Kunena 7.0.4 Released

The Kunena team has announce the arrival of Kunena 7.0.4 [K 7.0.4] in stable which is now available for download as a native Joomla extension for J! 5.4.x/6.0.x. This version addresses most of the issues that were discovered in K 6.2 / K 6.3 / K 6.4 and issues discovered during the last development stages of K 7.0

Please Read This First:


Please read the guides posted as sticky topics in this category. For a quicker response, please give as much information to help us understand the problem (see How To Ask Questions The Smart Way and What information should I include when I ask for help (including how to post my configuration report)? ).

This category is only for reporting defects with K 2.0 Please read, before you post, Before you post your question, read this first .

Do not use this category:
  • if this website ( www.kunena.org ) works but works differently to how you expected
  • for requests to add or remove the standard features of Kunena;
  • for questions commonly asked or "how to" in nature (see the FAQs menu tab above);
  • for help with Kunena versions that are not the latest stable release; or
  • for general Joomla or website administration matters

You must include your K 2.0 configuration report; if you do not include your configuration report, your topic may be closed (locked) or deleted without any further warnings from the moderators.

K 2.0 support will cease on 31 August 2013 and this section of the forum will be closed and archived after that time and no further questions will be answered about this version.

Important Security: Search option exposes account login data

More
13 years 1 month ago #142379 by Winuser
Kunena has had a long history of confounding the username and screen name, and I think I've discovered yet another security problem connected with that old habbit.

Searching for a member name triggers a list of login names--not only for the user in question, but for other members with a matching search!

Am I correct in assuming that the search option behavior assumes login = real name? What a terrible revelation for websites that opt for separate login and display names.

If you search for a known screen name, you can get a list of member's login names. Wow!

Please Log in or Create an account to join the conversation.

More
13 years 1 month ago #142383 by sozzled
Your K 2.0 configuration report would greatly assist.

Please Log in or Create an account to join the conversation.

More
13 years 1 month ago #142385 by Winuser
It hasn't changed. I'll refer you a few topics down:

www.kunena.org/forum/K-2-0-Support/12699...ntom-accounts#141786

As an aside, there ought to be fewer knee-jerk configuration requests and more emphasis on thinking about what is being reported.

I've described a design flaw that impacts the use of "Real Name" logic, so obviously the only relevant setting is Display User Name, which must be disabled if the website is using separate display and login names.

You'll probably save precious time by ignoring the configuration report and instead going directly to your source code to confirm or deny that a problem exists when you search for posts by JohnScreenName, who logs in using john.at.mail.dot.com.

Wouldn't you get a nice little droplist revealing email addresses for users matching the search???

Please Log in or Create an account to join the conversation.

More
13 years 1 month ago - 13 years 1 month ago #142410 by sozzled
Whenever the Kunena team sees the word "SECURITY" (in capitals) as the subject of a topic posted in the K 2.0 Support category, everything stops! We take security questions very seriously! Whenever someone reports something that has this keyword "SECURITY" in the topic, we assume that people are serious and do not want the team to overlook something that could have massive repercussions both in terms of the reputation and prestige of Kunena as a product, but also in terms of the potential risks that people believe exist for the whole community.

In serious cases, like these, the quicker we get the most up-to-date configuration report, the sooner we can investigate the problem.

Therefore, let's forget that we had to spend time searching around the forum to try to find the last configuration report that you posted and had hoped that nothing had changed since then and now.

"Knee-jerk reaction" assertions, aside, we're only trying to obtain the most information that we can obtain to establish what's going on in this case - the only one that has been reported so far - to see whether we can reproduce the conditions on our own testing environments.

Winuser wrote: Searching for a member name triggers a list of login names--not only for the user in question, but for other members with a matching search!

I spent a lot of time trying this out, here, at www.kunena.org . In our case here, entering a partial name in the "search by username" field (see image below) generates a list of username "suggestions" populated by AJAX:



Is this what we are discussing?

I want to be very clear that we understand exactly what it is that you believe is a security issue. Looking forward to your reply.
Last edit: 13 years 1 month ago by sozzled.

Please Log in or Create an account to join the conversation.

More
13 years 1 month ago #142555 by Matias
I think it's this one.

Personally I don't see this as security bug as it cannot be used on attacks against the site. If someone wants to attack and knows an existing vulnerability, why not create account by his own and use that instead..

But that said, I do agree that the search box is revealing information that administrator wants to hide, which is why it needs to be fixed.

github.com/Kunena/Kunena-2.0/issues/1620

Please Log in or Create an account to join the conversation.

More
13 years 1 month ago #142571 by Winuser
I kind of pointed out earlier why this might not appear like an important security issues at THIS website: you assume login name = display name !!!

The entire purpose of the Real Name toggle is to secure the login details. I really wish the developers would stop lapsing on this fact, because it has been explained to the team before and backed up by other ordinary Joomla administrators.

So start with the Sozzled screenshot, but don't turn off your brain yet. You have to change the Real Name mode and imagine that members login with a private string (e.g., an email address). For example, I am seen as "winuser" but maybe I login as "winuser4321."

If you cannot see this as a legitimate security issue, then you have no real business designing forum software that will be used on thousands and thousands of Joomla websites. I say that out of pure astonishment--not to impugn your work or dedication.

Please Log in or Create an account to join the conversation.

Time to create page: 0.211 seconds