vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 4.x Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=245)
-   -   Major Additions - ibProArcade - professional Arcade System (https://vborg.vbsupport.ru/showthread.php?t=101554)

g00gl3r 02-13-2012 07:48 PM

I had this installed and had a MySQL injection on my forum(s) via a couple of the games. I would strongly recommend checking your versions of this plugin as quickly as possible.

Schoelle 02-13-2012 08:09 PM

@googl3r: with the current version? Are you willing to share some details or forward them to the coder?

Hippy 02-13-2012 08:40 PM

dido

@googl3r: with the current version? Are you willing to share some details or forward them to the coder?

skol 02-14-2012 08:40 AM

Quote:

Originally Posted by g00gl3r (Post 2299373)
I had this installed and had a MySQL injection on my forum(s) via a couple of the games. I would strongly recommend checking your versions of this plugin as quickly as possible.

If your using V2 games they are prone to the highscore hack.Simply use V32 although they are not totally secured against the hack,your everyday cheater won't get passed it.

skol 02-14-2012 08:58 AM

Quote:

Originally Posted by ellinofatsa (Post 2298496)
I have alot of tar files uploaded that I am trying to install. When I click install all I get an
Error 500 - Internal server error

How can i fix this?

http://www.ellinofatsa.net/forums/arcade.php

One of two things.

1.You don't have enough memory to install the amount of games in one go.Take alook at your max_file_size,max memory_limit and try installing games in smaller batches.

2. You have a corrupted game/games that won't install.You have to install one game at a time until you find the culprit and delete it.Make sure it is deleted off your server,or you'll get it back when you come to upload/install more games.

skol 02-14-2012 09:51 AM

1 Attachment(s)
Can anyone direct me to were the post is for adding "Play Game in new window"...As below.

Attachment 136455

KProjects 02-14-2012 01:56 PM

Thanks - Installed!

g00gl3r 02-14-2012 03:00 PM

Quote:

Originally Posted by skol (Post 2299522)
If your using V2 games they are prone to the highscore hack.Simply use V32 although they are not totally secured against the hack,your everyday cheater won't get passed it.

I've removed the arcade system from all my forums. It's just not secure enough. I lost quite a bit of traffic and Adsense revenue the last month due to it.

I can't have that happen again just for the sake of getting members to play the odd game on the forums.

I just thought I'd let you guys know so you could check your forums if you're running it.

Schoelle 02-14-2012 03:05 PM

@googl3r, could you explain in more detail please. What has happened exactly? If there is a security flaw you should explain it so everyone is warned. A general "it is not secure" for sure does not help anyone. So please let us all know. Thank you!

g00gl3r 02-14-2012 03:37 PM

I wouldn't want to post full details online. It was more to get the developer (who I've PM'd also) to check what's going on with it.

PM me your email address and I'll send you some details we've obtained about this possible flaw.

Though the basics of it was there was a redirect being added to the forum which meant traffic coming from search engines was being directed to a dodgy URL with spam, malware, and ads and pop-ups all over it. This affected upto 25% of traffic from search engines on one forum hosted on one server, and even affected several forums hosted on another server using different security software and a slightly different setup. So I'm guessing whoever/whatever has found this flaw, can find all forums with the flaw.

Not saying it's all arcades that will be affected here, but certainly all mine running the arcades had been effectively hacked and redirection code injected. Took a while to find out what the cause of it was too!

I have my host(s), vbulletin, and vbseo all suggesting fixes and monitoring the servers / sites now to make sure we have actually locked the rest down now we've removed it.


All times are GMT. The time now is 04:50 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.07070 seconds
  • Memory Usage 1,746KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (7)pagenav_pagelinkrel
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete