vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 3.5 Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=113)
-   -   Top 'X' Stats (https://vborg.vbsupport.ru/showthread.php?t=93065)

Delphiprogrammi 09-08-2006 01:23 PM

hi people,

I've changed this modification a bit and performed two tests on my own board.I tryed an XSS attack (failed) and i tryed a meta redirect(failed) looks like clean to me now

georgedd 09-08-2006 04:50 PM

Well Delphiprogrammi, the original fix would have stopped the two attacked in your screenshots already. What I'm curious is the reports that people are still getting hacked after applying the fix, yet no one has provided (via pm) an example of what the hacker used. Are the reports due to they not applying the fix correctly (not overwriting the buggy version somehow), or is there really still a hole?

Delphiprogrammi 09-08-2006 05:02 PM

Quote:

Originally Posted by georgedd
Well Delphiprogrammi, the original fix would have stopped the two attacked in your screenshots already. What I'm curious is the reports that people are still getting hacked after applying the fix, yet no one has provided (via pm) an example of what the hacker used. Are the reports due to they not applying the fix correctly (not overwriting the buggy version somehow), or is there really still a hole?

yeah that's what i like to know to besides the XSS and the meta refresh exploits no hole is known is this but still people complain about being hacked hmmmz

chadlyou812 09-09-2006 12:12 PM

How do you limit what columns show up on topXstats.php? I just want Latest Replies to show.

Thanks

chadlyou812 09-09-2006 12:13 PM

Does this hack open up holes in a site? Is it secure?

SuperFly 09-09-2006 01:15 PM

It is now.

chadlyou812 09-09-2006 03:07 PM

Thanks for letting me know the hack is secure.

One more thing...

How do you limit what columns show up on topXstats.php? I just want Latest Replies to show.

Thanks

Shazz 09-09-2006 04:45 PM

Quote:

Originally Posted by chadlyou812
Thanks for letting me know the hack is secure.

One more thing...

How do you limit what columns show up on topXstats.php? I just want Latest Replies to show.

Thanks

There is already a module for "Latest Replies"

Mr. Blur 09-09-2006 11:07 PM

i try to import the product, both allow overright and not allowing it, and get this every time:

XML Error: not well-formed (invalid token) at Line 1

yes i have the right version

geniuz14 09-10-2006 09:40 AM

if i wanted the top x stats table to appear under my shoutbox....instead of under the "whats going on box" how would i do so???plz reply :)

DementedMindz 09-10-2006 09:51 AM

Quote:

Originally Posted by Mr. Blur
i try to import the product, both allow overright and not allowing it, and get this every time:

XML Error: not well-formed (invalid token) at Line 1

yes i have the right version


so erase the old one and install the new one

chadlyou812 09-10-2006 01:47 PM

Quote:

Originally Posted by Shazz
There is already a module for "Latest Replies"

I know but, I just want the Latest Replies to appear and not Top Posters and Newest Members. Basically, how do I edit what columns appear?

Thanks!

Karabaja 09-10-2006 02:47 PM

Hello everyone.

Any idea on how to add forum names next to latest thread?

I tried searching this thread but didn't find anything, sorry if I missed something.

It would be very useful to me, most of the times thread title doesn't clearly indicate in which section thread was posted so people check threads which they are actually not interested in.

I've seen it done on one board so I guess it must be possible.

Delphiprogrammi 09-10-2006 03:16 PM

Quote:

Originally Posted by chadlyou812
I know but, I just want the Latest Replies to appear and not Top Posters and Newest Members. Basically, how do I edit what columns appear?

Thanks!

you cannot do that without "heavy" editing the source code

geniuz14 09-10-2006 06:04 PM

could anyone plz tell me how to move the whole box to be just under my shout box? anyone???

DementedMindz 09-10-2006 06:06 PM

move the could that you put in your forum template.

Karabaja 09-10-2006 06:33 PM

Quote:

Originally Posted by geniuz14
could anyone plz tell me how to move the whole box to be just under my shout box? anyone???


You just move

Code:

<if condition="$show['topXstats']">
$topXstats
</if>

anywhere you want it displayed in your forumhome template.

geniuz14 09-11-2006 12:42 PM

thats just it though..im useless with templates...could u possibly direct me to where exactly i should post it?

Karabaja 09-11-2006 01:59 PM

Well I don't have shoutbox installed so I am not sure whats the code for in forumhome template but you'll spot it easily it will mention shoutbox. Just go to style manager open forumhome tepmplates then a template called forumhome. Find that code for topxstats I wrote earlier and move it to the top of the template. You'll see on top something like:

$header
$navbar

somewhere under it should be a shoutbox code, and you can add topxstats under that shoutbox code if that's where you want to display it.

roe 09-15-2006 07:13 AM

Quote:

Originally Posted by chadlyou812
I know but, I just want the Latest Replies to appear and not Top Posters and Newest Members. Basically, how do I edit what columns appear?

Thanks!

i edited the xml file. i deleted the tables for the top posters and newest members and it seems to work just fine.

http://forum.realmofexcursion.com

Lance Carbuncle 09-15-2006 04:59 PM

My site has been hacked. I was runnng Top X, amongst other hacks. I have uninstalled it, but am not sure if this was how the site was hacked, or what to do to get it back. The index pages for my forum, and photopost, and photopost classifieds all show the hackers page, Unfortunately, I am not well versed at this stuff and could really use some help getting my site back... Could someone PM me or reply please? At least let me know if the hack on my site was from running Top X, or I have another problem....

If the site is visited from anywhere but the index page, everything works fine

http://www.forums.repashy.com/cmps_index.php

my site: http://www.forums.repashy.com/



Sincerely, Lance

UPDATE.... I re uploaded my index pages and everything SEEMS normal... Is this all I needed to do? .... Sorry I am such a moron, but I could use the piece of mind from someone to let me know if that's all I need to do.......

UPDATE 2 .... I have figured out that the index page of every subdomain has been hacked. these are outside vbulletin's folder.... might be unrelated to this hack vulnerability and just a coincedence.... anyone?

UPDATE 3... Well, after hours on my site I figured out it was unrelated to this hack and actuall a critical vulnerability in flashchat..... if you are running that script, make sure you check it out. No message was sent out by the author, even though it is a paid script and the support forum on the site is flooded with info on it.....

Lance

whitesoxzone 09-17-2006 03:19 AM

hi guys, my mod. seems to work fine. I did both step 1 and 3. but i didn't do step 2: 2) Upload topXstats.php to your forums directory. Is that okay? will it work fine without doing that. also, if I really have to do that, what exactly do I do? Thanks guys.

SuperFly 09-17-2006 03:12 PM

using ftp or uploading program, upload it to your main forum directory, with index.php in it. You need to for it to work.

RFViet 09-20-2006 04:33 PM

Quote:

Originally Posted by RFViet
it's showing weird characters like 7&###&98

Here is the problem with language
Anyone knows how to fix ???

Shazz 09-21-2006 12:36 AM

English PleasE?

RFViet 09-21-2006 12:44 AM

Quote:

Originally Posted by Shazz
English PleasE?

Did I write in other language ??

ngocha85 09-22-2006 04:06 AM

this hack is very bad with Unicode!

Apfelfrucht 09-24-2006 09:05 PM

Hello,

I've installed this hack successfully and i'd like ask 2 questions :
1. How to not display the "Administrators and Moderators" nicknames on "Top Posters" ?

2. Is it possible to have some "Top Posters only from the Week Beginning", i mean to display only the Top Poster Person who makes some messages from "Sunday to Monday" and not displaying the entire messages from the Registration of that Top Poster Person. Is it possible and how ?

Thanks in advance.

desiforums 10-04-2006 07:42 PM

can you tell me how can i put this on the top instead of bottom...
When i installed it, the state is at the bottom of the forum can you tell me how can i put it on the top of the forum. thanks...

bigmonay2k 10-04-2006 09:13 PM

this work with 3.6.1??

desiforums 10-04-2006 09:55 PM

ya worked for me

desiforums 10-04-2006 09:56 PM

but i want to know how can put it on the top of the forum its at the bottom anyone knows????

Shazz 10-04-2006 10:57 PM

Quote:

Originally Posted by desiforums
but i want to know how can put it on the top of the forum its at the bottom anyone knows????

In your "navbar" template
Add to the very bottom
PHP Code:

    <if condition="$show['topXstats']">
    
$topXstats
    
</if> 

-Hope it works :)

cbr929rrerion 10-07-2006 07:04 PM

this is STILL a security risk..

Forum was redirected again today...

Yes I have the newest version and it still is insecure..

DementedMindz 10-07-2006 07:07 PM

Quote:

Originally Posted by cbr929rrerion
this is STILL a security risk..

Forum was redirected again today...

Yes I have the newest version and it still is insecure..


report it and have the admins look at it.

murrtex 10-07-2006 08:14 PM

Quote:

Originally Posted by cbr929rrerion
this is STILL a security risk..

Forum was redirected again today...

Yes I have the newest version and it still is insecure..


delete and forget this hack..

and try this
https://vborg.vbsupport.ru/showthread.php?t=122986

be sure you will be glad ;)

Shazz 10-07-2006 08:26 PM

I can't figure out how the crap people redirect This?!!
Im removing it :(

Paul M 10-07-2006 09:32 PM

Quote:

Originally Posted by DementedMindz
report it and have the admins look at it.

I had a look at this tonight.

If this is installed from scratch then it cannot be exploited.

However, because of the the way the fix has been implemented - it is possible that it may still be exploitable if someone updated their older version to the new code, and they had customised the templates, but did not revert or re-edit those templates.

This is because the older versions used $getstats_thread[title], the fix uses $getstats_thread[titletrimmed] - but the old variable is still available, and if displayed by an old template, will still cause a redirect.

The best workaround to this is to make sure you revert any old topXstats templates. The author should fix this properly by making sure that the old variable $getstats_thread[title] is either removed, or also made 'harmless' by using htmlspecialchars().

DementedMindz 10-07-2006 10:20 PM

yeah I havent had a problem Paul since the fix but others are claiming they are so I told them to report it if so.

apdcanari 10-08-2006 03:17 PM

Hello,

Thread preview, it is possible (lasts threads) ?

Tks,

C?dric ;)


All times are GMT. The time now is 11:50 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01741 seconds
  • Memory Usage 1,825KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_code_printable
  • (1)bbcode_php_printable
  • (13)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete