Hello all,
I realized I hadn't been able to announce a previous security fix,
which I apologize profusely. So, I'm writing about it now! Previously,
I've been alerted to two specific security holes in Enthusiast 3.0 --
the join form (which is, like any other web form, vulnerable to
spammers) and the login processes of Enth.
That said, please secure your Enth 3.0 installations by downloading
the two security fixes at
http://scripts.indisguise.org/enthusiast/download.php?select=3&agree=yes&cat=11
-- they are called the Join Form Security fix, and the Login Security
fix. Installing them simply means overwriting your Enth installation
files with the files in these zips.
Rest assured that these holes have been addressed in Enthusiast 3.1
since the start of the beta test, but I'm still continously improving
the release and smoothing out small kinks. :)
xx Angela