Big Security Problem

I found that if you configure the APP with any user, you can get and post forms in the server.

example:

https://kc.humanitarianresponse.info/hrfcambodia

https://kc.humanitarianresponse.info/franck26

https://kc.humanitarianresponse.info/uga_mdc

https://kc.humanitarianresponse.info/ukraineshe

https://kc.humanitarianresponse.info/ibpf

https://kc.humanitarianresponse.info/aidmi

Hi Sebastian,

That’s the default setting - but you can change in your account Settings to require authentication with a username and password. We might make this the default setting in the future, but for the moment many users prefer not having to set up usernames and passwords on their individual devices.

To change the setting: Open the menu, then click Settings. Among the options on that page choose 'Require authentication to see forms and submit data:

Inline image 1

Best,

Tino

···

On Tue, Oct 27, 2015 at 11:40 AM, Sebastián Lamonega slam...@gmail.com wrote:

I found that if you configure the APP with any user, you can get and post forms in the server.

example:

https://kc.humanitarianresponse.info/hrfcambodia

https://kc.humanitarianresponse.info/franck26

https://kc.humanitarianresponse.info/uga_mdc

https://kc.humanitarianresponse.info/ukraineshe

https://kc.humanitarianresponse.info/ibpf

https://kc.humanitarianresponse.info/aidmi

You received this message because you are subscribed to the Google Groups “Kobo Users” group.

To unsubscribe from this group and stop receiving emails from it, send an email to kobo-users+...@googlegroups.com.

To post to this group, send email to kobo-...@googlegroups.com.

Visit this group at http://groups.google.com/group/kobo-users.

For more options, visit https://groups.google.com/d/optout.

Tino, have to be the default setting.

thanks!

···

2015-10-27 12:43 GMT-03:00 Tino Kreutzer tino.k...@kobotoolbox.org:

Hi Sebastian,

That’s the default setting - but you can change in your account Settings to require authentication with a username and password. We might make this the default setting in the future, but for the moment many users prefer not having to set up usernames and passwords on their individual devices.

To change the setting: Open the menu, then click Settings. Among the options on that page choose 'Require authentication to see forms and submit data:

Best,

Tino

You received this message because you are subscribed to a topic in the Google Groups “Kobo Users” group.

To unsubscribe from this topic, visit https://groups.google.com/d/topic/kobo-users/4fL7OYfVEoY/unsubscribe.

To unsubscribe from this group and all its topics, send an email to kobo-users+...@googlegroups.com.

To post to this group, send email to kobo-...@googlegroups.com.

Visit this group at http://groups.google.com/group/kobo-users.

For more options, visit https://groups.google.com/d/optout.

On Tue, Oct 27, 2015 at 11:40 AM, Sebastián Lamonega slam...@gmail.com wrote:

I found that if you configure the APP with any user, you can get and post forms in the server.

example:

https://kc.humanitarianresponse.info/hrfcambodia

https://kc.humanitarianresponse.info/franck26

https://kc.humanitarianresponse.info/uga_mdc

https://kc.humanitarianresponse.info/ukraineshe

https://kc.humanitarianresponse.info/ibpf

https://kc.humanitarianresponse.info/aidmi

You received this message because you are subscribed to the Google Groups “Kobo Users” group.

To unsubscribe from this group and stop receiving emails from it, send an email to kobo-users+...@googlegroups.com.

To post to this group, send email to kobo-...@googlegroups.com.

Visit this group at http://groups.google.com/group/kobo-users.

For more options, visit https://groups.google.com/d/optout.

Tino, you or one your friends could help me to install a docker version of Kobo?

I don´t have IT skills.

tell me about the costs.

Sebas

···

2015-10-27 12:54 GMT-03:00 Sebastián Lamonega slam...@gmail.com:

Tino, have to be the default setting.

thanks!

2015-10-27 12:43 GMT-03:00 Tino Kreutzer tino.k...@kobotoolbox.org:

Hi Sebastian,

That’s the default setting - but you can change in your account Settings to require authentication with a username and password. We might make this the default setting in the future, but for the moment many users prefer not having to set up usernames and passwords on their individual devices.

To change the setting: Open the menu, then click Settings. Among the options on that page choose 'Require authentication to see forms and submit data:

Best,

Tino

You received this message because you are subscribed to a topic in the Google Groups “Kobo Users” group.

To unsubscribe from this topic, visit https://groups.google.com/d/topic/kobo-users/4fL7OYfVEoY/unsubscribe.

To unsubscribe from this group and all its topics, send an email to kobo-users+...@googlegroups.com.

To post to this group, send email to kobo-...@googlegroups.com.

Visit this group at http://groups.google.com/group/kobo-users.

For more options, visit https://groups.google.com/d/optout.

On Tue, Oct 27, 2015 at 11:40 AM, Sebastián Lamonega slam...@gmail.com wrote:

I found that if you configure the APP with any user, you can get and post forms in the server.

example:

https://kc.humanitarianresponse.info/hrfcambodia

https://kc.humanitarianresponse.info/franck26

https://kc.humanitarianresponse.info/uga_mdc

https://kc.humanitarianresponse.info/ukraineshe

https://kc.humanitarianresponse.info/ibpf

https://kc.humanitarianresponse.info/aidmi

You received this message because you are subscribed to the Google Groups “Kobo Users” group.

To unsubscribe from this group and stop receiving emails from it, send an email to kobo-users+...@googlegroups.com.

To post to this group, send email to kobo-...@googlegroups.com.

Visit this group at http://groups.google.com/group/kobo-users.

For more options, visit https://groups.google.com/d/optout.