Register Members List Search Today's Posts Mark Forums Read

Reply
 
Mod Options
vBFirewall v1.0 Details »
vBFirewall v1.0
Mod Version: 1.00, by invisiblea (Member) invisiblea is offline
Developer Last Online: Dec 2008 I like it Show Printable Version Email this Page

vB Version: 3.8.0 Beta 2 Rating: (45 votes - 4.71 average) Installs: 680
Released: 20 Nov 2008 Last Update: Never Downloads: 3256
Not Supported Uses Plugins Auto-Template Is in Beta Stage  

This is my first mod for vBulletin and I have tried to make it as better as I could.



What is vBFirewall?
Its a PHP script which blocks all kinds of attacks on your vBulletin Forum! Like: URL Poisoning, Remote File Inclusion, SQL Injection, XSS and other kinds of attacks.

I have tested each and every function of this mod before releasing it and have used it myself for 1 month

It has a attacker logger, which logs the IP and many details of the attacker so that you can reach him

This is still in beta version and I will add more features in it to make your vBulletin more secure Suggestions are always welcome.


How to install?

1) Go to Admin and Import the xml file product-firewall_vb_rs.xml using the plugin manager.
2) Keep an eye on the log file which can be found here: www.yourvbforumurl.com/logfile_worms.txt (This file will only be created when a attack occour)
3) Your website is now secure from hackers



Thanks

Download Now

Only licensed members can download files, Click Here for more information.

Show Your Support

  • To receive notifications regarding updates -> Click to Mark as Installed.
  • If you like this modification support the author by donating.
  • This modification may not be copied, reproduced or published elsewhere without author's permission.
  #226  
Old 04 Aug 2009, 19:03
Itchy Nips's Avatar
Itchy Nips Itchy Nips is offline
 
Join Date: Jun 2009
installed and I guess its working for me. All addons are working for me, as of right now. I do not have those two addons that are specified in a couple posts above, though
Reply With Quote
  #227  
Old 05 Aug 2009, 02:36
massi64 massi64 is offline
 
Join Date: Jun 2009
still dosen't work i mean a dose not his job , bots users keep registering , and on the log (logfile_worms.txt) the only log it is my ip , probably when i made a mistake with my password.
any idea to make this mod work right ?
Reply With Quote
  #228  
Old 06 Aug 2009, 16:06
Itchy Nips's Avatar
Itchy Nips Itchy Nips is offline
 
Join Date: Jun 2009
it just prevented me from viewing the control panel log in the admincp. When I click on:

ADMINCP > USERGROUPS > ADMINISTRATOR PERMISSIONS > VIEW CONTROL PANEL LOG

it displays an error and emails me that a hack attempt was just made.

Last edited by Itchy Nips; 03 Sep 2009 at 16:12.
Reply With Quote
  #229  
Old 06 Aug 2009, 23:20
CMD CMD is offline
 
Join Date: Dec 2005
Originally Posted by Itchy Nips View Post
it just prevented me from viewing the control panel log in the admincp. When I click on:

ADMINCP > USERGROUPS > ADMINISTRATOR PERMISSIONS > VIEW CONTROL PANEL LOG

it displays an error and emails me that a hack attempt was just made.
Same problem...
Reply With Quote
  #230  
Old 23 Aug 2009, 16:32
xyzmary2001 xyzmary2001 is offline
 
Join Date: May 2008
Oh, well, since no one specialized offers any help, I will offer myself. This is - or should be embarrassing - to let a lawyer who knows nothing about coding to solve the technical problems caused to other ppl by your own hack.
After 30 minutes of testing the most weird things on the test forum, I did as follows:

1. I created the logfile_worms.txt and uploaded it in forum root.

2. CHMOD-ed it to 0666.

3. Disabled the addon and noticed that the error was gone.

4. Uninstalled the addon - the error still gone

5. Deleted the damned .txt file from the root and felt very proud of myself )

Hope this will work for everyone.

Extremely disappointed of this type of lack of responsibility.
Reply With Quote
  #231  
Old 03 Sep 2009, 16:12
Itchy Nips's Avatar
Itchy Nips Itchy Nips is offline
 
Join Date: Jun 2009
just an update for others thinking about installing this:
vb3.8.3 - users cannot access their subscriptions page. this mod blocks their attempt and thinks its a hack attempt

disabled for now
Reply With Quote
  #232  
Old 03 Sep 2009, 16:15
RvG2's Avatar
RvG2 RvG2 is offline
 
Join Date: Jan 2007
Originally Posted by Itchy Nips View Post
just an update for others thinking about installing this:
vb3.8.3 - users cannot access their subscriptions page. this mod blocks their attempt and thinks its a hack attempt

disabled for now
a solution is given on previous pages.
Reply With Quote
  #233  
Old 03 Sep 2009, 16:15
Itchy Nips's Avatar
Itchy Nips Itchy Nips is offline
 
Join Date: Jun 2009
thanks. i wasnt aware of that
Reply With Quote
  #234  
Old 03 Sep 2009, 20:30
RvG2's Avatar
RvG2 RvG2 is offline
 
Join Date: Jan 2007
Originally Posted by Itchy Nips View Post
it just prevented me from viewing the control panel log in the admincp. When I click on:

ADMINCP > USERGROUPS > ADMINISTRATOR PERMISSIONS > VIEW CONTROL PANEL LOG

it displays an error and emails me that a hack attempt was just made.
find:

'st=-', 'cat%20', 'include', '_path=');

add below:

$securityexclusions = array(
'do=viewsubscription','do=removesubscription', 'do=addsubscription', 'do=doaddsubscription', 'do=view&script'
);

in addition to the fix for subscription.
Reply With Quote
  #235  
Old 04 Sep 2009, 21:27
d0cpaul's Avatar
d0cpaul d0cpaul is offline
 
Join Date: Aug 2009
How do I know what kind of attack I am getting? Here is an attack I received a couple times today.


Block Disabled:      (Update License Status)  
Suspended or Unlicensed Members Cannot View Code.

Reply With Quote
  #236  
Old 11 Sep 2009, 09:25
iEdster iEdster is offline
 
Join Date: Aug 2009
How can I remove it? I removed it via Product page, it still gives me hack attempts sent to my email. I wanna remove it completely, because it conflicts with other plugins, and gives me errors.
Reply With Quote
  #237  
Old 13 Sep 2009, 15:52
badheeu badheeu is offline
 
Join Date: Oct 2007
I have some mails

Hello!

Hack Attempt has been successfully prevented for your vBulletin forums at:
KMA® Warez Forums

Report:
============================

1||1252849941||115.84.147.15||do=viewsubscription&folderid=all||http://www.kma-forum.com/usercp.php||Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/530.5 (KHTML, like Gecko) Chrome/2.0.172.43 Safari/530.5

============================

but no report logs created
Reply With Quote
  #238  
Old 16 Sep 2009, 01:49
solarhosts solarhosts is offline
 
Join Date: Sep 2009
sweet thanks.
Reply With Quote
  #239  
Old 28 Sep 2009, 07:30
foroalfaromeo foroalfaromeo is offline
 
Join Date: Feb 2009
I've installed it, but it had no effect in my forum what so ever.
What parameters does it work on?

I only see a Menu that tuns log & notifications on or off.
Reply With Quote
  #240  
Old 05 Oct 2009, 17:48
Kolbi's Avatar
Kolbi Kolbi is offline
 
Join Date: Mar 2009
Real name: Matthias
There is an big bug. Users can´t unsubscribe from thread without getting blocked from the firewall.
Need to be fixed.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Mod Options

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


New To Site? Need Help?

All times are GMT. The time now is 09:50.

Layout Options | Width: Wide Color: