Welcome, Guest. Please login or register.

Author Topic: Latest Posts restored (updated)  (Read 4841 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline KentTopic starter

  • Hero Member
  • *****
  • Join Date: Feb 2002
  • Posts: 680
    • Show only replies by Kent
    • http://amiga.org/modules/mylinks/visit.php?lid=87
Latest Posts restored (updated)
« on: February 13, 2004, 03:39:44 AM »
The latest posts module has now been restored to service.

The Latest posts module has been restored, thanks to the input provided by DaveP and code fix written by Orgin.  Thanks guys.

The Amiga.org development Team
I love the modern age world of this middle age crises America... all these SUVs driving around like there\\\'s gas to spare and then some.

http://www.RequestFocus.com

W. Kent Seaton ~ RequestFocus.com
 

Offline CodeSmith

  • Sr. Member
  • ****
  • Join Date: Sep 2002
  • Posts: 499
    • Show only replies by CodeSmith
Re: Latest Posts removed
« Reply #1 on: February 13, 2004, 04:10:48 AM »
I'd say this is a good thing.  I'd much rather put up with a small amount of inconvenience for a couple weeks, than try to log in one morning and find out that the site got 0wned by some #### who got a canned exploit off some website.
 

Offline that_punk_guy

  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 4526
    • Show only replies by that_punk_guy
Re: Latest Posts removed
« Reply #2 on: February 13, 2004, 04:37:26 AM »
True... but, argh! That's my most-used module!

Ah well :-(
 

Offline weirdami

  • Hero Member
  • *****
  • Join Date: Jan 2003
  • Posts: 3776
    • Show only replies by weirdami
    • Http://Bindingpolymer.com
Re: Latest Posts removed
« Reply #3 on: February 13, 2004, 06:41:42 AM »
I didn't even know there was such a thing. All I ever used was the recent discussions thing on the main page. So, I guess I'm unaffected.
----
Binding Polymer: Keeping you together since 1892.
 

Offline that_punk_guy

  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 4526
    • Show only replies by that_punk_guy
Re: Latest Posts removed
« Reply #4 on: February 13, 2004, 06:44:26 AM »
Well, the only real difference is that Talk-about threads don't appear on the front page. I think that's the only forum that's excluded from the front page.
 

Offline lempkee

  • Hero Member
  • *****
  • Join Date: Apr 2002
  • Posts: 2860
    • Show only replies by lempkee
    • http://www.amigaguru.com
Re: Latest Posts removed
« Reply #5 on: February 13, 2004, 07:06:55 AM »
oh ok, damn i where just about to direct "haymiggan" to amiga.org to download some modules that he could have played in his modplayer :))))

(he axed me for some mods yesterday :))

anyway, i have never heard any music on amiga.org   so i guess thats another pc only feature ? :DDDDDDDDD

/sarcasm OFF
Whats up with all the hate!
 

Offline iamaboringperson

  • Hero Member
  • *****
  • Join Date: Jun 2002
  • Posts: 5744
    • Show only replies by iamaboringperson
Re: Latest Posts removed
« Reply #6 on: February 13, 2004, 07:14:54 AM »
I was wondering what was happenning, I thought you had started to update the site.

That's where I usually start from.



"DoomMaster" would have loved to know about that! :-o


---Edit:

I suppose you can't tell us what the problem was, can you? Please? Pretty please with sugar on top? ? :-)
 

Offline KentTopic starter

  • Hero Member
  • *****
  • Join Date: Feb 2002
  • Posts: 680
    • Show only replies by Kent
    • http://amiga.org/modules/mylinks/visit.php?lid=87
Re: Latest Posts removed
« Reply #7 on: February 13, 2004, 07:42:33 AM »
To keep the security level at a normal level on other Xoops sites, no.  Just know that it was a major security risk, not just for the Amiga.org server, but for your personal computer system as well.  With the right scripts, you could go so far as to potentially pull out a password, or install software to the unknowing user.  I was able to reproduce both with very basic account settings (ie, not using the admin).

I'll leave it at this... it was a very big hole waiting to be hacked.  Not to mention, there are other Xoops sites still using the "Latest Posts" module.  I am working on picking the source appart to create my own module.  I don't think it will be available until after the the new site is already in place and running for a while.  The development has to take the back burner to family, school, and work in that order.  Unfortunately I'm quite swamped at school and family life is no better.

:pint:
I love the modern age world of this middle age crises America... all these SUVs driving around like there\\\'s gas to spare and then some.

http://www.RequestFocus.com

W. Kent Seaton ~ RequestFocus.com
 

Offline uncharted

  • Hero Member
  • *****
  • Join Date: Mar 2002
  • Posts: 1520
    • Show only replies by uncharted
Re: Latest Posts removed
« Reply #8 on: February 13, 2004, 08:45:13 AM »
Is this problem still there in XOOPS2?
 

Offline mikeymike

  • Hero Member
  • *****
  • Join Date: Nov 2002
  • Posts: 3413
  • Country: 00
    • Show only replies by mikeymike
Re: Latest Posts removed
« Reply #9 on: February 13, 2004, 08:53:32 AM »
Quote
Is this problem still there in XOOPS2?

That's something we're looking into atm.

@ everyone
Remember that you can click on the 'forums' link, and talk-about open, you'd get much the same view.
 

Offline DaveP

  • Hero Member
  • *****
  • Join Date: Feb 2002
  • Posts: 2116
    • Show only replies by DaveP
Re: Latest Posts removed
« Reply #10 on: February 13, 2004, 10:51:32 AM »
Kent

Here is an example of the kind of patches it needs:

$topic_title = $myts->makeTboxData4Show($arr["topic_title"]);

                        echo "  ".$topic_title."";

That will "safe" the topic for you and fix the remote code exploit although its not perfect, calling sanitize directly to turn off the use of smileys would be better.


Compliments of amigaworld.net.
Hate figure. :lol:
 

Offline System

  • Full Member
  • ***
  • Join Date: Jul 2003
  • Posts: 199
    • Show only replies by System
    • http://amiga.org
Re: Latest Posts removed
« Reply #11 on: February 13, 2004, 12:02:51 PM »
Quote
Is this problem still there in XOOPS2?
Yes.  Since the author abandoned it, there is no Xoops 2 version of the same module. It could only be adapted.

Wayne
 

Offline DaveP

  • Hero Member
  • *****
  • Join Date: Feb 2002
  • Posts: 2116
    • Show only replies by DaveP
Re: Latest Posts removed
« Reply #12 on: February 13, 2004, 03:00:02 PM »
*cough*

I wrote the code fix and Orgin suggested which method to use from that class ;-)

Not that thats important, oh shut up Dave ;-)


Dave.
Hate figure. :lol:
 

Offline that_punk_guy

  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 4526
    • Show only replies by that_punk_guy
Re: Latest Posts removed
« Reply #13 on: February 13, 2004, 03:25:01 PM »
That's better... :relief:
 

Offline DanDude

  • Hero Member
  • *****
  • Join Date: Feb 2002
  • Posts: 505
    • Show only replies by DanDude
Re: Latest Posts removed
« Reply #14 on: February 13, 2004, 03:26:27 PM »
Good thing you guys caught it in time.

Well Done!  :-)
#AmIRC
mesra.dal.net or hotspeed.dal.net
irc2.beyondirc.net