The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
Multiple account login detector (AE Detector) Details »» | |||||||||||||||||||||||||||
Multiple account login detector (AE Detector)
Developer Last Online: Dec 2016
Mod of the Month winner! Top 10 most installed mods for vB3.6! Same plug-in found here: https://vborg.vbsupport.ru/showthread.php?t=107566 There are no differences as this plug-in works with both 3.5 and 3.6 versions of vBulletin. If you are like me and migrated from .threads, a common modification was an "AE detector", a simple mod that saved a cookie of a history of ids logged into on your site. If someone logged into more than one account, you got a PM letting you know that your site was being accessed from multiple accounts. Over the years this was very helpful in identifying users who were posting under multiple accounts (alter-egos!) and users who would return after being banned. You might be wondering why I don't use the vbcookie call - well, thats because on logout all vB cookies are cleared, so we need to store a cookie that is not effected by the login/logout process. New Installation 1. Add New Product with attached XML 2. Go to vBulletin Options -> AE Multiple Login Detection Settings and set your specific settings. Time to install: Easy - 2 minutes. Upgrade If you installed this as a Plug-in manually, you can delete that plugin and install this Product, just make sure to go into the Options and set them accordingly. I hope you find this useful and will click INSTALL if you use it; should it prove useful to enough people I can look at making this installation more automated without the need for edits and an Admin Options page. To upgrade you will want to reimport this XML file and edit your options accordingly. 1.0.3 ----- . Added a check to ensure that users weren't deleted when reporting violations . added htmlspecialchars_uni call to username Note: I am unable to get the call to construct_phrase with $vbphrase['multiplelogin_alert'] to work reliably, as such the $message variable is still set manually inside the plug-in and not via the phrase. If anyone has an idea of why this might not always work, I'm all ears. 1.0.2 ----- . Updated to include exclusion groups, users . Changed so PM is sent by ae sender id 1.0.1 ----- . Released as a Product (thank you PHPGeek2k3 for your help) . Added option to post to a forum versus send a PM (or both) . All settings moved into Admin Option 1.0.0 ----- Initial release. Show Your Support
|
Благодарность от: | ||
too_cool_3 |
Comments |
#492
|
||||
|
||||
Look at the code.
|
#493
|
|||
|
|||
I know it was this hack because i have known this guy for 9 years and he lives 5 blocks from me. Look at the aim conversation that him and me had he says it right there. That should be fact enough for any one to investigate it.
|
#494
|
||||
|
||||
This mod is working perfact on vbulletin 3.7.1 [checked creating thread option - not checked pm function as i don't use it.]
|
#495
|
||||
|
||||
There is only one query in this mod; it's used to grab a username for formatting on the post itself. The query is protected by checking for a NULL value and a is_numeric value. If someone were to try an injection, these two checks would prevent it.
What *can* be done is someone can mess with the cookie to make it look like they are logging into a ton of accounts - if they want to throw a ton of userids into the cookie, they can. AE Detector will simply report what's stored in the cookie. Never say never, but this plug-in contains very little code and only one query to the vB user database. |
#496
|
||||
|
||||
Well, I'll say never as to this not being the way in that hacker used on his site.
Welcome back, sir. |
#497
|
||||
|
||||
I have no doubt that someone may have done that to you - but not via this modification. Its simply not possible.
|
#498
|
|||
|
|||
Quote:
|
#499
|
|||
|
|||
Hi Guys,
sorry for posting that here but I have posted it from 17th to "Multiple Account Registration prevation" and I had no answer so far. So I am posting it again here in case you can tell my why. thanks in advance. Quote:
|
#500
|
||||
|
||||
Yes, that would be nice. But if he's trying to avoid getting caught via cookie he can just clear his cookies. Or he could use a different computer.
It's probably not real unusual for us to have a husband & wife discover our forum and register from the same IP within minutes of each other, but on their own computers. Note also as I've pointed out, there's some other mod or something out there disabling this mod. It's working good on one of my forums, but not the other. |
#501
|
|||
|
|||
listen not only can he log in to my account he can edit anything he wants. He can sign into my name and be full admin.
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|