Go Back   vb.org Archive > vBulletin Modifications > Archive > vB.org Archives > vBulletin 2.x > vBulletin 2.x Full Releases

Reply
 
Thread Tools
Improved Thread Preview Hack Details »»
Improved Thread Preview Hack
Version: 1.00, by N!ck N!ck is offline
Developer Last Online: Oct 2008 Show Printable Version Email this Page

Version: 2.2.x Rating:
Released: 03-02-2002 Last Update: Never Installs: 88
 
No support by the author.

The idea for this hack was originally that of Parker Clack, a regular here on vBulletin.org.

What this hack does:
Basically, this hack pops up a little box/window when the mouse is run over a thread title that shows the first three hundred characters of the first post in the thread (that is, the post that started the thread).

Improvements to Parker Clack's hack:
  • Far, far less code...
  • Easier installation (one file edit, one template edit)...
  • Less space usage...the beginning of the first post in each thread is not stored twice - only once now!...

Versions:
3.0: Overgrow's search page thread preview instructions.
2.1: Added some necessary instructions.
2.0 Reduced MySQL queries significantly.
1.0 Initial release.

Comments appreciated...

A version for vbHacker is available here - note: some files may need fixing afterward if they present parse errors!

How to Censor Previews (by nakkid)
See page seven of this thread.

A very important security fix is available here - I have not updated the ZIP, so install it after you install the hack

Show Your Support

  • This modification may not be copied, reproduced or published elsewhere without author's permission.

Comments
  #122  
Old 08-01-2002, 10:43 PM
Massiel Massiel is offline
 
Join Date: Feb 2002
Location: Australia
Posts: 166
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Has this been finalized? Is there one file that has all the fixes in it?
Reply With Quote
  #123  
Old 08-09-2002, 04:05 AM
Schorsch's Avatar
Schorsch Schorsch is offline
 
Join Date: Jul 2002
Location: Germany
Posts: 345
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally posted by Massiel
Has this been finalized? Is there one file that has all the fixes in it?
good question!! would like to know this too!

Schorsch
Reply With Quote
  #124  
Old 08-14-2002, 10:42 AM
2 X Viverridae's Avatar
2 X Viverridae 2 X Viverridae is offline
 
Join Date: Jul 2002
Location: Undisclosed
Posts: 61
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Installed the thread preview, and search preview - works slick!

Thanks a lot for a great hack!
Reply With Quote
  #125  
Old 08-21-2002, 11:37 PM
EnriqueHavoc EnriqueHavoc is offline
 
Join Date: May 2002
Posts: 22
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

could someone please explain how to "run" the tpinstall.php?
Reply With Quote
  #126  
Old 08-22-2002, 12:08 AM
2 X Viverridae's Avatar
2 X Viverridae 2 X Viverridae is offline
 
Join Date: Jul 2002
Location: Undisclosed
Posts: 61
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Sure - upload it to your forum, and then open it with your browser, using the address your_forum_address/tpinstall.php

Hope this helps.
Reply With Quote
  #127  
Old 08-22-2002, 02:12 AM
EnriqueHavoc EnriqueHavoc is offline
 
Join Date: May 2002
Posts: 22
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

thanks very much!

installed and works awesome
Reply With Quote
  #128  
Old 09-10-2002, 03:27 PM
~rc~ ~rc~ is offline
 
Join Date: Mar 2002
Posts: 5
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Hello folks, I'm Overgrow's partner and a security concern was pointed out to me about this hack. Overgrow has been using the version of this hack since he last posted here so I haven't checked to see if his version is the exact same as what you are using now but if you follow the instructions below, it may help you discover if you have security breach in your private forums. Here are the details that were sent to me to help you test it;

---------------------------------------------------------------------------
first of all this is what I came up with since 8:00 tonight or so.
I found ONE way to read the Mods forums. It has in part to do with an "upgrade" by Overgrow made not too long before he left, the Post preview option.

So go to my overgrow, update profile, then options.


View thread previews?
If you select yes, you will get a short preview of the thread when you mouseover the title. yes no



This is part of the problem.
Now while your looking at a thread in the forum listing, drag your mouse over the thread title, a pop-up screen should appear with a snippet of the content of the thread.
At this point I'll consider this part of it is understood.

Now to the next piece.

Go to the top of the page, click forums,
scroll down to the list of current users online.

Click the hyperlink on Currently Active Users.

This brings you to a monitoring page...
I can see what everyone is doing.
I can monitor the movement of the MODS and ADMINS.
This will make sense in a few mins.

Next Subject.
URL Manipulation can let people view all the searches that
people have done.

Here's a link for you to follow of one such search made
by someone with MOD or ADMIN access.

http://www.overgrow.com/edge/search...searchid=502803

With that link I can see what MODS are posting. Give it a shot. Log in as some normal user account and go for it.

Now using this I can gain info about what is being said.
All they have to do is change the number on the end and
they see a different search. Eventually they will stumble across a doozie with lots of sensitive things in the search results.

Here's where the Currently Active page ties into it all, you can
save time by monitoring Mods or Admins activity I can estimate where their searches will be by performing my own search and checking out the #'s and searching that area.

------------------------------------------------------------------------------
Credit goes to The White Rabbit for finding this. The results here may be different for most as I said before, the hack here may have been altered by Overgrow and the results may not be the same for everyone. Anyway, better to check and be sure before you continue to use this hack.

Also, to the Mods/Admins here. This post may used by others as information to gain access to private information on other boards so feel free to modify this post if you feel it may pose a security threat. I for one have done away with this hack and since doing so Overgrow has shown quite an increase in speed. Not sure if this could have been a cause but I am keeping watch. Thanks.
Reply With Quote
  #129  
Old 09-11-2002, 09:02 PM
cobradude cobradude is offline
 
Join Date: Nov 2001
Posts: 93
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Works well on 2.2.7. Thanks.
Reply With Quote
  #130  
Old 09-12-2002, 01:01 AM
cobradude cobradude is offline
 
Join Date: Nov 2001
Posts: 93
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

By the way, I did find one typo in the search.php stuff....

Quote:
11) Find:

################################################## ##########
<a href="showthread.php?s=$session[sessionhash]&threadid=$searchresult[threadid]$highlightwords">$searchresult[threadtitle]</a>
################################################## ##########

12) Replace with:

################################################## ##########
<a href="showthread.php?s=$session[sessionhash]&threadid=$searchresult[threadid]$highlightwords" title="fppreview">$searchresult[threadtitle]</a>
################################################## ##########

13) Save template.
title="fppreview" should be title="$fppreview"
Reply With Quote
  #131  
Old 09-19-2002, 09:36 AM
Learner29's Avatar
Learner29 Learner29 is offline
 
Join Date: Nov 2001
Posts: 174
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

this hack is one of the VERY VERY best ones.

I just love it !!!!!

it is so straightforward, so easy to install, and it just works !!!!!

Thank you a milliono nicksaunders !!!!!
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 07:51 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2024, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.05166 seconds
  • Memory Usage 2,310KB
  • Queries Executed 27 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)modsystem_post
  • (1)navbar
  • (6)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (1)pagenav_pagelinkrel
  • (11)post_thanks_box
  • (11)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (11)post_thanks_postbit_info
  • (10)postbit
  • (11)postbit_onlinestatus
  • (11)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete