Thread: Major Additions - DownloadsII
View Single Post
  #3330  
Old 01-28-2009, 10:01 PM
Vaupell's Avatar
Vaupell Vaupell is offline
 
Join Date: Apr 2008
Location: Esbjerg, Denmark
Posts: 1,036
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by jimjam View Post
We just had our databased Nuked by a hacker,

I saw that a new user had uploaded a file called aaaaaaaa, or somthing like that. (don;t know the extension) I noticed it on a "Recent Uploads" mod on the VBadvanced front page. When I had a look in the downloads section the aaaaaaa file was not there, shortly after the site fell over.

Subsequent investigations found these files in the DownloadsII folder. see attached

We do not allow these files to be uploaded, any idea how they got there, I do not want to re-activate the downloads mod just in case. Thanks
Tx for shareing.

I have uploads disabled, but added the magaupload box for members
so they can share through them without limits.

only admiin and supmod can upload actual files.
rest is just shares.


And ive diabled the upload botton so now only share links availible.
Only specified group can share
Find :
Code:
<font size="-3" {$errors['upload']}>{$vbphrase['ecdownloads_upload_a_file']}</font><br />
       <input name="upload" type="file" size="20" />
Replace with
Code:
<!-- Original upload box code start -->
<font size="-3" {$errors['upload']}>{$vbphrase['ecdownloads_upload_a_file']}</font><br />
       <input name="upload" type="file" size="20" /> 
<!--original upload box code end -->

<!-- New remove upload box code start -->
<if condition="is_member_of($bbuserinfo, GROUPID)"><font size="-3" {$errors['upload']}>{$vbphrase['ecdownloads_upload_a_file']}</font><br />
       <input name="upload" type="file" size="20" /> <else></if> 
<!-- new remove upload box code end -->
Change the GROUPID name to which usergroup u want to give acces,, perhaps trustet members.. syntax : '"is_member_of($bbuerinfo, group,group,group)"

See image, left a member login on the right a moderator..

Attachment 93635

hope it helps.
Reply With Quote
 
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01343 seconds
  • Memory Usage 1,786KB
  • Queries Executed 12 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD_SHOWPOST
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_code
  • (1)bbcode_quote
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_box
  • (1)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit_info
  • (1)postbit
  • (1)postbit_onlinestatus
  • (1)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • reputationlevel
  • showthread
Included Files:
  • ./showpost.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showpost_start
  • bbcode_fetch_tags
  • bbcode_create
  • postbit_factory
  • showpost_post
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • showpost_complete