WebsiteBaker Logo
  • *
  • Templates
  • Help
  • Add-ons
  • Download
  • Home
*
Welcome, Guest. Please login or register.

Login with username, password and session length
 

News


WebsiteBaker 2.13.6 is now available!


Will it continue with WB? It goes on! | Geht es mit WB weiter? Es geht weiter!
https://forum.websitebaker.org/index.php/topic,32340.msg226702.html#msg226702


The forum email address board@websitebaker.org is working again
https://forum.websitebaker.org/index.php/topic,32358.0.html


R.I.P Dietmar (luisehahne) and thank you for all your valuable work for WB
https://forum.websitebaker.org/index.php/topic,32355.0.html


* Support WebsiteBaker

Your donations will help to:

  • Pay for our dedicated server
  • Pay for domain registration
  • and much more!

You can donate by clicking on the button below.


  • Home
  • Help
  • Search
  • Login
  • Register

  • WebsiteBaker Community Forum »
  • WebsiteBaker »
  • Security Announcements »
  • Website Baker Security Problem
  • Print
Pages: [1]   Go Down

Author Topic: Website Baker Security Problem  (Read 30229 times)

susigross

  • Guest
Website Baker Security Problem
« on: December 26, 2010, 08:21:13 AM »
As found out by different sources, all current versions of Website Baker are vulnerable to CSRF attacks.
(If you do not know what CSRF is, google for it or have a look into Wikipedia.)
The upcoming version 2.8.2 of Website Baker will not be vulnerable anymore, but is not available yet.

To some degree, you can protect yourself against CSRF attacks if you do as follows:
  • 1. If you did it not already, install a second web browser
  • 2. Use another than your default web browser to administer your Website Baker site. The default browser is the one who opens when you click on a link in your email program, for instance.
  • 3. In the browser you are using for administration, do not open any other web pages as long as you are logged on to your WB site. Use the default browser for opening any other web site.
  • 4. As soon as you finished your administration task, log off from the WB site.

Frank
Logged

  • Print
Pages: [1]   Go Up
  • WebsiteBaker Community Forum »
  • WebsiteBaker »
  • Security Announcements »
  • Website Baker Security Problem
 

  • SMF 2.0.19 | SMF © 2017, Simple Machines
  • XHTML
  • RSS
  • WAP2