vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 3.7 Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=228)
-   -   Miscellaneous Hacks - Cyb - PayPal Donate (https://vborg.vbsupport.ru/showthread.php?t=177563)

welovehiphop 12-27-2008 06:06 PM

very nice thanks

Chewy954 12-28-2008 08:10 PM

What was the exploit associated with this? I wanna see if I can patch it myself.

Replicators 12-28-2008 08:10 PM

WTH, i get a email stating this mod has been Quarantined, but no info if it's been fixed yet or not, or anything about it here.

howcome 12-28-2008 08:12 PM

Quote:

Originally Posted by Replicators (Post 1695769)
WTH, i get a email stating this mod has been Quarantined, but no info if it's been fixed yet or not, or anything about it here.

yea same should i uninstall this mod until further notice or what?

Voltar 12-28-2008 08:12 PM

I got a quarantined email also just now, has it been fixed already?

jlew24asu 12-28-2008 08:15 PM

disabled until fix is confirmed

fattony69 12-28-2008 08:16 PM

I am assuming there is a fix since the last update 4.8.1, it was done today and this mod isn't in the graveyard.

jlew24asu 12-28-2008 08:24 PM

Quote:

Originally Posted by fattony69 (Post 1695778)
I am assuming there is a fix since the last update 4.8.1, it was done today and this mod isn't in the graveyard.

true. but would be nice to get a confirmation

masterross 12-28-2008 08:26 PM

Please explain where was the exploit???
Because I use some old version!!!

cheesegrits 12-28-2008 08:38 PM

Quote:

Originally Posted by masterross (Post 1695789)
Please explain where was the exploit???

I sincerely hope nobody answers this question! Posting details of the exploit wouldn't be very smart, would it?

Quote:

Because I use some old version!!!
Suggest you update to todays version. As the mod seems to be out of the graveyard, we can assume the problem has been resolved. Although as jlew says, it would be nice to get some confirmation.

Personally I'm disabling my copy until we have confirmation from cyb. I can live for a while without the $1 every other leap year I get from our Donations page. :)

-- hugh

jammiedodger546 12-28-2008 08:42 PM

Not enabling/upgrading until there is a post from Cyb saying its fixed.

consolegaming 12-28-2008 08:44 PM

Got this e-mail 15 minutes ago, which is exactly 1 hour after I received an e-mail that this hack was quarantined.

* Restore Notification *

The following quarantined modification has now been restored.

https://vborg.vbsupport.ru/showthread.php?t=177563

If you have this modification installed then please make sure you update to the
latest version to ensure you are safe from the previously discovered exploit.

Thank you,

vBulletin.org Staff

nicker 12-28-2008 08:47 PM

I got that too, I'm going for it, as was said we don't want to know what the exploit was and I'm sure Cyber will post that the update is ok.

exportforce 12-28-2008 08:49 PM

Quote:

Originally Posted by jammiedodger546 (Post 1695805)
Not enabling/upgrading until there is a post from Cyb saying its fixed.

Is fixed, otherwise this mod wouldn't be free again.
Dunno what it was too.

Fr4n-FX 12-28-2008 08:53 PM

so, download and install again?

nicker 12-28-2008 08:57 PM

Quote:

Originally Posted by Fr4n-FX (Post 1695820)
so, download and install again?

Just overwrite the XML with the new one.

Valter 12-28-2008 09:12 PM

v4.8.1/4.8.2 - Dec 29. 2008.
- Security fix/subscriptions bug fix

Please take a minute to upgrade. Just import product XML, allow overwrite.

DesiSugar 12-28-2008 09:14 PM

Quote:

Originally Posted by Cybernetec (Post 1695832)
v4.8.1/4.8.2 - Dec 29. 2008.
- Security fix/subscriptions bug fix

Please take a minute to upgrade. Just import product XML, allow overwrite.

Thnx cyb:)

jlew24asu 12-28-2008 09:15 PM

thanks cyb

Dave-M 12-28-2008 09:17 PM

Thanks for the fix. :)

tnedator 12-28-2008 09:33 PM

Quote:

Originally Posted by Cybernetec (Post 1695832)
v4.8.1/4.8.2 - Dec 29. 2008.
- Security fix/subscriptions bug fix

Please take a minute to upgrade. Just import product XML, allow overwrite.

Thanks for the update.

In the previous version, anytime someone signed up for a subscription, Paypal wound up collecting one donation and then cancelling the subscription. Is this fixed?

raywjohnson 12-28-2008 09:43 PM

Flawless execution!

I get a security notice email telling me to disable and within the hour another to tell me it is fixed!

Thanks!

I do have a small request. Could you add a little formatting to the output?

I made these changes to my install
PHP Code:

In:
  
Cyb PayPal Donate Link      (parse_templates hook)

Find:
  
$cybpp_donbar_left 100 $cybpp_donbar_done;

Add:
  
$cybpp_donbar_total '$'.number_format($cybpp_donbar_total,2,'.',',');
  
$cybpp_donbar_goal '$'.number_format($cybpp_donbar_goal,2,'.',','); 

Works great!

--RayJ

masterross 12-28-2008 10:03 PM

So can I know which versions affect this security issue?

-=Leb=- 12-28-2008 10:15 PM

Thx cyb for your wonderful work <3

howcome 12-28-2008 10:18 PM

you guys fixed this pretty fast lol nice job

smokey7722 12-28-2008 11:23 PM

thanks for the quick fix guys!

JKatz 12-28-2008 11:54 PM

Thank you! Appreciate your fast work!

echo2kk5 12-29-2008 01:23 AM

Thank you for the update! :up:

jammiedodger546 12-29-2008 08:18 AM

cheers cyb

ETDC 12-29-2008 12:14 PM

Is this update going to hose my stats?...

Birute 12-29-2008 02:45 PM

Thanks for the fix

GrendelKhan{TSU 12-29-2008 03:08 PM

awesome..

anyone know if works for vb 3.8?

kollam003 12-30-2008 08:21 AM

great hack thanks

punk23 12-30-2008 08:40 AM

Hi all

Since applying the new version, my donors are no longer added to the list automatically. Their payments are confirmed and the pm's work...it's just that they're not added to the list.

Sure, I can add them manually but it would be nice if this feature worked again. If I uninstall the product I will lose all records..right?

Thanks.

Valter 12-30-2008 06:16 PM

Yes, if you uninstall product donation log will be lost.
To save the list just export 'cybppdonate' table from your forum database.

Are they donated when version 4.8.1 was installed, or latest one?

Bounce 12-30-2008 08:09 PM

Having a similiar issue...

Just got a pm saying someone had donated but when I went to the donations page it aint there and all thats there is this text...

No Donors or not added.

Bounce 12-30-2008 08:14 PM

Quote:

Originally Posted by GrendelKhan{TSU (Post 1696438)
awesome..

anyone know if works for vb 3.8?

yes

Bounce 12-31-2008 09:38 AM

Another 3 donations...

Quote:

Donate system has been used by gerry on 31-12-08, 02:57.

You should check this donation and update it's status on PayPal Donation listing page.
Same thing on donations page, how can I update it's status when its no there https://vborg.vbsupport.ru/external/2008/12/4.gif:D

Rene Kriest 12-31-2008 09:44 AM

Thank you for your fast fix. I appreciate your work. Happy new year!

Bounce 12-31-2008 10:46 AM

Fixed my issue....

Had to uninstall the previous version and reinstall.. seems like overwrite did not work...

Anyhow back in business,thanks :up:


All times are GMT. The time now is 03:15 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.02160 seconds
  • Memory Usage 1,795KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_php_printable
  • (10)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete