Replies: 6 comments 4 replies
-
Have you eliminated the possibility it's AV grabbing up your installer for testing in their sandboxes? |
Beta Was this translation helpful? Give feedback.
-
You mean user accounts in the meshcentral GUI? |
Beta Was this translation helpful? Give feedback.
-
@SomeGuru You mind looking me up on the Tactical RMM discord, would like to have a chat with you for more info. Thx! |
Beta Was this translation helpful? Give feedback.
-
can you please clarify what you mean with |
Beta Was this translation helpful? Give feedback.
-
Hi. Looking at this discussion, there is not sufficient information to do anything. If you have an server that allows account creation and people create accounts with odd names, that is not in itself an issue. On MeshCentral.com, people create accounts with odd names or numbers all the time. As long as the account name is handled correctly throughout the MeshCentral web site, that is ok. For example if I create a Also, what is "BXSS"?? If it's "Blind XSS" - Please provide evidence. Unless SomeGuru has actionable information, having an open server and people creating off account names is not an issue. If there is a vulnerability, please create an issue and put as much detail as possible or mail me directly if the information could lead to others using it to exploit MeshCentral servers. - Thanks. |
Beta Was this translation helpful? Give feedback.
-
Do let you SSO administrator know right away that this is happening. When configured for SSO, MeshCentral delegated the user login trust to the SSO server. Obviously, if the SSO server is allowing bad things to happen, MeshCentral can't help much. SSO should have logs showing exactly what is going on. |
Beta Was this translation helpful? Give feedback.
-
Hi community, has anyone else noticed accounts showing up as random series of numbers like 90004637 and or {script%!()aH9*} if so, when did you start seeing these accounts and what are your cross site config settings looking like? I noticed this three weeks ago now and have wondered if this is seen by others.
-SomeGuru
Beta Was this translation helpful? Give feedback.
All reactions