![]() |
GREAT NEWS!
http://www.vbulletin.com/forum/forum...57#post4015757 The vBulletin.com user alexm has managed to re-compile the uploader.swf file with this exploit (and another) fixed! He has uploaded a new .zip file with a new uploader.swf file to the post I linked to above. This file is a direct replacement for uploader.swf and you can upload it over your current uploader.swf file and go back to the flash uploader! Warning: alexm admits he is not a flash developer and there is no guarantee additional exploits don't exist- but it looks good to me. |
For those of us that are lazy.. Here's the jist of it.
http://www.vbulletin.com/forum/forum...57#post4015757 Quote:
Code:
uploader.swf?allowedDomain=\%22}%29%29%29}catch%28e%29{alert%28document.domain%29;}// Quote:
|
That's the problem: How many Flash exploits have there been over the past year alone? I applaud Alex for his efforts but he found another security vulnerability a day after he released his version. For some time, it appeared that Adobe was releasing a new version of Flash every month or so.
I think most people are going to be better off with a non-Flash solution. From alexm at http://www.vbulletin.com/forum/forum...81#post4015881 Quote:
|
Thanks Joe.
|
Alexm released it here on vBulletin.org as a mod now: https://vborg.vbsupport.ru/showthread.php?t=307008
Please be sure you nominate it MOTM if you like it, I did. :up: |
Have been having issues with 4.2.2 PL1 and the patched SWF so I found this and gave it a go.
THANK YOU!!!! Flash just needs to be declared DEAD so we can all move on from it.* |
Brilliant fix, I've been using it for many months now. We run an American and Classic car club, and we have many photos of events we have attended, could be up to 1000 photos to upload.
A few years ago, I remember just setting up there 1000 to upload and leaving it. However after about 50 the gap between uploads gets greater. Therefore slowing to almost a halt at 100. I dont think it is the change of this fix, but something else that has crept in. Has anyone else noticed this? I wonder if that is fixable. I've never tried SWF coding, my area is AVR assembler, ASP, VB or C++. |
Quote:
|
Quote:
I will carry on running tests, just wondered if anyone else noticed this. |
Just to make sure, this solution is not based on flash? It is working like a charm, thank you so much!
|
All times are GMT. The time now is 11:38 PM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|