Uploaded image for project: 'phpBB'
  1. phpBB
  2. PHPBB-7871

Potenitial for Jabber misuse by reusing the same jabber username or cloning the board's jabber use

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • 3.0.4
    • 3.0.3
    • Other
    • None
    • PHP Environment: 5.2.5
      Database: 4.1.16

      Today I received a series of strange jabber messages to my forum's jabber account. These messages were communications from the board to one particular user regarding password reactivation and topic subscription area notifications.

      I then realised that I had set the board admin jabber account to be the same as the board itself jabber account. I've change this and now I now longer receive these messages for the particular user? I don't fully understand why I was in the first place as the forum admin account had a jabber address but was set to only receive email alerts from the site and had nothing to do with the other users interactions with the board.

      However, it then made me realise that any user could join the board and then set their user profile jabber name to become the boards name. Seeing as any communication sent using jabber from user to user shows as coming from the board's account. Of course they wouldn't be able to get access to the jabber password and therefore read any of the board's jabber communications (hopefully).

      Shouldn't the system check for unique jabber addresses as it does for unique email addresses if the admin wants it to?

            Acyd Burn Meik Sievertsen [X] (Inactive)
            x-rayman x-rayman [X] (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: