Go Back   vb.org Archive > vBulletin Modifications > Archive > vB.org Archives > vBulletin 2.x > vBulletin 2.x Beta Releases

Reply
 
Thread Tools
Details »»

Version: , by merk merk is offline
Developer Last Online: Mar 2012 Show Printable Version Email this Page

Version: 2.2.x Rating:
Released: 09-20-2001 Last Update: Never Installs: 3
Is in Beta Stage  
No support by the author.

Thats right!

Ive _almost_ finshed the hack, however, it needs to be tested a bit more than what ive done before i can release it.

Im looking for 2/3 beta testers, preferably regulars here, etc,etc

If you think ill want you, pls PM me, or reply here

PS. I would have to say tommorow for the hack, its really only needing some mod testing!

Show Your Support

  • This modification may not be copied, reproduced or published elsewhere without author's permission.

Comments
  #2  
Old 09-21-2001, 07:23 AM
Martz's Avatar
Martz Martz is offline
 
Join Date: Oct 2001
Location: UK
Posts: 156
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Sign me up I got my own version of the panel working now, but I am very keen to see your version and how you have gone about it differently. If possible, I'll beta test the style hack on a fresh forum on my Intranet and check everything is hunky-dorey
Reply With Quote
  #3  
Old 09-21-2001, 07:53 AM
merk merk is offline
 
Join Date: Nov 2001
Location: Canberra, Australia
Posts: 601
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Sure.

Youll need to email me, so i can send you the file.

Im curious, how did you go about it, and what features did you cut?

Basically, ive set it up, so that each mod has a different level of access, depending on what you set.

Some are allowed to edit the same that an admin can, or some cant edit templates, some cant edit the doctype / body tag, and some cant edit the widths.

Pretty simple a guess.

I cut the downloading features, and didnt bother setting up the template/replacment variable stuff.
Reply With Quote
  #4  
Old 09-21-2001, 09:19 AM
Martz's Avatar
Martz Martz is offline
 
Join Date: Oct 2001
Location: UK
Posts: 156
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Firstly - I don't know your e-mail address, I'm hoping I can find your address on your site.

Anyway, what I have done is to copy the styles.php into the /mod directory, and clamped it down by running querys to check which forums the user moderates and has [b]caneditstyles[b] set to 1. If this is the case, the user/moderator may edit the associated style of the forum.

I also put some checks in the modifystyles function, and changed all the "typos" of canmodifystyles to caneditstyles in the admin cp.

It works ok, however I am not confident in my rather dodgy php skills, so I want it to be secure and unhackable. Have you considered people may enter html or php (i dont think its parsed in templates?) which could allow mallicious activity?

Regards,

Martin
Reply With Quote
  #5  
Old 09-21-2001, 10:59 AM
DarkReaper DarkReaper is offline
 
Join Date: Oct 2001
Posts: 429
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

The way you did it sounds like the only reasonable way to do it, check if they have the variable "canmodifystyles" set to 1. I'm assuming you did it this way also merk?

Quote:
Have you considered people may enter html or php (i dont think its parsed in templates?) which could allow mallicious activity?
Youn could not allow them to use phpinclude, which would thwart almost anything malicious they could do.
Reply With Quote
  #6  
Old 09-21-2001, 11:38 AM
Admin's Avatar
Admin Admin is offline
Coder
 
Join Date: Oct 2023
Location: Server
Posts: 1
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Contact me if you wish:
firefly@poolie.net
Reply With Quote
  #7  
Old 09-21-2001, 12:01 PM
merk merk is offline
 
Join Date: Nov 2001
Location: Canberra, Australia
Posts: 601
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

1) The security, is a big issue. So heres what ive done:-

I changed the system for the database storing either 0 or 1 for caneditstyles, to store 0/1/2/3/4. 0= no access, 1= colours, fonts only, 2= table widths+1, 3= DOCTYPE and BODY tags+1+2, 4=templates plus all.


Basically thats how it works

Now, i just have to make my modification to the admincp to allow this, and ill distrobute to you fellas, give me about 30 mintues.
Reply With Quote
  #8  
Old 11-01-2001, 06:40 PM
Snake~eyes Snake~eyes is offline
 
Join Date: Oct 2001
Posts: 191
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I'd be interested and willing to be a beta tester. I have been looking for somthing like this for awhile.

Thx
Reply With Quote
  #9  
Old 11-03-2001, 07:05 PM
SharkY-GA's Avatar
SharkY-GA SharkY-GA is offline
 
Join Date: Oct 2001
Posts: 25
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

As would I... This would make my life a whole lot easier! Hosting team forums is a strain on ya...
Reply With Quote
  #10  
Old 11-04-2001, 12:20 PM
Snake~eyes Snake~eyes is offline
 
Join Date: Oct 2001
Posts: 191
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

i know what ya mean!

Merk! please help!
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 10:51 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.05694 seconds
  • Memory Usage 2,283KB
  • Queries Executed 23 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)modsystem_post
  • (1)navbar
  • (6)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (9)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete