Previous Thread
Next Thread
Print Thread
Rate Thread
Joined: Feb 2000
Posts: 61
Member
Member
Offline
Joined: Feb 2000
Posts: 61
Name: CodeFilter_5xx v1.02

Description This modification prevents users from posting executable Javascript code within a UBBCode tag. It closes a nasty security vulnerability found in all UBB 5.4x versions. See the instructions for a detailed description.

Author: el84

Compatibility: Tested on 5.47e, but should work on any 5.4x version.

Link: http://el84.addr.com/ubbmods/CodeFilter_5xx_102.txt

[ April 08, 2001: Message edited by: el84 ]


"Waffles are nothing more than a vehicle for butter and syrup" - Dr. Clayton Forrester
Sponsored Links
Joined: Nov 2000
Posts: 168
Member
Member
Offline
Joined: Nov 2000
Posts: 168
Quote
quote:
Wasn't this fix the purpost of Ubb 5.47e???

Joined: Mar 2000
Posts: 344
Member
Member
Offline
Joined: Mar 2000
Posts: 344
Perhaps.

However, read his description in the text file. It may not have been completely squashed.


Administrator / WTF.com / IWantMy80s.com
http://www.wtf.com
http://www.iwantmy80s.com
Joined: Feb 2000
Posts: 61
Member
Member
Offline
Joined: Feb 2000
Posts: 61
Rev 1.01 is done. I know of no bugs in this version.

Link: http://el84.addr.com/ubbmods/CodeFilter_5xx_101.txt

Changes:
  • Fixed leak in EMAIL UBBCode filter
  • Added filter for fixed size FLASH UBBCode
  • Small change to UBB Code Buttons code to make use of fixed size FLASH UBBCode safe
  • Added filter for SOUND UBBCode
  • Now only looks for unsafe use of double-quote character in UBBCode tags. Previous version might not have allowed some valid URLs.
  • Added a kludge that eliminates the false positives described in v1.00 instructions. Ugly, but it works nicely.


All you still using UBB5.47e (or earlier) really should install this mod. Unfortunately, this is a mod that adds no cool features. Your users won't even know it's there. Only thing it does is prevent someone from trying to hijack your board, or mess up threads by slipping Javascript in the post.

Maybe this thread should be moved to finished hacks before UBB5 support disappears from this site. I see no reason to make any changes unless someone finds a bug with this mod.


"Waffles are nothing more than a vehicle for butter and syrup" - Dr. Clayton Forrester
Joined: Feb 2000
Posts: 61
Member
Member
Offline
Joined: Feb 2000
Posts: 61
Whoops. There was a bug in v1.01.

It screws up smilies that are preceded by a space. Fixed now.

Link: http://el84.addr.com/ubbmods/CodeFilter_5xx_102.txt

FYI, the UBB6 version of this mod never had this bug.


"Waffles are nothing more than a vehicle for butter and syrup" - Dr. Clayton Forrester
Sponsored Links
Joined: Jul 2001
Posts: 5
Junior Member
Junior Member
Offline
Joined: Jul 2001
Posts: 5
nice fix. thanks smile

Joined: May 2001
Posts: 6,708
Member
Member
Offline
Joined: May 2001
Posts: 6,708
I never saw this hack, Must have missed it anyway, Nice hack. smile


Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
isaac
isaac
California
Posts: 1,157
Joined: July 2001
Forum Statistics
Forums63
Topics37,573
Posts293,925
Members13,849
Most Online5,166
Sep 15th, 2019
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,833
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2024 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20221218)