![]() |
|
|
Thread Tools |
|
#1
|
|||
|
|||
|
stristr error
I'm getting a very similar error as was mentioned in this thread
I upgraded to ibProArcade v2.7.2+ yesterday and I'm getting this error at the top of the index page of the arcade.
No members have liked this post.
|
| Comments |
|
#2
|
|||
|
|||
|
Just updated and also have this error.
No members have liked this post.
|
|
#3
|
||||
|
||||
|
__________________
ibProArcade-Support-Forum in the Premium-Modification-Section
No members have liked this post.
|
|
#4
|
||||||||
|
||||||||
|
@Hippy
I tried those changes and it did not effect this error. The error points to line 5550... I've looked at the arcade.php file and line 5550 comes up as....
The full context of this section is...
Any help would be appreciated. No members have liked this post.
|
||||||||
|
#5
|
||||
|
||||
|
compare v2.7.1 and 2.7.2 and remove or comment out that code and the link above
stangger5 posted what will work in replace of till Mrz figures out the issue it fixes the security issue I updated 20+ arcade and 1/4 of them don't like this code.. it's a server issue I am guessing
__________________
ibProArcade-Support-Forum in the Premium-Modification-Section
No members have liked this post.
|
|
#6
|
||||||||||||||||||||
|
||||||||||||||||||||
|
I have used stangger5 fix but was getting the reported issue with stristr on a customer forum.
I did the below edit, code will do the same and is simpler. In arcade.php search for the ibp_cleansql function, search for
Add below :
Then search for :
Comment it out :
Add after :
That does the same but is fairly simpler... Though I must admit that Mrz fixed the 2.7.1 security issue rather uglily... That bit of code could remove actual correct content ...
__________________
|
||||||||||||||||||||
|
#7
|
||||
|
||||
|
I didnt upgrade to 2.7.2 for just two edits..
My one edit to the arcade.php file and the mod_arcade.php.. So my arcade doesnt have any of the:
code.. Thanks for the code update VBDev !! ![]()
__________________
vb ibProArcade: Download Game, Game Challenge, Report Game Systems.Plus more can be found here: next-level-arcade.com No members have liked this post.
|
||||
|
#8
|
||||||||||||||||||||||||
|
||||||||||||||||||||||||
|
Originally Posted by VBDev
so it should like this ?
I been using stangger5's edit and works on every update I did.. I am just wondering at this moment.. thanks
__________________
ibProArcade-Support-Forum in the Premium-Modification-Section
The following members like this post: dlewisr
Last edited by Hippy : 29 Apr 2012 at 11:46. |
||||||||||||||||||||||||
|
#9
|
||||
|
||||
|
Yep.
Dunno why but I didn't had that error on my install but a customer had the issue. Anyways I don't know the root cause of this function but honestly that shouldn't be done like that... It removes potential words from comments for example... That sucks ![]() --------------- Added 08 Mar 2012 at 09:53 ---------------
Originally Posted by stangger5
But if I do understand those fixed a security issue but I guess you fixed it manually
![]()
__________________
No members have liked this post.
|
||||
|
#10
|
||||
|
||||
|
The security issue was s_id,, which allowed it to be a string when it was supposed to be a int,, that is what allowed the exploit.
Comments should be ok because of the way strings are put in the database..
__________________
vb ibProArcade: Download Game, Game Challenge, Report Game Systems.Plus more can be found here: next-level-arcade.com No members have liked this post.
Last edited by stangger5 : 10 Mar 2012 at 02:57. |
|
#11
|
||||||||||||||||||||
|
||||||||||||||||||||
|
Originally Posted by VBDev
there is nothing in arcade.php
No members have liked this post.
|
||||||||||||||||||||
|
#12
|
||||
|
||||
|
Originally Posted by stangger5
Yeah, hence what I said he over corrected...
IMO, IBProArcade really needs a cleanup of the code one day... If you haven't installed 2.7.2 there indeed is nothing.
__________________
No members have liked this post.
|
|
#13
|
|||
|
|||
|
No members have liked this post.
|
|
#14
|
||||
|
||||
|
__________________
ibProArcade-Support-Forum in the Premium-Modification-Section
No members have liked this post.
|
![]() |
«
Previous Thread
|
Next Thread
»
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) |
| Thread Tools | |
|
|
| New To Site? | Need Help? |
All times are GMT. The time now is 02:21.




vb ibProArcade: Download Game, Game Challenge, Report Game Systems.

