# Security breach in Discourse forum with SSO

**URL:** https://meta.discourse.org/t/security-breach-in-discourse-forum-with-sso/55759
**Category:** SSO
**Created:** [2017 年 1 月 14 日午後 12:01 UTC](https://meta.discourse.org/t/security-breach-in-discourse-forum-with-sso/55759 "2017-01-14T12:01:32Z")
**Posts on this page:** 1
**Showing post:** 6

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [2017 年 1 月 14 日午後 12:04 UTC](https://meta.discourse.org/t/security-breach-in-discourse-forum-with-sso/55759/6 "2017-01-14T12:04:29Z")

</div>

Oh my bad, I read that as 1.7 beta2. You’re right, it is up to date 😉

You need to follow the advice here:

> [@What to do if your Discourse is compromised](https://meta.discourse.org/t/what-to-do-if-your-discourse-is-compromised/40129):
>
> We’ve recently had two reports of Discourse sites that were compromised, likely due to weak admin account passwords. So we’d like to document: what to do when compromise happens what we can do to better prevent this in the future The Database Please note that Discourse, for several years now, has the following protections in place around the site database: Full database backup download links will only be sent via valid email of a site administrator, so you can’t just log in (via shoulder …

You should also check the Admin, Logs for staff actions to determine if there are any unusual staff actions there. To be able to download the database they would need to

- have SSH access to your server

or

- become an admin on your site

---

_[View the full topic](https://meta.discourse.org/t/security-breach-in-discourse-forum-with-sso/55759)._
