XtremeForceGaming Posted March 9, 2006 Posted March 9, 2006 LoL Thank you, I was wondering if IPB was going to go with 2.2.0 next or 2.1.6.. Since 2.2.0 will be coming out its not really worth Upgrading to it once it comes out, reason is it will have no Mods.. So Im going to reinstall the 2.1.4 Files and update it to 2.1.5 .... Now my question is will I need to install the IPB 2.1.x Security Update (03-08-06) Still? If I just download the Upgrade of 2.1.5 now :S , no correct? O and Reason I will install the 2.1.4 Files again is my board is currently 2.1.4 with over 48 MoDs... It has a error where it doesn't show when people are viewing the same Forum / Topic as you, are the last click.. so to fix that Installing all the org. 2.1.4 Files will fix it.. Then Upgrading that to 2.1.5 then Reinstalling each of the 48 Mods to give you a fresh new Board :) Error Free :P
Guest The Rickster Posted March 9, 2006 Posted March 9, 2006 I just upgraded because of the security fix and it went quick and smoothly. The most time consuming thing is uploading the files. :P It was quick, everything went fine and it seems like it's a little easier every time I upgrade. Thanks IPS for the bug fixes and quick update! :thumbsup:
marcele Posted March 9, 2006 Posted March 9, 2006 We agree that it's a great idea - an extra set of eyes never hurts. I've been in talks with a couple of security auditing firms and we are going to shoot for an audit of 2.2. :) That's great to hear Lindy !!
bfarber Posted March 9, 2006 Posted March 9, 2006 @Phil_B - style_images/<foldername>/folder_js_skin/ips_menu_html.js { html += "\n"+'<iframe id="if_' + cid + '" src="' + ipb_var_image_url + '/iframe.html" scrolling="no" frameborder="1" style="position:absolute;top:0px;left:0px;display:none;"></iframe>'+"\n"; } if ( is_ie ) It's also called (nearly identical code) from skin_acp/IPB2_Standard/acp_js_skin/ips_menu_html.js
Bamfer Posted March 9, 2006 Posted March 9, 2006 Ensure that the has_gallery piece has been added inside the function view_profile(), and not just view_card(). Also, because of a bug in Gallery 2.0.4, the member will need to have created at least one new album since upgrading to Gallery 2.0.5, otherwise the key won't be set properly. Now I know I posted a question about this last night but the post seems to have vanished. :blink: Anyway, can something be run in the db to allow those with galleries that don't have the link in their profile to have it show up by running a Query? I tested it and it works like a charm if I create a gallery album but the problem is I only allow one gallery album per member. So this doesn't help those that have a gallery album created already. Also, when I click on SigmaChat in the ACP the page is blank. Is there a fix for this? Thanks! :)
dflorin Posted March 9, 2006 Posted March 9, 2006 the latest security patch (march 8) has a calendar.php file. what exactly does this one fix? the announcement does not say anything about the calendar? (i am waiting for a fix on a confirmed calendar bug)
Logan Posted March 9, 2006 Posted March 9, 2006 http://forums.invisionpower.com/index.php?...dpost&p=1368631 Upon using a comparison program I found no code changes, therefore like Brandon said the fix for the calendar must have just been included in the inital 2.1.5 release.
bfarber Posted March 9, 2006 Posted March 9, 2006 The calendar.php file was included as I was not positive if a particular exploit had been fixed in the main release. Upon reviewing the main 2.1.5 download, the fix was included with the original release and thus the file in the patch is redundant essentially. :) Bamfer - I checked with Adam and he indicated he might be able to add that to 2.0.6...unfortunately to do what you need done it would require at least two queries (one to get the member id's and one to do the update). He said he'd include it with 2.0.6, but there is no definite release date just yet.
dflorin Posted March 9, 2006 Posted March 9, 2006 ok. then that particular bug has to wait next version.
Bamfer Posted March 9, 2006 Posted March 9, 2006 Thanks bfarber! :) What about getting the blank page for SigmaChat in the ACP when I click on the link? Is there a fix for it?
bfarber Posted March 9, 2006 Posted March 9, 2006 Bamfer, I'd submit a ticket. I'll fix it up for you. :) This isn't a known issue however.
Bamfer Posted March 9, 2006 Posted March 9, 2006 bfarber, Out of curiosity I re-uploaded the chatsigma.php from my 2.1.4 backup files. The page is now visible and working properly as far as I can tell. What exactly changed within the chatsigma.php file between the two versions? Could the changes be posted here so I can manually add them?
