PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |
Old June 13th, 2005, 07:52 AM   #1 (permalink)
Member
Verified Customer
 
Lizard King's Avatar
 
Join Date: Nov 2005
Posts: 143
Is this exploit or etc ?

A friend of mine gave the following link and adviced me to close down my gallery I don't know about it but here is the link

he is telling me that anyone who knows our gallery folder can control over our sites . Maybe you shall check it

The main thing is if there is a picture a post for moderation anyone can delete or activate the picture or post.
Lizard King is offline  
Old June 13th, 2005, 07:58 AM   #2 (permalink)
Ultimate Member
 
Join Date: Jan 2004
Posts: 2,196
Re: Is this exploit or etc ?

I've moved a copy of your thread to our staff forum for invesitgation.

FYI that is a known pirate board and you should avoid being on it if at all possible
Zachery is offline  
Old June 13th, 2005, 08:08 AM   #3 (permalink)
Borgs8472
Guest
 
Posts: n/a
Re: Is this exploit or etc ?

Yikes, would like info ASAP if you get a fix for this!
 
Old June 13th, 2005, 08:43 AM   #4 (permalink)
Member
Verified Customer
 
Lizard King's Avatar
 
Join Date: Nov 2005
Posts: 143
Re: Is this exploit or etc ?

Quote:
Originally Posted by Zachery
I've moved a copy of your thread to our staff forum for invesitgation.

FYI that is a known pirate board and you should avoid being on it if at all possible
I have no idea what kind of forum it is Zachery , a friend of mine gave me the link and gave me some example links of it. Thats why i opened the thread in here.
Lizard King is offline  
Old June 13th, 2005, 08:46 AM   #5 (permalink)
Member
 
Join Date: Aug 2003
Posts: 98
Re: Is this exploit or etc ?

If thats the bug posted in teh lounge at vb.org, I tried it here on vbadvanced and it seems to work. I also tried it on my forum logged out and seemed to have an effect too.
PhoenixDown21 is offline  
Old June 13th, 2005, 08:52 AM   #6 (permalink)
Ultimate Member
Verified Customer
 
ConqSoft's Avatar
 
Join Date: Nov 2003
Location: Raleigh, NC
Posts: 1,417
Re: Is this exploit or etc ?

Yep. It only affects you if you are using Image or Post moderation in the Gallery. If you are using Image or Post moderation, it appears that the most that can happen is that any un-validated Images or Posts could be deleted.
ConqSoft is offline  
Old June 13th, 2005, 09:12 AM   #7 (permalink)
Junior Member
Verified Customer
 
Join Date: Feb 2005
Posts: 11
Re: Is this exploit or etc ?

Quote:
Originally Posted by ConqSoft
Yep. It only affects you if you are using Image or Post moderation in the Gallery. Otherwise, no damage can be done. If you are using Image or Post moderation, the most that can happen is that any un-validated Images or Posts could be deleted.
Has this been confirmed? That's all it can do? Which versions are effected?
imported_tamarian is offline  
Old June 13th, 2005, 09:13 AM   #8 (permalink)
Brian
Guest
 
Posts: n/a
Re: Is this exploit or etc ?

Quote:
Originally Posted by phoenixdown
If thats the bug posted in teh lounge at vb.org, I tried it here on vbadvanced and it seems to work. I also tried it on my forum logged out and seemed to have an effect too.
How exactly did it work here or on your forums? Did it actually allow you to moderate any images? I've just checked RC3 - 1.0.0 and you cannot validate/delete images unless you are a moderator (unless there's something I'm missing, which I don't think there is). They are correct in saying there is an error where it could allow you to moderate/delete posts though. For anyone that needs to fix this immediately, look in your gallery/moderate.php file for the following code:

Code:
Content visible to verified customers only.
Just Above that, Add:
Code:
Content visible to verified customers only.
 
Old June 13th, 2005, 09:22 AM   #9 (permalink)
Ultimate Member
Verified Customer
 
ConqSoft's Avatar
 
Join Date: Nov 2003
Location: Raleigh, NC
Posts: 1,417
Re: Is this exploit or etc ?

Quote:
Originally Posted by tamarian
Has this been confirmed?
No, not at all. I edited my response a bit. My response is not an official one from vBadvanced.
ConqSoft is offline  
Old June 13th, 2005, 12:25 PM   #10 (permalink)
Member
 
Join Date: Aug 2003
Posts: 98
Re: Is this exploit or etc ?

Quote:
How exactly did it work here or on your forums? Did it actually allow you to moderate any images?
When I tried it here, it brought me to the moderation screen for images and posts but there weren't any for validation so nothing more there.

On mine, I wasn't logged in (this was via IE which I never use and almost exclusively use for testing logged out parts of my site) and managed to validate some posts to the gallery.

I wont be able to patch till I get home. I can moderate posts for a gallery and you can take a look if you want.
PhoenixDown21 is offline  
Old June 13th, 2005, 01:07 PM   #11 (permalink)
Brian
Guest
 
Posts: n/a
Re: Is this exploit or etc ?

Ok, just wanted to make sure there wasn't something I was missing. There are images awaiting moderation on here, but the code to check the category moderator is working properly for those, so it's just a problem with the posts.
 
Old June 13th, 2005, 03:35 PM   #12 (permalink)
Member
Verified Customer
 
Join Date: Dec 2004
Posts: 32
Re: Is this exploit or etc ?

Can you shoot out an email when you do a firm update for this?
corriewf is offline  
Old June 13th, 2005, 04:01 PM   #13 (permalink)
Registered User
Verified Customer
 
KW802's Avatar
 
Join Date: Nov 2005
Posts: 1,408
Re: Is this exploit or etc ?

Quote:
Originally Posted by corriewf
Can you shoot out an email when you do a firm update for this?
Version updates are communicated through the Announcements forum. To get an automated type of email I'd suggest subscribing to the Announcements forum.
KW802 is offline  
Old June 13th, 2005, 04:03 PM   #14 (permalink)
Brian
Guest
 
Posts: n/a
Re: Is this exploit or etc ?

Unfortunatly it's not that easy to send out an email just to the users who have purchased the gallery. As Kevin said though, if you subscribe to the announcements forum then you will be notified of any new posts.
 
 


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 01:21 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0