[SOLVED] Security or bad setting ?

11 years 11 months ago - 11 years 11 months ago #200384 by mfe13
[SOLVED] Security or bad setting ? was created by mfe13
hello,
A user was able to register without completing the registration form CBSubs mandatory!
There is his email address but no other fields filled, it is not normal!
In the configuration joomla, registration is set to "no". How he did it??
Joomla 2.5.3
CBSubs 1.3.rc2

Thank you for your answers

Please Log in to join the conversation.

11 years 11 months ago #200418 by krileon
Replied by krileon on topic Re: Security or bad setting ?
They registered through Joomla instead of CB. Navigate to Backend > Users > User Manager > Options and disable registration. Now navigate to CB > Configuration > Registration and set CB to be independent of Joomla. This closes that backdoor. Our redirect plugin also resolves this by sending users away from Joomla (see CB Core Redirect in free downloads section).


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

11 years 11 months ago - 11 years 11 months ago #200422 by mfe13
Replied by mfe13 on topic Re: Security or bad setting ?

krileon wrote: They registered through Joomla instead of CB. Navigate to Backend > Users > User Manager > Options and disable registration. Now navigate to CB > Configuration > Registration and set CB to be independent of Joomla.

I am worried because this is already set like that !

krileon wrote: (see CB Core Redirect in free downloads section).

I'll look at it, thank you

Please Log in to join the conversation.

11 years 11 months ago #200444 by krileon
Replied by krileon on topic Re: Security or bad setting ?

I am worried because this is already set like that !

Maybe something else installed that allows registration? FBC, TC, CB Connect maybe?


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

11 years 11 months ago #200458 by mfe13
Replied by mfe13 on topic Re: Security or bad setting ?
Yes, cb_connect is enabled for registration and I have not properly adjusted. A little complicated, I will again.
Sorry, this is my fault!
thank you

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 0.180 seconds

Facebook Twitter LinkedIn