vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   News and Announcements (https://vborg.vbsupport.ru/forumdisplay.php?f=2)
-   -   Important: It is all about trust (https://vborg.vbsupport.ru/showthread.php?t=115640)

Zachery 05-27-2006 09:21 AM

Quote:

Originally Posted by Shaliza
Well, those coders will probably keep putting it in, but now I bet loads of people are checking the codes inside out now.

No, they won't if they continue to do so they will be punished for their unjust actions like we have stated.

peterska2 05-27-2006 10:55 AM

Quote:

Originally Posted by Shaliza
Well, those coders will probably keep putting it in, but now I bet loads of people are checking the codes inside out now.

Quote:

Originally Posted by Zachery
No, they won't if they continue to do so they will be punished for their unjust actions like we have stated.

The codes of flagged modifications along with another random sample will also be checked again to ensure that the code has been removed and has not appeared anywhere else.

If has not been removed, then as Zachery said, action will be taken.

Tim Skellett 05-27-2006 11:17 AM

Quote:

Originally Posted by Danny.VBT
There seems to be some confusion at the extent of what has happened.
...........The issue here is that some coders implemented a way to automatically click "Install" on vb.org whenever a product/plug-in was uploaded. The reason why we've decided to let users know about this, is because most of the time this happens with out the Admin's consent.

The "backdoor" involved here was with www.vbulletin.org, not your forum. ........

Ah, many thanks for the clarification. I have been following this matter somewhat closely, and it's nice to have a full explanation.

Xenon 05-27-2006 01:27 PM

Quote:

Originally Posted by Shaliza
now I bet loads of people are checking the codes inside out now.


this is the best things they could do!
never install anything without at least read through the code shortly. On the one hand you learn coding by reading, on the other hand, you can find out bugs faster!

Razasharp 05-27-2006 03:19 PM

Any possible security breaches/backdoors should be made known to the users really - now you've got a bunch of people worried, A) that there are real risks in using vb.org and its hacks and B) there's no way to find out which hacks are actually being questioned.

This is another reason why I think Jelsoft needs to employ someone to overlook things here, because ultimately whatever goes on at vb.org affects Jelsoft directly.

Why doesn't Jelsoft employ a staff member or two to look over these issues? I reckon they could go through all the hacks once submitted and approve them if they looked ok along with having enough time to run and support this site.

Or why not build a team of coders willing to look over code and seeing whether a hack should be approved or not? No hacks going 'live' without approval, and any changes to uploaded files having to be approved too. Jelsoft could pay them for their time.

If vBulletin was open-source this may be understandable, but it's not - it has enough resources to employ staff in these missing areas.

Zachery 05-28-2006 12:34 AM

Quote:

Originally Posted by Razasharp
Any possible security breaches/backdoors should be made known to the users really - now you've got a bunch of people worried, A) that there are real risks in using vb.org and its hacks and B) there's no way to find out which hacks are actually being questioned.

This is another reason why I think Jelsoft needs to employ someone to overlook things here, because ultimately whatever goes on at vb.org affects Jelsoft directly.

Why doesn't Jelsoft employ a staff member or two to look over these issues? I reckon they could go through all the hacks once submitted and approve them if they looked ok along with having enough time to run and support this site.

Or why not build a team of coders willing to look over code and seeing whether a hack should be approved or not? No hacks going 'live' without approval, and any changes to uploaded files having to be approved too. Jelsoft could pay them for their time.

If vBulletin was open-source this may be understandable, but it's not - it has enough resources to employ staff in these missing areas.

It wouldn't matter if we had 1000 people to check every single line of code here released ever. And that was all their job would be, eventually something would slip though. It is up to each admin to verify anything that they are installing will do what they want it to. Even if it means learning some basic php. You should always review any code you did not write yourself.

kall 05-28-2006 12:40 AM

Quote:

Originally Posted by Zachery
You should always review any code you did not write yourself.

Indeed.

People are up in arms about installing Encrypted software on their servers, yet so many are prepared to just say 'COOL! All I have to do is import an .xml file??' and slap-happily whack totally unknown code into their vB.

Madness. :)

Razasharp 05-28-2006 12:41 AM

Zachery, not everyone is a coder and even with basic knowledge may still not be at a level to see whether a hack was secure or not. (I've read half a book on php, know html, the web industry, but am still am unsure about many code-related things for example).

One slip up from a staff member would be far more acceptable than loads from vb.org users.

:)

Quote:

Originally Posted by kall
Indeed.

People are up in arms about installing Encrypted software on their servers, yet so many are prepared to just say 'COOL! All I have to do is import an .xml file??' and slap-happily whack totally unknown code into their vB.

Madness. :)

People may feel that code posted here for vB may be getting checked either by staff or other coders - in fact I've seen on many occasions how another coder has given a tip to someone else in their hacks' thread to cut-out a query for example (it's one of the reasons that made vb.org great).

Encrypted software is totally different in that you can't see it even if you wanted to, and the general consensus is that people don't like to use it, wherever possible.

Zachery 05-28-2006 06:21 AM

vBulletin.org is a community about users helping users modify vBulletin.

Lea Verou 05-28-2006 06:37 AM

Is this about easter eggs in hacks?
I have never added any, but I always wanted to add one :p :p


All times are GMT. The time now is 03:57 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03072 seconds
  • Memory Usage 1,751KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (8)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (1)pagenav_pagelinkrel
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete