Previous Thread
Next Thread
Print Thread
Rate Thread
Joined: Feb 2001
Posts: 15
Junior Member
Junior Member
Offline
Joined: Feb 2001
Posts: 15
The upload custom avatar hack by SaiyaMan at Spawn's UBB Hacks site (http://spawn.piratecove.org/ubbmods/) allows any user to change any other users custom avatar, a big security hole if you ask me. eek

Is there any way to have it check your username, then check the file name to make sure both are the same exact thing before uploading the avatar? I see it checks $FileName, so would putting a check $UserName thing in there be too difficult? I'm an idiot when it comes to UBB hacking, but a upload custom avatar script would be great, and the other one requires installing new files to the server, something my server won't let me do frown

Sponsored Links
Joined: May 2001
Posts: 6,708
Member
Member
Offline
Joined: May 2001
Posts: 6,708
Yeah, that Avatar hack can let you really upload anything, what you need to do is put a size limit so people can't upload and also somehow it should have been so it reads by your username not your Member number.


Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
isaac
isaac
California
Posts: 1,157
Joined: July 2001
Forum Statistics
Forums63
Topics37,573
Posts293,925
Members13,849
Most Online5,166
Sep 15th, 2019
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,833
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2024 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20221218)