vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 3.8 Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=235)
-   -   Miscellaneous Hacks - Cyb - Advanced Forum Rules (https://vborg.vbsupport.ru/showthread.php?t=201312)

Valter 05-05-2011 02:06 PM

Hacked by Team Animus?

Please read this thread:
https://vborg.vbsupport.ru/showthread.php?t=263202

ShawneyJ 05-05-2011 02:15 PM

Quote:

Originally Posted by Valter (Post 2192283)
Hacked by Team Animus?

Please read this thread:
https://vborg.vbsupport.ru/showthread.php?t=263202

you may have been the last to fix your site lol. blown over by now i hope. they all hit 24 hours ago. 10 hours of that was fixing all my forums because of your mod. i guess its install at own risk but still, should this hack be in the grave yard or will an update be released?

edit: opps sorry just sen the update, will wait for feed back thanks.

Valter 05-05-2011 02:29 PM

Bug has been fixed yesterday.

21:55 CET - Bug reported
‎22:22 CET - Bug fixed
22:26 CET - Update posted

ikorolis 05-05-2011 05:05 PM

i am waiting official answer this security bug/hack/exploit is fixed or not.

mod hacks is safe to use or not

cellarius 05-05-2011 05:09 PM

Whom "official" do you expect to answer here?

ikorolis 05-05-2011 05:13 PM

my question not answer here or vb.com

i know my friend

i know is big mistake give money to buy VB 3.x or VB 4.x and dont try other payment or open/free source software with good support.

cellarius 05-05-2011 05:39 PM

You did not give money to anyone in order to use this mod, and vBS does not check or take responsibility for third party code, which is entirely normal. But this is a modification thread, so this is OT.

ikorolis 05-05-2011 06:16 PM

my friend maybe dont understand me.

i give money to buy VB licence (software) 3.x Version and 4.x Version
i give money to buy DOMAIN NAME/HOST SERVICE

dont give any money this mod hacks or plugins (but support work this coders make this usefull plugins)

without this 3rd party plugins have one portal/site/forum/blog dont like to anyone.

all payment software for websites and all open source have plug ins and SAFE.

other coders/developers if know give good support

the vb.com i am sorry not have good support (except if pay this)

thats say big mistake give any money for VB.

next time to create website never using VB.

(sorry my english i am from greece)

Fenriz 05-05-2011 06:57 PM

/misc.php?do=cfrules_mng gives me a blank page after upgraded to 4.0.3 from 4.0.2. Anyone has the same problem?

Valter 05-06-2011 07:47 AM

v4.0.4 - May 06. 2011.
-Fixed: vbseo users not able to switch rules

To update:
-Import XML, allow overwrite

CMFINC 05-06-2011 08:30 AM

thanks for the hard work making this program as well as working on it. I'm sure i will use it again as i did like it. but at this time I'm going to wait a bit see the ones with more time and knowledge on fixing forums use this . as i have been trying to clean up now for next to 2 days .. and thats my fault for just learning this stuff.. LOL.

ikorolis 05-06-2011 11:58 AM

Valter is good and trusted coder and using many CYB_ mod hacks.

but this mod hack uninstalled from my site and maybe other mod hacks have uninstalled.

sorry nothing personal Valter but is too risk lost everything on my site/forum. (dont have much time to install and setup again)

sross 05-06-2011 12:14 PM

These things happen and can strike any software at any time. This is why I keep 3 different backups of my forums.. one on disk, one on a different box at the host, and one that is rsync'd to my local machine at home (in a vm session which is then shut down after sync and also duplicated to a NAS). If you do not have a good backup system in place, then you're asking for it.

ikorolis 05-06-2011 12:22 PM

BACKUP (many places is safe) is the first word to know anyone have job to IT Department.

dont worry my friend already using backup any day / any time (SQL DB / FILES DB) for many places on server and on my computer.

i am not trust any backup after hack attack (reason is the hacker have modify .php or .html files or templates or sql db or....and never see the "bad code")

i am say anyone hacked my VB 3.x force to deleted everything on my server and install / setup new VB 4.x without any mod/hack.

ShawneyJ 05-09-2011 03:23 AM

Quote:

Originally Posted by Valter (Post 2192601)
v4.0.4 - May 06. 2011.
-Fixed: vbseo users not able to switch rules

To update:
-Import XML, allow overwrite

you sound sure of your self that you have fixed the security hole.
like hundreds of forums hacked must hurt in some way yeah?

anyway, im going to put this to the test and re-install and go live.

one thing is the demo link still is not live which makes it iffy :rolleyes:

cellarius 05-09-2011 04:34 AM

Quote:

Originally Posted by jaycob (Post 2193525)
like hundreds of forums hacked must hurt in some way yeah?

What kind of bull**** is this? What do you want to hear? Is he to confess and wear sackcloth and ashes? Would you prefer a pillory? He's offering free addons for vB, and security issues have known to be found in any kind of software. Nobody forces you to use it, but if you're unaware that installing addons carries a risk, since all humans are prone to errors, it's your own fault. He sure did not do it on purpose. But if this kind of sniping is good for your ego...

And yes, the security hole is fixed indeed.

ShawneyJ 05-09-2011 10:16 PM

ok update, everything seems ok now for those that are to scared to re-install. been a night and half a day, all seems good. @cellarius, hey moron, i felt sorry for the guy. you need to think before talking out your rear end.

thanks Valter ;)

cellarius 05-10-2011 04:41 AM

Then you should make yourself clearer. Even after reading your wording again, I just can't understand it in any other way that I did - moron yourself.

Yakuza 05-10-2011 04:41 AM

After upgrading to 4.0.3 first and then 4.0.4 rules are not displayed, empty box at misc.php?do=cfrules

I wish i could download old versions, i was on 3.6, probably even not affected by the bug :/

Daverball 05-10-2011 09:23 AM

Quote:

Originally Posted by Yakuza (Post 2193897)
After upgrading to 4.0.3 first and then 4.0.4 rules are not displayed, empty box at misc.php?do=cfrules

I wish i could download old versions, i was on 3.6, probably even not affected by the bug :/

Everybody was affected by the bug, there was some unescaped POST-Data, so SQL-Injection was possible independant of the vBulletin-version.

I have updated to 4.0.3 first and then 4.0.4, my rules are still intact. You know that you have to reactivate the plugin, right? Because as long as you haven't activated it, you can't look at your rules and will be forwarded to the smiley page.

ShawneyJ 05-10-2011 02:31 PM

Quote:

Originally Posted by cellarius (Post 2193896)
Then you should make yourself clearer. Even after reading your wording again, I just can't understand it in any other way that I did - moron yourself.

if ya got a problem pm me, if not zip it ;)

----------

anyway BACK on topic!

when you click last post icon on a forum, it re-directs to rules nicely, but once accepted and submit a message shows: No Thread specified. If you followed a valid link, please notify the administrator.

cheers. :up:

RedDog69 05-11-2011 09:23 AM

There are still some bugs in this hack, i have jumped directly from 3.9.2 to v4.0.4 and i´m on vb 3.8.4 patch L 2.

Unique problem i have, that after forcing members to re read rules, he has no way of accepting them, he is directed to the rules page, but there is no button to agree with them ...

Any help would be appreciated, as is a great mod and addition to vbulletin

septimus 05-13-2011 04:31 PM

After the exploit, there were some recommendations that said to completely uninstall vs. disable, and that is what I did. If I reinstall, will the members that previously accepted have to reaccept again? I'm hoping not.

My questions rarely get answered here in the forums, so I don't expect this time to be any different, but I'll ask anyway :p

kh99 05-13-2011 05:20 PM

Quote:

Originally Posted by septimus (Post 2195172)
My questions rarely get answered here in the forums, so I don't expect this time to be any different, but I'll ask anyway :p

Well, now I have to answer, even if I don't know for sure. :) But looking at the code I'd say yes, it seems to save the "accepted" state for a user in the user table, and it drops that column when it's uninstalled, so they'll probably have to accept again.

Personally, I'm waiting a little longer before reinstalling.

RedDog69 05-13-2011 06:04 PM

Quote:

Originally Posted by septimus (Post 2195172)
After the exploit, there were some recommendations that said to completely uninstall vs. disable, and that is what I did. If I reinstall, will the members that previously accepted have to reaccept again? I'm hoping not.

My questions rarely get answered here in the forums, so I don't expect this time to be any different, but I'll ask anyway :p

Huh, i did un install it and it fudge up my custom styles ... and i like the hack so i?ll be still very happy if any one could help me with sorting my above problem

Thx in advance
RD

vijayninel 05-13-2011 06:10 PM

Very interesting and useful mod. I will be installing this shortly. :)

Valter 05-17-2011 09:43 PM

v4.0.5 - May 18. 2011.
-Fixed: Security bug
-Improved rule acceptance check

To upgrade:
Import XML, allow overwrite

dmark101 05-17-2011 10:54 PM

updated. thanks. :)

andrew67 05-17-2011 11:03 PM

Thanks for your swift responses to needed updates.

ShawneyJ 05-18-2011 04:39 AM

Quote:

Originally Posted by Valter (Post 2196916)
v4.0.5 - May 18. 2011.
-Fixed: Security bug
-Improved rule acceptance check

To upgrade:
Import XML, allow overwrite

you are the man, thanks ;)

M.C. 05-18-2011 01:33 PM

wait and see if this update fix problem as previouse didn't...

RedDog69 05-18-2011 04:59 PM

Still same problem as before, user is not able to accept the rules ... Uninstalled :(

Sixpackmark 05-19-2011 10:51 AM

Installed and updated, working and can accept the rules... Thanks Valter

FreshFroot 05-20-2011 06:52 AM

Quote:

Originally Posted by HMBeaty (Post 2192100)
Pretty sure he sleeps and has a life too.....

LOL.

Of course he does, but that doesn't mean he can't take 2 mins. To make a post to state that everyone using the hack could be hacked and should disable it. At least people could disable the hack quickly and save themselves from being hacked.

Anyways glad the problem has been fixed.

Truth be told I think many hacks here at vBorg are exploitable. But no one looks deeply into the code. And well the hackers out there do that since they have no life but to go around hacking boards.

AusPhotography 05-20-2011 07:11 AM

Quote:

Originally Posted by FreshFroot (Post 2197906)
Truth be told I think many hacks here at vBorg are exploitable. But no one looks deeply into the code. And well the hackers out there do that since they have no life but to go around hacking boards.

And possibly in vB itself. NO software is perfect.
I've reviewed all the plugins we use, and am happy were now ok. Not having a site tech and only relying on 3rd parties is not a good idea.

Kym

cellarius 05-20-2011 09:14 AM

Quote:

Originally Posted by FreshFroot (Post 2197906)
LOL.

Of course he does, but that doesn't mean he can't take 2 mins. To make a post to state that everyone using the hack could be hacked and should disable it. At least people could disable the hack quickly and save themselves from being hacked.

vb.org does that for him automatically once the addon goes into quarantine. A notification mail goes to everyone who has marked the addon as installed. They often end up in Spam Filters, though, as happened for me this time (just make sure you have your filters set up to let mails from vb.org through)

Eric 05-20-2011 09:47 AM

Quote:

Originally Posted by cellarius (Post 2197920)
vb.org does that for him automatically once the addon goes into quarantine. A notification mail goes to everyone who has marked the addon as installed. They often end up in Spam Filters, though, as happened for me this time (just make sure you have your filters set up to let mails from vb.org through)

Went to my spam folder as well. I am geussing it is because of "quarantine" being in the message.

septimus 05-21-2011 01:27 PM

Quote:

Originally Posted by kh99 (Post 2195196)
Well, now I have to answer, even if I don't know for sure. :) But looking at the code I'd say yes, it seems to save the "accepted" state for a user in the user table, and it drops that column when it's uninstalled, so they'll probably have to accept again.

Personally, I'm waiting a little longer before reinstalling.

When I came back to thank you the mod had been quarantined and I couldn't reply. So thank you very much for answering my question.

I personally love the concept of this mod, but I think some jerks are going to continue to try to break it.

The main feature I liked about this mod was redirecting users who've received an infraction to the general rules page. I also liked being able to setup different rules.

We have general, marketplace, and developers. I ended up creating FAQ pages for each and then created a pulldown in my navbar to get to them. So the only feature I am missing out on is the redirect for infractions. Maybe I'll write my own plugin that does that someday.

kh99 05-21-2011 03:46 PM

Quote:

Originally Posted by septimus (Post 2198364)
I personally love the concept of this mod, but I think some jerks are going to continue to try to break it.

Yeah, that's the way it goes I guess. Thing is, I feel pretty confident now that it's OK. After the first problem the focus was on the SQL statements, and a non-SQL problem was missed. But after the second time I think all user input has been gone over by more than one developer, so I think it's probably safe now.

FreshFroot 05-24-2011 03:34 AM

Quote:

Originally Posted by snoopytas (Post 2197910)
And possibly in vB itself. NO software is perfect.
I've reviewed all the plugins we use, and am happy were now ok. Not having a site tech and only relying on 3rd parties is not a good idea.

Kym

I never said scripts are perfect. I said they could've addressed it sooner. And for mods usually the script is NOT updated that fast compared to vB, which is fixed usually within a few hrs.

Quote:

Originally Posted by cellarius (Post 2197920)
vb.org does that for him automatically once the addon goes into quarantine. A notification mail goes to everyone who has marked the addon as installed. They often end up in Spam Filters, though, as happened for me this time (just make sure you have your filters set up to let mails from vb.org through)

That may have happened, but I believe they quarantined the mod so late that many websites were already hacked at that point.


All times are GMT. The time now is 09:16 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.02643 seconds
  • Memory Usage 1,836KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (16)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (3)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete