Register Members List Search Today's Posts Mark Forums Read

Reply
 
Thread Tools
  #1  
Old 18 Nov 2016, 14:42
mscottralston mscottralston is offline
 
Join Date: Apr 2013
Updated MySQL from 5.1 to 5.5, Intermittent Error

Hi folks,

I'm occasionally getting the following error on my forums after my server updated MySQL from 5.1 to 5.5:

Block Disabled:      (Update License Status)  
Suspended or Unlicensed Members Cannot View Code.

I'd love some advice, please! Clearly something is no longer valid in the new version of SQL, but I'm not sure where in vBulletin to edit the syntax, nor what I should be editing it to (some kind of bracketing issue, I'm guessing).

Last edited by TheLastSuperman; 18 Nov 2016 at 22:56. Reason: Removed members site url, if forumrunner is exploitable on his site best not to include the link respectively.
Reply With Quote
  #2  
Old 18 Nov 2016, 15:43
Dave Dave is offline
 
Join Date: Jun 2010
Real name: Dave
That's not related to your MySQL version, in fact, it's someone attempting to hack your forum!
Forumrunner was vulnerable to SQL injection not too long ago. You should immediately delete the forumrunner folder if you don't use it or update it to the latest version if you do use it.
__________________
https://technidev.com - security, development, exploits, vBulletin
dave[at]technidev[dot]com

Contact me for custom vBulletin 3/4 work & server/website management.
Reply With Quote
  #3  
Old 18 Nov 2016, 17:39
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Real name: Lynne
You should also upgrade your site to at least 4.2.2 as 4.2.0 has security issues since it is no longer updates with security patches.
__________________
Former vBulletin.org Staff Member

Try a search before posting for help. Many users won't, and don't, help if the question has been answered several times before.
W3Schools -
Online vBulletin Manual
If I post some CSS and don't say where it goes, put it in the additional.css template.
I will NOT help via PM (you will be directed to post in the forums for help.)
Reply With Quote
  #4  
Old 18 Nov 2016, 20:32
mscottralston mscottralston is offline
 
Join Date: Apr 2013
Wow!

Sorry, I'm new to vBulletin -- where is the forumrunner folder for me to delete, in a vBulletin installation?

--------------- Added 18 Nov 2016 at 20:46 ---------------

Never mind -- that much I found, at least, uninstalled both through the backend and directly by deleting the folder from the server. Sorry to be a pest, but if anyone has suggestions for the best documentation on how to upgrade one's vbulletin installation to a newer patched version, I'll get to reading!
Reply With Quote
  #5  
Old 18 Nov 2016, 22:55
TheLastSuperman's Avatar
TheLastSuperman TheLastSuperman is offline
 
Join Date: Sep 2008
Real name: Michael Miller Jr
Originally Posted by mscottralston View Post
Hi folks,

I'm occasionally getting the following error on my forums after my server updated MySQL from 5.1 to 5.5:


I'd love some advice, please! Clearly something is no longer valid in the new version of SQL, but I'm not sure where in vBulletin to edit the syntax, nor what I should be editing it to (some kind of bracketing issue, I'm guessing).
Dave is correct, see below.

Originally Posted by Dave View Post
That's not related to your MySQL version, in fact, it's someone attempting to hack your forum!
Forumrunner was vulnerable to SQL injection not too long ago. You should immediately delete the forumrunner folder if you don't use it or update it to the latest version if you do use it.
Another one they might try via forumrunner is also:


Block Disabled:      (Update License Status)  
Suspended or Unlicensed Members Cannot View Code.

So if ANYONE is seeing database error emails similar to either of the above posted examples, someone as Dave first mentioned is trying to hack your site and if you have quite a few of either database error email then they're actively and consistently trying to hack your site. As Dave also mentioned, if you're not using it, remove it entirely.

For upgrades mscott, simply follow the information in the manual, if going from 4.x to a higher 4.x it's fairly straight forward (just double-check the required PHP and MySQL versions beforehand).
__________________
Daddy Does Dios and Figs!
https://www.linkedin.com/in/thelastsuperman

Search - Use the search feature to find similar issues/answers.
Information - Include screenshots, copy/pasted error codes, url etc.
Fixed - Please return to your thread/post and let us know how it was fixed!
Thanks - For participating! Click the "Like" on a post if someone helped you!
Reply With Quote
  #6  
Old 19 Nov 2016, 06:35
MarkFL's Avatar
MarkFL MarkFL is offline
 
Join Date: Feb 2014
Real name: Mark
We got a couple of those errors at MHB recently, and I wondered what was up with that since we have Forumrunner disabled. But after reading this thread, I uninstalled it and deleted the folder earlier today.
__________________
Former vBulletin.org Staff Member



Support for my products (as well as updates/new product publishing) has been moved to MHB - vBulletin Products and TAZ - Add-ons
Reply With Quote
  #7  
Old 19 Nov 2016, 12:39
Paul M's Avatar
Paul M Paul M is offline
 
Join Date: Sep 2004
Real name: Paul M
This was noted in the patch announcement

http://www.vbulletin.com/forum/forum...or-vbulletin-4

Please note that you need to update regardless of whether you have Forumrunner enabled.


