Kunena 7.0.4 Released

The Kunena team has announce the arrival of Kunena 7.0.4 [K 7.0.4] in stable which is now available for download as a native Joomla extension for J! 5.4.x/6.0.x. This version addresses most of the issues that were discovered in K 6.2 / K 6.3 / K 6.4 and issues discovered during the last development stages of K 7.0

Question Visibility of attachments and image for guests

More
15 years 7 months ago - 15 years 7 months ago #63934 by xpozay
Actually, this is a very big issue. I only discovered this myself two weeks ago while I have been a happy kunena customer for the past year and FB before. It never occurred to me that my files were "open" to the public. While the use of a blank index.html in every directory helps, this doesn't solve the issue.

I looked at my other forum, phpbb which I use because I need group access to different sub-forums, and while the files are stored in the files directory, 1) by default the httaccess file is set so the directory is not accessible and 2) all the file names are nonsensical eg 2_0122d903f2adfc5100723a5d974daf8e. I recognise we can play with the httaccess file to restrict access however this is not for the faint hearted.

I wonder, moving forward, why can't the files be stored above the public_html folder. This is done with moodle where the moodledata directory is not public and users can still access, edit, add, delete content. This could be configurable so that those who do not have access to folders above public_html can still use kunena but for those who require the additional security the option is there.

I wonder is this something that we could hack to make work? Can we point kunena to a location above public_html?

Thanks in advance for your thoughts

Chris
Last edit: 15 years 7 months ago by xpozay.

Please Log in or Create an account to join the conversation.

More
15 years 5 months ago #70614 by xpozay
bump

Can somebody share if the Kunena team will be looking at these security issues.

Is it possible to hack Kunena so that the attachments & pictures are stored above the public_html directory?

Please Log in or Create an account to join the conversation.

More
14 years 11 months ago #95850 by xpozay
I would like to bump this post. Perhaps this is something that could be looked at as part of Kunena 2.0?

Please Log in or Create an account to join the conversation.

Time to create page: 0.253 seconds