vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Modification Graveyard (https://vborg.vbsupport.ru/forumdisplay.php?f=224)
-   -   Integration with vBulletin - Flashchat Integration for vB 3.5 (https://vborg.vbsupport.ru/showthread.php?t=91278)

TunerNetwork 02-19-2006 04:49 PM

Im lookin at it now paul, do you know what part I edit, and what do you recommend for a setting, thanks again

JAYEMULE 02-19-2006 07:38 PM

I have the Flashchat installed for a while now and forum members really enjoy it. Thanks kindly for putting this 'hack' together for us.
I have one question now though. When I installed it I set it up on only one forum style. I would like to add the flashchat link to the header of the other style in my forum but I can not seem to find the instructions on how to do this. Do I have to install it all over again for the other style or is there a way to add the flashchat link to the second style header ?
Thanks kindly for your time in helping with this as well.

Jaye
The Mule Skinners Forum

JAYEMULE 02-20-2006 12:18 PM

OK you can disregard my last post. I got it figured out :)

Jaye

TunerNetwork 02-20-2006 11:34 PM

Quote:

Originally Posted by Paul M
Check the settings in the flashchat config file.

what part do i edit? im checking now

RFViet 02-20-2006 11:50 PM

I found this from Tufat.com: http://www.tufat.com/docs/flashchat/integration.html
is it the same to your hack ??
If it's not, do i have to intergrate flashchat to vB before using your hack ???

RFViet 02-21-2006 01:09 PM

Where should I upload the add-ons to ???

Paul M 02-21-2006 05:01 PM

Did you read the note in the main post.

RFViet 02-21-2006 05:23 PM

Quote:

Originally Posted by Paul M
Did you read the note in the main post.

I did, but the WOL function doesn't work, so I try to upload the Add-ons :surprised:
Do I need to modify template ??

Railen 02-21-2006 05:47 PM

Anyone have an issue where the javascript dropdown menu divs (such as quick links) are hidden behind the iframe / flash object? I've been looking for a solution for some time now. I've tried setting the div z-index style to 2:
Quote:

<!-- user cp tools menu -->
<div class="vbmenu_popup" id="usercptools_menu" style="display:none; z-index:2">
and the iframe z-index to 1:
Quote:

<iframe style="z-index:1" src="http://.../forum/chat/flashchat.php" ...
This doesn't seem to fix it.

I've also tried adding the following to the object tag in flashChatTag.php:
Quote:

<param name="wmode" value="transparent">
This doesn't work either. I'm getting kinda annoyed here...

6impy 02-22-2006 02:46 AM

What is being done to improve FlashChat's integration security?

Just look at how easy it is to fake a login as an administrator:

http://www.tufat.com/forum/showthread.php?t=14166

Quote:

Hi,

i use a vBulletin 3.5.3 with FlashChat 4.4.2.

In this combination i have the following problem:

- I login in vb
- I enter the chat and leave them => a cookies "chat xxflashchatid" was set, the content of this cookie is my userid (i.e. 1)
- then I change the userid to another value, i.e. 33 (33 is the vb userid of another existing user)
- after this i can enter the chat as user 33 without a password !

So I can fake any user in the chat. I need a valid login only.

How can I eliminate this security vulnerability?
Reply With Quote

---

You actually were able to gain moderator powers having initially logged in as a normal user?

Edit:

Everything he said is true. I was able to log in as a regular user, change the user id in the cookie "bbflashuserid" to an admin's user id, and have access to all the admin powers.

This is a joke!

I don't care if this issue is fixed in new version. I will never use FlashChat again.

If the individual(s) who programmed FlashChat are clueless enough to include a hole like this, then I don't want any of their code running on my server.



All times are GMT. The time now is 08:49 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.02498 seconds
  • Memory Usage 1,746KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (6)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (3)pagenav_pagelinkrel
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete