vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 4.x Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=245)
-   -   Miscellaneous Hacks - login.php phishing patch (https://vborg.vbsupport.ru/showthread.php?t=264636)

GeekyDesigns 06-02-2011 10:00 PM

login.php phishing patch
 
1 Attachment(s)
Due to the recently announced Possibly Phishing Vector

I made a small/short patch which should stop a user from being exploited.

I've tested this internally and it seems to do the job.

GeekyDesigns 06-02-2011 10:57 PM

If there are other pages, that this can cause problems on, please let me know and I'll see what I can do to resolve it.

Special Pages 06-02-2011 11:45 PM

I'm using this for sure. Is this tested and working?

Zachery 06-03-2011 12:03 AM

I tested it as much as I could internally, it shouldn't ever impact normal users, only if someone, or something tries to pass url=X in the url.

MagicThemeParks 06-03-2011 12:26 AM

Will this work with all versions of vB?

Zachery 06-03-2011 12:58 AM

This should work on any version of vB4, the hook point im using I'm moderately sure isnt available in vb3.5-8

SuperTaz 06-03-2011 01:08 AM

Nice. Thank you. :)

Boofo 06-03-2011 01:56 AM

Quote:

Originally Posted by Zachery (Post 2202899)
This should work on any version of vB4, the hook point im using I'm moderately sure isnt available in vb3.5-8

init_startup is in init.php in 3.8.0. Not sure about earlier.

eJM 06-03-2011 03:16 AM

How will this affect things like VigLink?

Wonksta 06-03-2011 03:59 AM

Quote:

Originally Posted by eJM (Post 2202924)
How will this affect things like VigLink?

x2

AND - Does this phising vulnerability effect vB3.8.6?


All times are GMT. The time now is 03:22 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03081 seconds
  • Memory Usage 1,732KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete