Jump to content
Forum²

AWS

Forum² Admin
  • Posts

    1116
  • Joined

  • Last visited

  • Days Won

    18

Everything posted by AWS

  1. MyBB 1.6.13 is now available from the MyBB website and is a security and maintenance release. [HEADING=3]What’s added/changed in this version?[/HEADING] This release fixes 4 vulnerabilities and 38 reported issues causing incorrect functionality of MyBB. Please be aware that to be able to provide easy to manage updates not all issues have been fixed in this version. Vulnerabilities: Medium Risk: Possibility of executing PHP code through stylesheets – reported by http://community.mybb.com/user-83062.html" target="_blank">TonyS Medium Risk: Possibility of executing PHP code through language files – reported by http://community.mybb.com/user-8582.html" target="_blank">Pirata Nervo Low Risk: A XSS vulnerability in search system (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1840" target="_blank">CVE-2014-1840) Low Risk: Potential weak random string generator reported by – reported by http://community.mybb.com/user-61715.html" target="_blank">1llusion [*]Bugs fixed: http://docs.mybb.com/1613.html#Fixed_Issues">Fixed issues in 1.6.13 https://github.com/mybb/mybb/issues?labels=1.6&state=open">Unfixed issues Please view the http://docs.mybb.com/1613.html" target="_blank">1.6.13 changes on the Docs site for more information about the changes in this version. Please note, that you do need to run the upgrade script for this version. [HEADING=3]Upgrading from 1.6.12 and Other Versions[/HEADING] Before performing any upgrade please remember to backup your forum’s files and database and store them safely. If you have edited core files, including language files, please make sure you make a changelog for these changes so you can make them again (if necessary) once the upgrade is complete. To upgrade, follow the Upgrading process. The upgrade script is required. There are changes to 5 language files. 4 templates have been changed or added. Download and use the http://resources.mybb.com/downloads/changed_files_1613.zip">Changed Files Package (MD5: 5bc0f118fb6da1284b83f51d836796c2) http://docs.mybb.com/Upgrading.html#Beginning_the_Upgrade">Follow the Docs Upgrading Instructions If you’re using MyBB 1.6.11 or lower Download and use the http://resources.mybb.com/downloads/mybb_1613.zip">full 1.6.13 Release Package (MD5: 2fd6083b430d56ca503c7b3baed1286f) http://docs.mybb.com/Upgrading.html#Beginning_the_Upgrade">Follow the Docs Upgrading Instructions [HEADING=3]Reporting MyBB security vulnerabilities[/HEADING] If you think you’ve found a vulnerability in MyBB, we advise you not to publicly post it on these forums or publicly release information about it elsewhere until we’ve had time to prepare and release a patch. As always, you can send through security related messages on the MyBB website from the http://www.mybb.com/contact">Contact Us page or in our http://community.mybb.com/forum-135.html" target="_blank">Private Inquiries forum – where you can start a new thread that only you and the MyBB Team can see. Thanks, MyBB Team [HEADING=1]Note about updated package[/HEADING] Due to a minor issue with the original packages an updated package set has been released. If you installed or updated your forums using either the full or changed files packages prior to 9:30 a.m. on April 27, 2014 GMT please download a fresh package from the links above and replace the following file: admin/modules/style/themes.php You do not need to run the installer or make any further changes. You can use the file verification tool to determine whether you have the latest package, the file above will appear to be modified if you need to download an updated copy. We apologise of any inconvenience. http://feeds.wordpress.com/1.0/comments/blogdotmybbdotcom.wordpress.com/2118/ http://pixel.wp.com/b.gif?host=blog.mybb.com&blog=36724248&post=2118&subd=blogdotmybbdotcom&ref=&feed=1 View the full article
  2. We are releasing patches for IP.Board 3.3.x, IP.Board 3.4.x and IP.Nexus 1.5.x to address three potential file inclusion issues recently reported to us, as well as one cross site scripting issue reported to us. It has been brought to our attention that certain PHP configurations allow for a potential file inclusion security issue through some of our files intended to be run from the command line. We are releasing patches today to resolve this issue. Additionally, it has been brought to our attention that through social engineering it is possible to direct a user to a page which can trigger an XSS (cross site scripting) attach. We are also releasing a patch today to resolve this issue. To apply the patch Simply download the attached zip for your IP.Board version and upload the files to your forum server. You do not need to run any scripts or the upgrade system. The attached zip files also include the patch for IP.Nexus, if you are using IP.Nexus. IP.Board 3.3.x http://community.invisionpower.com/index.php?app=core&module=attach&section=attach&attach_id=57092" http://community.invisionpower.com/filestore/public/style_extra/mime_types/zip.gif" alt="Attached File" /> ;http://community.invisionpower.com/index.php?app=core&module=attach&section=attach&attach_id=57092" 3.3.x.zip ; ;28.75KB ; ;887 downloads IP.Board 3.4.x http://community.invisionpower.com/index.php?app=core&module=attach&section=attach&attach_id=57093" http://community.invisionpower.com/filestore/public/style_extra/mime_types/zip.gif" alt="Attached File" /> ;http://community.invisionpower.com/index.php?app=core&module=attach&section=attach&attach_id=57093" 3.4.x.zip ; ;31.31KB ; ;4985 downloads If you are an IPS Community in the Cloud client running IP.Board 3.3 or above, no further action is necessary as we have already automatically patched your account. If you are using a version older than IP.Board 3.3, you should contact support to upgrade. If you install or upgrade to IP.Board 3.4.6 or IP.Nexus 1.5.9 after the date and time of this post, no further action is necessary as we have already updated the main download zips. We extend our thanks to sijad ( http://community.invisionpower.com/user/194954-sijad/' class='bbc_url' title=''>http://community.invisionpower.com/user/194954-sijad/ ) for notifying us of the file inclusion issue privately and promptly. We extend our thanks to Christian Schneider (@cschneider4711) (http://www.christian-schneider.net/' http://www.christian-schneider.net/) for notifying us of the cross site scripting issue as well. View the full article
  3. We are releasing patches for IP.Board 3.3.x, IP.Board 3.4.x and IP.Nexus 1.5.x to address three potential file inclusion issues recently reported to us, as well as one cross site scripting issue reported to us. It has been brought to our attention that certain PHP configurations allow for a potential file inclusion security issue through some of our files intended to be run from the command line. We are releasing patches today to resolve this issue. Additionally, it has been brought to our attention that through social engineering it is possible to direct a user to a page which can trigger an XSS (cross site scripting) attach. We are also releasing a patch today to resolve this issue. To apply the patch Simply download the attached zip for your IP.Board version and upload the files to your forum server. You do not need to run any scripts or the upgrade system. The attached zip files also include the patch for IP.Nexus, if you are using IP.Nexus. IP.Board 3.3.x http://community.invisionpower.com/index.php?app=core&module=attach&section=attach&attach_id=57092" http://community.invisionpower.com/filestore/public/style_extra/mime_types/zip.gif" alt="Attached File" /> ;http://community.invisionpower.com/index.php?app=core&module=attach&section=attach&attach_id=57092" 3.3.x.zip ; ;28.75KB ; ;http://community.invisionpower.com/filestore/public/style_extra/mime_types/zip.gif" alt="Attached File" /> ;http://community.invisionpower.com/index.php?app=core&module=attach&section=attach&attach_id=57093" 3.4.x.zip ; ;31.31KB ; ;
  4. One of IPS Community Suite 4's main goals was to overhaul the user interface. We wanted to go further than just a few cosmetic changes to the theme, we wanted to examine each part of the user interface and see what could be improved. The community suite has a lot of functionality and there's a lot of tools that we all use regularly so we felt that any improvements on these common areas would be very welcomed. I'd like to focus on such a change in IP.Downloads. IP.Downloads has always had version control. Essentially, this allows you to upload new versions and keep a historical record of the older versions. You can read change logs and even download older versions where allowed. Let's take a look at how IP.Board 3 does it currently: Although there's nothing particularly wrong with this form, we can see that it mixes up the ability to upload a new version with the general file settings such as title and description. The end result is a bit confusing and a little intimidating the first few times you use it. The section to add your change log is a little lost in the file information block. Now lets take a look at how IPS Community Suite 4 handles this: The first step is to enable download revisions for this category inside the Admin CP. Now that this has been enabled, lets navigate to the "File Actions" menu to upload a new version. This loads the "Upload a new version form". As you can see, it's very clean, very easy to follow and isn't cluttered with settings and text fields that you aren't interested in editing. Once you've uploaded your new version, you can see what's new on the file listing page. You can even view previous change logs and the download link without leaving the page. Conclusion As this blog entry shows, IPS Community Suite 4 is really focused on making real improvements to everyday interfaces. We believe that these changes are very important to modernise the suite and to make it as easy to use as possible. [HEADING=3]Attached Thumbnails[/HEADING] http://community.invisionpower.com/filestore/uploads/monthly_02_2014/blogentry-62-0-82359600-1392721791_thumb.png http://community.invisionpower.com/filestore/uploads/monthly_02_2014/blogentry-62-0-06787400-1392721793_thumb.png http://community.invisionpower.com/filestore/uploads/monthly_02_2014/blogentry-62-0-18354000-1392721794_thumb.png http://community.invisionpower.com/filestore/uploads/monthly_02_2014/blogentry-62-0-20084700-1392721795_thumb.png http://community.invisionpower.com/filestore/uploads/monthly_02_2014/blogentry-62-0-35081700-1392721796_thumb.png http://community.invisionpower.com/filestore/uploads/monthly_02_2014/blogentry-62-0-20905400-1392722004_thumb.png http://community.invisionpower.com/blog/1174/entry-9648-40-ipdownloads-version-control/' class='bbc_url' title=''>View the full article View the full article
  5. One of IPS Community Suite 4's main goals was to overhaul the user interface. We wanted to go further than just a few cosmetic changes to the theme, we wanted to examine each part of the user interface and see what could be improved. The community suite has a lot of functionality and there's a lot of tools that we all use regularly so we felt that any improvements on these common areas would be very welcomed. I'd like to focus on such a change in IP.Downloads. IP.Downloads has always had version control. Essentially, this allows you to upload new versions and keep a historical record of the older versions. You can read change logs and even download older versions where allowed. Let's take a look at how IP.Board 3 does it currently: Although there's nothing particularly wrong with this form, we can see that it mixes up the ability to upload a new version with the general file settings such as title and description. The end result is a bit confusing and a little intimidating the first few times you use it. The section to add your change log is a little lost in the file information block. Now lets take a look at how IPS Community Suite 4 handles this: The first step is to enable download revisions for this category inside the Admin CP. Now that this has been enabled, lets navigate to the "File Actions" menu to upload a new version. This loads the "Upload a new version form". As you can see, it's very clean, very easy to follow and isn't cluttered with settings and text fields that you aren't interested in editing. Once you've uploaded your new version, you can see what's new on the file listing page. You can even view previous change logs and the download link without leaving the page. Conclusion As this blog entry shows, IPS Community Suite 4 is really focused on making real improvements to everyday interfaces. We believe that these changes are very important to modernise the suite and to make it as easy to use as possible. Attached Thumbnails http://community.invisionpower.com/blog/1174/entry-9648-40-ipdownloads-version-control/' class='bbc_url' title=''>View the full article View the full article
  6. Disclaimer: look at the date this was posted Following Facebook’s acquisition of the Oculus Rift, the popular Virtual Reality headset crowdfunded by Kickstarter, officials from Facebook contacted us with a similar proposal: purchasing MyBB and developing it into a more full, fun, and professional project. Today, we is pleased to announce that for $3.4 million, Facebook has acquired MyBB. What does this mean for MyBB? MyBB 1.8 will continue as scheduled, being the last of the 1.x series. It will have many new features integrated, such as chat, Facebook log in integration, etc. MyBB 2.0, however, will get an exciting new rewrite and a set release date of April 1, 2015. The new codebase What we’re most excited about is the code. No longer hundreds of thousands of lines long, the MyBB code on your server will shrink down to a simple interface that pings Facebook’s API to gather all the information needed. All forum data will be hosted on Facebook’s servers, offering a secure and fast platform for the database. Your forum’s database will seamlessly upload during the upgrade from 1.8 -> 2.0. The code on your server will remain LGPL as in the 1.x series, combining with Facebook’s server side code for a unique blend of open source and proprietary that will allow for the most modern, fast, and advanced social community software. Users & Profiles Another thing we’re excited for is user integration. No longer will your users need to remember long, complex passwords, as they will be able to login and register via their Facebook account. This will be the only login method, and your user’s data will be merged with Facebook during the upgrade process. The upgrade will auto-detect existing Facebook accounts based on email and merge them together. The profile page on your MyBB install will pull information directly from Facebook! No more is the need to upload avatars or change bios or locations, all will be integrated directly. Messaging Because we’ll be using Facebook accounts for your standard MyBB account, the opportunity for using Facebook’s messaging system is wide open. All members who have messaged each other on MyBB will automatically be made Facebook friends and will be able to carry out their discussion in the way so many members of the community have been asking for: conversation style. Forums & Posts Posts will take on the style of a Facebook post, with replies appearing as comments. This will allow us to utilize Facebook’s comment history and like features. Images will become the only form of attachments, and will display inline just like in a Facebook comment! Mobile Access This feature makes us especially happy: any MyBB forum will be accessible via the Facebook iOS or Android app! There will be no more need for a mobile MyBB theme or plugin, as the Facebook app will handle it all. Additional Features Mass emails will no longer require a mail server, but will send as a group message via Facebook. Facebook style notifications will also be on your forum, as well as the ability for members to create and moderate their own groups. Best of all, however, your new forum will be browsable by Oculus Rift. We’re excited as a team for this new opportunity and have more exciting announcements for you in the near future! … April Fools! http://pixel.wp.com/b.gif?host=blog.mybb.com&blog=36724248&post=2110&subd=blogdotmybbdotcom&ref=&feed=1 View the full article
  7. Disclaimer: look at the date this was posted Following Facebook’s acquisition of the Oculus Rift, the popular Virtual Reality headset crowdfunded by Kickstarter, officials from Facebook contacted us with a similar proposal: purchasing MyBB and developing it into a more full, fun, and professional project. Today, we is pleased to announce that for $3.4 million, Facebook has acquired MyBB. [HEADING=3]What does this mean for MyBB?[/HEADING] MyBB 1.8 will continue as scheduled, being the last of the 1.x series. It will have many new features integrated, such as chat, Facebook log in integration, etc. MyBB 2.0, however, will get an exciting new rewrite and a set release date of April 1, 2015. [HEADING=3]The new codebase[/HEADING] What we’re most excited about is the code. No longer hundreds of thousands of lines long, the MyBB code on your server will shrink down to a simple interface that pings Facebook’s API to gather all the information needed. All forum data will be hosted on Facebook’s servers, offering a secure and fast platform for the database. Your forum’s database will seamlessly upload during the upgrade from 1.8 -> 2.0. The code on your server will remain LGPL as in the 1.x series, combining with Facebook’s server side code for a unique blend of open source and proprietary that will allow for the most modern, fast, and advanced social community software. [HEADING=3]Users & Profiles[/HEADING] Another thing we’re excited for is user integration. No longer will your users need to remember long, complex passwords, as they will be able to login and register via their Facebook account. This will be the only login method, and your user’s data will be merged with Facebook during the upgrade process. The upgrade will auto-detect existing Facebook accounts based on email and merge them together. The profile page on your MyBB install will pull information directly from Facebook! No more is the need to upload avatars or change bios or locations, all will be integrated directly. [HEADING=3]Messaging[/HEADING] Because we’ll be using Facebook accounts for your standard MyBB account, the opportunity for using Facebook’s messaging system is wide open. All members who have messaged each other on MyBB will automatically be made Facebook friends and will be able to carry out their discussion in the way so many members of the community have been asking for: conversation style. [HEADING=3]Forums & Posts[/HEADING] Posts will take on the style of a Facebook post, with replies appearing as comments. This will allow us to utilize Facebook’s comment history and like features. Images will become the only form of attachments, and will display inline just like in a Facebook comment! [HEADING=3]Mobile Access[/HEADING] This feature makes us especially happy: any MyBB forum will be accessible via the Facebook iOS or Android app! There will be no more need for a mobile MyBB theme or plugin, as the Facebook app will handle it all. [HEADING=3]Additional Features[/HEADING] Mass emails will no longer require a mail server, but will send as a group message via Facebook. Facebook style notifications will also be on your forum, as well as the ability for members to create and moderate their own groups. Best of all, however, your new forum will be browsable by Oculus Rift. We’re excited as a team for this new opportunity and have more exciting announcements for you in the near future! … April Fools! http://feeds.wordpress.com/1.0/comments/blogdotmybbdotcom.wordpress.com/2110/ http://pixel.wp.com/b.gif?host=blog.mybb.com&blog=36724248&post=2110&subd=blogdotmybbdotcom&ref=&feed=1 View the full article
  8. Quick test. [ATTACH]2[/ATTACH]
  9. Welcome to the community.
  10. Welcome to the community.
  11. Welcome Matthew to the vBulletin Support Team. Matthew will be focusing primarily on the Forums at this time and will proceed to general support over time. Matthew has been an active contributor here at vBulletin.com and at vBulletin.org over the years going by the user name of Squall14716 and Link14716 at each site, respectively. We're please to have him helping our customers. View the full article
  12. Welcome Matthew to the vBulletin Support Team. Matthew will be focusing primarily on the Forums at this time and will proceed to general support over time. Matthew has been an active contributor here at vBulletin.com and at vBulletin.org over the years going by the user name of Squall14716 and Link14716 at each site, respectively. We're please to have him helping our customers. View the full article
  13. Try posting at http://dotnetforum.net for c sharp help.
  14. Try posting at http://dotnetforum.net for c sharp help.
  15. Due to circumstances beyond our control, we will be unable to provide telephone sales and support today. We are sorry for the inconvenience and will update you on any further changes. View the full article
  16. Due to circumstances beyond our control, we will be unable to provide telephone sales and support today. We are sorry for the inconvenience and will update you on any further changes. View the full article
  17. vBulletin has released a security patch to improve the security of the vBulletin 4 MAPI for 4.1.12 Suite & Forum as the result of a recent internal security review. Although no exploits have been reported, we urge our customers to upgrade as soon as possible. The changes do not affect vBulletin 4.0.0 - 4.1.1. This patch has been issued for vBulletin 4.1.12. A separate set of patches have been issued for vBulletin 4.1.2 - 4.1.11. The MAPI security improvements have been added for vBulletin 3.x with the release of 3.x MAPI 1.4.3. To improve the security of your vBulletin 4 installation, please download the patch from the members area of vBulletin: http://members.vbulletin.com/" target="_blank">http://members.vbulletin.com/ In addition to the security improvements, we've resolved the following 4.1.12 issues. http://tracker.vbulletin.com/browse/VBIV-14742" target="_blank">VBIV-14742 - Push notifications broken in FR 4.1.12 add-on. http://tracker.vbulletin.com/browse/VBIV-14685" target="_blank">VBIV-14685 - Tag in static page cause Fatal error on page with General Search widget set to return Static Pages http://tracker.vbulletin.com/browse/VBIV-14663" target="_blank">VBIV-14663 - Quoting doesn't work in the mobile style http://tracker.vbulletin.com/browse/VBIV-14660" target="_blank">VBIV-14660 - Static HTML in CMS always displays all content http://tracker.vbulletin.com/browse/VBIV-14754" target="_blank">VBIV-14754 - unset($VB_API_PARAMS_TO_VERIFY['vbseourl']) to match vB3 MAPI change. http://tracker.vbulletin.com/browse/VBIV-14681" target="_blank">VBIV-14681 - HTML is stripped from article previews http://tracker.vbulletin.com/browse/VBIV-14667" target="_blank">VBIV-14667 - Category pages do not load if using basic/advanced friendly URLs The upgrade process requires a few additional steps for this patch level release. Download PL1 for vBulletin 4.1.12 from https://members.vbulletin.com/" target="_blank">https://members.vbulletin.com. Extract the vBulletin patch files from the zip file. Upload the patch files to your server, overwriting the old files. Run yourdomain.com/forumfolder/install/upgrade.php. (Required for 4.1.12.) Download the "API-Log-Clean.xml" attached to this thread. (Included in the do_not_upload folder for full installs.) Import "API-Log-Clean.xml" using the "Manage Products" interface in the "Plugins & Products" section of your Admin CP. The cleanup script will run on install. (This is only required if you have logging turned on for MAPI.) AdminCP -> Plugins & Products -> Manage Products -> Add/Import Product Delete "API-Log-Clean" using the "Product Manager" option in the "Plugins & Products" section of your Admin CP. (Optional. The product is automatically disabled after the script runs.) Advanced Users - Files updated in the patch are: /api.php /forumrunner/push.php /includes/class_friendly_url.php /includes/init.php /install/vbulletin-mobile-style-blog.xml /install/vbulletin-mobile-style.xml /packages/vbcms/content/phpeval.php /packages/vbcms/content/staticpage.php /packages/vbcms/item/content/article.php /packages/vbcms/item/content/phpeval.php /packages/vbcms/search/result/staticpage.php Please note that this issue and fix affects BOTH vBulletin 4 SUITE and FORUM. Discuss the security patch - https://www.vbulletin.com/forum/showthread.php/400166-Discuss-the-MAPI-security-patch-for-vBulletin-4-1-2-4-1-12-Forum-amp-Suite?p=2286633#post2286633" target="_blank">HERE Discuss vBulletin 4.1.12 - https://www.vbulletin.com/forum/showthread.php/398902-4-1-12-Feedback-amp-Discussion" target="_blank">HERE Attached Files https://www.vbulletin.com/forum/attachment.php?attachmentid=59044&d=1335223929" target="_blank">API-Log-Clean.xml‎ (1.9 KB) View the full article
  18. vBulletin has released a security patch to improve the security of the vBulletin 4 MAPI for 4.1.12 Suite & Forum as the result of a recent internal security review. Although no exploits have been reported, we urge our customers to upgrade as soon as possible. The changes do not affect vBulletin 4.0.0 - 4.1.1. This patch has been issued for vBulletin 4.1.12. A separate set of patches have been issued for vBulletin 4.1.2 - 4.1.11. The MAPI security improvements have been added for vBulletin 3.x with the release of 3.x MAPI 1.4.3. To improve the security of your vBulletin 4 installation, please download the patch from the members area of vBulletin: http://members.vbulletin.com/" target="_blank]http://members.vbulletin.com/ In addition to the security improvements, we've resolved the following 4.1.12 issues. [li]http://tracker.vbulletin.com/browse/VBIV-14742" target="_blank]VBIV-14742 - Push notifications broken in FR 4.1.12 add-on.[li]http://tracker.vbulletin.com/browse/VBIV-14685" target="_blank]VBIV-14685 - Tag in static page cause Fatal error on page with General Search widget set to return Static Pages[li]http://tracker.vbulletin.com/browse/VBIV-14663" target="_blank]VBIV-14663 - Quoting doesn't work in the mobile style[li]http://tracker.vbulletin.com/browse/VBIV-14660" target="_blank]VBIV-14660 - Static HTML in CMS always displays all content[li]http://tracker.vbulletin.com/browse/VBIV-14754" target="_blank]VBIV-14754 - unset($VB_API_PARAMS_TO_VERIFY['vbseourl']) to match vB3 MAPI change.[li]http://tracker.vbulletin.com/browse/VBIV-14681" target="_blank]VBIV-14681 - HTML is stripped from article previews[li]http://tracker.vbulletin.com/browse/VBIV-14667" target="_blank]VBIV-14667 - Category pages do not load if using basic/advanced friendly URLs The upgrade process requires a few additional steps for this patch level release. https://members.vbulletin.com.[li]Extract the vBulletin patch files from the zip file.[li]Upload the patch files to your server, overwriting the old files.[li] Run yourdomain.com/forumfolder/install/upgrade.php. (Required for 4.1.12.)[li] Download the "API-Log-Clean.xml" attached to this thread. (Included in the do_not_upload folder for full installs.)[li] Import "API-Log-Clean.xml" using the "Manage Products" interface in the "Plugins & Products" section of your Admin CP. The cleanup script will run on install. (This is only required if you have logging turned on for MAPI.) AdminCP -> Plugins & Products -> Manage Products -> Add/Import Product[li] Delete "API-Log-Clean" using the "Product Manager" option in the "Plugins & Products" section of your Admin CP. (Optional. The product is automatically disabled after the script runs.) Advanced Users - Files updated in the patch are: [li] /api.php[li] /forumrunner/push.php[li] /includes/class_friendly_url.php[li] /includes/init.php[li] /install/vbulletin-mobile-style-blog.xml[li] /install/vbulletin-mobile-style.xml[li] /packages/vbcms/content/phpeval.php[li] /packages/vbcms/content/staticpage.php[li] /packages/vbcms/item/content/article.php[li] /packages/vbcms/item/content/phpeval.php[li] /packages/vbcms/search/result/staticpage.php Please note that this issue and fix affects BOTH vBulletin 4 SUITE and FORUM. Discuss the security patch - https://www.vbulletin.com/forum/showthread.php/400166-Discuss-the-MAPI-security-patch-for-vBulletin-4-1-2-4-1-12-Forum-amp-Suite?p=2286633#post2286633" target="_blank]HERE Discuss vBulletin 4.1.12 - https://www.vbulletin.com/forum/showthread.php/398902-4-1-12-Feedback-amp-Discussion" target="_blank]HERE Attached Files https://www.vbulletin.com/forum/attachment.php?attachmentid=59044&d=1335223929" target="_blank]API-Log-Clean.xml‎ (1.9 KB) View the full article
  19. vBulletin has released a security patch to improve the security of the vBulletin 4 MAPI (4.1.2 - 4.1.11 Suite & Forum) as the result of a recent internal security review. Although no exploits have been reported, we urge our customers to upgrade as soon as possible. The changes do not affect vBulletin 4.0.0 - 4.1.1. This patch has been issued for vBulletin 4.1.2 through 4.1.11. A separate PL1 has been issued for vBulletin 4.1.12. These MAPI security improvements have been added for vBulletin 3.x with the release of 3.x MAPI 1.4.3. To improve the security of your vBulletin 4 installation, please download the patch from the members area of vBulletin: http://members.vbulletin.com/" target="_blank">http://members.vbulletin.com/ The upgrade process requires a few additional steps for this patch level release. Download PL1 for the version of vBulletin you're currently running from https://members.vbulletin.com/" target="_blank">https://members.vbulletin.com/patches.php" target="_blank">https://members.vbulletin.comhttps://members.vbulletin.com/patches.php" target="_blank">/patches.php. Extract the vBulletin patch files from the zip file. Upload the patch files to your server, overwriting the old files. Download the "API-Log-Clean.xml" attached to this thread. (Included in the do_not_upload folder for full installs.) Import "API-Log-Clean.xml" using the "Manage Products" interface in the "Plugins & Products" section of your Admin CP. The cleanup script will run on install. (This is only required if you have logging turned on for MAPI.) AdminCP -> Plugins & Products -> Manage Products -> Add/Import Product Delete "API-Log-Clean" using the "Product Manager" option in the "Plugins & Products" section of your Admin CP. (Optional. The product is automatically disabled after the script runs.) Advanced Users - Files updated in the patch are: includes/init.php Please note that this issue and fix affects BOTH vBulletin 4 SUITE and FORUM. Discuss the security patch - https://www.vbulletin.com/forum/showthread.php/400166-Discuss-the-MAPI-security-patch-for-vBulletin-4-1-2-4-1-12-Forum-amp-Suite?p=2286633#post2286633" target="_blank">HERE Attached Files https://www.vbulletin.com/forum/attachment.php?attachmentid=59043&d=1335223883" target="_blank">API-Log-Clean.xml‎ (1.9 KB) View the full article
  20. vBulletin has released a security patch to improve the security of the vBulletin 4 MAPI (4.1.2 - 4.1.11 Suite & Forum) as the result of a recent internal security review. Although no exploits have been reported, we urge our customers to upgrade as soon as possible. The changes do not affect vBulletin 4.0.0 - 4.1.1. This patch has been issued for vBulletin 4.1.2 through 4.1.11. A separate PL1 has been issued for vBulletin 4.1.12. These MAPI security improvements have been added for vBulletin 3.x with the release of 3.x MAPI 1.4.3. To improve the security of your vBulletin 4 installation, please download the patch from the members area of vBulletin: http://members.vbulletin.com/" target="_blank]http://members.vbulletin.com/ The upgrade process requires a few additional steps for this patch level release. https://members.vbulletin.com/patches.php" target="_blank]/patches.php.[li]Extract the vBulletin patch files from the zip file.[li]Upload the patch files to your server, overwriting the old files.[li] Download the "API-Log-Clean.xml" attached to this thread. (Included in the do_not_upload folder for full installs.)[li] Import "API-Log-Clean.xml" using the "Manage Products" interface in the "Plugins & Products" section of your Admin CP. The cleanup script will run on install. (This is only required if you have logging turned on for MAPI.) AdminCP -> Plugins & Products -> Manage Products -> Add/Import Product[li] Delete "API-Log-Clean" using the "Product Manager" option in the "Plugins & Products" section of your Admin CP. (Optional. The product is automatically disabled after the script runs.) Advanced Users - Files updated in the patch are: [li]includes/init.php Please note that this issue and fix affects BOTH vBulletin 4 SUITE and FORUM. Discuss the security patch - https://www.vbulletin.com/forum/showthread.php/400166-Discuss-the-MAPI-security-patch-for-vBulletin-4-1-2-4-1-12-Forum-amp-Suite?p=2286633#post2286633" target="_blank]HERE Attached Files https://www.vbulletin.com/forum/attachment.php?attachmentid=59043&d=1335223883" target="_blank]API-Log-Clean.xml‎ (1.9 KB) View the full article
  21. To support the upcoming release of vBulletin Mobile Suite 1.3, which contains vBulletin's iOS Mobile App 1.3 and Android Mobile App 1.3, we have released vBulletin 3.x MAPI Plugin 1.4.3. This release contains http://tracker.vbulletin.com/secure/IssueNavigator.jspa?reset=true&jqlQuery=project+%3D+VBM+AND+fixVersion+%3D+%221.4.3%22+ORDER+BY+priority+DESC%2C+key+DESC" target="_blank">nine changes required to fix existing mobile app issues on forums running vBulletin 3. A security patch has been included to improve the security of the vBulletin 3.x MAPI plugin as the result of a recent internal security review. Although no exploits have been reported, we urge our customers to upgrade as soon as possible. vBulletin 3 customers should not upgrade unless they have the https://www.vbulletin.com/order/index.php?do=step1" target="_blank">vBulletin Mobile Suite. vBulletin 3.x MAPI Plugin 1.4.3 is compatible with vBulletin 3.7.5+. vBulletin Blogs customers must have https://www.vbulletin.com/forum/showthread.php/395802-vBulletin-Blogs-2-0-4-has-been-released" target="_blank">Blogs 2.0.4 installed before upgrading to 3.x MAPI Plugin 1.4.3. Please visit your http://members.vbulletin.com/" target="_blank">vBulletin Members Area to download it. The following additional steps need to be taken after upgrade to vBulletin 3.x MAPI Plugin 1.4.3. Download the "API-Log-Clean.xml" attached to this thread. (Included in the do_not_upload folder for full installs.) Import "API-Log-Clean.xml" using the "Manage Products" interface in the "Plugins & Products" section of your Admin CP. The cleanup script will run on install. AdminCP -> Plugins & Products -> Manage Products -> Add/Import Product Delete "API-Log-Clean" using the "Product Manager" option in the "Plugins & Products" section of your Admin CP. (Optional. The product is automatically disabled after the script runs.) Discuss the vBulletin 3.x MAPI Plugin 1.4.3 release - https://www.vbulletin.com/forum/showthread.php/400163-vBulletin-3-x-MAPI-Plugin-1-4-3-feedback-thread?p=2286630#post2286630" target="_blank">HERE Attached Files https://www.vbulletin.com/forum/attachment.php?attachmentid=59042&d=1335223773" target="_blank">API-Log-Clean.xml‎ (1.9 KB) View the full article
  22. To support the upcoming release of vBulletin Mobile Suite 1.3, which contains vBulletin's iOS Mobile App 1.3 and Android Mobile App 1.3, we have released vBulletin 3.x MAPI Plugin 1.4.3. This release contains http://tracker.vbulletin.com/secure/IssueNavigator.jspa?reset=true&jqlQuery=project+%3D+VBM+AND+fixVersion+%3D+%221.4.3%22+ORDER+BY+priority+DESC%2C+key+DESC" target="_blank]nine changes required to fix existing mobile app issues on forums running vBulletin 3. A security patch has been included to improve the security of the vBulletin 3.x MAPI plugin as the result of a recent internal security review. Although no exploits have been reported, we urge our customers to upgrade as soon as possible. vBulletin 3 customers should not upgrade unless they have the https://www.vbulletin.com/order/index.php?do=step1" target="_blank]vBulletin Mobile Suite. vBulletin 3.x MAPI Plugin 1.4.3 is compatible with vBulletin 3.7.5+. vBulletin Blogs customers must have https://www.vbulletin.com/forum/showthread.php/395802-vBulletin-Blogs-2-0-4-has-been-released" target="_blank]Blogs 2.0.4 installed before upgrading to 3.x MAPI Plugin 1.4.3. Please visit your http://members.vbulletin.com/" target="_blank]vBulletin Members Area to download it. The following additional steps need to be taken after upgrade to vBulletin 3.x MAPI Plugin 1.4.3. Plugins & Products -> Manage Products -> Add/Import Product[li] Delete "API-Log-Clean" using the "Product Manager" option in the "Plugins & Products" section of your Admin CP. (Optional. The product is automatically disabled after the script runs.) Discuss the vBulletin 3.x MAPI Plugin 1.4.3 release - https://www.vbulletin.com/forum/showthread.php/400163-vBulletin-3-x-MAPI-Plugin-1-4-3-feedback-thread?p=2286630#post2286630" target="_blank]HERE Attached Files https://www.vbulletin.com/forum/attachment.php?attachmentid=59042&d=1335223773" target="_blank]API-Log-Clean.xml‎ (1.9 KB) View the full article
  23. As we http://www.phpbb.com/community/viewtopic.php?f=14&t=2153062" class="postlink">excitedly announced last month, phpBB is participating in Google Summer of Code 2012. phpBB received a large number of fantastic proposals and we have had a blast getting to know some of the applicants over the past few weeks. Our mentors dedicated their utmost attention to carefully ranking the entries and filling the provided slots with proposals that we feel will have the greatest benefit for the phpBB community. We sincerely wish that we could accommodate every worthwhile proposal, however resources are limited and we are focusing on facilitating the best possible experience for our winners. Without further adieu, it is my pleasure to announce our 2012 GSoC winners (In no particular order): Search Backend Refactoring by Dhruv Goel, India Dhruv will focus on enabling proper abstraction in the search system and allowing for individual backends to modify the user interface. He will also integrate Sphinx and PostgreSQL Fulltext search into the phpBB codebase. Attachment Improvements by Kim Mantas, Hong Kong & UK Kim will improve both the interface and functionality of the attachment system by implementing multiple file uploads, an improved user interface and a tool for downloading several attachments at once. http://www.google-melange.com/gsoc/proposal/review/google/gsoc2012/hardolaf/1" class="postlink">Auth Plugin Refactoring & User Integration by Joseph Warner, United States Joseph will enable phpBB to simply integrate with third party authentication services. The generic interface will allow administrators to configure which services to accept or add additional services at a later time. In addition to the slots provided by Google, phpBB will be extending the program by two additional slots. phpBB Summer of Code 2012 will follow much of the same guidelines set forth by GSoC. This year, both slots have been awarded to students on our own development team: Closing RFCs Like a Boss by http://www.phpbb.com/community/memberlist.php?mode=viewprofile&u=315319" class="postlink">Joas Schilling, Germany Joas will focus on completing some http://area51.phpbb.com/phpBB/viewforum.php?f=84" class="postlink">existing RFCs, including events, proper grouping for the teams page, improved ACP layout, soft delete, a log class, native php timezone handling, and others. http://www.google-melange.com/gsoc/proposal/review/google/gsoc2012/imkingdavid/3001" class="postlink">Post Revisions/Edit Log by http://www.phpbb.com/community/memberlist.php?mode=viewprofile&u=1051825" class="postlink">David King, United States David will implement a post revision system, enabling moderators to view detailed differences between edits made to a post with the ability to revert. This feature will have an option to be disabled, and can be further configured via the ACP to enable revision pruning. If your proposal was not chosen, please accept our sincerest gratitude for your participation. Please do not feel discouraged to participate in the phpBB community regardless of GSoC as there are http://www.phpbb.com/get-involved/" class="postlink">many opportunities to apply your skills. Thank you, The phpBB Team You may discuss this announcement in the http://www.phpbb.com/community/viewtopic.php?f=64&t=2154960" class="postlink">discussion topic View the full article
  24. As we http://www.phpbb.com/community/viewtopic.php?f=14&t=2153062" class="postlink]excitedly announced last month, phpBB is participating in Google Summer of Code 2012. phpBB received a large number of fantastic proposals and we have had a blast getting to know some of the applicants over the past few weeks. Our mentors dedicated their utmost attention to carefully ranking the entries and filling the provided slots with proposals that we feel will have the greatest benefit for the phpBB community. We sincerely wish that we could accommodate every worthwhile proposal, however resources are limited and we are focusing on facilitating the best possible experience for our winners. Without further adieu, it is my pleasure to announce our 2012 GSoC winners (In no particular order): Dhruv will focus on enabling proper abstraction in the search system and allowing for individual backends to modify the user interface. He will also integrate Sphinx and PostgreSQL Fulltext search into the phpBB codebase. Kim will improve both the interface and functionality of the attachment system by implementing multiple file uploads, an improved user interface and a tool for downloading several attachments at once. Joseph will enable phpBB to simply integrate with third party authentication services. The generic interface will allow administrators to configure which services to accept or add additional services at a later time. In addition to the slots provided by Google, phpBB will be extending the program by two additional slots. phpBB Summer of Code 2012 will follow much of the same guidelines set forth by GSoC. This year, both slots have been awarded to students on our own development team: http://www.phpbb.com/community/memberlist.php?mode=viewprofile&u=315319" class="postlink]Joas Schilling, Germany Joas will focus on completing some http://area51.phpbb.com/phpBB/viewforum.php?f=84" class="postlink]existing RFCs, including events, proper grouping for the teams page, improved ACP layout, soft delete, a log class, native php timezone handling, and others. http://www.phpbb.com/community/memberlist.php?mode=viewprofile&u=1051825" class="postlink]David King, United States David will implement a post revision system, enabling moderators to view detailed differences between edits made to a post with the ability to revert. This feature will have an option to be disabled, and can be further configured via the ACP to enable revision pruning. If your proposal was not chosen, please accept our sincerest gratitude for your participation. Please do not feel discouraged to participate in the phpBB community regardless of GSoC as there are http://www.phpbb.com/get-involved/" class="postlink]many opportunities to apply your skills. Thank you, The phpBB Team You may discuss this announcement in the http://www.phpbb.com/community/viewtopic.php?f=64&t=2154960" class="postlink]discussion topic View the full article
  25. We're looking to add a member or two to our current Arabic-speaking support team. A qualified candidate will meet the following criteria: 1. Possess advanced to expert knowledge of the vBulletin product, including extensive moderator experience. 2. Possess the ability to accurately translate English into Arabic. 3. A time availability of at least 15 hours per week. 4. A positive history of contribution within the vBulletin community. If you meet these criteria and would like more information on this role, please send a PM to vBulletin Marketing & Operations Manager Lawrence Cole. View the full article
×
×
  • Create New...