vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vbBux / vbPlaza (https://vborg.vbsupport.ru/forumdisplay.php?f=171)
-   -   Who do I contact in regards to a bug/glitch issue for vbplaza? (https://vborg.vbsupport.ru/showthread.php?t=136730)

tester987654 02-06-2007 02:27 AM

Quote:

Originally Posted by mikeylikesitz (Post 1175595)
well as of now this hack is suggested to be disabled due to a XSS vulnerability

What is an XSS vulnerability? And does that mean it won't work at all even tho it's installed on my forum?

Sheesh... this is a bummer - I'm eager to get my forum "live" and yet here is another delay... ACK! lol

But BTW, did you ever have the jackpot issue I mentioned?

BrandiDup 02-06-2007 12:34 PM

Quote:

Originally Posted by tester987654 (Post 1175709)
What is an XSS vulnerability? And does that mean it won't work at all even tho it's installed on my forum?

Sheesh... this is a bummer - I'm eager to get my forum "live" and yet here is another delay... ACK! lol

But BTW, did you ever have the jackpot issue I mentioned?

It will still work if you keep it installed. However, the vulnerability can open your site up to being hacked. So, I would strongly recommend you uninstall.

subnet_rx 02-08-2007 01:55 PM

I'd either like to see the vuln so I can patch it myself, or see a patch released. My members are acting like they can't live without getting a few cents per post.

Mysticales 02-14-2007 10:32 AM

Well the author contacted me btw, I gave him the info I have. Also, yes I know about the XSS one too. If you wanna patch that real quick like, Goto the "Manage Items" and for "Donate" set it to "No" for Send PM to user.

Thats one of em. The most common used. I wont say what the user could do since I dont know if its allowed or not. But yea, that should set you back up.

Either way was a couple things I patched for and so far smooth sailing again. Will wait for the author to reply back again.

Oh I will say this, should someone need me, just send me a PM or so, Ill see what I can do. Only reason I dont post anything is cause I am not sure its my place to say it out in public or release a patch without the authors ok.

darkilla2 02-14-2007 07:35 PM

did u get ibpro and vbplaza to successfully give out and deduct points?

Mysticales 02-15-2007 03:10 AM

Hrm.. I mean seems to work for me, I mean arcade works fine, normal users can buy arcade passes and then pay per play while subscribed users get it for free. I mean if you wanna see the work I do, http://forums.qj.net

Acers 02-15-2007 04:30 AM

well the donate is not the only problem btw
you can reproduce the same bug with all things that send pm. (gift, ribbon etc, where the user is typing a message)
the simplest method to fix this is clean the input as i had written in the other thread.
The only problem being that only the author or the admins would know of any other vulnerabilities apart from this one, thats why we can't claim that it is a fix.

Mysticales 02-15-2007 05:03 AM

The main issue basically is that it doesnt have certain text input checking... which I added on mine to avoid it. Yes the author has to be the one to look at it, however if not, we may just release the patch.

Basically I think the biggest thing is to not allow it to use any form of scripts or ascii that isnt standard.. that would solve alot right there.

Acers 02-15-2007 11:14 AM

thats what i said.. instead of strip tags just make that htmlentity and it will protect you from xss exploit. You have to do that at 5-6 places. (HERE)
the only issue being if someone can confirm thats the only issue .. lol

AuroraStorm 02-17-2007 11:48 PM

If that's the fix to it, can somebody post the zip? I have to reinstall it but I can't find it anywhere...


All times are GMT. The time now is 12:57 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01042 seconds
  • Memory Usage 1,739KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete