If you are not registered or logged in, you may still use these forums but with limited features. Show recent topics
  [Search] Search   [Hottest Topics] Hottest Topics   [Members]  Member Listing   [FAQ]  FAQ 
[Register] Register / 
[Login] Login 
Messages posted by: Carbonize
Forum Index » Profile for Carbonize » Messages posted by Carbonize
Author Message
I'm guessing you updated from 2.2 to 2.3.1. This is a known problem and just requires you to change the field type of one of the SQL fields in book_auth. Do a search in this forum for login loop and you should find a fix.
Advanced Guestbook 2.3.1 saves all it's data in your MySQL database.
I was going to say that it uses valid javascript.
You could do this but in large sites the use of headers and footers is standard as this saves having to edit lots of files to make changes to the menu, banner etc.

There is a simpler way to do what you have done. Make the initial page as you say, leaving a space for the guestbook to go. Then simply copy everything from before where you want the guestbook to go into the header.php file and the code that appears after into the footer.php. This will add the html to both index and addentry pages.
Yup.

1 - Not to hard to implement.

2 - And short of having them require to have a username and password ow would you achieve this? You could store their IP but IP's change. You could store the entry in a cookie but they may elete the cookie or just not accept it in the first place. Basically unless they have to sign in to use your site this would be impossible.
I believe that 1.5 used a flatfile for storing the entries whilst 2.3.1 uses the database so to my knowledge there is no way of transfering the entries across.
They just need the password which is set in the General Settings part of the admin area.
ok first have you editted any of the files and did you give the permissions to the tmp and public folders?
It's not a security risk as I said. You could turn off ALL PHP error messages if you're that concerned.

As to stopping this message I could look into it if I can get off Halo 2 long enough.
The database's field for email is actually set at 60. God knows why the difference between database and html but ho hum.
Having the directory layout of a server is not a security risk, they still need to access the server to do anything. And if they access the server they will have full access to all directories.
The exploit is simple and posted in many places online. I don't feel it is appropriate for me to post it in here though. To unpatch simply do the reverse my fix.
this has been discussed before.Simply change the 30 to 60.
hmmmmmmm it's saying it cannot copy the image as it's not there to copy.
Which guestbook are we talking about? 1.5? 2.2 or 2.3.1?
 
Forum Index » Profile for Carbonize » Messages posted by Carbonize
Go to:   
Based on the open source JForum