vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Modification Graveyard (https://vborg.vbsupport.ru/forumdisplay.php?f=224)
-   -   Integration with vBulletin - Flashchat Integration for vB 3.6 (https://vborg.vbsupport.ru/showthread.php?t=120926)

TranceCan 09-03-2006 06:24 PM

What is the proper procedure for upgrading from 3.03 to 3.04?

Smitty 09-03-2006 07:49 PM

Quote:

Originally Posted by PamelaE
Ok apologies. Im only going by the discussion on Tufat where they claim not to know whats causing the hole and looking for access logs to fix it.

They've acknowledged it and the cause is known as a specific file that 99.9% of the users don't need and can delete.

Paul M 09-03-2006 08:05 PM

Quote:

Originally Posted by TranceCan
What is the proper procedure for upgrading from 3.03 to 3.04?

Import the product and replace the CMS file.

tobybird 09-03-2006 08:24 PM

A breeze to install. Thanks so much!

jw00dy 09-03-2006 11:18 PM

For those that haven't checked, they have released 4.6.2 to fix the problem.

Their are some changes he made to the vbulletin360.php file to note at the very top.

Is their anything we should do with the one we obtained from here? Or should we just use his?

Paul M 09-04-2006 12:38 AM

Technically you don't need to do anything, he mass updated the CMS files even though only one was affected, I have however added the little snippet of code to all the vb CMS file releases so that it will be included in any future updates (hence why this was updated to 3.04 today).

MaLTRaiN 09-04-2006 12:51 AM

You all should read this:

http://www.vbulletin.com/forum/showthread.php?t=198902

Very serious problem with flashchat...

Mark.B 09-04-2006 02:11 AM

Quote:

Originally Posted by MaLTRaiN
You all should read this:

http://www.vbulletin.com/forum/showthread.php?t=198902

Very serious problem with flashchat...

Yes, that's what the last few posts are talking about.

An updated version of Flashchat has been released which cures this.

trilOByte 09-04-2006 11:25 AM

Quote:

Originally Posted by Paul M
Excuse me ? - you might want to word that a little better - There are no holes in this modification, the recent hole in Flashchat itself is due to a CMS file for another system, and the offending file can simply be deleted.

Sorry, but that's a bit like saying "the operation was a complete success, unfortunately the patient died".

I get regular script updates from tufat, I just checked my emails and the last was on 20 August. I have read that there was a securityfocus exploit was published for this on June 16. I had no notification of this issue. I know that it's "not the fault of this mod" directly, but if I hadnt of had it installed, I wouldnt of spent 4 hours last night going through my site trying to repair the damage done by somne little idiot who exploited this.

I think I'll wait a good while before re-installing flashchat.

soletrader 09-04-2006 12:28 PM

I installed flash chat, edited the php files and uploaded the product. But I get no changes. Is there an option in the admincp?

Or is this automatic? What am I missing here?

Paul M 09-04-2006 01:49 PM

Quote:

Originally Posted by trilOByte
Sorry, but that's a bit like saying "the operation was a complete success, unfortunately the patient died".

Um .... :confused:

Quote:

Originally Posted by trilOByte
I have read that there was a securityfocus exploit was published for this on June 16. I had no notification of this issue.

The supposed exploit posted on June 16th refers to a file that doesn't exist in the Tufat version of Flashchat, afaik, it actually belonged to another chat product, also called flashchat (it's not a unique name). :cool:

Quote:

Originally Posted by trilOByte
I know that it's "not the fault of this mod" directly, but if I hadnt of had it installed, I wouldnt of spent 4 hours last night going through my site trying to repair the damage done by somne little idiot who exploited this.

It's not the fault of this mod at all, please get that fact very clear. It was the fault of Flashchat itself, installing this made no difference. I'm sorry you spent 4 hours cleaning up your damage, but I don't really appreciate you trying to take out your frustration on me, or my integration mod(s). :alien:

Quote:

Originally Posted by trilOByte
I think I'll wait a good while before re-installing flashchat.

That's your choice, and makes no difference to me :)

I do wonder if you will uninstall vbulletin next time a security hole is found in it ;)

trilOByte 09-04-2006 06:56 PM

Quote:

Originally Posted by Paul M

It's not the fault of this mod at all, please get that fact very clear. It was the fault of Flashchat itself, installing this made no difference. I'm sorry you spent 4 hours cleaning up your damage, but I don't really appreciate you trying to take out your frustration on me, or my integration mod(s). :alien:

I'm not looking for someone to blame.

..and yes, if vBulletin was so insecure that something like this happened, i would indeed review my choice of forum software. That has never happened though, partly due to the extremely vigilant and speedy security alerts which drop into my mailbox from time to time.

BTW, just FYI - the hackers came again tonight, it would seem that they have left something on the server, some shell script or something, which still gives them access even after flashchat has been completely removed. My host is trying to figure out what/where.

Smitty 09-04-2006 07:17 PM

Quote:

Originally Posted by trilOByte
this mod was used as the way in.

It was NOT the integration mod. It was a Flashchat CMS for aedating which, if you understood what a CMS is, was not necessary for vBulletin integration. Had you understood the Flashchat install, and how Flashchat worked, you would not have left the CMSs for all the other programs there to begin with. If you read the install notes with Flashchat (and here I think), it was specific that only the vBulleting CMS was needed. I deleted the other CMSes after the install as 'foreign' files not needed for Flashchat to run and, of course, I didn't get hacked.

If you don't understand what files you're installing, you should get someone who does to install the program you want installed for you.

trilOByte 09-04-2006 09:36 PM

Quote:

Originally Posted by Smitty
It was NOT the integration mod. It was a Flashchat CMS for aedating which, if you understood what a CMS is, was not necessary for vBulletin integration. Had you understood the Flashchat install, and how Flashchat worked, you would not have left the CMSs for all the other programs there to begin with. If you read the install notes with Flashchat (and here I think), it was specific that only the vBulleting CMS was needed. I deleted the other CMSes after the install as 'foreign' files not needed for Flashchat to run and, of course, I didn't get hacked.

If you don't understand what files you're installing, you should get someone who does to install the program you want installed for you.

Oh, yeah sorry, that's right it's my fault. Silly me. :rolleyes:

Paul M 09-05-2006 01:59 AM

@trilOByte, I have edited the inaccuracy from your previous post, despite it being made clear that this mod in no way contributed, your post inferred it was.

@everyone, I'm not prepared to allow this to flare up into a series of personal arguments, everyone please move on, any further off topic/argumentative posts are liable to be removed. Thanks.

trilOByte 09-05-2006 09:23 AM

Quote:

Originally Posted by Paul M
@trilOByte, I have edited the inaccuracy from your previous post, despite it being made clear that this mod in no way contributed, your post inferred it was..

Paul, I think you misunderstand me. Your mod has been excellent for my site, it has worked well and I can see no flaws in it. I do totally understand that your mod and tufats script are two different things.

That's not my point.

From my point of view, they come as a package. Like many others, I installed tufats script because of your excellent mod but your mod does need tufat's script to work. I'm not blaming anyone and I'm not looking for someone to moan at. But the fact remains that the package on offer here (your totally blameless mod + tufats flawed script), had or has a stinking great security hole in it.

Now I'm not sure if simply removing one file from the CMS's is going to plug the hole - I hope it does. But having spent the last 2 days running round chasing hackers off my server, I'm not inclined to place too much faith in that.

I hope the newer package from tufat is secure. If it proves to be in time, I will probably put you excellent mod back on my site, but for now, it (tufats script) consitutes too much of a risk. There are mixed messages on the forums. I've read in one thread that the kiddies were logged running a search for other files in the tufat installation. I dont know why, or if they are vulnerable, but the possibility that they might be, seems to exist.

trilOByte 09-05-2006 09:32 AM

Let me put it another way.

Can you guarantee that tufat's script is now secure?

If not, is it prudent to endorse it's use?

Smitty 09-05-2006 09:59 AM

Quote:

Originally Posted by trilOByte
if simply removing one file from the CMS's is going to plug the hole

There are a couple of aedating files to remove to be sure, not just one file:

aedating4CMS.php
aedatingCMS2.php
aedatingCMS.php

And you may as well remove all the other cms files (they are unnecesary) except the vBulletin cms for your vBulletin version.

The hole was plugged in 4.6.2.

trilOByte 09-05-2006 10:45 AM

Quote:

Originally Posted by Smitty
There are a couple of aedating files to remove to be sure, not just one file:

aedating4CMS.php
aedatingCMS2.php
aedatingCMS.php

And you may as well remove all the other cms files (they are unnecesary) except the vBulletin cms for your vBulletin version.

The hole was plugged in 4.6.2.

Look here...

http://www.zone-h.org/component/opti...berLord/page,2

Smitty 09-05-2006 10:59 AM

And here: http://forum.tufat.com/showthread.php?t=24428

MThornback 09-05-2006 01:31 PM

Paul,

Can you think of a reason why flashchat wouldn't let me log in to any area (admin or chat) itself after I log out and try to log back in? I logged out yesterday, and now all I get is a white screen on the flashchat on misc.php and trying to use the flashchat file in the /chat/ folder.

Paul M 09-05-2006 02:40 PM

Quote:

Originally Posted by trilOByte
Can you guarantee that tufat's script is now secure?

Of course I can't, anymore than I could guarantee any product is secure (inc vbulletin).

Quote:

Originally Posted by trilOByte
If not, is it prudent to endorse it's use?

See above. providing this (or any) mod is not endosing anything, just providing extra for those who chose to use something.

Paul M 09-05-2006 02:42 PM

Quote:

Originally Posted by MThornback
Paul,

Can you think of a reason why flashchat wouldn't let me log in to any area (admin or chat) itself after I log out and try to log back in? I logged out yesterday, and now all I get is a white screen on the flashchat on misc.php and trying to use the flashchat file in the /chat/ folder.

