View Single Post
  #1544  
Old 09-02-2006, 07:55 PM
jeremycs jeremycs is offline
 
Join Date: Jul 2004
Posts: 26
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by AdmiralSpock
We don't allow users to post using the [media] tags. It's just admins, mods, and other staff. I'm not that stupid.
Depending on the forum audience, it should be fine to allow the media tags.

As long as they are mature enough to know that it's possible that they will likely see something they might wish they hadn't once in awhile. :P

But it's allowing .swf (and other macromedia flash type) files to be played that is the problem. A person could easily create a flash file that would automatically redirect the browser upon loading. They could redirect it to a page that looks just like your forum login screen, steal the password & log the user user back in as if nothing happened.

The files from places like youtube, google video, etc when played through their respective players are flash & could pose the exact same problem.... but I seriously doubt that google or youtube will attempt to do anything malicious to your forum.


Quote:
Originally Posted by AdmiralSpock
And if you would have taken the time to look at the first post, Crist states that he does not know if he will update the hack or not. If I knew PHP I would do it in a heartbeat. Perhaps someone else will update the hack, I don't know. Que sera, sera.
I don't need to look at the first post to know that authors of any of these free hacks are subject to disappear at any time. How's that for stability? :P

I understand what you're saying, but every time you click "INSTALL" you have to understand that you are taking and accepting a large number of risks.

If you're really worried about it, then don't install what you (or your programmers) can't audit & maintain.


The only thing that is really guaranteed is the base Vbulletin code.... and they do a pretty fine job

But you pay annually for updates to Vbulletin.

If you didn't, you could be sure that the Vbulletin wouldn't have anywhere near as many updates and timely fixes.
Reply With Quote
 
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01981 seconds
  • Memory Usage 1,767KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD_SHOWPOST
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_box
  • (1)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit_info
  • (1)postbit
  • (1)postbit_onlinestatus
  • (1)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • reputationlevel
  • showthread
Included Files:
  • ./showpost.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showpost_start
  • bbcode_fetch_tags
  • bbcode_create
  • postbit_factory
  • showpost_post
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • showpost_complete