The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
Cyb - Login To User Account Details »» | |||||||||||||||||||||||||||||||||||||
Info:
This will allow forum administrators to simply login to user accounts (to test forum functions, permissions etc...). SuperAdmin can choose admins who are able to use this function. SuperAdmin can set also who can login to other admin accounts. "Login As User" is shown in member profiles and Quick User Links (can be disabled). Option is automatically hidden in your own account and if target user is admin while you have no permissions to login to admin accounts. See screenshots. Installation: 1. Import XML file (as product): AdminCP > Plugin System > Manage Products > [Add/Import Product] Variables: -Link to login to user in memberinfo: $cyb_ltoua_link_mi -Logged in as user alert: $cyb_ltoua_alert To set options: Go to: AdminCP > vBulletin Options > Cyb - Login To Other User Account Versions: v1.0 - May 20. 2006. -First Release v1.1 - May 21. 2006. -Now SuperAdmin can log into other admins v1.2 - Aug 04. 2006. -Release of this hack for vB v3.6 v1.5 - Aug 29. 2006. -Added option to easily go back to admin account -Alert can be enabled/disabled -Added "Product Version Checking" -Only Admins allowed to use function can see "Login As" links -Several code improvements v1.6 - Sep 01. 2006. -Fixed bug (error message at the top of "add new user" page) -Fixed bug (uncached template) v1.7 - Sep 05. 2006. -Now only SuperAdmin can access settings where you choose which Admins can use the hack -You can also set Admins who will be able to use other Admins accounts (only SuperAdmin can set this) -Alert moved to navbar so it is now shown on any page to Admin who is logged in as someone else v1.8 - Apr 23. 2007. -"Last activity" not changed for target user when admin used account -"Login As User" automatically hidden in your own account and if target user is admin and you have no permissions to login to admin accounts -Admin not logged out from ACP when back to original account, except session expired regularly -Added option to modify alert box CSS -Many other code improvements and optimizations -If you have older version of this hack installed please uninstall it before installing latest version or it will not work properly v1.9.1 - Jul 23. 2007. -Fixed bug (Security Exploit) -Fixed bug ("login as user" doesn't work if you access user profile via last post info) -"Go back" alert moved to header (for must of users there is no need to edit custom styles anymore) -Now you can go back from banned user accounts without clearing cookies manually v2.0 - Nov 08. 2007. -New: Actions logged in Moderator Log -Fixed bug where admins with primary usergroup different than 6 are not able to use hack -Several minor bugs fixed --You MUST uninstall older version before installing this one in order to get it working properly v2.1 - May 03. 2008. -Compatible with vBulletin 3.7 -Minor bugs fixed v2.2 - Jun 23. 2008. -Added option to disable logs -Added option to switch to vB 3.6.x compatibility mode -Fixed bug (session lost for target user when you go back to admin) -Fixed bug (sessions lost for guests/bots when you login as another user) -Made several compatibility improvements v2.3 - Apr 11. 2009. -Bug fix (non-Admins able to login to user accounts in some cases) -Bug fix (Admin can not search product entries in ModLog by product ID) -Bug fix (logging error if username contains special characters) -Bug fix (Admin must be member of usergroup 6 to use product) -Minor bugs fixed Click INSTALL if you like this hack. Download Now
Screenshots
Show Your Support
|
Comments |
#62
|
|||
|
|||
Did somebody already cross check versions 3.7, 3.6 and 3.5 if they have the same heavy bug?
btw: every admin using this AddOn should be informed "asap" by eMail as soon as Cybernetec or vb-Admin has confirmed this bug. |
#63
|
|||
|
|||
Here I go again...
Seems like we have a worst-case-scenario... I just tried to "hijack" an admin account of a forum postet in the signatur of an user using the 3.7-Version. Unfortunatly, I was successfull... I now have full access of his forum! Don't worry - I will not do any harm! ADMINs! Please remove all versions of this AddOn & inform every admin to disable this AddOn as soon as possible! If vb-Admins would like to test hijacking forums - send PN an I'll give you some links to vunerable forums. There you can hijack any account you want. Unbelivable!!!! :down: |
#64
|
|||
|
|||
Confirm the Phobos49 called Bug!
|
#65
|
|||
|
|||
Told you it wasnt impossible The only mod that does the same and seems secure right now is:
https://vborg.vbsupport.ru/showthread.php?t=168819 ________ FISTING MILF |
#66
|
|||
|
|||
I think now the problem fixed :P
|
#67
|
|||
|
|||
changelog?
|
#68
|
|||
|
|||
Im currently using this hack for my forum. But how is it possible that somebody easily uses the url ? Does he need an account on the forum or which way does it work ?
|
#69
|
||||
|
||||
a confirmation from cyb will be nice.
Sorry if i ask Cyb, is this mod safe now? can i install it? |
#70
|
||||
|
||||
if this mod safe now, plz edit phobos post above!
|
#71
|
|||
|
|||
Why? Version 2.2 ist absolutly unsafe!
Version 2.3 should be safe now (did not test myself yet). But every admin MUST updated to 2.3 to secure his forum! So I am not going to edit my posting. |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|