Register Members List Search Today's Posts Mark Forums Read

Reply
 
Mod Options
Disallow HTML code in Thread Titles Details »
Disallow HTML code in Thread Titles
Mod Version: 1.01, by steadicamop (Member) steadicamop is offline
Developer Last Online: Dec 2014 I like it Show Printable Version Email this Page

This modification is in the archives.
vB Version: 3.6.0 Rating: (0 vote - 0 average) Installs: 18
Released: 03 Sep 2006 Last Update: 03 Sep 2006 Downloads: 73
Not Supported Code Changes  

Disallow HTML code in Thread Titles v1.01

Originally Posted by Staff Note
Staff Note:
Unmodified vBulletin will not evaluate HTML in thread titles. Using this modification without a hack installed that has security vulnerabilities is useless.

Also installing this modification, even with a modification installed that would make your board vulnerable to this type of HTML posting in thread titles, only will give you a false sense of security since there are many other options to exploit this, even without the use of the ">" character.

Everyone is encouraged to remove or update the vulnerable modification instead of using this hack.

Marco van Herwaarden.
By Jason Williams/Andrew Calderbank
03/09/2006

Recently there has been a spate of members posting html redirection code in thread titles, which when parsed on the forum homepage runs and redirects to whatever site they insert into the title.

This code simply disallows the characters < and > from being used in the thread titles, this is also is checked when editing the post.

It's fairly simple but puts to and end members signing up and posting redirect links. I don't know whether you'd class this as a hack or bug fix, but I hope this helps other members who are frustrated with this issue.

2 file edits
1 new phrase

Should be fairly straightforward to install.

**ALWAYS BACK UP FILES BEFORE YOU EDIT THEM!!**

v1.00

Original release

v1.01

Slight code update

Download Now

Only licensed members can download files, Click Here for more information.

Show Your Support

  • To receive notifications regarding updates -> Click to Mark as Installed.
  • This modification may not be copied, reproduced or published elsewhere without author's permission.
Comments
  #2  
Old 03 Sep 2006, 22:05
steadicamop's Avatar
steadicamop steadicamop is offline
 
Join Date: Jul 2004
Real name: Jason Williams
Reserved for updates
Reply With Quote
  #3  
Old 03 Sep 2006, 22:15
Puck 24/7 Puck 24/7 is offline
 
Join Date: Aug 2006
Good idea, steadicamop.

edit: there seems to be a problem in: /includes/functions_newpost.php find:

error:
Warning: preg_match(): Delimiter must not be alphanumeric or backslash in /includes/functions_newpost.php on line 379

Last edited by Puck 24/7; 03 Sep 2006 at 22:37.
Reply With Quote
  #4  
Old 03 Sep 2006, 23:01
steadicamop's Avatar
steadicamop steadicamop is offline
 
Join Date: Jul 2004
Real name: Jason Williams
Originally Posted by Puck 24/7
Good idea, steadicamop.

edit: there seems to be a problem in: /includes/functions_newpost.php find:

error:
Warning: preg_match(): Delimiter must not be alphanumeric or backslash in /includes/functions_newpost.php on line 379
Ok, replace the code for this:


Block Disabled:      (Update License Status)  
Suspended or Unlicensed Members Cannot View Code.

That should solve it.
Reply With Quote
  #5  
Old 03 Sep 2006, 23:04
Paul M's Avatar
Paul M Paul M is offline
 
Join Date: Sep 2004
Real name: Paul M
Both those files have hooks, can these changes not be done via plugins ?
__________________
Former vBulletin.org Staff Member


Cable Forum
Please do not PM me about custom work - I no longer undertake any.
Note: I will not answer support questions via e-mail or PM - please use the relevant thread or forum.
Reply With Quote
  #6  
Old 03 Sep 2006, 23:07
steadicamop's Avatar
steadicamop steadicamop is offline
 
Join Date: Jul 2004
Real name: Jason Williams
I'll look into remaking it as a plugin - I've never dealt with creating plugins before so it's something I will have to my research on.
Reply With Quote
  #7  
Old 03 Sep 2006, 23:08
Snake's Avatar
Snake Snake is offline
 
Join Date: Mar 2005
Location: Cleveland, OH
Real name: Josh
Thanks for this!
Reply With Quote
  #8  
Old 03 Sep 2006, 23:09
Paul M's Avatar
Paul M Paul M is offline
 
Join Date: Sep 2004
Real name: Paul M
Okay, just asking.

I think far more people are likely to make use of it if no file edits are involved.
__________________
Former vBulletin.org Staff Member


Cable Forum
Please do not PM me about custom work - I no longer undertake any.
Note: I will not answer support questions via e-mail or PM - please use the relevant thread or forum.
Reply With Quote
  #9  
Old 03 Sep 2006, 23:10
steadicamop's Avatar
steadicamop steadicamop is offline
 
Join Date: Jul 2004
Real name: Jason Williams
Originally Posted by Paul M
Okay, just asking.

I think far more people are likely to make use of it if no file edits are involved.
Something I'm going to try and do right now
Reply With Quote
  #10  
Old 04 Sep 2006, 00:58
DementedMindz DementedMindz is offline
 
Join Date: Jan 2006
so even if you dont allow html they can still post html in thread titles? if thats the case it seems strange that vbulletin wouldnt patch that. as you could just do this all day long with a google search finding vbulletin sites. would suck to have to use a plugin, hack, php file edit what ever to stop it and secure your site.
Reply With Quote
  #11  
Old 04 Sep 2006, 01:11
Nuguru's Avatar
Nuguru Nuguru is offline
 
Join Date: Jun 2006
Question 3.5.4 Compatible?

Hello,

I was wondering if this security issue applies to 3.5.4 and will this fix work with 3.5.4? Or how to I get the same result making code changes with 3.5.4. Advice would be appreciated.



Thank You,

Nuguru
Reply With Quote
  #12  
Old 04 Sep 2006, 02:59
eclectica eclectica is offline
 
Join Date: Sep 2003
Isn't this a vBulletin bug you are fixing?
Reply With Quote
  #13  
Old 04 Sep 2006, 13:27
chimaira chimaira is offline
 
Join Date: Feb 2005
Originally Posted by steadicamop
Ok, replace the code for this:


Block Disabled:      (Update License Status)  
Suspended or Unlicensed Members Cannot View Code.

That should solve it.
replace what code with that exactly ?


Block Disabled:      (Update License Status)  
Suspended or Unlicensed Members Cannot View Code.

^^ that?
Reply With Quote
  #14  
Old 04 Sep 2006, 14:57
xman_79's Avatar
xman_79 xman_79 is offline
 
Join Date: Jun 2006
Real name: Suleiman
The ideea is very good , but i have a problem.

I wrote in the title a HTMl code and it worked (the html code) . I wrote the second time and the message :Could not find phrase 'nohtml' appeared.


Please tell me how can I solve the problem .

Thanks .

Last edited by xman_79; 04 Sep 2006 at 15:03.
Reply With Quote
  #15  
Old 04 Sep 2006, 15:54
steadicamop's Avatar
steadicamop steadicamop is offline
 
Join Date: Jul 2004
Real name: Jason Williams
you need to add the phrase in the text file, its the last step in the instructions:

In the AdminCP -> Language & Phrases -> Phrase Manager -> Add New Phrase

Phrase Type : Front-End Error Messages
Product : VBulletin
Varname : nohtml
Text : Sorry, you are not allowed to post HTML in Thread titles, please go back and change it.

HTH
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Mod Options

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


New To Site? Need Help?

All times are GMT. The time now is 19:27.

Layout Options | Width: Wide Color: