• This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn more.

security

  1. Freelancer

    Won't fix Security Error through editor while switching Rich Text to BBCode

    Some add-ons utilize the Redactor Editor in the ACP. The following setting produces the infamous security error ("Security Error – hit back, refresh page" etc) Login to the front end as some test user* New browser tab, login to the ACP as admin* Visit add-on page with redactor text editor Click...
  2. Alfa1

    Error Reports without security sensitive details

    When posting Error Reports in public forums like xenforo.com or a developers forum its unwise to post raw error reports as that will expose server details, user details and xenforo details of the website, which can be abused by hackers. The report itself could still show the full details. but...
  3. Mouth

    Add support for Duo to two-step verification

    Duo is a well respected two-factor authentication provider. Please add support for Due to Xenforo. https://duo.com/docs/duoweb contains documentation, including GitHub php library for easy integration.
  4. Welder

    Website Security Experts Needed

    Hello, I am looking for a companies and/or individuals who are considered website security experts.... if that's what their called... I don't know, but I'm looking for some. :ROFLMAO: Okay, no seriously. I would like to hire someone who knows the in's and out's of securing a website from all...
  5. Foxtrek_64

    Add-on XenForo LDAP Authentication

    Details for this enhancement request.... Feature list (This will be updated with suggestions as people add them): Multiple Authentication Methods... Support authentication using LDAP/LDAPS, Kerberos, or local DB (LDAP/LDAPS is highly desired for compatibility with multiple platforms.)...
  6. DragonByte Tech

    [DBTech] DragonByte Security 3.3.0

    DragonByte keeps a watchful eye over your forum even when you are not there, and has the capability to alert you of any suspicious activity. Uses DragonByte is the ideal product for forums that are concerned about security, or wish to be alerted when something suspicious happens. Featuring...
  7. Foxtrek_64

    XF 1.5 xenForo Active Directory/LDAP

    Hello all, After looking around on the forums, I found this thread discussing LDAP and Active Directory. However, seeing as the thread was from 2011, I thought it better to make my own thread instead of necro-ing the other one. That being said, I am trying to use LDAP to enable Single Sign-On...
  8. nanocode

    Unmaintained [n] Template Security 1.1.0

    Enhance the security on your site using this very basic add-on. There has been a surprising increase in malicious attacks to XenForo sites through injection of malicious code into your templates. Limiting the access of all templates to yourself and a small handful may not always be a...
  9. Chris D

    Potential FFmpeg security vulnerability

    It recently came to our attention that there is a potential vulnerability in FFmpeg which has the potential to be exploited via XenForo Media Gallery if you have FFmpeg features enabled (or are using any other code that uses FFmpeg). The issue is exploitable by using a specially constructed...
  10. PumpinIron

    User complaining about not being able to login at work?

    Okay, I have a user on my forum who tells me that he can view my forum just fine (as a guest) at work, but when he tries to login to my forum he gets the following error message: He tells me that he can login just fine without any error messages from his smart phone or his home computer...
  11. Dan Allen

    XF 1.5 How Does "Stay Logged Work?"

    disregard. It works just fine
  12. Alfa1

    Alert Admin in case of unusual high login attempts

    If an attacker tries to login to many accounts, then the admin should be made aware of this. This allows the admin to take countermeasures and reevaluate security. Please consider to add a function to notify the admin of such event. It can be in the form of an email or an on-site alert or...
  13. Alfa1

    Limit username validation attempts to improve security

    The registration form has a username validation function. it seems this can be abused by attackers to find out what accounts are present on the site. The attacker can run a script to try millions of possible usernames to get a member list. I have recently encountered such attack on my vbulletin...
  14. Shiro

    Crowdsourced Human Spammers

    You may be aware of services like Amazon Mechanical Turk or Microworkers. These are crowdsourcing services that allow vendors to pay small amounts of money for the completion of tasks. These tasks often range from things like helping Google and Bing rank search results (human experience), and...
  15. Formina Sage

    2FA: Remember device indefinitely

    I think having to re-authenticate every 30 days is a bit of a hassle, personally. Large services like Google and Facebook don't make me re-authenticate every 30 days, they permanently remember the browser unless cookies are cleared. Having the option to adjust the 30 day period to be longer...
  16. R

    Deactivating 2FA is too easy

    Let's take the following scenario: An attacker has gained access to the users password and one of these requirements: he has access to the device where the user selected 'remember this device for 30 days' or he can somehow bypass the login 2FA, because the user has selected 'remember this...
  17. Shiro

    Trust+ 1.0.13

    Trust+ Risk Analysis System Trust+ is a security and risk analysis system designed to help stop spammers, trolls, and other bad-actors from registering an account on your forum. Unlike similar services, Trust+ takes a multi-faceted approach to identify different risk factors. Currently, Trust+...
  18. Shiro

    Add-on Trust+ - Intelligent Security Service

    Hello, I am currently working on developing a security and risk assessment service called Trust+, and I intend to release an add-on for Xenforo which utilizes the service. Trust+ will be launched with the following features; The ability to intelligently detect and block disposable email...
  19. Shiro

    Block Disposable Email Addresses [Deleted]

    This resource has been replaced by the Trust+ Risk Analysis system.
  20. vbuser

    XF 1.5 FYI about 2 step verification

    Google Authenticator accounts only exist on your phone. There is no back up. I reset my phone and lost access to all sites using Google Authenticator. I'm using Authy now which can sync with multiple mobile devices. Authy also backs up your accounts. Also, "Regenerate secret for a new...