[DEV] Extension List

A place for Extension Authors to post and receive feedback on Extensions still in development. No Extensions within this forum should be used within a live environment!
Scam Warning
Forum rules
READ: phpBB.com Board-Wide Rules and Regulations

IMPORTANT: Extensions Development rules

IMPORTANT FOR NEEDED EVENTS!!!
If you need an event for your extension please read this for the steps to follow to request the event(s)
User avatar
tas2580
Registered User
Posts: 295
Joined: Wed May 30, 2007 1:56 am
Location: Stuttgart, Germany
Contact:

Re: [DEV] Extension List

Post by tas2580 »

david63 wrote:Is there not a potential security issue with showing everyone which extensions are installed?
It's possible to check witch extensions are installed without this extension too. You can do this on any forum, if you want to try it -> https://tas2580.net/test.php
This checks for about 150 extensions, more coming soon.
Mauron wrote:I guess Jessica meant to mark some installed extensions as private i. e. to check whether an extension can be listed in this public list or not.
Maybe I will add a option for that in the next version.

User avatar
david63
Registered User
Posts: 17375
Joined: Thu Dec 19, 2002 8:08 am
Location: Lancashire, UK
Name: David Wood
Contact:

Re: [DEV] Extension List

Post by david63 »

tas2580 wrote:t's possible to check witch extensions are installed without this extension too.
It might if that script worked.

Do you think it wise to post a script that, if worked, could reveal to any Internet Troll what you have installed on a any phpBB site?
David
Remember: You only know what you know and - you don't know what you don't know!
My CDB Contributions | How to install an extension
I will not be accepting translations for any of my extensions in Github - please post any translations in the appropriate topic.
No support requests via PM or email as they will be ignored

User avatar
tas2580
Registered User
Posts: 295
Joined: Wed May 30, 2007 1:56 am
Location: Stuttgart, Germany
Contact:

Re: [DEV] Extension List

Post by tas2580 »

The script works, I have tested it on 5 forums and on each of it it worked.

I don't think that this script is a problem, I also don't think that it is a problem if anyone knows which extensions are installed.

If you think it's a problem that someone sees which extensions are installed is not the script the problem but that it is possible to read out this information. Security through obscurity is never a good idea ;) So if you don't want that anyone knows which extensions you have installed you need to do something against the public readable .json files.

User avatar
david63
Registered User
Posts: 17375
Joined: Thu Dec 19, 2002 8:08 am
Location: Lancashire, UK
Name: David Wood
Contact:

Re: [DEV] Extension List

Post by david63 »

tas2580 wrote:The script works
No it doesn't - it just returns a blank page
David
Remember: You only know what you know and - you don't know what you don't know!
My CDB Contributions | How to install an extension
I will not be accepting translations for any of my extensions in Github - please post any translations in the appropriate topic.
No support requests via PM or email as they will be ignored

User avatar
tas2580
Registered User
Posts: 295
Joined: Wed May 30, 2007 1:56 am
Location: Stuttgart, Germany
Contact:

Re: [DEV] Extension List

Post by tas2580 »

Try it with https://www.phpbb.com/community as URL. If you send me a PM with the URL you have tested I can look where the problem is, maybe the webserver does not allow to access .json files, than it will not work.

User avatar
RMcGirr83
Recognised Extension Developer
Posts: 21034
Joined: Wed Jun 22, 2005 4:33 pm
Location: Your display
Name: Rich McGirr
Contact:

Re: [DEV] Extension List

Post by RMcGirr83 »

I just ran it on http://rmcgirr83.org and it returned this
"NetworkError: 503 Service Unavailable - https://tas2580.net/test.php"


so yeah, doesn't seem to work.
In times of change, learners inherit the earth, while the learned find themselves beautifully equipped to deal with a world that no longer exists - Eric Hoffer
Former Modifications/Extensions Team Member | My extensions
Appreciate the extensions/mods/support then buy me a beer
All requests for support via PM will be ignored

User avatar
tas2580
Registered User
Posts: 295
Joined: Wed May 30, 2007 1:56 am
Location: Stuttgart, Germany
Contact:

Re: [DEV] Extension List

Post by tas2580 »

Time: 7.451s
Your Forum is too slow for my Webserver :cry: Try it with phpBB.com or give me a bigger Webserver ;)

The principle behind the script is quite simple, you can access ext/phpbb/collapsiblecategories/composer.json with your browser. So you can use a script that tries all available extensions and get the information from the composer.json. For that you need only a fast enough server (sorry my public webserver is not fast because I'm poor) and a list with all extensions.

If you want to prevent that insert in your .htaccess

Code: Select all

<Files "*.json">
	Order Allow,Deny
	Deny from All
</Files>

User avatar
RMcGirr83
Recognised Extension Developer
Posts: 21034
Joined: Wed Jun 22, 2005 4:33 pm
Location: Your display
Name: Rich McGirr
Contact:

Re: [DEV] Extension List

Post by RMcGirr83 »

Not sure where you are getting that time. In the footer of that forum it states under 1 second. Not that I really care I'll never use this extension.

Just tried it again and it returned a blank white page and that was using phpbb.com
In times of change, learners inherit the earth, while the learned find themselves beautifully equipped to deal with a world that no longer exists - Eric Hoffer
Former Modifications/Extensions Team Member | My extensions
Appreciate the extensions/mods/support then buy me a beer
All requests for support via PM will be ignored

Post Reply

Return to “Extensions in Development”