That usually means an error is occuring. By default flashchat supresses the displaying of php error messages (not very helpful, I disable that).

soletrader 09-05-2006 09:03 PM

No matter what I do I can not get flashchat to run inside my vbulletin. Can anyone please help? Thank you

Paul M 09-05-2006 09:59 PM

Quote:

Originally Posted by soletrader
No matter what I do I can not get flashchat to run inside my vbulletin. Can anyone please help? Thank you

From the main post ;
Quote:

Support: Please check any file edits carefully, and make sure you have uploaded any edited files to the correct location - the vast majority of problems reported are due to an error made in editing or uploading a file. If you are still stuck and want me to take a look then feel free to PM me your site address, an admin user, and ftp access details, without these I cannot help you. I will look when I have time.

Zombie-F 09-06-2006 12:17 AM

I've managed to change the "Flashchat on a vb page" link back to the "old" flashchat link in the Who's Chatting box, but I can't seem to find where to make the change to change it in the "Quick Links" in the navbar. My users don't seem to like it displayed in the vBulletin window, so I'd just like to eliminate all links to that. Where can I find where to change this link? I've searched my templates and my phrases to no avail.

Thank you for the great hack.

Paul M 09-06-2006 12:26 AM

It's code within the plugins (1 & 3).

popowich 09-06-2006 03:25 PM

Quote:

v3.04 : Security (anti-hacking) code added (as supplied by Darren).
Hello,

Was an e-mail sent to all members who clicked "installed" when this version was released?

Is that even possible for a project owner to do?

I am not bashing anyone involved with this specific project,
but I am becoming increasingly annoyed with the lack of notifications for product updates generally speaking at vbulletin.org.

I'm an open source person. I'm fine with the way free software and systems work.

Proper notifications as new versions and/or patches are made available, especially security releases, would be great.

-Raymond

Paul M 09-06-2006 07:13 PM

Notifications are only sent by me if it's necessary to upgrade, in this case it isn't.

popowich 09-06-2006 07:16 PM

Quote:

Originally Posted by Paul M
Notifications are only sent by me if it's necessary to upgrade, in this case it isn't.

OK, understood, thank you for the reply.

-Raymond

andreamarucci 09-07-2006 12:52 PM

Where can I see a demo of the FC VB integration?

MThornback 09-07-2006 12:55 PM

Quote:

Originally Posted by Paul M
That usually means an error is occuring. By default flashchat supresses the displaying of php error messages (not very helpful, I disable that).


Save me some time and tell me which file to look in? :cross-eyed:

Paul M 09-07-2006 06:11 PM

The top of common.php

Metal-R-US 09-08-2006 10:26 AM

I find the the url showing up in WOL rather ugly looking so I edited the online_location_unknown hook to make it just say FlashChat. Perhaps an idea for a next update?

adwade 09-09-2006 04:10 AM

Quote:

Originally Posted by Smitty

In the thread referenced above, it mentions this file located in: /public_html/chat/getxml.php being a security risk. They go on to say "This is the 2nd file found from FlashChat to contain vulnerabilities.".

Yet I've not seen any discussion of it here, like the (un-needed) files in the CMS directory I just got rid of. So it is needed for Flashchat functionality, or can it be removed?

adwade 09-09-2006 04:43 AM

Quote:

Originally Posted by Paul M
at http://forum.tufat.com/showthread.php?t=24428&page=10

Another point to note, the hole in the aedating scripts could only be exploited if you had register_globals set to "on" in PHP - this is a security problem in itself, and anyone who can should turn that option off in their php.ini

For those of us not in the know about such things, where is the php.ini file you referred to?

Paul M 09-09-2006 05:06 AM

Quote:

Originally Posted by adwade
In the thread referenced above, it mentions this file located in: /public_html/chat/getxml.php being a security risk. They go on to say "This is the 2nd file found from FlashChat to contain vulnerabilities.".

Yet I've not seen any discussion of it here, like the (un-needed) files in the CMS directory I just got rid of. So it is needed for Flashchat functionality, or can it be removed?

There are no known vulnerabilities in getxml.php, if you delete it, Flashchat will cease to function.

Paul M 09-09-2006 05:09 AM

Quote:

Originally Posted by adwade
For those of us not in the know about such things, where is the php.ini file you referred to?

It's a system file, if you don't know where/what it is then you're probably best leaving it alone and getting help from someone who does, otherwise you may break your php.

BETIServices 09-09-2006 05:11 AM

is been 3 days that my forum was hacked and now I started from scratch after 3 weeks of setting up the site, I will advise to get the flash chat a boot out as my self will not use it again. I had to paid a security company to secure the servers and network and a backup system on the way...

what a wayto learn ...

Paul M 09-09-2006 07:52 AM

Sorry but this is not the place to comment on Flashchat, they have their own forums for that.


All times are GMT. The time now is 01:34 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.02508 seconds
  • Memory Usage 1,850KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (26)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (1)pagenav_pagelinkrel
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete