The AnimeFanlistings Network Message Board

Fanlisting Management => Fanlistings Chit-Chat => Topic started by: Jackie on April 29, 2006, 12:09:20 PM

Title: Enthusiast Security Fix Available - Nov 2008
Post by: Jackie on April 29, 2006, 12:09:20 PM
Enthusiast has a security fix available at <a href="http://scripts.indisguise.org/" target="_blank"><a href="http://scripts.indisguise.org/" target="_blank"><a href="http://scripts.indisguise.org/" target="_blank">http://scripts.indisguise.org/ (http://\"http://scripts.indisguise.org/\")[/url][/url][/url]

Edit: Angela's file currently has a problem.  On line 60 in the new show_join.php:

Code: [Select]
if( $_POST['email'] && ereg("^[_a-z0-9-]+(\.[_a-z0-9-]+)*@[a-z0-9-]+(\.[a-z0-9-]+)*(\.[a-z]{2,6})$", $_POST['email'])
should be:

Code: [Select]
if( $_POST['email'] && ereg("^[_a-z0-9-]+(\.[_a-z0-9-]+)*@[a-z0-9-]+(\.[a-z0-9-]+)*(\.[a-z]{2,6})$", $_POST['email']) )There seems to be missing an extra ) at the end.  So, if you download Angela's file, add in the extra ) before uploading.  I don't know if there're any other problems; Angela or one of the coding gurus will probably let us know. :]

In the meantime, if you still have problems, you can also edit the file show_join.php manually by following this tutorial (http://\"http://www.jemjabella.co.uk/post.php?title=20060427_enthusiast3_potential_security_risk\").

UPDATE NOVEMBER 2008: See Indiscripts (http://\"http://scripts.indisguise.org/\") for the latest Enthusiast security upgrade (upgrade to version 3.1.5).
Title: Enthusiast Security Fix Available - Nov 2008
Post by: Mitzrael on April 29, 2006, 12:20:04 PM
updated  :/  thank you Jackie!
Title: Enthusiast Security Fix Available - Nov 2008
Post by: Jackie on April 29, 2006, 12:23:06 PM
Eek, it seems there's something wrong with the fix.  I wouldn't download the one from Angela's site at the moment.  You can manually fix the file show_join.php by following this tutorial (http://\"http://www.jemjabella.co.uk/post.php?title=20060427_enthusiast3_potential_security_risk\").
Title: Enthusiast Security Fix Available - Nov 2008
Post by: Mitzrael on April 29, 2006, 12:34:38 PM
XD okay, I will do this after lunch  :/ meanwhile I re-uploaded the original file o.รณ
Title: Enthusiast Security Fix Available - Nov 2008
Post by: Mura on April 29, 2006, 12:37:32 PM
Thanks for the heads up, Jackie.  :/

*will go through tutorial after lunch*
Title: Enthusiast Security Fix Available - Nov 2008
Post by: Rainie on April 29, 2006, 12:43:00 PM
thanks <3 I've upload it manually due to the error, and now it works ;D !
Title: Enthusiast Security Fix Available - Nov 2008
Post by: Lia on April 29, 2006, 12:46:42 PM
Thanks for posting how to fix it. My joined forms seem fine after the upgrade. :/
Title: Enthusiast Security Fix Available - Nov 2008
Post by: Meli on April 29, 2006, 01:03:32 PM
Thanks, Jackie! :) I will definitely make sure to upgrade my file soon. :/
Title: Enthusiast Security Fix Available - Nov 2008
Post by: Mitzrael on April 29, 2006, 02:59:53 PM
:/ mines aren't working, i've done it manualy too ._.

never mind I get it now  :)
Title: Enthusiast Security Fix Available - Nov 2008
Post by: Firefly on April 29, 2006, 03:09:03 PM
Thanks!  I've been getting some of those lately, with odd fields, and I thought it was odd that Enth3 did not catch them.
Title: Enthusiast Security Fix Available - Nov 2008
Post by: Mitzrael on April 29, 2006, 03:31:01 PM
o.o by the way, I really hope the spam fix is going to work ^^U. Someone already emailed me back after two of his emails were added without him filling the form or even visit the site ^^;;
Title: Enthusiast Security Fix Available - Nov 2008
Post by: Crystal on April 30, 2006, 02:58:49 AM
I've done the fixes. Thanks for the heads up. :/
Title: Enthusiast Security Fix Available - Nov 2008
Post by: Luinthoron on April 30, 2006, 07:49:38 AM
Thanks, updated! :/
Title: Enthusiast Security Fix Available - Nov 2008
Post by: Matx on May 06, 2006, 06:55:57 PM
Thanks for posting the fix Jackie! Updated my Enth's forms... ^_^
Title: Enthusiast Security Fix Available - Nov 2008
Post by: Michiru on August 01, 2006, 01:30:38 AM
Angela has a new enth security fix for the login. You can find more info about it on codegrrl here (http://\"http://codegrrl.com/forums/index.php?s=&showtopic=12815&view=findpost&p=68649\").

If you haven't already updated it, here's the link to the download: http://scripts.indisguise.org/enthusiast/download/3/?cat=11 (http://\"http://scripts.indisguise.org/enthusiast/download/3/?cat=11\")
Title: Enthusiast Security Fix Available - Nov 2008
Post by: Mitzrael on November 14, 2008, 09:57:57 PM
I know some of us miss those news although we've got a seed to keep up-to-date *looks at self*  :D :D   so i hope it's okay to bring this thread back to life xD; *clings on Marie* thanks lady!

URGENT : Security Upgrade this way~ (http://\"http://scripts.indisguise.org/2008/11/13/enthusiast-315-urgent-security-upgrade/\")