Go Back   vb.org Archive > Community Discussions > Modification Requests/Questions (Unpaid)
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 10-07-2003, 11:23 PM
RedHot5 RedHot5 is offline
 
Join Date: Aug 2002
Posts: 4
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Admin directory move hack

Hi, I'm kinda new to VB and just purchased my license this month.

I have a community that I run and I spent all last weekend setting up the new board and changing the templates to match what we were used to seeing from our last BB system.

As soon as we went live on the new server, a user who has always been a real pain to us, found his way into the CP and started changing things and deleting users. Needless to say I was ticked.

We found out that he somehow got the password for one of our admin accounts (of which there was only 3) and then through that promoted himself to full admin.

I think that we plugged that security hole however for future security but I thought it would be helpful if I changed the actual location of the /admin directory so ever if he gets another password, he won't know where to get to the /admin directory to log in.

I took a look through all the current hacks but didn't notice anything like this.

I even tried to attempt the hack myself but I keep on running into parts of the code that no matter what I attempt to put in, doesn't want to load the pages properly.

So if anyone knows of this hack already being written or wants to tackle it themselves, I'm open to listening to what you have to say.

Thanks
RH5
Reply With Quote
  #2  
Old 10-07-2003, 11:25 PM
RedHot5 RedHot5 is offline
 
Join Date: Aug 2002
Posts: 4
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I forgot to mention which VB I'm using. I'm using V 2.3.2.

Let me know if you need any more information.
Reply With Quote
  #3  
Old 10-08-2003, 02:27 AM
RedHot5 RedHot5 is offline
 
Join Date: Aug 2002
Posts: 4
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I've been playing around with the PHP files some more and I think I may have figured out all the codes that were giving me trouble.

Right now I've managed to move my admin directory to another directory and I have the board and admin panel working properly, as far as I can tell.

If anyone is interested in this hack let me know and I'll write it up.

Moderators, I think you can close this thread of move it to another appropriate forum.

Thanks
RH5
Reply With Quote
  #4  
Old 10-08-2003, 10:03 AM
Logician's Avatar
Logician Logician is offline
 
Join Date: Nov 2001
Location: inside vb code
Posts: 4,449
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

If you already managed it, my suggestion might be useless to you but I'm giving it anyway for other readers: Instead of hacking vb to change admin dir's location, you could have apply a .htaccess protection to the admin cp & modcp directories so nobody could enter without knowing the directory password even if they know the admin password.. I guess many solutions has already been provided in vb.org to do this (and there maybe even a hack released?)
Reply With Quote
  #5  
Old 10-08-2003, 04:15 PM
RedHot5 RedHot5 is offline
 
Join Date: Aug 2002
Posts: 4
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Logician, thank you for the response to my request. I had read about the posibility of password protecting a directory with Cpanel and thankfully our host is using that software. That will be one of the steps I take to secure our board.

I was up quite late last night trying to track down all the changes that needed to be made to the VB files to allow it support a changed admin directory and while I have the board running quite well, I've hit a wall with images showing up in the admin panel and in the user "post new reply" screen.

When I set the smilie's, icons and avatars to show themselves in the admin panel so that the admin knows what they are selecting the images do not show up in the user post screen and when I change the location of the images in the admin panel they no longer show up there but do show up in the user post screen.

Is there already a way to get the images to show up in both places properly and allow them to be selected and used as normal?

I'll be trying to get this to work tonight but any feedback in the meatime would be very helpful.

Thanks
RH5
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 06:24 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2024, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.05353 seconds
  • Memory Usage 2,197KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (5)post_thanks_box
  • (5)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (5)post_thanks_postbit_info
  • (5)postbit
  • (5)postbit_onlinestatus
  • (5)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete