Dokuwiki hacked?

No Gravatar

When I visited ASecurePC.com, someone has added an external link to a website.  Furthermore, there was a user added to my list of users.  At first, I thought someone has hacked Dokuwiki.  Then I realized that nobody hacked Dokuwiki, I invited a new user.

If you look at the familar login screen below, you will see that there is a link called You don’t have an account yet? Just get one: Register. Therefore, anyone with an email can register for an account on your Dokuwiki.  Upon registering, he/she has the ability to change whatever he/she wants on your Dokuwiki.  Therefore, how does one prevent it?

By changing the permissions.

When you look at the permissions below, @ALL and @user can only read, but that is not the default.  By default, Dokuwiki sets the permissions for @user with upload.  Therefore, when someone registers for an account, he/she can read, edit, create and upload to your Dokuwiki.

Since this wiki is meant to be edited by only me, I had to change the permissions to reflect that.  One could definitely try to remove the link to create an account, but it is easier just to change @user to read.

For those that believe that their Dokuwiki got hacked, it is possible.  It is also possible that you just gave them the option to become a user to edit your Dokuwiki.

Leave a Reply