leftBG


BrugernavnAdgangskode Bliv oprettet som bruger...
 Søg 
bajoBG
topRightCorner
spacer
Navigation
Forside
Brugerforum
Downloads
Zikula Links
Nyhedsarkiv

Artikler
Din egen Linux-server
Postnuke Lyrik

Hvordan gør jeg?
Ofte Stillede Spørgsmål
Installation af PostNuke
Installation af moduler
Opgradér PostNuke
Tilladelser i PostNuke
Tag backup
Anvend Link modul

PagEd
Installation
Nyhedsvisning

Om Zikula.dk
Kontakt


UK XForum support
Problem med skift ...(0)
Installation Probl...(2)
Problem with Postn...(11)
Maybe I can contri...(8)
English XForum sup...(10)
Can't install on ...(1)

Seneste forumindlæg
Zikula v 1.0.3 og ...(0)
I-Members 2.9(0)
Oversættelse af Zi...(3)
Kan man genbruge s...(2)
Opgradering til PH...(5)
Konverter fra Xfor...(0)
Dansk sprogpakke t...(0)
VIRUS -Hacker !!(12)
Hvilken version ha...(2)
zikula download mo...(1)

spacer
Brugerforum
Du er ikke logget ind
Tidspunkt for seneste indlæg: 10/9/10 kl. 12:43

page_down.gif
print.gif< Forrige indlæg   Næste indlæg >Sorter stigendeSorter faldende  
Forfatter: Emner: Maybe I can contribute...

Junior medlem
stars


avatar

Indlæg: 6
Oprettet: 20/12/06
Status: Offline

smilies/cool.gif   indsendt den 20/12/06 kl. 22:24
Hi,

I'm surprised to see that XForum ist still alive.

Not knowing about your project, I have debugged and enhanced my own XForum 1.81.1 installation during the last couple of weeks. I did not take a look at your version 1.82 yet; my modifications may overlap with yours. However, perhaps you can gain a little benefit bit from my work. This is what I've done so far:

http://www.smart-roadster-club.de/off-topic/XForum/XForumPost NukedFrom1.81.1to1.9a6.zip

The zip file contains only those files that I have modified. The remainder conforms to the original 1.81.1 by Trollix. I've included a brief description of all changes in modules/XForum/docs/changelog.txt.

The most interesting issue thereby is a security flaw. Despite the changelog for 1.8 mentions it as fixed, it is still possible to inject JavaScript via BBCode. Some month ago an attacker successfully hijacked user accounts in our XForum using that method.
Well, I've fixed that by means of more rigid content filtering. However, the XForum security relies on the principle of "enumerating badness" here, which is probably not the best way to do.

Regards,
Stefan


PS:
For whoever wants to carry out a test... the complete zip file:
http://www.smart-roadster-club.de/off-topic/XForum/XForumPost Nuked1.9a6.zip
But be warned: I've never tried to install that. Up to now I only modified my already running installation.

[Editiert am 21/12/2006 von SAM]

[Editiert am 26/12/2006 von SAM]

[Editiert am 24/1/2007 von SAM]

[Editiert am 31/1/2007 von SAM]

[Editiert am 6/3/2007 von SAM]

 
profile.gif find.gif
pagetop2.gif pagebot2.gif

Administrator
11

avatar

Indlæg: 2578
Oprettet: 25/3/02
Status: Offline

smilies/cool.gif   indsendt den 21/12/06 kl. 10:41
Hi Stefan and welcome to the Danish PostNuke community smilies/smile.gif

I will take a look at your changelog and ofcourse implement all relevant fixes and enhancements.
Version 1.82 that can be downloaded here at the moment is NOT current.
My dev version is now running with PHP5 and is W3C compliant.

The reason it's not in the download section yet is a lack of time for basic testing and that I wanted to do a little more fixing first!

I'm over my head in daily (and nightly) work at the moment so I won't have time for another week.

Thanks for your (continued??) contribution... come back and visit us again smilies/smile.gif

 
____________________
/KimE
---------------------------------------------------------
"Der findes 2 måder at udvikle fejlfri software på, men det er kun den 3. der virker!!"

 
profile.gif site.gif find.gif
pagetop2.gif pagebot2.gif

Junior medlem
2

avatar

Indlæg: 6
Oprettet: 20/12/06
Status: Offline

  indsendt den 21/12/06 kl. 18:19
Just updated the links above to new version 1.9a2.

(Once you start looking at the code, you find more and more bugs...) smilies/wink.gif

 
profile.gif find.gif
pagetop2.gif pagebot2.gif

Junior medlem
2

avatar

Indlæg: 6
Oprettet: 20/12/06
Status: Offline

  indsendt den 26/12/06 kl. 15:56
Another update to version 1.9a3 in the first post.

Fixed a nasty user profile corruption issue.

 
profile.gif find.gif
pagetop2.gif pagebot2.gif

Administrator
11

avatar

Indlæg: 2578
Oprettet: 25/3/02
Status: Offline

smilies/cool.gif   indsendt den 28/12/06 kl. 14:01
Hi Stefan,

Happy to see you back here, but maybe you schould wait a little with more changes since at least some of them already have been made in our version smilies/wink.gif

 
____________________
/KimE
---------------------------------------------------------
"Der findes 2 måder at udvikle fejlfri software på, men det er kun den 3. der virker!!"

 
profile.gif site.gif find.gif
pagetop2.gif pagebot2.gif

Junior medlem
2

avatar

Indlæg: 6
Oprettet: 20/12/06
Status: Offline

  indsendt den 24/1/07 kl. 20:52
Hi Kim,

yes, you're certainly right. However, I found some more bugs today, and I could not resist ... smilies/wink.gif

(new Version 1.9a4 above)


 
profile.gif find.gif
pagetop2.gif pagebot2.gif

Junior medlem
2

avatar

Indlæg: 6
Oprettet: 20/12/06
Status: Offline

  indsendt den 31/1/07 kl. 19:58
1.9a5

I think this is the last one for the time being, since I have fixed those issues that annoyed me most of all.

 
profile.gif find.gif
pagetop2.gif pagebot2.gif

Junior medlem
2

avatar

Indlæg: 6
Oprettet: 20/12/06
Status: Offline

  indsendt den 16/2/07 kl. 21:47
Rash words, that. smilies/sad.gif

--> version 1.9a6 above

( It is amazing how many bugs can be placed in such a little bit of code. smilies/shocked.gif )


Besides, a question crossed my mind: Do you plan to make XForum usable with register_globals=off eventually? Is it even possible to run PostNuke without register_globals?

 
profile.gif find.gif
pagetop2.gif pagebot2.gif

Administrator
11

avatar

Indlæg: 2578
Oprettet: 25/3/02
Status: Offline

smilies/cool.gif   indsendt den 16/2/07 kl. 22:33
quote:Do you plan to make XForum usable with register_globals=off eventually?


Answer: Yes smilies/smile.gif

W3C compliant: almost complete
PHP5 compliant: almost complete
PN.8 "compliant": asap
pnAPI compliant: eventualy

I'm just too busy working right now smilies/sad.gif

BTW. thanks for your bugfixes!


[Redigeret den 16/2/2007 af kimenemark]
 
____________________
/KimE
---------------------------------------------------------
"Der findes 2 måder at udvikle fejlfri software på, men det er kun den 3. der virker!!"

 
profile.gif site.gif find.gif
pagetop2.gif pagebot2.gif
 

page_up.gif

Powered by XForum 1.82a.1 from PostNuke.dk
Based on XForum 1.81.1 by Trollix Software

0.1560140 - 79 queries
spacer
bottomLeftCorner tableBaseLeft tableBaseRight bottomRightBG


Alle logoer og varemærker på Zikula.dk tilhører deres respektive ejere.
Kommentarer tilhører forfatteren og kan ikke tages som udtryk for Zikula.dk´s synspunkter.
Ophavsretsligt beskyttet © 2000-2008.