Logan Posted March 9, 2006 Posted March 9, 2006 Use Beyond Compare, it's excellent for finding code differences: http://scootersoftware.com/
Msb_last Posted March 9, 2006 Posted March 9, 2006 What with this:Invision Power Board Showtopic SQL Injection Vulnerability This issue can be exploited through a web client. The following proof of concept URI is available:http://www.example.com/index.php?showtopic...d=1366158&st=-1[sql*]entry1366158http://www.securityfocus.com/bid/16971/info Next exploit code in few days after latest IPB release ;/
Philip_B Posted March 9, 2006 Posted March 9, 2006 @Phil_B - style_images/<foldername>/folder_js_skin/ips_menu_html.js if ( is_ie ) { html += "\n"+'<iframe id="if_' + cid + '" src="' + ipb_var_image_url + '/iframe.html" scrolling="no" frameborder="1" style="position:absolute;top:0px;left:0px;display:none;"></iframe>'+"\n"; } It's also called (nearly identical code) from skin_acp/IPB2_Standard/acp_js_skin/ips_menu_html.js found it thanks. It seems that this in effect acts as a small DoS attack on the server its used on. The IE bug must in effect add alot of impressions on the iframe.html file which in effect relates to multiple (very fast) hits on the server? Maybe im wrong but i was seeing 155 connections to port 80... which is massive !
Invisionary Posted March 9, 2006 Posted March 9, 2006 Who says we ignore any more posts about the (apparently) bogus SQL injection exploit? :blink:
Michael Posted March 9, 2006 Posted March 9, 2006 Who says we ignore any more posts about the (apparently) bogus SQL injection exploit? :blink: Aye!
Bamfer Posted March 10, 2006 Posted March 10, 2006 Could someone explain why I'm getting this error when I click on Manage Members in the ACP.Forbidden You don't have permission to access /forums/admin.php on this server. Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request. It's happened twice since I upgraded to 2.1.5. I can eventually get to the Manage Members screen but it takes another try to do so.
Will L. Posted March 10, 2006 Posted March 10, 2006 Could someone explain why I'm getting this error when I click on Manage Members in the ACP. [b]Forbidden You don't have permission to access /forums/admin.php on this server. Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.[/b] It's happened twice since I upgraded to 2.1.5. I can eventually get to the Manage Members screen but it takes another try to do so. if you are root-admin check in forums root folder in ftp for any .htaccess files if there is remove it if that does not work try and reupload member.php in sources/action_admin
gmgmaster22 Posted March 10, 2006 Posted March 10, 2006 Um my prgrade is not working lol, can't ge tinto the client center, forgot what I used for email and password cause I have like 4 emails and I think I deleted the message so how can I go to the client upgrade?? I have a link in my admin cp center saying there is an upgrade avliable but when I press it it has like an error message -.-
Bamfer Posted March 10, 2006 Posted March 10, 2006 if you are root-admin check in forums root folder in ftp for any [b].htaccess[/b] files if there is remove it if that does not work try and reupload [b]member.php in sources/action_admin[/b] I don't have a .htaccess file in my forums root folder. Also, I re-uploaded member.php and that didn't work. Everytime I go to Manage members for the first time after logging into the ACP I get that error. I have to hit my back button in order to get to the Manage Member page. :/ My host moved my site twice in two days to differeent servers. Would that cause this problem? Its very frustrating I get that error. *sigh*
Bamfer Posted March 10, 2006 Posted March 10, 2006 Use Beyond Compare, it's excellent for finding code differences: http://scootersoftware.com/ Very nice program. :D Found the problem.//$this->ipsclass->admin->show_inframe( 'http://www.sigmachat.com/' ); Should be: $this->ipsclass->admin->show_inframe( 'http://www.sigmachat.com/' ); Now if I can get that Forbidden Error fixed. >_<
Ravenwillow Posted March 10, 2006 Posted March 10, 2006 INSERT INTO ibf_task_manager VALUES ('', 'Update Topic Views Counter', 'updateviews.php', 1142018340, -1, -1, 3, -1, 'ddce954b5ba1c163bc627ca20725b595', 0, 'Used when topic views are not incremented immediately', 1, 'updateviews', 0, 0); Out of range value adjusted for column 'task_id' at row 1 Every time I try to install the Forums, I'm getting this message. Can someone help me past this?
Recommended Posts
Archived
This topic is now archived and is closed to further replies.