Version: 2.0, by Zero Tolerance
Developer Last Online: Nov 2023
Version: 3.5.0 RC2
Rating:
Released: 07-27-2005
Last Update: 04-22-2006
Installs: 1831
Uses Plugins Template Edits
Additional Files
No support by the author.
[high]Staff Edit/Update[/high]
I have released an updated version of this hack (version 2.0.1), this version fixes some security issues with this hack. All version prior to this one allow users to insert html in their shouts, this can cause problems with them using html that breaks the site layout or malicious javascript. Download the new zip file (vBshout_fixed.zip) and upload the new vbshout.php file to patch/upgrade. If you want to manual instructions they are in the zip file, in the file bugfixes.txt
Second Staff update
I've uploaded a new version of this hack, dubbed '2.0.2'. This one should fix the html injection issues without breaking special characters. To upgrade, download the new zip file and upload the new vbshout.php file.
Please note that this only fixes the html injection issues. I do not use this hack on my own forum (although I've tested this on a client's board) so I will not be fixing the server load issues. I suggest you do not install this hack if you can't deal with the extra server load, as it's rather intensive.
- Brad
[high]End staff edit[/high]
Well, been a while since I've been to vb.org and released anything, thought i'd break the trend and whip up something quick while I have a little spare time.
A shoutbox as you would assume, a very simple one to start off with, but does include AJAX Technology, which pushes the shoutbox 1 step closer to live, messages from other people will appear with no refreshing, and so will yours that you post
A preview is below, i'd estimate a 50 second installation max
Primary Features:
- AJAX Technology (no refreshing)
- Administration control an display element options
- Fast format editor
Change Log::
- v1.1:
WOL (Who's Online) Correction
- v1.2:
New Posting Featurs (Bold/Italic/Underline/Colour/Font)
Admin Controls
- Change location/position of shoutbox
- Change number of shouts displayed
- Switch vbcode/similes on/off
- v1.3
Firefox javascript issue fixed
New Admin Controls
- Command Activation
- Swtch extra format options on/off
- Change position of editor (above/below messages)
New Commands
- /prune (Clears the shoutbox completely)
- /prune [username] (Clears all shouts posted by specified user)
- v1.4
Usergroup HTML Markup For Usernames
Clear Editor Button
Emoticons Pop Up Menu
Time display configurated to vBulletin settings
Username Links To Profile
New Admin Conrols
New vBShout Position (Directly Above Forums)
Banned Users
Banned Usergroups
Banned Permissions
Smilie Pop-Up Box Height
Smilie Pop-Up Box Width
New Commands
"/me" - Action message (all users are able to use this command)
/pruneshout [shout] - Deletes a single shout
- v1.5
Improved Smilies Display
XHTML 1.0 Transitional Valid (couple of errors fixed)
New Admin Options
Shoutbox Height
Smilies To Show
Shout Messages Order
Banned Permissions (fixed)
- v1.6
Bug Fixes:
- Unable to delete shouts that used /me command fixed
- Shouts being displayed from bottom-upwards only showed first 20 shouts
Automatically parses URL's
- v2.0
New Archive
- Displays shouts and pages
- Stats and top 10 shouters
- AJAX Edit/Delete (staff can edit/delete all shouts)
Enjoy,
- Zero Tolerance
Show Your Support
This modification may not be copied, reproduced or published elsewhere without author's permission.
The code I would have thought was some type of re-write code, because it looked like I had placed a passworded directory on my entire site. There was an image, with a red x but nothing showed up, but no text was showing - just the username. I won't post the whole contents on here, because its a public board, but I did a search on Google and it showed up in a number of places.
This is the second attempt within a few days, but the other person tried posting re-direct HTML in in a thread, luckily it failed.
I used to have FlashChat installed, but that now just leaves your site open to attack. Going to see if I can tighten my coding to prevent this happening again.
Please report all Security Vunerabilities to staff via the "Report This Modification" link under Mod Options. The staff will then evaluate your report and the modification, and proceed from there.
Please describe as best you can what happened and the code used...etc...etc..
If you add a " in my shoutbox, it shows up as " in the box. Any fix to this? I've updated it w/ the latest file available for download as of today.
My site was hacked through vbShout this evening. A new member joined and posted code numerous times, which caused a directory popup box to appear, asking for username and password.
that's the same thing that happened on mine, some users were able to get a word in here or there, but I had to ctrl/alt/del and shut down my browser through there.
I noticed that people who hadn't confirmed their emails could use the shoutbox (such as this freeze fellow), so I added that user group to the unable to use option. I also added freeze to the names not allowed on registration heh, because after I banned him he re-registered and had a completley different ip but still used freeze in his name.
I don't know what he typed in the shoutbox because I pruned it as soon as i could, the last thing I seen him say was daaaaaaaannnngeeeeeeerrrrrrrrrr
My site was hacked through vbShout this evening. A new member joined and posted code numerous times, which caused a directory popup box to appear, asking for username and password.
I managed to squeeze in a /prune to override it, and ban the user. I've now closed my site off to new registrations.
Another mod I need to uninstall...shame I liked this as well.