Announcement

Collapse
No announcement yet.

Manual Security Patch Instructions for VB 4.x.x

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • BirdOPrey5
    replied
    Originally posted by Infopro View Post
    7 days later: "Sorry all - my bad. "

    Nice. Thanks for the update, 7 days later.
    7 days, yes, but the first report in this thread of something not working was 6:17pm my time yesterday. Before 8pm yesterday (less than 2 hours) I had gone over the code line by line and found the problem.

    If someone was having a problem for the full 7 days I would hope they would have said something sooner.

    Best I can tell, like on my site, no one noticed until yesterday.

    Leave a comment:


  • Mark.B
    replied
    Joe wrote the instructions as a courtesy for customers who were unable to use the official .diff file we provided.

    The official .diff file was correct and was not missing the change listed above.

    Leave a comment:


  • Infopro
    replied
    7 days later: "Sorry all - my bad. "

    Nice. Thanks for the update, 7 days later.

    Leave a comment:


  • BirdOPrey5
    replied
    OK... I missed a step when converting the Diff files into manual instructions. MK_1 noticed this way back on the first page but I did not.

    Anyone who has already made the changes needs to go back and do one more. I have updated the original instructions so anyone making from here on out is OK.

    Go back to the /includes/functions_misc.php file

    Find the code:
    Code:
        $temp = unserialize($serializedarr);
    Replace with:
    Code:
        $temp = json_decode($serializedarr, true);
    And save changes.

    This will fix the "Invalid Action Specified" bug with in-line moderation.

    Sorry all - my bad.

    Leave a comment:


  • BirdOPrey5
    replied
    Originally posted by lekiemdan View Post
    This patch cause my forum 4.2.0 "invalid action specified" error with inlinemod funtion when the moderator session timeout and they need to enter the password to perform the inlinemod. Are there any solution for this ?
    Hmmm... I don't have an immediate solution but if it is a problem you could consider disabling the Enable Inline Moderation Authentication in General Settings so moderators won't have to log in a second time for in-line moderation.

    See next post.
    Last edited by BirdOPrey5; Wed 19 Mar '14, 5:01pm.

    Leave a comment:


  • lekiemdan
    replied
    This patch cause my forum 4.2.0 "invalid action specified" error with inlinemod funtion when the moderator session timeout and they need to enter the password to perform the inlinemod. Are there any solution for this ?

    Leave a comment:


  • Mark.B
    replied
    Originally posted by Johnny B View Post
    Thanks so much Mark B greatly appreciated I have done as requested

    Once again thank you
    This site has now been successfully patched.

    Leave a comment:


  • Zachery
    replied
    Originally posted by Ambro View Post
    Since I've manually patched using your provided instructions, how can I manually set the version number to the latest build?
    If that's not recommended, was anything else changed in PL1 which would have to be applied manually in order to be at Pl1 ?

    Just want to be current here and since I've manually applied the patch, the version still reflects 4.22 Albeit cosmetic, I'd rather be able to reflect the latest version on my site.
    You wouldn't. PL's are not something set in the versioning data stored in the software, we never display PL's to the end user either, just to administrators, in the AdminCP. If you're not already on 4.2.2, then you would need to upgrade, otherwise you're not on 4.2.2, even with the patch applied.

    Leave a comment:


  • Ambro
    replied
    Since I've manually patched using your provided instructions, how can I manually set the version number to the latest build?
    If that's not recommended, was anything else changed in PL1 which would have to be applied manually in order to be at Pl1 ?

    Just want to be current here and since I've manually applied the patch, the version still reflects 4.22 Albeit cosmetic, I'd rather be able to reflect the latest version on my site.
    Last edited by Ambro; Mon 17 Mar '14, 12:47pm.

    Leave a comment:


  • Johnny B
    replied
    Thanks so much Mark B greatly appreciated I have done as requested

    Once again thank you

    Leave a comment:


  • Mark.B
    replied
    Originally posted by Johnny B View Post
    Hello all,

    I am running 4.2.0 P4 and I followed the instructions to the letter but somehow must have done something wrong as I couldn't get my website to work and had to revert to uploading the old files.

    I know it would be a simple upgrade to 4.2.2 but I have ad on's I need to check 1st before doing that and while I release it is not a VB support problem it is very frustrating not to have access to simple files to upload and overwrite. I also don't want to do a complete version upgrade at the moment if possible.

    Can someone from VB Support not assist myself and others that have had problems with the manual upgrade by just making a simple up loadable patch available for version 4.2.0 P4

    PLEASE HELP HERE
    Please raise a support ticket, including your site URL, ftp credentials, and admincp credentials;
    The credentials should be put in the "Sensitive Data" field.
    http://www.vbulletin.com/go/techsupport

    Mark the ticket for my attention and I'll do the patching for you later today.

    Leave a comment:


  • Johnny B
    replied
    Hello all,

    I am running 4.2.0 P4 and I followed the instructions to the letter but somehow must have done something wrong as I couldn't get my website to work and had to revert to uploading the old files.

    I know it would be a simple upgrade to 4.2.2 but I have ad on's I need to check 1st before doing that and while I release it is not a VB support problem it is very frustrating not to have access to simple files to upload and overwrite. I also don't want to do a complete version upgrade at the moment if possible.

    Can someone from VB Support not assist myself and others that have had problems with the manual upgrade by just making a simple up loadable patch available for version 4.2.0 P4

    PLEASE HELP HERE

    Leave a comment:


  • BirdOPrey5
    replied
    OK, then I would suggest making the file changes again. This time do the changes one file at a time and test the forum after each one. Be sure to check several pages. Try to find the specific one causing the issue- the most likely problem was a typo in one of the changes.

    Is there a reason you can't upgrade to VB 4.2.2, that would be ideal.

    Leave a comment:


  • kandhro
    replied
    Originally posted by Joe D. View Post

    Hello,

    What software are you using when you edit the files? What it the name of the text editor you are using and what is your computer operating system?

    Hello
    iam using Notepad++ for editing as per suggested above , and iam on win7

    Regards

    Leave a comment:


  • MoreLinux
    replied
    Originally posted by vbsm View Post
    Might these two be the same?...

    /public_html/phpbb/includes/functions.php
    /public_html/forums/includes/functions.php
    Hi vbsm,
    That /public_html/phpbb directory might be there because you used my phpBB3Auth plug-in to migrate the phpbb3 user accounts to vBulletin4??
    phpBB3Auth - Migrate phpBB3 user/password to VB4 vBulletin 4.x Add-ons

    Leave a comment:

widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
Working...
X