The Arcive of vBulletin Modifications Site. |
|
login.php phishing patch Details »»
|
|||||||||||||||||||||||||||
Due to the recently announced Possibly Phishing Vector
I made a small/short patch which should stop a user from being exploited. I've tested this internally and it seems to do the job. Download Now
Supporters / CoAuthors Show Your Support
|
|||||||||||||||||||||||||||
| Comments |
|
#2
|
||||
|
||||
|
If there are other pages, that this can cause problems on, please let me know and I'll see what I can do to resolve it.
|
|
#3
|
|||
|
|||
|
I'm using this for sure. Is this tested and working?
|
|
#4
|
||||
|
||||
|
I tested it as much as I could internally, it shouldn't ever impact normal users, only if someone, or something tries to pass url=X in the url.
|
|
#5
|
||||
|
||||
|
Will this work with all versions of vB?
|
|
#6
|
||||
|
||||
|
This should work on any version of vB4, the hook point im using I'm moderately sure isnt available in vb3.5-8
|
|
#7
|
||||
|
||||
|
Nice. Thank you.
|
|
#8
|
||||
|
||||
|
init_startup is in init.php in 3.8.0. Not sure about earlier.
|
|
#9
|
||||
|
||||
|
How will this affect things like VigLink?
|
|
#10
|
|||
|
|||
|
x2
AND - Does this phising vulnerability effect vB3.8.6? |
![]() |
|
|