez.no forum search would be a good start, I think this topic has been already covered:
http://ez.no/developer/forum/general/security_issue_anonymous_user_without_user_name/re_security_issue_anonymous_user_without_user

--
Company: mediaSELF Sp. z o.o., http://www.mediaself.pl
eZ references: http://ez.no/partners/worldwide_partners/mediaself
eZ certified developer: http://ez.no/certification/verify/272585
eZ blog: http://ez.ryba.eu

Noicokuna Niemoge

Wednesday 18 March 2009 6:21:40 am

Hmm, my site is running on eZ 4.0.1 ... the whole user object was blank (hehe, of course with an exception of user ID) Well, maybe captcha plugin will work indeed. Thank you for reply. :)

Shiki soku ze ku...

Powered by eZ Publish™ CMS Open Source Web Content Management. Copyright © 1999-2014 eZ Systems AS (except where otherwise noted). All rights reserved.

eZ debug

Timing: Jan 18 2025 19:15:29
Script start
Timing: Jan 18 2025 19:15:29
Module start 'layout'
Timing: Jan 18 2025 19:15:29
Module start 'content'
Timing: Jan 18 2025 19:15:29
Module end 'content'
Timing: Jan 18 2025 19:15:29
Script end

Main resources:

Total runtime0.0164 sec
Peak memory usage4,096.0000 KB
Database Queries3

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0055 587.7813152.6094
Module start 'layout' 0.00550.0038 740.390639.3984
Module start 'content' 0.00920.0051 779.789193.2578
Module end 'content' 0.01430.0020 873.046934.3047
Script end 0.0163  907.3516 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.002816.9092140.0002
Check MTime0.00106.4017140.0001
Mysql Total
Database connection0.00084.967110.0008
Mysqli_queries0.003219.625530.0011
Looping result0.00000.098910.0000
Template Total0.001710.610.0017
Template load0.00105.937610.0010
Template processing0.00084.601910.0008
Override
Cache load0.00063.923910.0006
General
dbfile0.00063.625780.0001
String conversion0.00000.066940.0000
Note: percentages do not add up to 100% because some accumulators overlap

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1print_pagelayout.tpl<No override>extension/community/design/community/templates/print_pagelayout.tplEdit templateOverride template
 Number of times templates used: 1
 Number of unique templates used: 1

Time used to render debug report: 0.0001 secs