Thread: Miscellaneous Hacks - Live Topic
View Single Post
  #360  
Old 02-02-2009, 09:14 AM
p33r p33r is offline
 
Join Date: Sep 2004
Posts: 8
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I saw something curious while installing this on one of our new forums.

"Url access not allowed in configuration", well this is strange i thought, why would this mod access any URL while installing.

wich ofcourse led me to checking out the .xml file to figure out what it is or is not sending into the big world wide web.

Wich very quickly gave me this line of code: eval(base64_decode('ZmlsZV9nZXRfY29udGVudHMoJ2h0dH A6Ly90cmFjay5zY3JpcHRhc3kuY29t L2xpdmV0b3BpYy8xLjA1Yi8nLiRfU0VSVkVSWydIVFRQX0hPU1 QnXSk7'));

Translated into normal code that is: file_get_contents('http://track.scriptasy.com/livetopic/1.05b/'.$_SERVER['HTTP_HOST']);
a simple tracking code.

Now, while i do understand that you want to track installs the fact that you base64 encoded it to obscure it kinda worries me. What else are you thinking of hiding in there? And what is the reason?

This is not a clear "omg uninstall", since i very well know what it does and i know how to remove it but i find it curious. Why not just be upfront about it, why base64 it?

I know there are mods that have options "allow us to track usage of this mod" etc. and i'm sure most people who install would be happy to. It is after all an awesome mod.
Reply With Quote
 
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01306 seconds
  • Memory Usage 1,761KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD_SHOWPOST
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_box
  • (1)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit_info
  • (1)postbit
  • (1)postbit_onlinestatus
  • (1)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • reputationlevel
  • showthread
Included Files:
  • ./showpost.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showpost_start
  • bbcode_fetch_tags
  • bbcode_create
  • postbit_factory
  • showpost_post
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • showpost_complete