vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin.org Site Feedback (https://vborg.vbsupport.ru/forumdisplay.php?f=7)
-   -   vbBux & vbPlaza Removal (https://vborg.vbsupport.ru/showthread.php?t=138591)

Neal-UK 02-06-2007 06:20 AM

vbBux & vbPlaza Removal
 
Thanks for letting me know of the exploit, but now vb.org have removed the mod altogether from vb.org, I have no idea what files I must remove off my server and what changes I can revert to already modified templates.

When removing a hack, is it not advisable to leave a list of the files and where they would normally be uploaded to as well as the instructions for install / uninstall?

rjmjr69 02-06-2007 06:31 AM

Well you should really keep a history of changes theres actually a built in feature that allows you to I guess basicaly take a snap shot of the before.... Just a suggestion for future installs. And I still have the complete install files I'll up the read me just reverse your steps.




http://rapidshare.com/files/15151802/readme.txt.html

Sorry I do not usually use RapidFire I hate it but my normal host are doing upgrades to the software and server. I normally use http://www.mediafire.com

Well hope this helps you out.

Neal-UK 02-06-2007 06:35 AM

Can you send me the read me or attach it to this thread for the install please if you don't mind. I do keep a history, in my installed hacks section on vb.org....

hitboy 02-06-2007 07:01 AM

so whats wrong with vbbux its hackable or something? What other options are there besides icash??? For the latest version of VB?

Neal-UK 02-06-2007 07:15 AM

Quote:

Originally Posted by rjmjr69 (Post 1175810)
Well you should really keep a history of changes theres actually a built in feature that allows you to I guess basicaly take a snap shot of the before.... Just a suggestion for future installs. And I still have the complete install files I'll up the read me just reverse your steps.




http://rapidshare.com/files/15151802/readme.txt.html

Sorry I do not usually use RapidFire I hate it but my normal host are doing upgrades to the software and server. I normally use http://www.mediafire.com

Well hope this helps you out.

That's much appreciated, thankyou. :up:

Can you let me know what files went where so they can all be removed? Thanks again.

Zia 02-06-2007 07:22 AM

mmm what kinda exploit detected there ?

been long time we r on vbux..
removing it will be a reason of huge qus from users

Neal-UK 02-06-2007 07:27 AM

I think just disabling it will be enough.

Mudvayne 02-06-2007 07:36 AM

Quote:

Originally Posted by Neal-UK (Post 1175829)
Can you let me know what files went where so they can all be removed? Thanks again.

You can disable the modification & use it again when someone provide a fix :). Why you want to uninstall as that 'll remove every data?

Neal-UK 02-06-2007 07:40 AM

Not worth the risk to be honest, and i've only in the last week installed it on the site. I used to run it on another but got fed up of the template changes, etc when a new vb came out, so to be honest i'd rather just get rid.

It's a good hack, just too many things to mess with when there's an update to the forums, etc....

Paul M 02-06-2007 11:07 AM

Artificial_Alex reported an exploit which we investigated and confirmed - not only that but the investigations revealed other exploits in the code as well. As per our policy on such matters, the modification has been removed until such time as the holes are fixed.

Ziki 02-06-2007 01:36 PM

I know why you don't want to reveal the exploits but could you post it in the private coder discussion so other coders can help fixing it?It is a great hack and I believe everybody wants it back as soon as possible

Reeve of shinra 02-06-2007 01:50 PM

I agree, it would help if we knew the exploits so we could help fix or patch it.

Maybe in the future, these threads could be closed so that only the people who clicked install and the author can view it. This way, new people can't download it but people with it already installed can see about fixing it.

Acers 02-06-2007 02:21 PM

Unfortunately if you announce it i suppose you automatically open all customers who might not have had a chance to disable it, open to be exploited.

Xplorer4x4 02-06-2007 02:45 PM

Quote:

Originally Posted by Neal-UK (Post 1175839)
Not worth the risk to be honest, and i've only in the last week installed it on the site. I used to run it on another but got fed up of the template changes, etc when a new vb came out, so to be honest i'd rather just get rid.

It's a good hack, just too many things to mess with when there's an update to the forums, etc....

If members cant use the hack(sine it is disabled) then there would be no risk that I can think of.

Just update the templates manually. That is what i do when there is a new release. It doesnt usually require much effort.

Neal-UK 02-06-2007 03:55 PM

So, is a good idea then when a hack is removed, at least the uninstall features for the mod are still listed? That way, people can remove a problem modification and the files from the server?

Paul M 02-06-2007 04:05 PM

Quote:

Originally Posted by Ziki (Post 1175967)
I know why you don't want to reveal the exploits but could you post it in the private coder discussion so other coders can help fixing it

Sorry but no, we will not reveal details of the exploits.

Ziki 02-06-2007 07:32 PM

Quote:

Originally Posted by Paul M (Post 1176075)
Sorry but no, we will not reveal details of the exploits.

But the staff is fixing it right?I think Brad fixed the shoutbox as it is widely used.

Guest190829 02-06-2007 07:42 PM

Quote:

Originally Posted by Ziki (Post 1176278)
But the staff is fixing it right?I think Brad fixed the shoutbox as it is widely used.

No...the protocol says the staff may fix if it time is granted. With the shout box, it was just fortunate that it was fixed by a staff member.

Distance 02-06-2007 09:17 PM

Unfortunately they did a bad job with it, making more bugs.. making Zero Tolerance stop releasing on vBulletin.org

Paul M 02-06-2007 09:26 PM

They ?

We've already been down this road in another thread, it doesn't need another discussion here, please stick to the current topic.

Distance 02-06-2007 10:51 PM

Sorry.. But another thread? May i have linkage.. i can't see.. im not stirring things up, im just wandering as i know him quite well (Scot)

And that sucks... although i have never used it, its a shame.. such a good mod to go to waste

hitboy 02-07-2007 02:03 AM

So wait I dont understand if I keep using vbbux will my site get hacked?

Zia 02-07-2007 03:04 AM

Top X stats also fixed by one of vb staff......

why not vbux ?
this too pop mod...for vb

Exitilus 02-07-2007 03:27 AM

FYI .. The Developer has returned and is looking into this issue. See the Premium Forum for updates.

rjmjr69 02-07-2007 04:17 AM

Quote:

Originally Posted by Exitilus (Post 1176520)
FYI .. The Developer has returned and is looking into this issue. See the Premium Forum for updates.

Is there been a fix announced?

Exitilus 02-07-2007 04:32 AM

No but someone has posted a "possible" fix.

Neal-UK 02-07-2007 06:16 AM

So has anyone got any information on what files need to be removed from my server?

Zia 02-07-2007 06:40 AM

cmx returned ?

woha good news indeed

lets watch premium forum

Xplorer4x4 02-07-2007 07:35 AM

Quote:

Originally Posted by Neal-UK (Post 1176598)
So has anyone got any information on what files need to be removed from my server?

They all start with vbPlaza in the name. Check Admincp,includes,modcp,plugins,vbplaza(obviously huh:p ) and vbplaza.php in the forum root.

If you look in the premium support section there is already a partial(non confirmed by CMX) fix. So I would wait. If the plug in is disabled or deleted users cant use the plaza anyways so i dont see why it it so necessary to delete the scripts. Also if you delete the plug in this would erase all the database tables concerning vbplaza disabling the plaza as well.

Paul M 02-07-2007 10:29 AM

Quote:

Originally Posted by Zia (Post 1176511)
Top X stats also fixed by one of vb staff......

why not vbux ?
this too pop mod...for vb

The staff are not here to fix broken/exploited modifications, occasionally one may do so if they have the time (or use the mod themselves) but that's all. Fixing is the responsibility of the author.

hitboy 02-07-2007 01:57 PM

Well I hope this gets fixed as this was the main reason I choose vb in the first place. I need this points system or something like it but not as simple as icash I may have to move eh..

Exitilus 02-07-2007 04:48 PM

All we can do is hope to see a fix soon :)

%

hitboy 02-09-2007 02:42 PM

anyone have any word on this??

Aclikyano 02-09-2007 05:34 PM

Quote:

Originally Posted by hitboy (Post 1175820)
so whats wrong with vbbux its hackable or something? What other options are there besides icash??? For the latest version of VB?


O YES!.. this is a confirmation from OUR SITE!.
some user PMD me of a donation they sent and it said nice site!

then I noticed the site was in shambles and turned off!
so i UPLOADED the day befores database back up and removed vbplaza completly!.

snobird1211 02-10-2007 01:49 PM

yea i had a problem as well i got a bunch of points donated from a user saying alert cookie and after that memebere reported popus in the vb plaza with a bunch of numbers in it so i removed it as well

hitboy 02-11-2007 12:23 PM

Wow this sucks alot!!! can the staff at least tell the coder the problems with the mod/plugin? I totally understand its not good to release it to the public but telling the actually coder of the mod isnt effecting anyone and if it does it will be a benefit for all of us..

Paul M 02-11-2007 02:02 PM

The author is obviously informed of the exploit, it would be a bit hard asking them to fix it if they weren't.

snobird1211 02-11-2007 02:47 PM

no one should be mad at staff, staff here dose a good job, they arent even required to tell the creators antyhing. it should be the creators responbility to check on his or her product, but thanks to the great staff here they go the extra mile.

as far as problems go i would like to thank the staff for removing this as it has stopped problems form occuring and may have just saved my site and youre who knows.

so in my conclusion thanks staf for removing and be responisble people to inform us and also people the staff has alot on their hands so dont expect them to fix other peoples mods and or hacks

Zia 02-11-2007 04:50 PM

No one got mad to staffs..

Quote:

Originally Posted by snobird1211 (Post 1179931)
they arent even required to tell the creators antyhing.

but what does ur word mean? If the dont inform to the author ,then they need not to inform to the user too.

Both is same.

Tommy12345 02-11-2007 05:21 PM

If the hacker is not looking to exploit others, he/she would have gone to the authors site and messed it up with the exploit:up:


All times are GMT. The time now is 05:25 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01298 seconds
  • Memory Usage 1,817KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (11)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete