[Solved]phpBB Security :: Special Fields Help

Support for IntegraMOD 141

Moderator: Integra Moderator

[Solved]phpBB Security :: Special Fields Help

PostAuthor: dan0042 » Sun Apr 08, 2007 4:23 am

Your phpBB Version: 2.0.
phpBB Type: Standard phpBB
MODs: No
Your knowledge: Beginner
Board URL: [url]http://[/url]

PHP Version:
MySQL Version:


What was done before the problem appeared?



What was done to try to solve the problem?




De.scription and Message

Amount of allowed admins
This number will set how many admins are allowed to be on your site. So no one can inject an admin account to gain access.
You currently have 1 real users set to 'Admin' status in the users table. It appears you have more admins in the users table than allowed!
Amount of allowed mods
This number will set how many moderators are allowed to be on your site. So no one can inject a moderator account to gain access.
You currently have 0 real users set to 'Moderator' status in the users table. It appears you have more mods in the users table than allowed!
[hr:2t9hhkc4]
New Instill...Now this comeing up
Last edited by dan0042 on Tue Apr 10, 2007 3:36 pm, edited 1 time in total.
:#: <img>
User avatar
dan0042
Integra Member
Integra Member
 
Posts: 170
Likes: 0 post
Liked in: 0 post
Joined: Fri Apr 21, 2006 4:06 pm
Cash on hand: 0.00

Re: phpBB Security :: Special Fields Help

PostAuthor: Helter » Sun Apr 08, 2007 2:15 pm

go to
acp/security/special
and set the amount of allowed mods and admins
Last edited by Helter on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
"Success is getting what you want. Happiness is wanting what you get." - Dale Carnegie
User avatar
Helter
Administrator
Administrator
 
Posts: 4554
Likes: 40 posts
Liked in: 116 posts
Images: 0
Joined: Sat Mar 11, 2006 4:46 pm
Cash on hand: 1,959.15
Location: Seattle Wa
IntegraMOD version: phpBB2x

Re: phpBB Security :: Special Fields Help

PostAuthor: dan0042 » Sun Apr 08, 2007 3:55 pm

"HelterSkelter";p="23836" wrote:go to
acp/security/special
and set the amount of allowed mods and admins

Did that still same

You currently have 1 real users set to 'Admin' status in the users table. It appears you have more admins in the users table than allowed!
You currently have 5 real users set to 'Moderator' status in the users table. It appears you have more mods in the users table than allowed!
Last edited by dan0042 on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
:#: <img>
User avatar
dan0042
Integra Member
Integra Member
 
Posts: 170
Likes: 0 post
Liked in: 0 post
Joined: Fri Apr 21, 2006 4:06 pm
Cash on hand: 0.00

Re: phpBB Security :: Special Fields Help

PostAuthor: Helter » Sun Apr 08, 2007 6:12 pm

chmod includes/phpbb_security to 666
Last edited by Helter on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
"Success is getting what you want. Happiness is wanting what you get." - Dale Carnegie
User avatar
Helter
Administrator
Administrator
 
Posts: 4554
Likes: 40 posts
Liked in: 116 posts
Images: 0
Joined: Sat Mar 11, 2006 4:46 pm
Cash on hand: 1,959.15
Location: Seattle Wa
IntegraMOD version: phpBB2x

Re: phpBB Security :: Special Fields Help

PostAuthor: dan0042 » Sun Apr 08, 2007 7:29 pm

"HelterSkelter";p="23844" wrote:chmod includes/phpbb_security to 666

It was Chmod 666......Still the same mate
Last edited by dan0042 on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
:#: <img>
User avatar
dan0042
Integra Member
Integra Member
 
Posts: 170
Likes: 0 post
Liked in: 0 post
Joined: Fri Apr 21, 2006 4:06 pm
Cash on hand: 0.00

Re: phpBB Security :: Special Fields Help

PostAuthor: Helter » Sun Apr 08, 2007 8:17 pm

it wasnt 666 at the time of installation

http://www.integramod.com/forum/viewtopic.php?t=3012
Last edited by Helter on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
"Success is getting what you want. Happiness is wanting what you get." - Dale Carnegie
User avatar
Helter
Administrator
Administrator
 
Posts: 4554
Likes: 40 posts
Liked in: 116 posts
Images: 0
Joined: Sat Mar 11, 2006 4:46 pm
Cash on hand: 1,959.15
Location: Seattle Wa
IntegraMOD version: phpBB2x

Re: phpBB Security :: Special Fields Help

PostAuthor: .QUACK.Major.Pain » Mon Apr 09, 2007 4:59 am

Mine has never worked from day 1 and I did the chmod right away too.

Change to enable and change the values, but always returns back to disabled and blank values.
Last edited by .QUACK.Major.Pain on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.

.QUACK.Major.Pain
Sr Integra Member
Sr Integra Member
 
Posts: 986
Likes: 0 post
Liked in: 0 post
Joined: Sat Jan 27, 2007 11:15 am
Cash on hand: 0.00

Re: phpBB Security :: Special Fields Help

PostAuthor: dan0042 » Mon Apr 09, 2007 5:48 am

function phpBBSecurity_AdminConfigName()
{
return 'phpBBSecurity_max_admins';
}

function phpBBSecurity_ModConfigName()
{
return 'phpBBSecurity_max_mods';
}

function phpBBSecurity_UseSpecial()
{
return 'phpBBSecurity_use_max';
[hr:2zomzfey]
TBA mate iam lost with this

Open includes/phpbb_security.php.

FINDPHP: à¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ º à¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ ¹ Select à¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ ºÃƒÆ’ ¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ ¹ Contract à¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ º
function phpBBSecurity_AdminConfigName()
{
return 'phpBBSecurity_max_admins';
}

function phpBBSecurity_ModConfigName()
{
return 'phpBBSecurity_max_mods';
}

function phpBBSecurity_UseSpecial()
{
return 'phpBBSecurity_use_max';
}


phpBBSecurity_max_admins = sec_admin value
phpBBSecurity_max_mods = sec_mod value
phpBBSecurity_use_max = sec_name value

So if the value of your sec_admin is abcdefg, then replace phpBBSecurity_max_admins with abcdefg in the phpbb_security.php file. When you updated your phpbb_security.php file probably wasn't CHMOD'd to allow the update to write to it.
Last edited by dan0042 on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
:#: <img>
User avatar
dan0042
Integra Member
Integra Member
 
Posts: 170
Likes: 0 post
Liked in: 0 post
Joined: Fri Apr 21, 2006 4:06 pm
Cash on hand: 0.00

Re: phpBB Security :: Special Fields Help

PostAuthor: .QUACK.Major.Pain » Mon Apr 09, 2007 11:08 am

Open includes/phpbb_security.php.

FINDPHP: à¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ º à¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ ¹ Select à¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ ºÃƒÆ’ ¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ ¹ Contract à¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ º
function phpBBSecurity_AdminConfigName()
{
return 'phpBBSecurity_max_admins';
}

function phpBBSecurity_ModConfigName()
{
return 'phpBBSecurity_max_mods';
}

function phpBBSecurity_UseSpecial()
{
return 'phpBBSecurity_use_max';
}


phpBBSecurity_max_admins = sec_admin value
phpBBSecurity_max_mods = sec_mod value
phpBBSecurity_use_max = sec_name value

So if the value of your sec_admin is abcdefg, then replace phpBBSecurity_max_admins with abcdefg in the phpbb_security.php file. When you updated your phpbb_security.php file probably wasn't CHMOD'd to allow the update to write to it.


Not sure but I think he means manually edit the file.
If you have 3 admins and 7 mods, then it would look like this:

Open includes/phpbb_security.php.

FINDPHP: à¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ º à¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ ¹ Select à¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ ºÃƒÆ’ ¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ ¹ Contract à¢Ãƒ ¢Ã¢â‚¬Å¡Ã‚ ¬Ãƒâ€šÃ‚ º
function phpBBSecurity_AdminConfigName()
{
return '3';
}

function phpBBSecurity_ModConfigName()
{
return '7';
}

function phpBBSecurity_UseSpecial()
{
return 'phpBBSecurity_use_max';
}


phpBBSecurity_max_admins = sec_admin value
phpBBSecurity_max_mods = sec_mod value
phpBBSecurity_use_max = sec_name value

So if the value of your sec_admin is abcdefg, then replace phpBBSecurity_max_admins with abcdefg in the phpbb_security.php file. When you updated your phpbb_security.php file probably wasn't CHMOD'd to allow the update to write to it.


I tried it but nothing looks like it has changed.
Last edited by .QUACK.Major.Pain on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.

.QUACK.Major.Pain
Sr Integra Member
Sr Integra Member
 
Posts: 986
Likes: 0 post
Liked in: 0 post
Joined: Sat Jan 27, 2007 11:15 am
Cash on hand: 0.00

Re: phpBB Security :: Special Fields Help

PostAuthor: Helter » Mon Apr 09, 2007 3:47 pm

open
includes/phpbb_security
Find
Code: Select all
 //*** The return valuse in the next 3 functions MUST be changed to the default values prior to installing.See Michales_notes.txt in install directory before running an install ***//         function phpBBSecurity_AdminConfigName()     {         return 'phpBBSecurity_max_admins';     }             function phpBBSecurity_ModConfigName()     {         return 'phpBBSecurity_max_mods';     }             function phpBBSecurity_UseSpecial()     {         return 'phpBBSecurity_use_max';     }          


replace with

Code: Select all
 //*** The return valuse in the next 3 functions MUST be changed to the default values prior to installing.See Michales_notes.txt in install directory before running an install ***//         function phpBBSecurity_AdminConfigName()     {         return 'admins_allowed';     }             function phpBBSecurity_ModConfigName()     {         return 'mods_allowed';     }             function phpBBSecurity_UseSpecial()     {         return 'block_unwanted';     }      


using phpmyadmin, run this querry

Code: Select all
 INSERT INTO `phpbb_config` VALUES ('admins_allowed', '10');INSERT INTO `phpbb_config` VALUES ('mods_allowed', '10');INSERT INTO `phpbb_config` VALUES ('block_unwanted', '1');INSERT INTO `phpbb_config` VALUES ('sec_admin', 'admins_allowed');INSERT INTO `phpbb_config` VALUES ('sec_mods', 'mods_allowed');INSERT INTO `phpbb_config` VALUES ('sec_name', 'block_unwanted');  


be sure phpbb_security is chmodded to 666 (many times your ftp client will say it is 666, but it is not. You then have to set it from your web host control panel)
Now go to acp/security/special and set the number to what they should be


if the querry fails due to fields already exist use this


Code: Select all
 REPLACE INTO `phpbb_config` VALUES ('admins_allowed', '10');REPLACE INTO `phpbb_config` VALUES ('mods_allowed', '10');REPLACE INTO `phpbb_config` VALUES ('block_unwanted', '1');REPLACE INTO `phpbb_config` VALUES ('sec_admin', 'admins_allowed');REPLACE INTO `phpbb_config` VALUES ('sec_mods', 'mods_allowed');REPLACE INTO `phpbb_config` VALUES ('sec_name', 'block_unwanted');  
Last edited by Helter on Mon Apr 09, 2007 4:02 pm, edited 1 time in total.
"Success is getting what you want. Happiness is wanting what you get." - Dale Carnegie
User avatar
Helter
Administrator
Administrator
 
Posts: 4554
Likes: 40 posts
Liked in: 116 posts
Images: 0
Joined: Sat Mar 11, 2006 4:46 pm
Cash on hand: 1,959.15
Location: Seattle Wa
IntegraMOD version: phpBB2x

Re: phpBB Security :: Special Fields Help

PostAuthor: .QUACK.Major.Pain » Mon Apr 09, 2007 3:53 pm

Just to let you know, I tried the above and got the following CT debug error:

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Script-Filename: /forum/admin/admin_phpbbmyadmin.php
----------------

Request-Method: POST

Matching rule: insert
In variable: this_query

Matching rule: into
In variable: this_query

Matching rule: '
In variable: this_query

Possible solution:
------------------

#
#-----[ OPEN ]------------------------------------------
#
/forum/admin/admin_phpbbmyadmin.php

#
#-----[ FIND ]------------------------------------------
#
define('IN_PHPBB', 1);

#
#-----[ AFTER, ADD ]------------------------------------------
#
define('CT_SECLEVEL', 'MEDIUM');
$ct_ignorepvar = array('this_query');

#
#-----[ SAVE/CLOSE ALL FILES ]------------------------------------------
#
# EoM




After I did the debug, I got this:

Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in /home/k1jon/public_html/forum/db/mysql4.php on line 254

Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in /home/k1jon/public_html/forum/db/mysql4.php on line 254

Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in /home/k1jon/public_html/forum/db/mysql4.php on line 254


General Error
Error in SQL query INSERT INTO `phpbb_config` VALUES ('sec_admin', 'admins_allowed');
Click here to return to phpBBMyAdmin board.
Click here to return to Admin Control Panel board.

DEBUG MODE

SQL Error : 1062 Duplicate entry 'sec_admin' for key 1


Just to make sure, The phpbbmyadmin in ACP is ok to use?

I did check the ACP>Security>Special screen and changed values. It works now.
Last edited by .QUACK.Major.Pain on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.

.QUACK.Major.Pain
Sr Integra Member
Sr Integra Member
 
Posts: 986
Likes: 0 post
Liked in: 0 post
Joined: Sat Jan 27, 2007 11:15 am
Cash on hand: 0.00

Re: phpBB Security :: Special Fields Help

PostAuthor: Helter » Mon Apr 09, 2007 4:04 pm

I always use phpmyadmin from my webhost

if your having trouble, try this syntax
Code: Select all
 INSERT INTO phpbb_config VALUES ('admins_allowed', '9');INSERT INTO phpbb_config VALUES ('mods_allowed', '9');INSERT INTO phpbb_config VALUES ('block_unwanted', '1');INSERT INTO phpbb_config VALUES ('sec_admin', 'admins_allowed');INSERT INTO phpbb_config VALUES ('sec_mods', 'mods_allowed');INSERT INTO phpbb_config VALUES ('sec_name', 'block_unwanted');  
Last edited by Helter on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
"Success is getting what you want. Happiness is wanting what you get." - Dale Carnegie
User avatar
Helter
Administrator
Administrator
 
Posts: 4554
Likes: 40 posts
Liked in: 116 posts
Images: 0
Joined: Sat Mar 11, 2006 4:46 pm
Cash on hand: 1,959.15
Location: Seattle Wa
IntegraMOD version: phpBB2x

PostAuthor: dan0042 » Tue Apr 10, 2007 3:36 pm

its working thanks
Last edited by dan0042 on Wed Dec 31, 1969 5:00 pm, edited 1 time in total.
:#: <img>
User avatar
dan0042
Integra Member
Integra Member
 
Posts: 170
Likes: 0 post
Liked in: 0 post
Joined: Fri Apr 21, 2006 4:06 pm
Cash on hand: 0.00


Return to IntegraMOD 141

Who is online

Registered users: App360MonitorBot, Bing [Bot], Google [Bot], Majestic-12 [Bot]