vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 4.x Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=245)
-   -   Major Additions - ibProArcade - professional Arcade System (https://vborg.vbsupport.ru/showthread.php?t=101554)

Zahl 08-30-2011 05:05 PM

Anyone figured out yet what the change/fix is? I have modified my version of ibPA and would like to just apply the fix manually.... unless it includes a major remodeling of everything.

ForceHSS 08-30-2011 05:45 PM

just upload all the files and dont worry about where the fix is no one is going to tell you

ForceHSS 08-30-2011 05:46 PM

I would like to find a fix for my problem above I have this on my test forum but before I go live I need to know how to get it working

kh99 08-30-2011 05:49 PM

I have no more information than anyone else. I figured out what the issue was by looking at the release and comparing with the old files, but since the moderators and admins declined to post the info, I don't think I should either. But the files in the download zip file have dates on them and the mod was only quarantined a couple days ago, so there's nothing stopping someone from extracting the files into a directory and searching for the ones that were changed recently...

JacquiiDesigns 08-30-2011 05:50 PM

Quote:

Originally Posted by ForceHSS (Post 2240061)
just upload all the files and dont worry about where the fix is no one is going to tell you

easy to say when you haven't spent hours and hours and hours customizing your ibProArcade install! Anyway - hopefully someone will share the fix as I and others have asked:

Quote:

Thanks so much for the fix MrZeroPage.
I've a question please. The release history .txt says "one security-issue fixed"
Can you tell us how many and/or which files were changed to fix the security issue?
Perhaps instead of uploading/overwriting all files & reinstalling the product, we may be able to overwrite (patch) only the file that presented the security issue.

Thanks,

J.

Gemma 08-30-2011 06:09 PM

I took me about 3 minutes to compare all the files, probably as long...if not less time than as some of you have waited in this thread for answers. You call yourself admins...and some even claim to offer professional support - do yourself a favour and download a compare program (you'll need it to compare and make the edits to the files below if you would rather not just overwrite the files).

Between versions 2.7.0+ and 2.7.1+ the following files have changed (code changes as opposed to just something like 2.7.0+ becoming 2.7.1+ in the file)

arcade.php
admincp/arcade.php
functions/functions.php
modules/mod_favorites.php
modules/mod_league.php
modules/mod_report.php
modules/mod_settings.php
skins/skin_arcade.php
skins/skin_v3arcade.php

And the product file (obviously).

Some changes are only 1 line

That took about 3 minutes to find out and I even sent a text message inbetween comparing.

Go figure :rolleyes:

Thanks for the speedy update MrZeropage.

PossumX 08-30-2011 06:13 PM

Quote:

Originally Posted by Erica1977 (Post 2239982)
ok i will not upgrade since there's no support here will stay 2.7.0+

The coder makes it very clear, IF YOU READ THE TOP OF ALL THREAD PAGES (enjoy the vulnerability, as now that it is brought to light, it was not real hard to find it, and exploitation is now much more likely on lower versions):

** ...And remember that Support is given in the ibProArcade-Support-Forum **

Click here
to jump to the
ibProArcade-Support-Forum
in the Premium-Modification-Section

HMBeaty 08-30-2011 06:14 PM

Quote:

Originally Posted by PossumX (Post 2240076)
The coder makes it very clear, IF YOU READ THE TOP OF ALL THREAD PAGES:

** ...And remember that Support is given in the ibProArcade-Support-Forum **

Who reads anymore? :confused:

TheLastSuperman 08-30-2011 06:28 PM

Quote:

Originally Posted by JacquiiCooke (Post 2240018)
Thanks so much for the fix MrZeroPage.
I've a question please. The release history .txt says "one security-issue fixed"
Can you tell us how many and/or which files were changed to fix the security issue?
Perhaps instead of uploading/overwriting all files & reinstalling the product, we may be able to overwrite (patch) only the file that presented the security issue.

Thanks,

J.

Quote:

Originally Posted by Zahl (Post 2240041)
Anyone figured out yet what the change/fix is? I have modified my version of ibPA and would like to just apply the fix manually.... unless it includes a major remodeling of everything.

Quote:

Originally Posted by ForceHSS (Post 2240061)
just upload all the files and dont worry about where the fix is no one is going to tell you

Quote:

Originally Posted by JacquiiCooke (Post 2240070)
easy to say when you haven't spent hours and hours and hours customizing your ibProArcade install! Anyway - hopefully someone will share the fix as I and others have asked:

Let's think about this for a second... how many sites do you suppose are still running 2.7.0? From the install count and download count I would dare say QUITE a few do you all agree?

If you agree then why would we post the exact issue, allowing some script-kiddies just enough info to do harm to those sites still running 2.7.0? I love you guys (and gals Jacquii :D) however you can't always assume info is not disclosed because we simply don't want to tell you, that's silly tbo :p.

Mark.B 08-30-2011 06:31 PM

Quote:

Originally Posted by Gemma (Post 2240075)
I took me about 3 minutes to compare all the files, probably as long...if not less time than as some of you have waited in this thread for answers. You call yourself admins...and some even claim to offer professional support - do yourself a favour and download a compare program (you'll need it to compare and make the edits to the files below if you would rather not just overwrite the files).

Between versions 2.7.0+ and 2.7.1+ the following files have changed (code changes as opposed to just something like 2.7.0+ becoming 2.7.1+ in the file)

arcade.php
admincp/arcade.php
functions/functions.php
modules/mod_favorites.php
modules/mod_league.php
modules/mod_report.php
modules/mod_settings.php
skins/skin_arcade.php
skins/skin_v3arcade.php

And the product file (obviously).

Some changes are only 1 line

That took about 3 minutes to find out and I even sent a text message inbetween comparing.

Go figure :rolleyes:

Thanks for the speedy update MrZeropage.

Yes I found most of these.... :)

Though I confess, using Beyond Compare on a clean 2.7.1 versus a clean 2.7.0, it didn't find any differences in functions/functions.php

Many of the changes are just to do with branding free licences however.

I can't go into any any more detail than that.....as Gemma says, a good admin should be able to pull out the required changes and patch up nicely in no time. :)

That's what I've done due to heavy customisation, however that's a temporary measure and I'll be running the full upgrade in a week or two when I get the time to re-apply everything. :)


All times are GMT. The time now is 02:17 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.06096 seconds
  • Memory Usage 1,758KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (9)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (7)pagenav_pagelinkrel
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete