vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 4.x Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=245)
-   -   Major Additions - ibProArcade - professional Arcade System (https://vborg.vbsupport.ru/showthread.php?t=101554)

8thos 08-30-2011 08:31 PM

Quote:

Originally Posted by Paul M (Post 2240138)
Are you taking something ? It was fixed within 24 hours. How in any world is that "taking so long".

No Paul. The security flaw was there long before that.

Paul M 08-30-2011 08:35 PM

Quote:

Originally Posted by Octavius. (Post 2240141)
No Paul. The security flaw was there long before that.

Right - so when did you get a time machine then ?

Alternatively, perhaps you would enlighten us all as to how you fix an issue before you are informed of it.

8thos 08-30-2011 08:36 PM

Quote:

Originally Posted by MrZeropage (Post 2240140)
"so long to fix the issue" ?! I was noticed 29th August at 12:50 and provided the fixed Update within 24 hours on 30th August at 12:15 to vb.org where it got published at 15:26 after the staff checked the fix.
I think this is bad advertising for an alternative product, I was here in time and provided a fix within one day !

Ron, thanks, I will setup vB4 latest release next weekend on my testsite and implement fixes for that, leading in ibProArcade v2.7.2+ then

Oh okay.

Does this mean:

A. You finally fixed the previous security flaw that's been up for months.

B. You noticed the previous security flaw during an update and fixed it thinking it was new.

C. You only fixed the new security flaw.

8thos 08-30-2011 08:38 PM

Quote:

Originally Posted by Paul M (Post 2240144)
Right - so when did you get a time machine then ?

Alternatively, perhaps you would enlighten us all as to how you fix an issue before you are informed of it.

Your right. I don't know if they posted the issue in this thread after they got hacked.

If anything, I should've mentioned it myself in this thread after it happened last month.

Sorry.

BirdOPrey5 08-30-2011 09:04 PM

If no one reports a confirmed hack neither the staff or the mod author have any idea anyone is "being hacked" through this mod.

You can report being hacked by using the "Report Post" feature on the top post or PMing a staff member. Posting in a thread is not a report because quite frankly we don't all read every post, and the details should be kept confidential anyway.

TheLastSuperman 08-30-2011 09:08 PM

Quote:

Originally Posted by Octavius. (Post 2240147)
Your right. I don't know if they posted the issue in this thread after they got hacked.

If anything, I should've mentioned it myself in this thread after it happened last month.

Sorry.

Yes it's very important to let us know, don't specifically post the code for the reasons I noted a few posts back, use the report feature as a member did recently who brought this to our attention, it was further reviewed by staff then submitted to MrZeroPage who then promptly fixed it and that's how anyone should handle this from here on out.

I also understand how some want to notify everyone "ohh there's a flaw let's post it and warn others" i.e. helping while genuinely sincere can cause mass panic (I mean really ladies and gents the insults that are thrown or hinted to are simply ridiculous sometimes, honestly or I wouldn't take the time to say so please try to afterwards, understand from another perspective that they are unwarranted at best imo.) when all you need to do in nearly all similar situations is disable or uninstall the mod and security should not be pfff'd away as you all say and stress - it's up to everyone one of us to secure our forums, it's up to end-users to trust in those forums yet we must all assume responsibility for using the sites ourselves imo as we can't always take action against those doing the actual harm :o.

MentaL 08-30-2011 09:21 PM

the update just wiped my game list :(

/edit

fixed, damn vboptimize pro , flush = fix.

Paul. 08-30-2011 10:04 PM

Quote:

Originally Posted by MentaL (Post 2240165)
the update just wiped my game list :(

/edit

fixed, damn vboptimize pro , flush = fix.

Will updating make it appear as thought my games have been wiped?
If so, how do I get them back to normal?
I will update tomorrow.
Thanks for updating this @ Mr Zero :)

rolfw1 08-30-2011 10:10 PM

Just updated to latest version and now get this message when trying to submit a score:

Code:

Your submission could not be processed because a security token was missing.

If this occurred unexpectedly, please inform the administrator and describe the action you performed before you received this error.


Black Tiger 08-30-2011 10:21 PM

Thanks for the quick security fix.

However, I discovered a bug which was also present in 2.7.0.
Quote:

Upgrade to 2.7.1 or disable the mod completely.
Disabling won't work, because if you set this to disable in the Plugin and products section, the arcade won't be disabled at all. I can still keep playing games.
This should not be the case.

I can even still play games if the arcade is turned of in the arcarde main settings, but this could be because I'm admin.
However, when disabled within plugins and products, the game is -not- disabled. This would need a fix too.


All times are GMT. The time now is 01:44 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.05980 seconds
  • Memory Usage 1,747KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_code_printable
  • (7)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (7)pagenav_pagelinkrel
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete