vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   News and Announcements (https://vborg.vbsupport.ru/forumdisplay.php?f=2)
-   -   vBulletin 3.0.7 released (https://vborg.vbsupport.ru/showthread.php?t=76645)

sim tech 02-20-2005 06:19 PM

Is there going to be a discussion area on which mods will have to be redone if I chose the "upgrade" option over the single file patch? My license with Vbulletin is only a month old, so I can do the full upgrade if I want.

But I have installed - "for members who posted today" hack,
Installed pm.php AND users.php hack - for PMs
Also installed V3Arcade
vbookie installed
ucash and ustore installed

Crud - will I have to redo all of these?? Would it be worth it to upgrade from 3.0.6 to 3.0.7 or is just the patch good enough?

Erwin 02-20-2005 08:03 PM

With only 4-5 hacks, best to upgrade to 3.0.7 which fixes some bugs (albeit minor ones) and reapply the hacks. You will have to do all of them.

Paul M 02-20-2005 08:55 PM

Remember it's only the file edits you need to re-do, not complete hack re-installs.

oldfan 02-20-2005 09:49 PM

I got 27 mods/addons/hacks installed.. :(
I think I may pass this upgrade u..

Lizard King 02-21-2005 01:20 AM

Quote:

Originally Posted by oldfan
I got 27 mods/addons/hacks installed.. :(
I think I may pass this upgrade u..

Why dont you use araxis merge or something like that. You can check this thread and upgrade your forum within 30 minutes.

hendri 02-21-2005 04:56 AM

Quote:

Originally Posted by Lizard King
Why dont you use araxis merge or something like that. You can check this thread and upgrade your forum within 30 minutes.

i have upgraded to 3.07 everything seems fine

Blootix 02-23-2005 05:56 AM

Quote:

Originally Posted by Erwin
With only 4-5 hacks, best to upgrade to 3.0.7 which fixes some bugs (albeit minor ones) and reapply the hacks. You will have to do all of them.

*Sigh* yeah. I had to... Even though I only had about 4 hacks. The AWS hack is extremely loooooong though, so that counts as 2! ;)

Delphiprogrammi 02-23-2005 08:02 PM

1 Attachment(s)
hi,

this is pretty obvious goto your admincp => vbulletin settings => general settings

"add template name in html comments" => no that's all there is to it

for a list of bugs fixed in 3.07 you can go here

offcource if you want the fixes you need the full upgrade ....

SaN-DeeP 02-25-2005 05:10 AM

Upgraded to 3.0.7 quite easily :).

Revan 02-25-2005 10:48 PM

I now know why the "Add Template Name In HTML Comments" are a serious (!) security vulnerability.
With an unpatched board with this feature enabled, a cracker can inject malicious PHP code (yes, ANY PHP code) by the use of a malformed URL.
Of course, I'm not about to state HOW this is done, but let me just say that if *I* could find it (and I wasn't even LOOKING for this info!), then a cracker with a grudge will surely find it.

I hope this helps to make users patch themselves, if some are still in doubt of the severity of this exploit :)


All times are GMT. The time now is 02:41 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.02177 seconds
  • Memory Usage 1,727KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete