vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 3.6 Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=194)
-   -   Major Additions - vBCredits - Ultimate Points System (https://vborg.vbsupport.ru/showthread.php?t=151924)

Darkwaltz4 07-22-2007 08:34 PM

Yes, ALL input from every location is throughly cleaned before it is ever displayed or put into the database. Most of it uses the built-in cleaning capabilities of vbulletin (which is what they are there for, and many times a hack that was removed due to exploitations is because they failed to do this).

This protects it even from remotely created and executed mock pages designed to evade many frontend validations such as html attributes and javascript. #1 rule for security is never trust anything that you output, always validate it again on the side you have control over :) No variable is used unless my script was the one to define it in the same scope.

Kingzor 07-22-2007 09:06 PM

Quote:

Originally Posted by Darkwaltz4 (Post 1298534)
...and many times a hack that was removed due to exploitations is because they failed to do this)

Seems to be the reason that Icash has been removed, further investigation revealed that stock Icash contains a donate file which doesn't properly clean variables ;/

Chase 07-22-2007 09:11 PM

I'm no php coder but darkwaltz... you're makin a believer out of me. You really seem to know what your doing.

PixelFx 07-22-2007 11:22 PM

He's almost GOD Like ;)

TR?PST?R 07-23-2007 01:45 AM

Hmm what about integrating a hide-hack and having it where you can set how many credits they have to have or give to you for the hidden content to become unhidden?

Darkwaltz4 07-23-2007 02:20 AM

that is a feature for the shop addon, which i will be adding

im almost done guys :) this update is enormous and more than doubles the power of 1.2. im making everything perfect and seamless and bugtesting right now

also happy to report the plugins are being ported successfully, should hopefully be no file edits to make.

as of this post, you may all remove the file edits to all files EXCEPT functions_databuild.php. the rest are gone. will update in short time. promise! :)

Mum 07-23-2007 02:50 AM

Will ibparcade use be available soon?

jasculs 07-23-2007 04:19 AM

Patience is a virtue

|Jordan| 07-23-2007 04:21 AM

Oh man the waiting is killing me. I've never been this excited for a vb modification before.

Dark, did you get my pm?

Darkwaltz4 07-23-2007 04:26 AM

sorry this is taking a little long.

i have it down to 3 file edits left in functions_databuild.php. they are for undelete_thread, approve_thread, and delete_thread. as plugins they have to appear in like 7 different places... now you know why i initially used file edits :)

but all for the sake of quality. thanks for your patience everyone.

arcade addons are still not ready, focusing on 1.3 right now :)


All times are GMT. The time now is 07:41 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.02225 seconds
  • Memory Usage 1,734KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (4)pagenav_pagelinkrel
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete