[Topics Anywhere] - Security issue

To talk about mods and code.
Patches requests, solutions and SEO tweaks sharing.

Moderator: Moderators

[Topics Anywhere] - Security issue

Postby PerfRen » Mon Dec 03, 2007 2:18 pm

Hi all,

When i enter http://www.domain.com/forum/topics_anywhere.php I get the following message...

"Sorry, it appears this is your first visit since we added the security questions to accounts. You will only be able to view your profile until you update it and add a question and answer. Thanks!

Click here to goto your profile."

Do you know why this might be happening?
PerfRen
 
Posts: 36
Joined: Thu Nov 01, 2007 4:11 pm

Advertisement

Postby Peter77 » Tue Dec 04, 2007 11:02 am

Sounds like something more to do with your hosting company or whoever runs your forum. Nothing in the topics anywhere MOD evokes that message.

Good luck.
Peter77
phpBB SEO Team
phpBB SEO Team
 
Posts: 520
Joined: Wed May 10, 2006 9:46 am
Location: Michigan

Postby PerfRen » Tue Dec 04, 2007 11:06 am

I have actually done some tracking down and it is some code in the MOD that is conflicting with phpBBSecurity.

It is something about the way the topics_anywhere system is instantiated which brings up this message.

It is the only php file on my forum that does this! It must be something in the code before the session management.
PerfRen
 
Posts: 36
Joined: Thu Nov 01, 2007 4:11 pm

Postby Peter77 » Tue Dec 04, 2007 11:24 am

hm, CTracker gave me the same issue with topics_anywhere.php back when I tried it ( none seo version ). I suppose your best bet would be to ask at phpbbsecurity's support site. sorry about that.
Peter77
phpBB SEO Team
phpBB SEO Team
 
Posts: 520
Joined: Wed May 10, 2006 9:46 am
Location: Michigan

Postby PerfRen » Tue Dec 04, 2007 11:26 am

Hmmm it could be CTracker or phpBBSecurity then!

What did you do to solve it?
PerfRen
 
Posts: 36
Joined: Thu Nov 01, 2007 4:11 pm

Postby Peter77 » Thu Dec 06, 2007 7:33 am

I got rid of CTracker :lol: .
Really, its was too heavy of a MOD for what it says it does, IMO You can help block bad bots other ways.
Peter77
phpBB SEO Team
phpBB SEO Team
 
Posts: 520
Joined: Wed May 10, 2006 9:46 am
Location: Michigan

Postby PerfRen » Thu Dec 06, 2007 8:59 am

Ok there is something at the start of the topics anywhere file that is getting/setting variables differently that that of a normal phpBB forum.

It si one of the calls before the session handling that I believe is making the baord thinking it is the first time of using the updated security feature.

Can anyone tell me what all the calls before the session management section are doing and why they are needed.

Many thanks!
PerfRen
 
Posts: 36
Joined: Thu Nov 01, 2007 4:11 pm

Postby SeO » Thu Dec 06, 2007 12:35 pm

Honestly, I'm not very much convinced by ctracker and phpbbsecurity. They mostly protect against old, known and fixed security holes.

I don't know precisely, but it may be possible to deactivate protection for this file only.

Then, you can as well use the GYM sitemaps rss feeds to output links to a last posts/topic listing everywhere, which would have the advantage of providing with links bot can see, topic anywhere is using JS.
SeO
Admin
Admin
 
Posts: 6333
Joined: Wed Mar 15, 2006 9:41 pm

Postby PerfRen » Thu Dec 06, 2007 3:12 pm

I already use the GYM sitemaps so will have a look at the topic you posted thanks :)

Still as asked previously, can anyone tell me what all the calls before the session management section are doing and why they are needed in the topics anywhere file.

Would love to be able to help others and provide a solution for them too :)
PerfRen
 
Posts: 36
Joined: Thu Nov 01, 2007 4:11 pm

Postby PerfRen » Mon Dec 10, 2007 9:10 am

Anyone? :)
PerfRen
 
Posts: 36
Joined: Thu Nov 01, 2007 4:11 pm

Postby Peter77 » Mon Dec 10, 2007 2:14 pm

Well, everything above the // Start session management line has to do with the time & date configurations and as well as the SEO part of the MOD. If Your wondering about the SEO code having anything to do with the issue... I had the same problem even with the regular topics_anywhere version.
Peter77
phpBB SEO Team
phpBB SEO Team
 
Posts: 520
Joined: Wed May 10, 2006 9:46 am
Location: Michigan


Return to phpBB2 Mods and Code

 


  • Related topics
    Replies
    Views
    Last post

Who is online

Users browsing this forum: No registered users and 2 guests