What software are you using when you edit the files? What it the name of the text editor you are using and what is your computer operating system?
Announcement
Collapse
No announcement yet.
Manual Security Patch Instructions for VB 4.x.x
Collapse
X
-
Originally posted by kandhro View Post
What software are you using when you edit the files? What it the name of the text editor you are using and what is your computer operating system?
-
Hello
iam looking for some of ur help in regards of , i have done manual editing in my vb 4.2.0 for the files as per instructions here in top ,
the noted results i have seen is no any member is able to login and same with admin after i place right details and click login it show blank screen
with as follow link www.xyzzzz.com/login.php?do=login
then i tried to restore edited files back from backup my forum works fine as usual, suggest me
hope to have a solution
Leave a comment:
-
If you installed vBulletin into the /phpbb/ directory then yes they may very well be the same. If you can find that code in it, go ahead and make the changes.
Leave a comment:
-
Might these two be the same?...
/public_html/phpbb/includes/functions.php
/public_html/forums/includes/functions.php
Leave a comment:
-
Yes you can go straight to 4.2.2, that is what JoeD said if you read the post again, database errors are rare and usually occur for a reason. Remember to do a full backup before an upgrade so you can restore your forum as it was if things do go wrong.
Leave a comment:
-
Originally posted by Joe D. View Post
Hello, if you are on 4.2.0 you have two choices at this point-
1) You download 4.2.2 PL1 (the full version) from the Member's Area and upgrade to 4.2.2. Then you are good.
2) You follow the instructions in Post #1 to manually patch your existing 4.2.0 install, then you are also safe from this latest exploit.
You choose 1 OR 2, not both.
So I can jump from 4.2.0 to 4.2.2 PL1 without doing the updates in-between (4.2.2 PL! is an inclusive update)? Also, I noticed some people having database errors after the update. Is this common? (Our PHP is greater than 5.2)
Leave a comment:
-
Originally posted by supergaijin View PostSo just to be clear, if I'm on 4.2.0 PL3, I need to follow the manual instructions in the OP to upgrade to 4.2.2 PL1 and can't just copy the pre-patched files to bring my 4.2.0 up to 4.2.2?
Thanks in advance.
1) You download 4.2.2 PL1 (the full version) from the Member's Area and upgrade to 4.2.2. Then you are good.
2) You follow the instructions in Post #1 to manually patch your existing 4.2.0 install, then you are also safe from this latest exploit.
You choose 1 OR 2, not both.
Leave a comment:
-
Originally posted by Pony View PostUpdated from 4.1. to 4.2.2, and after that was done applied PL1.
ACP does not show that I'm running PL1, and the new files are showing up as 'file does not contain expected contents'. I have verified all files in PL1 are uploaded.
Just want to make sure I'm good.
EDIT; I see at the very bottom of the screen the "powered by" 4.2.2 pl1, so I'm guessing I'm good. Was too busy looking at the top that I missed the bottom.
Anyone choosing to upgrade to 4.2.2 at this point who download a fresh copy of 4.2.2 does not have to apply the patch, it is already included in 4.2.2 at this point.
Leave a comment:
-
So just to be clear, if I'm on 4.2.0 PL3, I need to follow the manual instructions in the OP to upgrade to 4.2.2 PL1 and can't just copy the pre-patched files to bring my 4.2.0 up to 4.2.2?
Thanks in advance.
Leave a comment:
-
Updated from 4.1. to 4.2.2, and after that was done applied PL1.
ACP does not show that I'm running PL1, and the new files are showing up as 'file does not contain expected contents'. I have verified all files in PL1 are uploaded.
Just want to make sure I'm good.
EDIT; I see at the very bottom of the screen the "powered by" 4.2.2 pl1, so I'm guessing I'm good. Was too busy looking at the top that I missed the bottom.1 Photo
Leave a comment:
-
I understand this marks a change in how people are used to getting patches for 4.x because we only supplied an actual patch for VB 4.2.2. However this is not the thread for complaints. Any post that is not a valid request for support or feedback on actually applying the above changes will be deleted. Anyone posting off topic past this point will get infractions. Please use the Licensed Customer Feedback forum to provide feedback on the exploit/patches/bug fixes in general. This topic is for support of people trying to secure their sites.
Leave a comment:
-
Originally posted by kandhro View Postfor manual patching
do i have to upload patch files downloaded from mebers area + manually edit files or just manual editing is all what i have to do in this patch ?
and thanks for the good support Mark B
It's either upload the patch files or manually edit the existing files.
Leave a comment:
-
very easy instructions - took no more than 5 minutes. I shake my head at some guys who are confused about how to do this.
Leave a comment:
-
for manual patching
do i have to upload patch files downloaded from mebers area + manually edit files or just manual editing is all what i have to do in this patch ?
and thanks for the good support Mark B
Leave a comment:
widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
Leave a comment: