Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: MOD Implementation
 security leak PM Mod
 New Topic  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

crash
Advanced Member

Netherlands
2064 Posts

Posted - 25 April 2002 :  00:53:07  Show Profile  Visit crash's Homepage
one of my moderators was playing around and found this leak in the PM Mod: he was able to catch a reply i was sending to another member and simply replied me with his findings, including the text i sent to another member... is this problem known?



Crash's Site | Crash is from

RichardKinser
Snitz Forums Admin

USA
16655 Posts

Posted - 25 April 2002 :  00:56:36  Show Profile
how was he able to "Catch a reply"?

Bug reports for MODS, don't belong in the DEV: Bug Reports (Open) Forum. That is only for bugs with the base forum.
Go to Top of Page

RichardKinser
Snitz Forums Admin

USA
16655 Posts

Posted - 25 April 2002 :  01:01:19  Show Profile
Now that I think about it, I do seem to remember something awhile back where you could just randomly put in #'s and it would sometimes come back with a PM from someone else. Thought it was fixed by now though. Is this what you are referring to?

As far as I know, if you have the very latest version, then you should not have that problem. It can be found: here
Go to Top of Page

crash
Advanced Member

Netherlands
2064 Posts

Posted - 25 April 2002 :  01:01:38  Show Profile  Visit crash's Homepage
that he will tell me within a couple of hours (he's off to bed right now)...

sorry for the wrong posting...

(also, if you receive mail from "me" telling you i have some great tool and it includes and .exe: do not open it. someone has been sending emails pretending to be me. i cannot seem to find him/her or even why he/she hacked me. dayve from burningsouls has received one... Richard, please help me with this MSN hack...)



Crash's Site | Crash is from
Go to Top of Page

crash
Advanced Member

Netherlands
2064 Posts

Posted - 25 April 2002 :  01:03:23  Show Profile  Visit crash's Homepage
i use the one included in Huwr's modded code... i was under the impression that it was bugfixed, but apparently not. where can i get this updated file?



Crash's Site | Crash is from
Go to Top of Page

RichardKinser
Snitz Forums Admin

USA
16655 Posts

Posted - 25 April 2002 :  01:03:31  Show Profile
As far as I know, if you have the very latest version, then you should not have that problem. It can be found: here
Go to Top of Page

crash
Advanced Member

Netherlands
2064 Posts

Posted - 25 April 2002 :  01:06:19  Show Profile  Visit crash's Homepage
thanks! can you tell me which file i need to replace, for i have changed my existing ones (to match my site)



Crash's Site | Crash is from
Go to Top of Page

RichardKinser
Snitz Forums Admin

USA
16655 Posts

Posted - 25 April 2002 :  01:08:28  Show Profile
privateread.asp is used to read private messages that you have received. privatesent.asp is used to read private messages that you have sent to others. You should probably update both of them.

But, I'm pretty sure that I did some other modifications, so it might be better if you replaced all of your files with the new ones. You'd have to re-edit them to fit with your site, but I think it would be worth it to have the latest version of it.
Go to Top of Page

RichardKinser
Snitz Forums Admin

USA
16655 Posts

Posted - 25 April 2002 :  01:21:55  Show Profile
crash, you might want to contact Huw first before editing any files. I think Huw had included some additional features in the PM Mod he has in his download. The Ignore feature I believe. This is not in the files I have for download, it is only in Huw's download.
Go to Top of Page

crash
Advanced Member

Netherlands
2064 Posts

Posted - 25 April 2002 :  02:46:39  Show Profile  Visit crash's Homepage
thanks Richard! i will contact Huwr on this matter.

then we still have the hacking thing open... but i'll post another topic about that.

Thanks again for your help!



Crash's Site | Crash is from
Go to Top of Page

crash
Advanced Member

Netherlands
2064 Posts

Posted - 25 April 2002 :  04:31:52  Show Profile  Visit crash's Homepage
here's what my moderator had to say:

Ok here is the explanation, as for the fix I am having to tweak AU 4 to d oit and hammering that out as yet.

When a person is in PM, how far I do not yet know since I have only done the one attempt and got that result. or for that matter when they are anywhere in the forums you get the location and a link to that location. Now what I did did not take me into that PM Box, after sending it simply returned to my own, it did however place the replying to PM in the window with the message. I am going to have to do an if then statement specifically omitting PM's from becoming a link in AU any other pages I am going to have to test out might have you goto admin options once and see what happens, lol





Crash's Site | Crash is from
Go to Top of Page

crash
Advanced Member

Netherlands
2064 Posts

Posted - 25 April 2002 :  12:59:06  Show Profile  Visit crash's Homepage
fix found for it:

in the file active_users.asp, find the code (which i added myself - i see now) that says:
strPage = strPage & fLang(strLangMOD_Ls3kAU_xxxxx)

remove the red part from it to remove the clickable link!

may not be the best bugfix, but i believe that it'll do good as temporary fix!



Crash's Site | Crash is from
Go to Top of Page

Gremlin
General Help Moderator

New Zealand
7528 Posts

Posted - 25 April 2002 :  20:17:14  Show Profile  Visit Gremlin's Homepage
Yes Active_users is what brought this bug to peoples attention a few months back, since then both the PM and Active Users mod have been re-released and if you've upgraded to them you should be fine.

www.daoc-halo.com
Go to Top of Page

crash
Advanced Member

Netherlands
2064 Posts

Posted - 26 April 2002 :  00:55:38  Show Profile  Visit crash's Homepage
it's been fixed. thanks for all the help guys!



Crash's Site | Crash is from
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.5 seconds. Powered By: Snitz Forums 2000 Version 3.4.07