1
rebelus
Re: What do you think about new login in Xoops 2.2
  • 2005/7/24 22:20

  • rebelus

  • Just popping in

  • Posts: 10

  • Since: 2002/7/1 1


Quote:

Mithrandir wrote:
Before you call it paranoic and exaggarated, let me tell you a little story:

A site running with XOOPS 2.0.10 and autologin hack is hacked. How? Because of a hacker being able to construct a cookie that resembles the autologin cookie of an administrator. How did he do that? He used the password hash of the administrator, which he got from the database through an SQL injection hole in the XML-RPC interface. How did he get the password hash? He knew the username of the administrator.

So what is the solution to making sure this doesn't happen again? We first closed the hole in the XML-RPC interface, but is that enough? I don't think so. If another hole appears somewhere else in the core or in a module, we have the whole problem once again.
...


Sory but I disagree!

if somebody can read or write to sql because any reason, can find any user record; there is uid field used many times. It's not hard work to know any user's uid.

If you know uid, you can easyly locate this user's record in the db.

It's realy not necessary to know the user's login name.



2
rebelus
NewBB 1 cokie problem
  • 2005/2/14 22:12

  • rebelus

  • Just popping in

  • Posts: 10

  • Since: 2002/7/1 1


Hi,

Just after upgrade to latest Version of XOOPS (2.0.9.2) the known problem of newbb2 is now for newbb1 !

Our users getting;
Quote:
Bad Request
Your browser sent a request that this server could not understand.
Size of a request header field exceeds server limit.


Cookie: NewBBLastVisit=1108385866; newbb_topic_lastread=a%3A173%3A%7Bi%3A21128%3Bi%3A1104816579%3Bi%3A21100%3Bi%3A1104759570%3Bi%3A21125%3Bi%3A1104759631%3Bi%3A21082%3Bi%........


error at forum pages.

We are not upgrade to newbb2 yet.



3
rebelus
Re: Hiding users from non members
  • 2004/10/28 9:55

  • rebelus

  • Just popping in

  • Posts: 10

  • Since: 2002/7/1 1


Thank You. It's done.

But I think, this option should be regulary in Xoops; it should nt need any hack.

e.g. if userinfo.php was in the users module, by disabling access to this module this problem will be resolved without any hack.
by the way, this is not your problem...

Thank you again.



4
rebelus
xoops session problem
  • 2004/10/27 16:50

  • rebelus

  • Just popping in

  • Posts: 10

  • Since: 2002/7/1 1


Hi,

I'm moved from 1.3 to 2.0.7 last week but I have problem with Custom Session... It does NOT work.

it's interesting, because, I copy all the site content to a sub-domain, create new db and copy all original db to the new one, just chenge db name from mainfile.php: Ooops. all working with my custom session settings.

Any idea how and why ???



5
rebelus
Hiding users from non members
  • 2004/10/27 16:40

  • rebelus

  • Just popping in

  • Posts: 10

  • Since: 2002/7/1 1


Hi.

Is there any way to hide users from non members?

Details: I need non members can read forums and other modules but can NOT see user's profiles. Is it possible?



6
rebelus
Re: time to say goodbye to newbb?
  • 2003/6/24 8:49

  • rebelus

  • Just popping in

  • Posts: 10

  • Since: 2002/7/1 1


Why to change NewBB???

- Does PhpBb or IBF have "threaded view" options ?
(This is very important for looong discussions)
- Is it possible to integrate it with XOOPS "Comments"?
(This is also important for finding a specific user's messages)

I'm fine with NewBB. The one and only question about it "Why there is no Neasted view option like Comments?"



7
rebelus
Re: Login problem when changing language ...
  • 2003/3/10 8:01

  • rebelus

  • Just popping in

  • Posts: 10

  • Since: 2002/7/1 1


nothing to say???



8
rebelus
Login problem when changing language ...
  • 2003/3/7 17:50

  • rebelus

  • Just popping in

  • Posts: 10

  • Since: 2002/7/1 1


I installed xoops2RC2 to my test server. For testing purpose, I'm trying to upgrade from XOOPS 1.3.7

after 4 try, and final fresh install wihth only XOOPS default modules and only default theme, it was OK. But when I try to change language it's fail on login.

I'm just copied standard english language folders to "turkish" folders and just and only changed global.php's 3 lines:

define('_CHARSET', 'ISO-8859-1');
define('_LANGCODE', 'en');
define("XOOPS_USE_MULTIBYTES", "0");
to
define('_CHARSET', 'ISO-8859-9');
define('_LANGCODE', 'tr');
define("XOOPS_USE_MULTIBYTES", "1");

(I try also to change 1 by 1)

after changing "CHARSET' to 'ISO-8859-9' I can't login to the site.

Another situation; i'ts working without any problems until loging out and reentering to the site.

-------------
Additional info: when I'm changing the language to 'english' from db, It's working well again .
Also it's failing when I'm changing default language (english) global.php.


--------------
System Info:
PHP Version: 4.1.2
MySQL Version: 3.23
Apache Version: 1.3.22




TopTop



Login

Who's Online

172 user(s) are online (110 user(s) are browsing Support Forums)


Members: 0


Guests: 172


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Apr 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits