Search found 54 matches

by meisterberger
Wed Apr 24, 2019 7:28 pm
Forum: [3.2.x] Support Forum
Topic: Getting SQL Injection Attack warnings when people use PhotoBucket
Replies: 13
Views: 865

Re: Getting SQL Injection Attack warnings when people use PhotoBucket

â?? I ended up exporting the entire forum database, then opened it in NotePad ++ next, I search for and removed ALL occurrences of the above character in the entire database. Mostly I found them in place of apostrophes. Finally, I re-imported the "cleaned-up" database back into MySQL. Everything se...
by meisterberger
Wed Apr 24, 2019 7:25 pm
Forum: [3.2.x] Support Forum
Topic: Getting SQL Injection Attack warnings when people use PhotoBucket
Replies: 13
Views: 865

Re: Getting SQL Injection Attack warnings when people use PhotoBucket

The term "magic quotes" is wrong. I don't understand? Isn't that what it was called? Magic quotes. Magic quotes was a feature of the PHP scripting language, wherein strings are automatically escaped—special characters are prefixed with a backslash—before being passed on. It was introduced to help n...
by meisterberger
Sun Apr 07, 2019 1:18 pm
Forum: [3.2.x] Support Forum
Topic: Getting SQL Injection Attack warnings when people use PhotoBucket
Replies: 13
Views: 865

Re: Getting SQL Injection Attack warnings when people use PhotoBucket

I'm finding a lot of these (thousands (make that 10's of thousands) of them) in the old vBulletin posts..... â?? in this context.... For me itâ??s a fine line, So, maybe Magic Quotes was escaping apostrophes with â?? Unless I'm mistaken, these characters are not compatible with phpBB ? And I think M...
by meisterberger
Sun Apr 07, 2019 1:45 am
Forum: [3.2.x] Support Forum
Topic: Escape Characters inserted into posts
Replies: 0
Views: 888

Escape Characters inserted into posts

Is it possible to delete this thread?

I may have accidentally made a duplicate post.
by meisterberger
Tue Apr 02, 2019 4:45 pm
Forum: [3.2.x] Support Forum
Topic: Getting SQL Injection Attack warnings when people use PhotoBucket
Replies: 13
Views: 865

Re: Getting SQL Injection Attack warnings when people use PhotoBucket

Most likely \\x22 was the trigger - phpBB stores this as HTML entity ( " ). So yes: the data stored in your database tables (not only post texts) might be improper. You always write "upgrade", but you needed to convert to phpBB first. Maybe a fault of the converter which just is not that caref...
by meisterberger
Mon Apr 01, 2019 5:18 pm
Forum: [3.2.x] Support Forum
Topic: Getting SQL Injection Attack warnings when people use PhotoBucket
Replies: 13
Views: 865

Re: Getting SQL Injection Attack warnings when people use PhotoBucket

One other thing.... My current 3.2.5 install was upgraded originally from vBulletin 3.6.10 In that version of vBulletin they used MAGIC QUOTES. Which as since been deprecated and is no longer used. But, all those posts were copied verbatim into 3.2.5 during the upgrade. I have over 225,000 posts and...
by meisterberger
Mon Apr 01, 2019 5:15 pm
Forum: [3.2.x] Support Forum
Topic: Getting SQL Injection Attack warnings when people use PhotoBucket
Replies: 13
Views: 865

Re: Getting SQL Injection Attack warnings when people use PhotoBucket

Brf wrote:
Mon Apr 01, 2019 5:12 pm
Modsecurity is typically matching something in post text to a known malicious pattern.
Since phpBB's post text is escaped before it is stored, there is no known pattern that could possibly be malicious.
Ok, that's what I was looking for.

Thanks again
by meisterberger
Mon Apr 01, 2019 4:46 pm
Forum: [3.2.x] Support Forum
Topic: Getting SQL Injection Attack warnings when people use PhotoBucket
Replies: 13
Views: 865

Re: Getting SQL Injection Attack warnings when people use PhotoBucket

modsecurity is set by your web host. You would have to ask them to turn off that rule. Of course. (I'm the host :-) I was just wondering if anyone else with phpBB has had this same problem and if it "could" be an issue with phpBB's interaction with PhotoBucket or if it definitely is not anything to...
by meisterberger
Mon Apr 01, 2019 3:53 pm
Forum: [3.2.x] Support Forum
Topic: Getting SQL Injection Attack warnings when people use PhotoBucket
Replies: 13
Views: 865

Getting SQL Injection Attack warnings when people use PhotoBucket

Good morning, I'm having an issue with some members of my forum getting constantly blocked by ModSecurity. The logs are showing SQL Injection Attacks from these users, but they say they have updated malware and virus scanners and their computers are virus and malware free. These are long time member...
by meisterberger
Fri Mar 22, 2019 3:42 pm
Forum: [3.2.x] Support Forum
Topic: Smilies calling for file xxxxxxx.gif but ICON_xxxxxx.gif are actual names of smilies
Replies: 1
Views: 114

Re: Smilies calling for file xxxxxxx.gif but ICON_xxxxxx.gif are actual names of smilies

NIX this question.

Sry.

Turns out the smilies simply were not copied from the /images/smilies directory of the old forum to the new forum.
by meisterberger
Fri Mar 22, 2019 3:22 pm
Forum: [3.2.x] Support Forum
Topic: Smilies calling for file xxxxxxx.gif but ICON_xxxxxx.gif are actual names of smilies
Replies: 1
Views: 114

Smilies calling for file xxxxxxx.gif but ICON_xxxxxx.gif are actual names of smilies

Another odd issue...... None of the smilies show up in the Right side of the Post Edit page, Reply to Post page or New Post page. (See --------------------------------->>>>>> On THIS board...here is the URL to one of the smilies to the right https://www.phpbb.com/community/images/smilies/icon_e_bigg...
by meisterberger
Thu Mar 21, 2019 6:09 pm
Forum: [3.2.x] Support Forum
Topic: All tables Are Missing Auto Increment
Replies: 7
Views: 147

Re: All tables Are Missing Auto Increment

Steve, Thanks again. I'm sure your method was safest and the best bet. I just wanted to try this shortcut. Hopefully I won't regret it. I finished changing all the necessary table ID fields to Auto Increment as needed a bit ago......only took about 10 minutes....and the board seems to be running fin...
by meisterberger
Thu Mar 21, 2019 5:52 pm
Forum: [3.2.x] Support Forum
Topic: All tables Are Missing Auto Increment
Replies: 7
Views: 147

Re: All tables Are Missing Auto Increment

Thanks Robert. The specific tables and fields that require AI can be found easily by looking at the SQL dump file, at the bottom of the file where all keys, unique keys and Auto Increment settings are applied. as I'm 100% certain you already knew. That said...please don't take this as not appreciati...
by meisterberger
Thu Mar 21, 2019 5:03 pm
Forum: [3.2.x] Support Forum
Topic: All tables Are Missing Auto Increment
Replies: 7
Views: 147

Re: All tables Are Missing Auto Increment

Do a full backup and also a data-only backup of your database. Then, DROP all the phpbb tables in your database. Do a fresh install of your version of phpBB on the now empty database. When that is done, empty all the tables and import the data-only backup. Roger that. Will do and THANKS! If I under...
by meisterberger
Thu Mar 21, 2019 4:22 pm
Forum: [3.2.x] Support Forum
Topic: All tables Are Missing Auto Increment
Replies: 7
Views: 147

Re: All tables Are Missing Auto Increment

david63 wrote:
Thu Mar 21, 2019 4:19 pm
meisterberger wrote:
Thu Mar 21, 2019 4:16 pm
Is this coming from a PHP.INI setting or from phpBB and in either case, how do I turn off the verbosity so all this information is not exposed?
It depends what the errors are - a link to your board would help
Hello David.
I don't dare put the board back online until this is sorted out.

Go to advanced search