<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[Latest posts for the topic "Advanced Guestbook Fixes and Mods"]]></title>
		<link>https://proxy2.de/forum/posts/list/3.php</link>
		<description><![CDATA[Latest messages posted in the topic "Advanced Guestbook Fixes and Mods"]]></description>
		<generator>JForum - http://www.jforum.net</generator>
			<item>
				<title>Advanced Guestbook Fixes and Mods</title>
				<description><![CDATA[ Fixes for Version 2.3.1 Exploits:<br /> [list]Patch for add.class.php, by Carbonize:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=4144" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=4144</a><br /> <br /> Workaround Patch for index.php, from Security Focus:<br /> <a class="snap_shots" href="http://www.securityfocus.com/bid/11798/solution/" target="_blank" rel="nofollow">http://www.securityfocus.com/bid/11798/solution/</a>[/list]<br /> Fix for Version 2.2 Exploit, by Carbonize:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3650" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3650</a><br /> <br /> Security Issues, by Trevor: <br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3475" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3475</a><br /> <br /> Help with Upgrade from 2.2 to 2.3.1: <br /> [list]Guestbook 2.2. to 2.3.1 upgrade script, by Carbonize:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=4010" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=4010</a><br /> <br /> Discussion on Manual Upgrade:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3334" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3334</a>[/list]Admin Loop (Keeps going back to Login): <br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?p=11334&amp;highlight=#11334" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?p=11334&amp;highlight=#11334</a><br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3786" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3786</a><br /> <br /> Admin config.inc.php file:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3654" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3654</a><br /> <br /> Password Lock, by Carbonize: <br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?p=9621&amp;highlight=#9621" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?p=9621&amp;highlight=#9621</a> <br /> <br /> Changing the Admin Password:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3744" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3744</a><br /> <br /> Resetting the Admin Password:<br /> [list]With Carbonize's reset.php file: <br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=4071" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=4071</a><br /> <br /> In PhpMyAdmin, by Jam'n:   <br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=2595" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=2595</a><br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=1711" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=1711</a><br /> ([b]Important: Only follow Jam'n's instructions for resetting the password.  Do Not follow others' suggestions to Overwrite the v2.3.1 session.class.php file with the 2.2 version![/b])[/list]Make a backup .sql file of guestbook entries:<br /> [list]Export/Import MySQL Database:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3580&amp;highlight=sql" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3580&amp;highlight=sql</a><br /> <br /> Guestbook MySQL database transfer:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?p=5819&amp;highlight=#5819" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?p=5819&amp;highlight=#5819</a><br /> <br /> Where is the guestbook database?:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=2761&amp;highlight=sql" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=2761&amp;highlight=sql</a><br /> [/list]Change the Guestbook Picture:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3827&amp;highlight=picture" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3827&amp;highlight=picture</a><br /> <br /> How To Change The Drop Down Menu In Advanced Guestbook, by Trevor: <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3315" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3315</a><br /> <br /> How to change the required fields in Advanced Guestbook, by Trevor:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=2877" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=2877</a><br /> <br /> Change the Comments Text Color:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3380" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3380</a><br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3219" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3219</a><br /> <br /> Image Verification script, by Carbonize (Help reduce Guestbook spam): <br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?p=9976" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?p=9976</a><br /> <a class="snap_shots" href="http://www.carbonize.co.uk/verification.zip" target="_blank" rel="nofollow">http://www.carbonize.co.uk/verification.zip</a> is the official download for the image verification mod<br /> <br /> Quick Mod to have AG 2.3.1 log the IP rather than the hostname, by Carbonize: <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?p=10108&amp;highlight=#10108" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?p=10108&amp;highlight=#10108</a><br /> <br /> Admin Panel Logout redirect, by Carbonize: <br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3409" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3409</a><br /> <br /> "Warning: Cannot modify header information - headers already sent by...": <br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3200&amp;highlight=cannot+modify+headers" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3200&amp;highlight=cannot+modify+headers</a><br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3093&amp;highlight=cannot+modify+header" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3093&amp;highlight=cannot+modify+header</a><br /> <br /> "Warning: fopen(./templates/body.php): failed to open stream: Permission denied in..."<br /> "Warning: fwrite(): supplied argument is not a valid stream resource in..."<br /> "Warning: fclose(): supplied argument is not a valid stream resource in..."<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3580&amp;highlight=fopen" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3580&amp;highlight=fopen</a><br /> <br /> "Fatal error: Cannot instantiate non-existent class: "<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3812" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3812</a><br /> <br /> "Warning: fread(): Length parameter must be greater than 0"<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3351&amp;postdays=0&amp;postorder=asc&amp;highlight=fread&amp;start=30" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3351&amp;postdays=0&amp;postorder=asc&amp;highlight=fread&amp;start=30</a><br /> <br /> Missing Pictures in Guestbook:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3628&amp;highlight=missing+pictures" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3628&amp;highlight=missing+pictures</a><br /> <br /> Configuring Smilies in Guestbook: <br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3901" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3901</a><br /> <br /> Getting Your Logo and Menus In The Guestbook:<br /> [list]Include your header, by Carbonize: <br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3460" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3460</a><br /> <br /> How can I integrate my guestbook into an existing site?:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3863" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3863</a><br /> <br /> A newbies guide to placing the guestbook in an html page, by fatjack:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3921" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3921</a><br /> <br /> How To Change The Drop Down Menu In Advanced Guestbook, by Trevor: <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3315" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3315</a><br /> <br /> Adding Guestbook to a Frame: <br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?p=9728" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?p=9728</a>[/list]Changing the wording ("here you can leave your mark."... etc.): <br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?p=9870" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?p=9870</a><br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?p=9264" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?p=9264</a> <br /> <br /> Encrypt visitors email addresses in guestbook (stop email harvesters):<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3778" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3778</a><br /> <br /> Making Email a Required field:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3388&amp;highlight=required+field" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3388&amp;highlight=required+field</a><br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=2877" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=2877</a><br /> <br /> Remove visitors email addresses from guestbook view:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?p=10856&amp;highlight=#10856" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?p=10856&amp;highlight=#10856</a><br /> <br /> Increase email field size to 60 characters (in templates/form.php):<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3912" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3912</a><br /> <br /> Increase homepage field size to 65 characters (in templates/form.php):<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=4075" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=4075</a><br /> <br /> Change the Time in Advanced Guestbook:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3758" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3758</a><br /> <br /> Advanced Guestbook Manual, by Jam'n: <br /> <a class="snap_shots" href="http://www.geocities.com/nathalonia/gbpoll" target="_blank" rel="nofollow">http://www.geocities.com/nathalonia/gbpoll</a><br /> <br /> Explanation of Chmod File Permissions:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?p=10072&amp;highlight=#10072" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?p=10072&amp;highlight=#10072</a><br /> <br /> How to change File Permissions from the CPanel:<br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?p=10713&amp;highlight=#10713" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?p=10713&amp;highlight=#10713</a><br /> <br /> Advanced Guestbook versions for Content Management Systems:<br /> [list]TPK Guestbook 3.1.1  (PhpNuke Version)<br /> See it at: <a class="snap_shots" href="http://www.tp-krefeld.de/modules.php?name=Guestbook" target="_blank" rel="nofollow">http://www.tp-krefeld.de/modules.php?name=Guestbook</a><br /> Download it at: <a class="snap_shots" href="http://www.phpnuke-module.de/" target="_blank" rel="nofollow">http://www.phpnuke-module.de/</a><br /> <br /> Nuke Guestbook 2.0.0 (PhpNuke Version)<br /> <a class="snap_shots" href="http://www.codec-download.com/modules.php?name=Guestbook" target="_blank" rel="nofollow">http://www.codec-download.com/modules.php?name=Guestbook</a> (English)<br /> <a class="snap_shots" href="http://www.rideo.de/modules.php?cid=18&amp;d_op=viewdownload&amp;min=30&amp;name=Downloads" target="_blank" rel="nofollow">http://www.rideo.de/modules.php?cid=18&amp;d_op=viewdownload&amp;min=30&amp;name=Downloads</a> (German)<br /> <br /> There are probably more PhpNuke versions out there.  <br /> <br /> Html code enabled does not appear to pose a risk, but that could be because the admin is using Sentinel (a must-have for PhpNuke Security!).<br /> <br /> <a class="snap_shots" href="http://www.3hc.co.uk/studentsupport/" target="_blank" rel="nofollow">http://www.3hc.co.uk/studentsupport/</a> (PhpWebSite Version) <br /> Note:  Some CMS versions are based on early versions of Advanced Guestbook (not 2.3.1), so you should investigate re: security.  Mods listed here may not work with these versions.[/list]]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/10233.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/10233.php</link>
				<pubDate><![CDATA[Thu, 2 Sep 2004 15:33:52]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Here's the correct link to the post for Carbonize's header instructions:<br /> <br /> <a class="snap_shots" href="http://proxy2.de/forum/viewtopic.php?t=3460" target="_blank" rel="nofollow">http://proxy2.de/forum/viewtopic.php?t=3460</a>]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/10243.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/10243.php</link>
				<pubDate><![CDATA[Thu, 2 Sep 2004 19:39:54]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Damn this thread makes it look like I need a life <img src="https://proxy2.de/forum//images/smilies/1cfd6e2a9a2c0cf8e74b49b35e2e46c7.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/10275.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/10275.php</link>
				<pubDate><![CDATA[Sat, 4 Sep 2004 19:49:07]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ You mean you have a life? Besides redoing most of the GB code.  <img src="https://proxy2.de/forum//images/smilies/69934afc394145350659cd7add244ca9.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/10277.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/10277.php</link>
				<pubDate><![CDATA[Sat, 4 Sep 2004 21:11:40]]> GMT</pubDate>
				<author><![CDATA[ JTD]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="Carbonize"]Damn this thread makes it look like I need a life <img src="https://proxy2.de/forum//images/smilies/1cfd6e2a9a2c0cf8e74b49b35e2e46c7.gif" />[/quote]<br /> <br /> This is your life.  <img src="https://proxy2.de/forum//images/smilies/97ada74b88049a6d50a6ed40898a03d7.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/10285.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/10285.php</link>
				<pubDate><![CDATA[Sat, 4 Sep 2004 23:00:54]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *bump*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/11480.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/11480.php</link>
				<pubDate><![CDATA[Fri, 5 Nov 2004 05:12:57]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *BUMP*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/11492.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/11492.php</link>
				<pubDate><![CDATA[Fri, 5 Nov 2004 13:10:52]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *bump*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/11737.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/11737.php</link>
				<pubDate><![CDATA[Sun, 14 Nov 2004 08:16:08]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *BUMP*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/11759.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/11759.php</link>
				<pubDate><![CDATA[Mon, 15 Nov 2004 02:49:33]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *bump* there it is.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/11770.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/11770.php</link>
				<pubDate><![CDATA[Mon, 15 Nov 2004 09:49:20]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *bump*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/11830.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/11830.php</link>
				<pubDate><![CDATA[Wed, 17 Nov 2004 04:29:00]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *bump*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/11928.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/11928.php</link>
				<pubDate><![CDATA[Sat, 20 Nov 2004 09:04:49]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *BUMP* <img src="https://proxy2.de/forum//images/smilies/283a16da79f3aa23fe1025c96295f04f.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12061.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12061.php</link>
				<pubDate><![CDATA[Wed, 24 Nov 2004 08:03:33]]> GMT</pubDate>
				<author><![CDATA[ JTD]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *bump*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12090.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12090.php</link>
				<pubDate><![CDATA[Thu, 25 Nov 2004 15:11:51]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *bump*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12224.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12224.php</link>
				<pubDate><![CDATA[Thu, 2 Dec 2004 15:00:34]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *bump*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12278.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12278.php</link>
				<pubDate><![CDATA[Fri, 3 Dec 2004 16:50:13]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *bump*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12343.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12343.php</link>
				<pubDate><![CDATA[Tue, 7 Dec 2004 20:47:08]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Lot of bumps there Amber. You a bit accident prone ?]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12348.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12348.php</link>
				<pubDate><![CDATA[Tue, 7 Dec 2004 21:30:01]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Inspector Clouseau strikes again.  <img src="https://proxy2.de/forum//images/smilies/97ada74b88049a6d50a6ed40898a03d7.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12365.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12365.php</link>
				<pubDate><![CDATA[Thu, 9 Dec 2004 05:50:16]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *BUMP*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12493.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12493.php</link>
				<pubDate><![CDATA[Sun, 19 Dec 2004 08:55:22]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [b]*BUMP*[/b]]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12586.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12586.php</link>
				<pubDate><![CDATA[Wed, 22 Dec 2004 00:54:58]]> GMT</pubDate>
				<author><![CDATA[ JTD]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *bump*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12615.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12615.php</link>
				<pubDate><![CDATA[Sun, 26 Dec 2004 05:14:55]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *BUMP*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12711.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12711.php</link>
				<pubDate><![CDATA[Fri, 31 Dec 2004 03:57:46]]> GMT</pubDate>
				<author><![CDATA[ JTD]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Thank you for bumping this. I found the answer to what was driving me crazy and can feel my sanity returning.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12714.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12714.php</link>
				<pubDate><![CDATA[Fri, 31 Dec 2004 04:26:33]]> GMT</pubDate>
				<author><![CDATA[ Takara]]></author>
			</item>
			<item>
				<title>Thanks for all the hard work on this!!!</title>
				<description><![CDATA[ I was recently hacked by  samehelmasry.jeeran.com - guestbook data entirely wiped out but I always keep regular backups.   <img src="https://proxy2.de/forum//images/smilies/2786c5c8e1a8be796fb2f726cca5a0fe.gif" />  <br /> <br /> Hacker came directly to the guestbook from Google with keyword phrase  powered by Guestbook 2.2  - just to let you know, I've never had the html enabled - but the gb was still swiped  <img src="https://proxy2.de/forum//images/smilies/908627bbe5e9f6a080977db8c365caff.gif" /> <br /> <br /> It is a comfort to be able to check in here to find the solutions. You all are the bestest!!!<br /> <br /> Thanks  <img src="https://proxy2.de/forum//images/smilies/97ada74b88049a6d50a6ed40898a03d7.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12801.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12801.php</link>
				<pubDate><![CDATA[Mon, 3 Jan 2005 09:31:36]]> GMT</pubDate>
				<author><![CDATA[ ET]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ I take it you have now patched the login exploit that plagues version 2.2?]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12802.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12802.php</link>
				<pubDate><![CDATA[Mon, 3 Jan 2005 10:34:58]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title>Thanks</title>
				<description><![CDATA[ Thanks for asking Carbonize.  <br /> <br /> I have it fixed - and just to be safe, have moved the gb outta the Google path into a new directory and left a mockup version on the old path in the event the individual feels the need to try again.... After going to Google and typing in that keyword phrase, I see that tons and tons of people are hacked - some pretty nasty stuff out there  <img src="https://proxy2.de/forum//images/smilies/499fd50bc713bfcdf2ab5a23c00c2d62.gif" />  <br /> <br /> The only reason I caught it so quickly is because of an error alert that I got when s/he typed in the word "admin.php" incorrectly - The error log picked it up and sent me a notice.  <img src="https://proxy2.de/forum//images/smilies/97ada74b88049a6d50a6ed40898a03d7.gif" /> Otherwise, I wouldn't have known for a few days (or more) Yeesh!!! <img src="https://proxy2.de/forum//images/smilies/2786c5c8e1a8be796fb2f726cca5a0fe.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12803.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12803.php</link>
				<pubDate><![CDATA[Mon, 3 Jan 2005 11:38:56]]> GMT</pubDate>
				<author><![CDATA[ ET]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [color="purple"]*BUMP* Will someone sticky these damn things please.[/color]]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12916.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12916.php</link>
				<pubDate><![CDATA[Fri, 7 Jan 2005 19:32:57]]> GMT</pubDate>
				<author><![CDATA[ JTD]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ bump]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/12958.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/12958.php</link>
				<pubDate><![CDATA[Sun, 9 Jan 2005 06:51:32]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *bump*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13025.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13025.php</link>
				<pubDate><![CDATA[Wed, 12 Jan 2005 10:06:06]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *bump*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13189.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13189.php</link>
				<pubDate><![CDATA[Wed, 19 Jan 2005 04:24:36]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Great post amber222, thanks!!!<br /> <br /> And what about:<br /> http://www.securityfocus.com/bid/11798/exploit/<br /> (or did you already mention it?)<br /> <br /> There's fix/workaround there too.<br /> <br /> I added (guestbook/index.php)[code]    $entry = strip_tags&#40;$entry&#41;;[/code]<br /> after<br /> [code]    $entry = &#40;isset&#40;$HTTP_POST_VARS&#91;&quot;entry&quot;&#93;&#41;&#41; ? $HTTP_POST_VARS&#91;&quot;entry&quot;&#93; &#58; $entry;[/code](2x) and it seems to work<br /> <br /> but probably their fix is better (adding [b]$entry = htmlspecialchars ($entry);[/b]) since I'm not a programmer<br /> <br /> BTW: the exploit seems to work on both 2.2. and 2.3.1]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13194.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13194.php</link>
				<pubDate><![CDATA[Wed, 19 Jan 2005 10:42:30]]> GMT</pubDate>
				<author><![CDATA[ PandA.nl]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="PandA.nl"]<br /> <br /> BTW: the exploit seems to work on both 2.2. and 2.3.1[/quote]<br /> <br /> The sql exploit ony works on 2.3.1 if you have a very outdated version of php.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13195.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13195.php</link>
				<pubDate><![CDATA[Wed, 19 Jan 2005 11:52:27]]> GMT</pubDate>
				<author><![CDATA[ JTD]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="JTD"]The sql exploit ony works on 2.3.1 if you have a very outdated version of php.[/quote]That's not what I read, are you sure we're talking about the same thing?]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13197.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13197.php</link>
				<pubDate><![CDATA[Wed, 19 Jan 2005 16:36:21]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ the exploit works on Advanced guestbook 2.2 and 2.3, 2.3.1 was released to fix the exploit. It works on some copies of 2.3.1 because the webmasters have replaced the 2.3.1 session.inc.php file with the one from 2.2. It is also alledged that sometimes the addslashes function of older PHP versions fails.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13200.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13200.php</link>
				<pubDate><![CDATA[Wed, 19 Jan 2005 20:24:00]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Aha, thanks for the explanation!<br /> <br /> I noticed a strange thing though. I'm using version 2.3.1 i.c.w. PHP 4.3.10 on two guestbooks, HTML disabled, but several times visitors managed to enter url's (spamming type url's) into the messages they added. <br /> <br /> This shouldn't be possible is it? I assume [b]&lt;a href="...[/b] should be disabled as all other html.  <img src="https://proxy2.de/forum//images/smilies/136dd33cba83140c7ce38db096d05aed.gif" /><br /> <br /> edit: BTW these guestbooks weren't upgraded, so no old files are being used. And, not sure if it's related in anyway but, trying the hack on those guestbooks, a popup appeared (before I added the strip_tags() to the $entry variable, after adding strip_tags() it didn't happen anymore).]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13251.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13251.php</link>
				<pubDate><![CDATA[Fri, 21 Jan 2005 00:31:25]]> GMT</pubDate>
				<author><![CDATA[ PandA.nl]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ AGcode, or as it is more commonly known BBcode, allows the posting of URL's by placing them between url tags as such<br /> <br /> [url]http://somesite.com[/url]]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13252.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13252.php</link>
				<pubDate><![CDATA[Fri, 21 Jan 2005 00:34:51]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ I noticed, but it weren't [url]'s, but it really were html anchors like &lt;a href="...<br /> <br /> edit: oops, I suppose the [url]'s are translated to href's by the script of course. Sorry about that  <img src="https://proxy2.de/forum//images/smilies/3b63d1616c5dfcf29f8a7a031aaa7cad.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13254.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13254.php</link>
				<pubDate><![CDATA[Fri, 21 Jan 2005 00:40:21]]> GMT</pubDate>
				<author><![CDATA[ PandA.nl]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Carbonize, when I read this Security Focus bulletin, it sounds like it is talking about an entirely different exploit, not the one that was in 2.2.  It says this exploit is found in 2.3.1, and the suggested patch is for the index.php file, not the session.class.php.  But it also says the malicious user "could create a link", perhaps this threat does not exist if html is turned off? Even so, I think if it is really an exploit it should be patched even on those books where html is always turned off.<br /> <br /> So, could you please take another look and clarify.  It sounds like we also need to patch index.php.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13268.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13268.php</link>
				<pubDate><![CDATA[Fri, 21 Jan 2005 07:00:43]]> GMT</pubDate>
				<author><![CDATA[ amber222]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ basically the email you sent is saying that the contents of that particular field are not checked nor altered and so anything can be put in there. With a little HTML or possibly PHP knowledge they could do small things. Remember the field in question is limited to 40 characters.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13279.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13279.php</link>
				<pubDate><![CDATA[Fri, 21 Jan 2005 14:22:43]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ Ignore my above post. That so called exploit you sent to me is total crap. It does not exist. I have now emailed the person that submitted it explaining what a moron they are. the guestbook already checks the URL that is submitted using this statement[code]if &#40;htmlspecialchars&#40;$this-&gt;url&#41; != &quot;$this-&gt;url&quot;&#41; &#123;<br /> $this-&gt;url = '';<br /> &#125;[/code]Which basically says if there is any html characters in the url such as &lt;, &gt; or &amp; then it will not accept the url and removes it from the entry.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13323.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13323.php</link>
				<pubDate><![CDATA[Sat, 22 Jan 2005 14:47:10]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ [quote="Carbonize"][code]if &#40;htmlspecialchars&#40;$this-&gt;url&#41; != &quot;$this-&gt;url&quot;&#41; &#123;<br /> $this-&gt;url = '';<br /> &#125;[/code]Which basically says if there is any html characters in the url such as &lt;, &gt; or &amp; then it will not accept the url and removes it from the entry.[/quote]<br /> <br /> Maybe I don't understand what's happening, but before I did the strip_tags() this exploit:<br /> [quote]http://www.example.com/index.php?entry=&lt;script&gt;alert(document.cookie)&lt;/script&gt;[/quote]generated a popup and mysql error, and after I added the strip_tags the popup didn't show anymore (still get a mysql error message). So, allthough it might not be harmfull, it does not look like the html is removed!]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13383.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13383.php</link>
				<pubDate><![CDATA[Sun, 23 Jan 2005 10:58:43]]> GMT</pubDate>
				<author><![CDATA[ PandA.nl]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ No the exploit exists. I have been in touch with the person that posted it and I was confusing the URL input with the actual URI. I think it was actually recently fixed in 2.3.1 but nothing was said as I noticed soem new lines when I downloaded it agan recently.]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13389.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13389.php</link>
				<pubDate><![CDATA[Sun, 23 Jan 2005 15:33:22]]> GMT</pubDate>
				<author><![CDATA[ Carbonize]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *BUMP*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13439.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13439.php</link>
				<pubDate><![CDATA[Tue, 25 Jan 2005 02:31:17]]> GMT</pubDate>
				<author><![CDATA[ JTD]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *BUMP*<br /> <br /> Thank you all for everything<br /> <br /> *BUMP*<br /> <br />  <img src="https://proxy2.de/forum//images/smilies/2786c5c8e1a8be796fb2f726cca5a0fe.gif" />]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13742.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13742.php</link>
				<pubDate><![CDATA[Sun, 30 Jan 2005 19:43:02]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *BUMP*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13783.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13783.php</link>
				<pubDate><![CDATA[Tue, 1 Feb 2005 12:30:32]]> GMT</pubDate>
				<author><![CDATA[ JTD]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *bumped*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13866.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13866.php</link>
				<pubDate><![CDATA[Thu, 3 Feb 2005 03:47:00]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *BUMP*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/13976.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/13976.php</link>
				<pubDate><![CDATA[Sat, 5 Feb 2005 03:22:11]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
			<item>
				<title></title>
				<description><![CDATA[ *bumped to top*]]></description>
				<guid isPermaLink="true">https://proxy2.de/forum/posts/preList/3563/14029.php</guid>
				<link>https://proxy2.de/forum/posts/preList/3563/14029.php</link>
				<pubDate><![CDATA[Sun, 6 Feb 2005 05:26:07]]> GMT</pubDate>
				<author><![CDATA[ Anonymous]]></author>
			</item>
	</channel>
</rss>