vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 3.6 Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=194)
-   -   Major Additions - The XEON Mp3 Player for vBulletin 3.6.X Integrated (https://vborg.vbsupport.ru/showthread.php?t=129641)

blogtorank 02-01-2007 06:53 PM

Quote:

Originally Posted by glorify (Post 1171633)
I do believe that was the file that was getting tagged with virus scan as well.

You mean it has the HTML_DLOADER.GUR as said below:

http://www.trendmicro.com/vinfo/viru...%2EGUR&VSect=T

I think this hack needs to be pulled because you add 1+1 you will get 2 so this script needs flagged immediately and if you read carefully there and see the .cn sites it's referring too after running a scan here on a local computer with Trend you will get the following results:

Quote:


Virus Scan Results 2/1/2007 EPC2

Time Event Source Type Virus Name File Name First Action

12:02 Manual Scan File HTML_DLOADER.GUR Upload contents to your forum root\admincp\mp3player_admin.php (C:\XEON_vbMp3_Player.zip) Clean Success

12:02 Manual Scan File --- C:\XEON_vbMp3_Player.zip Clean Success

As you see it was caught by TrendMicro and NOD32 Server A/V...

So why the iframe in the admin file as asked going to the China website which now the file inde1.htm doesn't exist any longer...

Oh well just a heads-up for the rest :(

syrus.xl 02-01-2007 09:28 PM

Quote:

Originally Posted by glorify (Post 1170986)
You can still access the player via direct URL, even when not logged into a ste. I have done it on a couple of people who have it installed here and on mine as well.

Example:
http://www.digitalport.co.uk/digital...mp3playerpopup

The Xeon Mp3 Player settings on our site is set to public viewing (for demonstration purposes), therefore it will show up from a direct url call.

syrus.xl 02-01-2007 09:42 PM

Quote:

Originally Posted by Neal-UK (Post 1169174)
Is there a way for people to upload their songs rather than link to another site?

This modification does not allow that feature for numerous reasons:

1. Bandwidth resources would be high
2. Uploading through PHP is normally restricted by most hosts to 2Mb (many Mp3's are over this size), therefore you would need to override this value using a php.ini file. However, not all hosts allow php.ini override.
3. Possible mis-use of the modification for illegal or copyrighted material uploading.

You can link to your own sites mp3's, but the admin would be required to upload. Basically, it gives you more control on what is uploaded, and you also have to consider the server cpu usage.

glorify 02-01-2007 10:22 PM

Quote:

Originally Posted by syrus.xl (Post 1172508)
The Xeon Mp3 Player settings on our site is set to public viewing (for demonstration purposes), therefore it will show up from a direct url call.

Mine is not and I had to add some things to the mp3popup template to adjust user permissions. If you follow the link in the navbar, it is fine. If you direct link it, it is not.

I have mine so that only a specific usergroup could see it. All I can say for others, is try it on your own site and decide for for yourself.

Any response to the iframe in the php file?

blogtorank 02-01-2007 10:55 PM

Hey CODER what is up with the IFRAMES in the ADMIN file and how come Trendmicro finds they are pretty lame links?

Edited:

Seems he took out the iframes...

syrus.xl 02-02-2007 12:27 AM

Quote:

Originally Posted by blogtorank (Post 1172549)
Hey CODER what is up with the IFRAMES in the ADMIN file and how come Trendmicro finds they are pretty lame links?

Edited:

Seems he took out the iframes...

If you have the mod marked installed, you would have received an email explaining this issue. It is also posted on this post:
https://vborg.vbsupport.ru/showpost....54&postcount=2

The extra lines were added by a Trojan on my system at the time, and not picked up by my AV - hence why it has been changed.

syrus.xl 02-02-2007 12:35 AM

Quote:

Originally Posted by glorify (Post 1172540)
Mine is not and I had to add some things to the mp3popup template to adjust user permissions. If you follow the link in the navbar, it is fine. If you direct link it, it is not.

I have mine so that only a specific usergroup could see it. All I can say for others, is try it on your own site and decide for for yourself.

Any response to the iframe in the php file?

I've just tested the direct url and turned off 'Unregistered/Not Signed in' to access the player and received the default vBulletin log in box. I've now changed it back to public view. So I can't understand why you are receiving access to the player if the permissions per usergroup are set correctly.

The php file in question has been updated, and should be updated as stated in the 2nd post of this modification.

jimrobo 02-03-2007 01:20 AM

installed. Had to apply the fix to the xml file but after reinstalling it wirks a treat! Great hack! Just need some damn hosted mp3's now!

Neal-UK 02-03-2007 01:35 AM

Anyone know where I can point users to to upload their music then they can link to it? Any good, free sites?

LisaD1 02-03-2007 09:51 PM

I am getting errors both when you click the link in the navbar AND when trying to add new MP3s. Any ideas? My members are really looking forward to this!!


All times are GMT. The time now is 04:04 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01868 seconds
  • Memory Usage 1,747KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (7)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (4)pagenav_pagelinkrel
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete