vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Modification Graveyard (https://vborg.vbsupport.ru/forumdisplay.php?f=224)
-   -   Forum Display Enhancements - Multi Domain Login (https://vborg.vbsupport.ru/showthread.php?t=221026)

Adult SEO 08-15-2009 10:00 PM

Multi Domain Login
 
1 Attachment(s)
If you are using seperate domains for subforums (e.g. forumX.com and forumXsubforum.com), you will have encountered the problem that it isn't possible to share cookies over multiple domains.

This mod will enable the user to login on subforum domains using a javascript check on the main domain that will return a login key to sign the user in automaticly.

To see how it works you can check out www.scooterhulp.com and for example the subforum http://www.scooterwetgeving.nl/

fionix 08-17-2009 10:40 AM

Thank you, installed, but don't work if the user has disabled Java!

Adult SEO 08-17-2009 10:54 AM

Yes, that is correct. It is just an extra service for users that have javascript enabled (almost all users).

Other users are able to login using the form themselfs and would need to do so for every subforum if they want to post a reply.

amin 09-06-2009 01:58 PM

before you use this hake please check this
http://www.vbulletin.com/forum/showthread.php?p=1786188

thanx

New Joe 09-06-2009 02:31 PM

So why hasn't this hack been pulled?

Adult SEO 09-06-2009 04:15 PM

This hack is being used on www.papegaaienforum.nl and www.scooterhulp.com for 3+ years.

So I am pretty sertain this mod can't be the reason that users are able to login with any password.

Paul M 09-06-2009 07:01 PM

Quote:

Originally Posted by New Joe (Post 1880579)
So why hasn't this hack been pulled?

So far no one has demonstrated that this has a problem. Anyone can just say a mod is at fault, it will not be pulled unless a security issue is proven.

New Joe 09-07-2009 10:57 AM

I'm cool with that.

Amenadiel 09-07-2009 02:31 PM

I installed this on a 3.7.5 VB, but the configuration options doesn't show up on my admin panel.

sectomy 09-19-2009 09:41 AM

3.8

Warnung: parse_url() expects exactly 1 parameter, 2 given in [path]/includes/init.php(298)

no access to AdminPanel...

removed it... sad.. thats what i need for my forum :(

Setokaiba (SW) 10-05-2009 11:30 PM

Be careful, this mod allowed to enter any forum account without knowing the password, even logged in to the account of one of my managers and some members banned, so that the damage was not greater.

Paul M 10-06-2009 10:36 AM

If you can demonstrate this then please PM details to the staff here so we can check it, Thanks.

Floris 10-06-2009 12:18 PM

Nice mod, but waiting until proven if it is exploitable or not.

That said, the phrase has a small typo: automaticly

automatically <- corrected. :p VROEM!

Jhonnydc 10-07-2009 08:05 AM

i have this problem when i install the product:

Warning: parse_url() expects exactly 1 parameter, 2 given in [path]/includes/init.php(298) : eval()'d code on line 3

Adult SEO 10-08-2009 09:30 AM

@ Setokaiba (SW)

Can you please let me know how you were able to login to any account with this mod? The temporary login key that is generated is unique for every user. It should be at least as secure as any normal password.

Jhonnydc 10-08-2009 12:56 PM

Quote:

Originally Posted by Jhonnydc (Post 1896031)
i have this problem when i install the product:

Warning: parse_url() expects exactly 1 parameter, 2 given in [path]/includes/init.php(298) : eval()'d code on line 3

the forum is locked too....

Now it's disinstalled... i wait an answer... ;)

Adult SEO 10-08-2009 02:33 PM

I now see the second parameter of parse_url() was added in PHP 5.1.2.

http://www.php.net/manual/en/function.parse-url.php

I will revise this script probably tomorrow for use on one of my own forums, and update this mod with a version that should be compatible with PHP 4.

ViewMy.biz 10-08-2009 11:44 PM

I need this feature

I was hoping approved "white space" would allow logging in from different domains

Floris 10-10-2009 10:45 AM

A shame, people jump to false accusations with no data to back their claim up.

C'mon, show that it's exploitable, or apologize for being wrong.

fattony69 10-13-2009 03:11 AM

Quote:

Originally Posted by Floris (Post 1897510)
A shame, people jump to false accusations with no data to back their claim up.

C'mon, show that it's exploitable, or apologize for being wrong.

Correct me if I am wrong, but I believe the issue that was brought up wasn't a problem with this modification, but with vbulletin itself and the release that was put out a few days ago.

Floris 10-13-2009 05:11 PM

Good, then we can move on :)

bondjetta 10-14-2009 01:04 PM

FYI I just installed this mod and had the same problems as described. I could log in as any user simply by typing in a random password, I was using '12345'.

vB v3.8.0
PHP v5.2.10
MySQL v5.0.81

PM me if you want more specifics. I had to uninstall this mod due to the security threat.

Floris 10-24-2009 09:48 PM

Can one of the vBulletin.org staff please review this - public or graveyard.

This is a very very serious security issue if indeed valid and confirmation would be nice.


All times are GMT. The time now is 01:01 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01117 seconds
  • Memory Usage 1,753KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (23)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete