The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
Multiple account login detector (AE Detector) Details »» | |||||||||||||||||||||||||||
Multiple account login detector (AE Detector)
Developer Last Online: Dec 2016
Mod of the Month winner! Top 10 most installed mods for vB3.6! Same plug-in found here: https://vborg.vbsupport.ru/showthread.php?t=107566 There are no differences as this plug-in works with both 3.5 and 3.6 versions of vBulletin. If you are like me and migrated from .threads, a common modification was an "AE detector", a simple mod that saved a cookie of a history of ids logged into on your site. If someone logged into more than one account, you got a PM letting you know that your site was being accessed from multiple accounts. Over the years this was very helpful in identifying users who were posting under multiple accounts (alter-egos!) and users who would return after being banned. You might be wondering why I don't use the vbcookie call - well, thats because on logout all vB cookies are cleared, so we need to store a cookie that is not effected by the login/logout process. New Installation 1. Add New Product with attached XML 2. Go to vBulletin Options -> AE Multiple Login Detection Settings and set your specific settings. Time to install: Easy - 2 minutes. Upgrade If you installed this as a Plug-in manually, you can delete that plugin and install this Product, just make sure to go into the Options and set them accordingly. I hope you find this useful and will click INSTALL if you use it; should it prove useful to enough people I can look at making this installation more automated without the need for edits and an Admin Options page. To upgrade you will want to reimport this XML file and edit your options accordingly. 1.0.3 ----- . Added a check to ensure that users weren't deleted when reporting violations . added htmlspecialchars_uni call to username Note: I am unable to get the call to construct_phrase with $vbphrase['multiplelogin_alert'] to work reliably, as such the $message variable is still set manually inside the plug-in and not via the phrase. If anyone has an idea of why this might not always work, I'm all ears. 1.0.2 ----- . Updated to include exclusion groups, users . Changed so PM is sent by ae sender id 1.0.1 ----- . Released as a Product (thank you PHPGeek2k3 for your help) . Added option to post to a forum versus send a PM (or both) . All settings moved into Admin Option 1.0.0 ----- Initial release. Show Your Support
|
Благодарность от: | ||
too_cool_3 |
Comments |
#472
|
||||
|
||||
I think he is pulling your chain on this hack being the exploit. He got in another way and is directing you to this hack so you won't look elsewhere.
|
#473
|
|||
|
|||
Thank you for the warning Frank. We'll be removing this hack until the issue is resolved.
|
#474
|
||||
|
||||
There is no issue with this hack.
|
#475
|
|||
|
|||
folks, if this hack has an exploit the Crew put this onto the graveyard ...
|
#476
|
||||
|
||||
And it would have showed up way before now. I trust Michael's code.
|
#477
|
|||
|
|||
All i know is it's better safe than sorry. I feel horrible for posting that this hack has an exploit but it does. I have actually seen the exploit in .txt format when he did remote desktop with me earlier today. He didn't mean to shut down the server he said. But who knows if he really did mean to. He has been banned but, i suggest disabling it for now if you have it uploaded to your site.
|
#478
|
||||
|
||||
If you have seen the exploit, please PM me with the proof and I will gladly eat my words. Otherwise, it is not right to label a hack as having exploits unless you can prove it.
|
#479
|
|||
|
|||
Frank if you're sure about this, tell what you know to Marco, Paul or someone ... you cannot came here with these posts ...
|
#480
|
||||
|
||||
I sort of agree. You're misinterpreting the AE Detector output for the problem, when it's only doing what you asked it to.
It could be a lot of exploits. Have you checked versions and updated everything like vbulletin, PHP and MySQL? And - it should go without saying, but change ALL your passwords. |
#481
|
|||
|
|||
exactly!
|
Thread Tools | |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|