dr..mike wrote: 
> Assuming, someone 'only' installed the gallery plugin: does this allow
> reading / downloading also PDFs, excels, docs and so on? Or 'only' shows
> pictures it finds?
> 
> Am I understanding correctly, that once someone accessed the LMS, the
> user & password had to be set, i.e. max one person can go inside as it's
> locked afterwards?
> 

The Gallery plugin was developed for pictures only. That said I know
that some of the attackers did install modified versions of the plugin.
They could potentially do anything they want. They could as well just
write their own to download all those files, yes. But then I'm not aware
of an attack at that level.

The password can be used by anyone knowing it. Most likely this is only
being set to annoy the users, and potentially have a bit more time to
explore whatever content they got access to.



Michael

http://www.herger.net/slim-plugins - Spotty, MusicArtistInfo
------------------------------------------------------------------------
mherger's Profile: http://forums.slimdevices.com/member.php?userid=50
View this thread: http://forums.slimdevices.com/showthread.php?t=107165

_______________________________________________
discuss mailing list
discuss@lists.slimdevices.com
http://lists.slimdevices.com/mailman/listinfo/discuss

Reply via email to