If you are patched (which you should be) then you dont need to delete anything.
__________________
Former vBulletin.org Staff Member


Cable Forum
Please do not PM me about custom work - I no longer undertake any.
Note: I will not answer support questions via e-mail or PM - please use the relevant thread or forum.
Reply With Quote
  #8  
Old 21 Dec 2016, 16:35
mscottralston mscottralston is offline
 
Join Date: Apr 2013
Hi folks,

I've since updated my forums to 4.2.3, deleted and reinstalled plugins, and so forth, and things were quiet until this morning. I just want to check if the following rapid series of errors (I've gotten over a hundred in an hour) look like hacking to you. Lots of IPs and usernames are attached, though 'JDAntoine' is always the unknown column. Checking in on the username, this is an existing user who was banned some time ago, if that matters.

Database error in vBulletin 4.2.3:

Invalid SQL:

SELECT COUNT(*) AS threads

FROM thread AS thread


WHERE thread.forumid = 2
AND sticky = 0

AND visible = 1
AND thread.postuserid NOT IN (JDAntoine);

MySQL Error : Unknown column 'JDAntoine' in 'where clause'
Error Number : 1054
Request Date : Wednesday, December 21st 2016 @ 11:08:27 AM
Error Date : Wednesday, December 21st 2016 @ 11:08:27 AM
Script : http://REDACTED/forumdisplay.php?2-REDACTED-Discussion
Referrer :
IP Address : 63.239.33.129
Username : MysticTemplar
Classname : vB_Database
MySQL Version :


Database error in vBulletin 4.2.3:

Invalid SQL:

SELECT post.postid, post.attach
FROM post AS post

WHERE post.threadid = 265851
AND post.visible = 1
AND post.userid NOT IN (JDAntoine)

ORDER BY post.dateline
LIMIT 440, 40;

MySQL Error : Unknown column 'JDAntoine' in 'where clause'
Error Number : 1054
Request Date : Wednesday, December 21st 2016 @ 11:08:28 AM
Error Date : Wednesday, December 21st 2016 @ 11:08:28 AM
Thanks for your time, I really appreciate it!

Last edited by mscottralston; 21 Dec 2016 at 16:37. Reason: More information
Reply With Quote
  #9  
Old 21 Dec 2016, 16:38
Dave Dave is offline
 
Join Date: Jun 2010
Real name: Dave
That does not look like a hacking attempt. I guess it's caused by one of your plugins that hooks into forumdisplay_query_threadscount.

Disable all of your plugins one by one and see if at some point the error is gone, that way you can locate the plugin that is the cause of this.
__________________
https://technidev.com - security, development, exploits, vBulletin
dave[at]technidev[dot]com

Contact me for custom vBulletin 3/4 work & server/website management.
Reply With Quote
  #10  
Old 21 Dec 2016, 17:34
mscottralston mscottralston is offline
 
Join Date: Apr 2013
Thanks Dave!
Reply With Quote
  #11  
Old 21 Dec 2016, 18:20
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Real name: Lynne
OR, please check AdminCP > Settings > Options > User Banning Options > Global Ignore and make sure you entered a NUMBER, not a username. It should be the userid, not the username, there.
__________________
Former vBulletin.org Staff Member

Try a search before posting for help. Many users won't, and don't, help if the question has been answered several times before.
W3Schools -
Online vBulletin Manual
If I post some CSS and don't say where it goes, put it in the additional.css template.
I will NOT help via PM (you will be directed to post in the forums for help.)
Reply With Quote
  #12  
Old 21 Dec 2016, 20:48
Paul M's Avatar
Paul M Paul M is offline
 
Join Date: Sep 2004
Real name: Paul M
Lynne is correct, those errors indicate you added a username to the Global Ignore, not a userid.
__________________
Former vBulletin.org Staff Member


Cable Forum
Please do not PM me about custom work - I no longer undertake any.
Note: I will not answer support questions via e-mail or PM - please use the relevant thread or forum.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


New To Site? Need Help?

All times are GMT. The time now is 19:02.

Layout Options | Width: Wide Color: