PriMoThemes — now s2Member® (official notice)

This is now a very OLD forum system. It's in READ-ONLY mode.
All community interaction now occurs at WP Sharks™. See: new forums @ WP Sharks™

Exploit?

s2Member Plugin. A Membership plugin for WordPress®.

Exploit?

Postby Westendorf » June 3rd, 2010, 5:17 pm

Typing: ?feed=rss2 at the end of the URL of a blog with s2Member installed exposes all content, as far as I can tell.

Has this been addressed before? Is there a way to protect the RSS feed?
User avatar
Westendorf
Registered User
Registered User
 
Posts: 2
Joined: May 31, 2010

Re: Exploit?

Postby drbyte » June 3rd, 2010, 10:47 pm

looking at this issue!!! It does using IE, not in FireFox

Jason, can you please look into this issue and let us know

Thank you
Last edited by drbyte on June 3rd, 2010, 11:13 pm, edited 1 time in total.
User avatar
drbyte
Experienced User
Experienced User
 
Posts: 269
Joined: May 6, 2010

Re: Exploit?

Postby drbyte » June 3rd, 2010, 11:01 pm

Ok I found a quick fix to this issue

Within your WordPress Admin page go to Settings------>Reading Settings------> and change For each article in a feed, show from Full Text to Summary

Delete your IE Cache and try again. It should work

Sam
User avatar
drbyte
Experienced User
Experienced User
 
Posts: 269
Joined: May 6, 2010

Re: Exploit?

Postby Jason Caldwell » June 23rd, 2010, 5:57 pm

This is the intended behavior. However, I'm looking for ways to address this issue and make s2Member more secure in this regard. Please have a look at this thread, where I've discussed the reasoning behind it, and feel free to chime in and give me your opinions. viewtopic.php?f=4&t=231&p=866&hilit=feeds#p866
~ Jason Caldwell / Lead Developer
& Zeitgeist Movie Advocate: http://www.zeitgeistmovie.com/

Is the s2Member plugin working for you? Please rate s2Member at WordPress.org.
You'll need a WordPress.org account ( comes in handy ). Then rate s2Member here Image
.
User avatar
Jason Caldwell
Lead Developer
Lead Developer
 
Posts: 4045
Joined: May 3, 2010
Location: Georgia / USA


Return to s2Member Plugin

Who is online

Users browsing this forum: Exabot [Bot] and 2 guests

cron