dr..mike wrote: > Assuming, someone 'only' installed the gallery plugin: does this allow > reading / downloading also PDFs, excels, docs and so on? Or 'only' shows > pictures it finds? > > Am I understanding correctly, that once someone accessed the LMS, the > user & password had to be set, i.e. max one person can go inside as it's > locked afterwards? >
The Gallery plugin was developed for pictures only. That said I know that some of the attackers did install modified versions of the plugin. They could potentially do anything they want. They could as well just write their own to download all those files, yes. But then I'm not aware of an attack at that level. The password can be used by anyone knowing it. Most likely this is only being set to annoy the users, and potentially have a bit more time to explore whatever content they got access to. Michael http://www.herger.net/slim-plugins - Spotty, MusicArtistInfo ------------------------------------------------------------------------ mherger's Profile: http://forums.slimdevices.com/member.php?userid=50 View this thread: http://forums.slimdevices.com/showthread.php?t=107165 _______________________________________________ discuss mailing list discuss@lists.slimdevices.com http://lists.slimdevices.com/mailman/listinfo/discuss