![]() |
login.php phishing patch
1 Attachment(s)
Due to the recently announced Possibly Phishing Vector
I made a small/short patch which should stop a user from being exploited. I've tested this internally and it seems to do the job. |
If there are other pages, that this can cause problems on, please let me know and I'll see what I can do to resolve it.
|
I'm using this for sure. Is this tested and working?
|
I tested it as much as I could internally, it shouldn't ever impact normal users, only if someone, or something tries to pass url=X in the url.
|
Will this work with all versions of vB?
|
This should work on any version of vB4, the hook point im using I'm moderately sure isnt available in vb3.5-8
|
Nice. Thank you. :)
|
Quote:
|
How will this affect things like VigLink?
|
Quote:
AND - Does this phising vulnerability effect vB3.8.6? |
Did I install this wrong?
Product: vBulletin Hook Location: init_startup Title: Login php phishing patch Execution Order: 5 Plugin PHP Code: paste text of xml file here I got a blank screen when I clicked the What's New button. |
Installed with thanks on 4.1.3 .... :)
Regards, Doug |
Quote:
|
Quote:
probably you copied along a character that shouldn't be there and that is causing a blank page |
Quote:
|
Thank you.
|
Could someone please make a vb3.8 version? With the announcement all over the net, it would be good to patch it.
|
This will work in 3.8.
|
Thanks!
|
Great idea *TheLastSuperman installs :D
|
Is this mod still needed with vb 4.1.5?
|
No, it isn't.
|
The code is the same for the emailpassword section. Where was it fixed?
|
Quote:
Quote:
|
It does work on vB 4.x.x though :p
|
Quote:
|
It doesn't stop working on newer versions of the software, it just doesn't fix anything.
|
So, should we run it on 4.1.5, or not?
|
Quote:
Quote:
|
Well, Zachery beating around the bush doesn't make things very clear.
|
Actually, FWIW, this addon would still be useful if you wanted to disable the newer security fix by vbulletin but still retain some of the protection.
|
All times are GMT. The time now is 05:06 AM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|