vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 2.x Full Releases (https://vborg.vbsupport.ru/forumdisplay.php?f=4)
-   -   Improved Thread Preview Hack (https://vborg.vbsupport.ru/showthread.php?t=35645)

Massiel 08-01-2002 10:43 PM

Has this been finalized? Is there one file that has all the fixes in it?

Schorsch 08-09-2002 04:05 AM

Quote:

Originally posted by Massiel
Has this been finalized? Is there one file that has all the fixes in it?
good question!! would like to know this too!

Schorsch

2 X Viverridae 08-14-2002 10:42 AM

Installed the thread preview, and search preview - works slick!

Thanks a lot for a great hack!

EnriqueHavoc 08-21-2002 11:37 PM

could someone please explain how to "run" the tpinstall.php?

2 X Viverridae 08-22-2002 12:08 AM

Sure - upload it to your forum, and then open it with your browser, using the address your_forum_address/tpinstall.php

Hope this helps.

EnriqueHavoc 08-22-2002 02:12 AM

thanks very much!

installed and works awesome

~rc~ 09-10-2002 03:27 PM

Hello folks, I'm Overgrow's partner and a security concern was pointed out to me about this hack. Overgrow has been using the version of this hack since he last posted here so I haven't checked to see if his version is the exact same as what you are using now but if you follow the instructions below, it may help you discover if you have security breach in your private forums. Here are the details that were sent to me to help you test it;

---------------------------------------------------------------------------
first of all this is what I came up with since 8:00 tonight or so.
I found ONE way to read the Mods forums. It has in part to do with an "upgrade" by Overgrow made not too long before he left, the Post preview option.

So go to my overgrow, update profile, then options.


View thread previews?
If you select yes, you will get a short preview of the thread when you mouseover the title. yes no



This is part of the problem.
Now while your looking at a thread in the forum listing, drag your mouse over the thread title, a pop-up screen should appear with a snippet of the content of the thread.
At this point I'll consider this part of it is understood.

Now to the next piece.

Go to the top of the page, click forums,
scroll down to the list of current users online.

Click the hyperlink on Currently Active Users.

This brings you to a monitoring page...
I can see what everyone is doing.
I can monitor the movement of the MODS and ADMINS.
This will make sense in a few mins.

Next Subject.
URL Manipulation can let people view all the searches that
people have done.

Here's a link for you to follow of one such search made
by someone with MOD or ADMIN access.

http://www.overgrow.com/edge/search...searchid=502803

With that link I can see what MODS are posting. Give it a shot. Log in as some normal user account and go for it.

Now using this I can gain info about what is being said.
All they have to do is change the number on the end and
they see a different search. Eventually they will stumble across a doozie with lots of sensitive things in the search results.

Here's where the Currently Active page ties into it all, you can
save time by monitoring Mods or Admins activity I can estimate where their searches will be by performing my own search and checking out the #'s and searching that area.

------------------------------------------------------------------------------
Credit goes to The White Rabbit for finding this. The results here may be different for most as I said before, the hack here may have been altered by Overgrow and the results may not be the same for everyone. Anyway, better to check and be sure before you continue to use this hack.

Also, to the Mods/Admins here. This post may used by others as information to gain access to private information on other boards so feel free to modify this post if you feel it may pose a security threat. I for one have done away with this hack and since doing so Overgrow has shown quite an increase in speed. Not sure if this could have been a cause but I am keeping watch. Thanks.

cobradude 09-11-2002 09:02 PM

Works well on 2.2.7. Thanks.

cobradude 09-12-2002 01:01 AM

By the way, I did find one typo in the search.php stuff....

Quote:

11) Find:

################################################## ##########
<a href="showthread.php?s=$session[sessionhash]&threadid=$searchresult[threadid]$highlightwords">$searchresult[threadtitle]</a>
################################################## ##########

12) Replace with:

################################################## ##########
<a href="showthread.php?s=$session[sessionhash]&threadid=$searchresult[threadid]$highlightwords" title="fppreview">$searchresult[threadtitle]</a>
################################################## ##########

13) Save template.
title="fppreview" should be title="$fppreview"

Learner29 09-19-2002 09:36 AM

this hack is one of the VERY VERY best ones.

I just love it !!!!!

it is so straightforward, so easy to install, and it just works !!!!!

Thank you a milliono nicksaunders !!!!!


All times are GMT. The time now is 03:00 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01389 seconds
  • Memory Usage 1,742KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (1)pagenav_pagelinkrel
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete