Jump to content

Forum upgrade from ver 2.0.4 to 2.1.6 and now to 2.1.7


dbiel

Recommended Posts

Please note that on 5-12-06 this forum was upgraded from version 2.0.4 to version 2.1.6

The upgrade was done before we wanted to do it due to some serious attacks on the forum that could only be stopped by doing the upgrade.

Much of the look, feel and appearance of the forum has been changed due to the upgrade.

You will find that numerious things work differently now, may not work at all, or have disappeared. We are working on restoring much of the previous functionability. It will take some time to complete, as it requires a very significate amount of work to alter the code base. Please bear with us during this conversion process.

This forum FAQ also needs to be updated to reflect the current software version changes.

Thank you for your patience during this difficult time.

Please feel free to post your questions, concerns, etc about the forum upgrade in this topic.

The following is a list of some of the changes due to the version upgrade. It is not complete and will be added to and updated as quickly as possible.

Thank you for your cooperation and support.

Changes due to version upgrade:

Post creation/edit interface has changed dramaticly

Spell Check location and access changed. It is now found at the top of the edit box as a new icon: spellcheck.gif It is small, so it can easily be missed.

newpost.gif (the new post flag) has been reset on all topics in the forum. (see Wazoo's explaination in the following post)

See Wazoo's post that follows for additional information.

Edited by dbiel
Link to comment
Share on other sites

Page heading bars with links added back in

Navigation bar modified to include links to working stuff

Logo changed

SpellCheck modification applied (not a button this time, look for the icon at the top of the edit box)

Save sent PM to your Sent Folder as default modification made again

Sort issue with posts shown on the Portal page made

Upgraded version of a Custom Page Mod installed ... problem is that old posts need revision to the URL .. working through that ..

Missing in action:

SCKB - alternate view of the SpamCop FAQ

Start Here link now broken ... missing the above Mod

.... fixed by building a new page, using the latest Custom Page Mod ....

.... same 'fix' applied to the first entry in the SpamCop FAQ here ....

Member bar "View Your Posts" modification

Server status link in the logo bar - layout issues I'll have to work through for starters

.... In place and working link on the Portal Page ... either hit the spamcop.net logo at the top of the screen or enter at http://www.forum.spamcop.net/ .....

Save copy of Warn PM to Sent Folder

Need to do:

Forum FAQ needs some updating in places

Complete check of links floating around ... most internal links should work fine, but ... as above, some tools not present now ....

Explanation:

(the new post flag) has been reset on all topics in the forum.

Cookie information was changed, the old cookie data doesn't match the database stuff at the first login to this install

This just a quick scan though a couple of files here on things done, todo, need to figure out, etc.

any updates, oversights would be appreciated.

Link to comment
Share on other sites

If you had http://forum.spamcop.net bookmarked, yoi may have been very confused upon hitting the (under work) Portal page. Assumedly, you followed one of the links to the Forum to get here .....

In addition, the SpamCop.net logo link has been changed to also bring up the Portal page ...

To jump back to the Forum 'front' page ....

use your browser's Back button

use the 'Navigation Breadcrumbs' provided towards the top of this screen by

SpamCop Discussion > Discussions & Observations > How to use ...

Clicking ^^^^^^^ here

Link to comment
Share on other sites

If you are using the portal page and following "Latest Discussions" it is important to remember that they are date sorted based on the date of the first post in the topic.

So an older topic that all of a sudden get a lot of new replies will not appear in this list

Link to comment
Share on other sites

For those of you who prefer the layout of the newsgroups; you may want to try using the new display option: Display Mode = Outline.

To select this Mode, click on the [Options ] drop down box found on the right edge of the topic title bar.

The display mode appears to be a system wide setting, so once changed it will remain set for all topics, not just the selected topic. It can be toggle back and forth as often as desired.

Note: the first post will be displayed in its entirety, but all following reply will be listed in outline format.

Link to comment
Share on other sites

Wazoo, thanks for removing the drop down link when clicking on the edit button, the second choice was a real waste. Its nice to have it back the way it was before. Thank you

Link to comment
Share on other sites

Wazoo, thanks for removing the drop down link when clicking on the edit button, the second choice was a real waste. Its nice to have it back the way it was before. Thank you

There's that scare factor again. No edits made to forum code today ... the last several hours as been spent going through IPB forums, collecting notes, some code bits, etc. A check before hitting Reply showed me both fill and quick editing in a drop down ...

The difference really shows up based on just wht you're going to edit. If it's just a word, extra paragragh, add a line, the the "quick" thing is based on not having to repaint the entire screen with the whole editing box .... whereas, if you want to use the icon tools to add a link, change formatting, etc, then "full" edit would be the way to go ...

On the flip side, more people crying about their updated / patched / whatever 2.1.6 forums getting hacked ...

Started out be reading (what I consider a pretty strange) post some guy granted Moderator powers based on ???? (guessing code contributions .. but perhaps just on bfarber's decision) ... anyway, here we go with a week-end thing again ...

IPSBeyond _ IPB Assistance _ Hacking Topics, Notice to ALL Members

Posted by: Charles C. Yesterday, 07:34 PM

All topics that have to do with hacking have been closed until these can be proved, I've posted about this in the staff section to make Management aware of this. Do not request to re-open or post another until someone in the Management group updates on the subject. The actual IPS Staff are off on weekends, but you still can post a ticket in the customer center.

Yet, as per the norm, the new Topics continue .... however, no real data provided, other than the results of the hacks ....

Link to comment
Share on other sites

There's that scare factor again. No edits made to forum code today ...

Actually thats my mistake. Did not realize that the Edit button works differently dependant upon what and where you are doing the editing. Some places it gives you the drop down choices, some places it does not. Sorry about the confusion.
Link to comment
Share on other sites

hmmm, wondering where the "does not" mode show up ...???? (or maybe I don't want to know <G>)
Maybe I am just confused and don't know what I am talking about, or maybe it was a temporary thing, or maybe I just got lost; but the Edit button seems to work the same everywhere now - you get the drop down list. Sorry about that :(:huh:
Link to comment
Share on other sites

  • 1 month later...

And changes they keep a comming.

Due to a serious hack that took the Forum down for over 24 hours, it has become necessary to do another upgrade; this time to 2.1.7

This upgrade was for security purposes, to avoid future hacks like the one we just experienced.

The problem with any upgrade of this system is that there are countless individual modification to make the software do what we want it to.

Many of those modification need to be done over and some may not work the same as before, if at all.

But the dilgent Wazoo is working as fast as he can to put everything back into place.

We are greatly indebted to him for getting it back up as fast as he did.

Thank you.

Some of the items still to be reinstalled include:

SpellCheck - (has been repaired)

The link to the Reporting Server Status Charts - (has been repaired)

Note: if you happen to find something that is still not working the way it use to, please post it in this topic so it can be addressed.

Wazoo does a unbelievable job, but even he can miss something when there are as many modifications involved as with this Forum.

Edited by dbiel
Link to comment
Share on other sites

  • 2 weeks later...

Due to a serious hack that took the Forum down for over 24 hours, it has become necessary to do another upgrade; this time to 2.1.7

This upgrade was for security purposes, to avoid future hacks like the one we just experienced.

Hi.

I rarely post to this forum, or even read it, because I greatly prefer the news groups.

About 30 minutes ago, someone on 69.44.165.63 requested my forum password. Of course, the request went to my account, not them, so that's fine, but it puzzled me. I logged in, checked the announcements and saw that the forum account information had been compromised. This greatly surprised me because the the only mention by WazoO on the news group about the forum hack made no mention of losing account information.

Could you please tell me how this message board software stores passwords and such? Does it store them in plain text? Encrypted? If so, how is the password secured? Hashed? Hashed with a salt? What kind of hash?

[edit: I found the answers to these questions in the "lounge" section.]

I don't much care about my email address being leaked, but I need to know if I should change my password here.

Also, for those of us spamcop users who hang out mostly in the newsgroup, it would be nice if this information was posted there too.

Edited by wayne
Link to comment
Share on other sites

<snip>

Could you please tell me how this message board software stores passwords and such? Does it store them in plain text? Encrypted? If so, how is the password secured? Hashed? Hashed with a salt? What kind of hash?

[edit: I found the answers to these questions in the "lounge" section.]

I don't much care about my email address being leaked, but I need to know if I should change my password here.

<snip>

...The answer to that question, I believe, is also in the Wazoo's first reply in the aforementioned post in the "lounge" section.
Link to comment
Share on other sites

I hope you dont mind but I will suggest you to setup mod_security on the server with customised rules. You should prevent users from executing commands from browser and security risk of database injection and php injection would reduce.

Upgrading kernel version to version 2.6.17.6 or higher is also recommended as we have faced similar problems on some of our managed servers and mod_security alongwith kernel upgrade has been the only solution.

Link to comment
Share on other sites

  • 11 years later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...