vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 3.8 Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=235)
-   -   vBFirewall v1.0 (https://vborg.vbsupport.ru/showthread.php?t=196791)

MrEyes 11-22-2008 08:32 PM

Quote:

Originally Posted by 7lanet (Post 1670436)
i try used this with Version 3.7
but hake vbAnonymizer

And also used vbAnonymizer
But at the entry of any link

Quote:

Originally Posted by Fungsten (Post 1670694)
Same here.

If you have applied the fix I mentioned earlier you can fix this by using the following exclusions:

Code:

$securityexclusions = array(
        'do=viewsubscription',
        '=http'
);

However this mean that you have switched off one of the actual checks and people will be able to pass urls as querystrings. This being said there are alot of mods out there that use this sort of thing and not many hacks that can abuse it. Your call.

There are better solutions, but this would need the entire mod to be reworked. For example the ability to set an exclusion at a page level. So you could exclude viewsubscription for misc.php but not payments.php, and http for redirector.php (vbAnonymizer mod)

Quote:

Originally Posted by dtv100 (Post 1670246)
another error i get is when send activation codes:

ried to send a member the activation codes got this

This could probably also be fixed by exclusions

dtv100 11-23-2008 12:03 AM

Quote:

Originally Posted by MrEyes (Post 1670808)
If you have applied the fix I mentioned earlier you can fix this by using the following exclusions:

Code:

$securityexclusions = array(
        'do=viewsubscription',
        '=http'
);

However this mean that you have switched off one of the actual checks and people will be able to pass urls as querystrings. This being said there are alot of mods out there that use this sort of thing and not many hacks that can abuse it. Your call.

There are better solutions, but this would need the entire mod to be reworked.

any way to make it that user group 6 is ignore by firewall ?

MrEyes 11-23-2008 10:21 AM

Quote:

Originally Posted by dtv100 (Post 1670904)
any way to make it that user group 6 is ignore by firewall ?

Yes, but I think I have gone to far already with the mod hacks and I don't want to be accused of show stealing, so I will leave that as a suggestion for the mod author.

However if the author doesn't want to or isn't able to make these changes I am more than happy to take this mod on, it is a great idea and it would be a real shame to see it die.

invisiblea 11-23-2008 02:48 PM

I am working on the new version, Just give me a day or 2 more
I will update you guys once I am done with the new version :)

invisiblea 11-24-2008 10:24 AM

Excluding =http will make this mod useless :P

Quote:

Originally Posted by MrEyes (Post 1670808)
If you have applied the fix I mentioned earlier you can fix this by using the following exclusions:

Code:

$securityexclusions = array(
        'do=viewsubscription',
        '=http'
);

However this mean that you have switched off one of the actual checks and people will be able to pass urls as querystrings. This being said there are alot of mods out there that use this sort of thing and not many hacks that can abuse it. Your call.

There are better solutions, but this would need the entire mod to be reworked. For example the ability to set an exclusion at a page level. So you could exclude viewsubscription for misc.php but not payments.php, and http for redirector.php (vbAnonymizer mod)



This could probably also be fixed by exclusions


7lanet 11-24-2008 02:16 PM

how uesd this
Quote:

$securityexclusions = array(
'do=viewsubscription',
'=http'
);

DangerousDale 11-24-2008 04:39 PM

Hi thanks for this hack, love it.

I have found one issue where I try to create a new page in vba cmps the "[PHP File Page]" process gets blocked and I am unable to create a php page. Just had to turn it off to get through ;)

pein87 11-24-2008 07:05 PM

Question I have thisinstalled on my test server at home and I wasnt able to change the cookie settinsg to my forum it shows access denied you`ve been logged! and whne I check the txt file it shows a log of me trying to access the cookies part of vbotions.

FiMeTi 11-24-2008 07:08 PM

nominated! Waiting for next (stabil) version and a paypal link 4 donation. :)
thx!

rob01 11-24-2008 11:57 PM

is a nice mod, but i will wait for new updates.. since i get erros when i use vbanonymiser and "Search in Templates"


All times are GMT. The time now is 11:33 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01350 seconds
  • Memory Usage 1,745KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_code_printable
  • (7)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (1)pagenav_pagelinkrel
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete