Page Index Toggle Pages: 1 ReplyAdd Poll Send Topic
Hot Topic (More than 10 Replies) New RSS problem (Read 3537 times)
 
Paste Member Name in Quick Reply Box Dandello
Forum Administrator
YaBB Modder
*****
Offline


I love YaBB 2.7!

Posts: 2234
Location: The Land of YaBB
Joined: Feb 12th, 2014
Gender: Female
Mood: Annoyed
Zodiac sign: Virgo
Re: New RSS problem
Reply #1 - Jan 13th, 2018 at 11:22pm
Mark & QuoteQuote  
If RSS isn't turned on (and I don't see any RSS buttons on your forum), calling RSSrecent WILL throw an error.
  

Perfection is not possible. Excellence, however, is excellent.
Back to top
WWW  
IP Logged
 
Paste Member Name in Quick Reply Box Rucola
Senior Member
****
Offline



Posts: 286
Location: Country Children Song
Joined: Aug 9th, 2017
Gender: Male
Mood: Adventurous
Zodiac sign: Taurus
Re: New RSS problem
Reply #2 - Jan 14th, 2018 at 12:03am
Mark & QuoteQuote  
so we therefore turned off that there was another problem with the rss, there was no notice of the admin-buttons, and no, it's someone who attacks me with a bot or scripts-in the error crib
  
Back to top
 
IP Logged
 
Paste Member Name in Quick Reply Box Rucola
Senior Member
****
Offline



Posts: 286
Location: Country Children Song
Joined: Aug 9th, 2017
Gender: Male
Mood: Adventurous
Zodiac sign: Taurus
Re: New RSS problem
Reply #3 - Jan 14th, 2018 at 12:05am
Mark & QuoteQuote  
what does it mean that you write on the link click-fear you leave your forum and the guest-visible version is the system information and under the version of lege to look for vulnerability-critical vulnerability
  
Back to top
 
IP Logged
 
Paste Member Name in Quick Reply Box Dandello
Forum Administrator
YaBB Modder
*****
Offline


I love YaBB 2.7!

Posts: 2234
Location: The Land of YaBB
Joined: Feb 12th, 2014
Gender: Female
Mood: Annoyed
Zodiac sign: Virgo
Re: New RSS problem
Reply #4 - Jan 14th, 2018 at 12:51am
Mark & QuoteQuote  
Browsers without RSS support also see version/revision information - Guest or not.

On the screen in Chrome on localhost:
Code
Select All
http://localhost/YaBBtests/test_strict/Build_1926/cgi-bin/yabb2/YaBB.pl en-us Build 1926 Up Sun, 14 Jan 2018 00:42:08 GMT http://blogs.law.harvard.edu/tech/rss YaBB 2.7.00 Revision: 1928 30 http://localhost/YaBBtests/test_strict/Build_1926/cgi-bin/yabb2/YaBB.pl?num=1509458567/0#0 Build 1926 Up/General Board http://localhost/YaBBtests/test_strict/Build_1926/cgi-bin/yabb2/YaBB.pl?num=1509458567/0#0 (Administrator) Tue, 31 Oct 2017 14:02:47 GMT Welcome to your new YaBB 2.7.00 forum.<br /><br />The YaBB team would like to thank you for choosing Yet another Bulletin Board for your forum needs. We pride ourselves on the cost (FREE), the features, and the security. Visit <a href="http://www.yabbforum.com" target="_blank">http://www.yabbforum.com</a> to view the latest development information, read YaBB news, and participate in community discussions.<br /><br />Make sure you login to your new forum as an administrator and visit the Admin Center. From there, you can maintain your forum. You'll want to look at all of the settings, membergroups, categories/boards, and security options to make sure they are set properly according to your needs. 



The ONLY WAY currently to disable this is to go into Sources/Sublist.pm and actually comment out
Code (Perl)
Select All
'RSSboard'            => 'RSS.pm&rss_board', 

AND
    
Code (Perl)
Select All
'RSSrecent'           => 'RSS.pm&rss_recent', 



But then, anybody looking at actual urls knows the urls and the Revision number means nothing unless you actually are comparing revisions.

And again, this is NOT a new problem - this is a Chrome problem.
  

Perfection is not possible. Excellence, however, is excellent.
Back to top
WWW  
IP Logged
 
Paste Member Name in Quick Reply Box Rucola
Senior Member
****
Offline



Posts: 286
Location: Country Children Song
Joined: Aug 9th, 2017
Gender: Male
Mood: Adventurous
Zodiac sign: Taurus
Re: New RSS problem
Reply #5 - Jan 14th, 2018 at 12:54am
Mark & QuoteQuote  
and the rest of the settings for what in the rss? -may there what can be properly configured? -just there everything in English, not a single Russian letter in translation
  
Back to top
 
IP Logged
 
Paste Member Name in Quick Reply Box Rucola
Senior Member
****
Offline



Posts: 286
Location: Country Children Song
Joined: Aug 9th, 2017
Gender: Male
Mood: Adventurous
Zodiac sign: Taurus
Re: New RSS problem
Reply #6 - Jan 14th, 2018 at 12:56am
Mark & QuoteQuote  
completely disagree with you as well as the first mistake of the rss, the fact is that I do not have any chrome in my opera and the standard edge
  
Back to top
 
IP Logged
 
Paste Member Name in Quick Reply Box Rucola
Senior Member
****
Offline



Posts: 286
Location: Country Children Song
Joined: Aug 9th, 2017
Gender: Male
Mood: Adventurous
Zodiac sign: Taurus
Re: New RSS problem
Reply #7 - Jan 14th, 2018 at 12:57am
Mark & QuoteQuote  

still this problem and vulnerability has nothing to do with the browser and I have a version of 1932-you yourself put
  
Back to top
 
IP Logged
 
Paste Member Name in Quick Reply Box Rucola
Senior Member
****
Offline



Posts: 286
Location: Country Children Song
Joined: Aug 9th, 2017
Gender: Male
Mood: Adventurous
Zodiac sign: Taurus
Re: New RSS problem
Reply #8 - Jan 14th, 2018 at 12:58am
Mark & QuoteQuote  
critical red vulnerability-requires correction
  
Back to top
 
IP Logged
 
Paste Member Name in Quick Reply Box Rucola
Senior Member
****
Offline



Posts: 286
Location: Country Children Song
Joined: Aug 9th, 2017
Gender: Male
Mood: Adventurous
Zodiac sign: Taurus
Re: New RSS problem
Reply #9 - Jan 14th, 2018 at 1:03am
Mark & QuoteQuote  

you do not understand it nor did I find it, but the bot of the person who attacks me-see the error log-he also sorts out the number of topics and messages
  
Back to top
 
IP Logged
 
Paste Member Name in Quick Reply Box Rucola
Senior Member
****
Offline



Posts: 286
Location: Country Children Song
Joined: Aug 9th, 2017
Gender: Male
Mood: Adventurous
Zodiac sign: Taurus
Re: New RSS problem
Reply #10 - Jan 14th, 2018 at 1:05am
Mark & QuoteQuote  
not an error? -When is it possible to prevent an attacker from putting on the test this version which does not mean and to attack it? -you then delete the old ones from the resource so that they are not available for download
  
Back to top
 
IP Logged
 
Paste Member Name in Quick Reply Box Dandello
Forum Administrator
YaBB Modder
*****
Offline


I love YaBB 2.7!

Posts: 2234
Location: The Land of YaBB
Joined: Feb 12th, 2014
Gender: Female
Mood: Annoyed
Zodiac sign: Virgo
Re: New RSS problem
Reply #11 - Jan 14th, 2018 at 1:53am
Mark & QuoteQuote  
You are talking about the RSS feed which is simply an XML formatted version of 'action=recenttopics'. If an attacker can determine vulnerabilities from the RSS feed then that attacker can get the same information (and more) from running a bot (or any link checker) over your forum.

The error in your error log is from not having RSS turned on.
However, I've also attached an older version of RSS.pm.

This MAY solve the problem of FireFox not properly rendering the RSS, but will do nothing about Chrome, Opera, or Edge.

(And yes, much of the 'Russian' Admin.lng is in English because nobody has translated it.)
« Last Edit: Jan 15th, 2018 at 3:44pm by Dandello »  

rss.zip ( 6 KB | 169 Downloads )

Perfection is not possible. Excellence, however, is excellent.
Back to top
WWW  
IP Logged
 
Paste Member Name in Quick Reply Box Dandello
Forum Administrator
YaBB Modder
*****
Offline


I love YaBB 2.7!

Posts: 2234
Location: The Land of YaBB
Joined: Feb 12th, 2014
Gender: Female
Mood: Annoyed
Zodiac sign: Virgo
Re: New RSS problem
Reply #12 - Jan 14th, 2018 at 4:32am
Mark & QuoteQuote  
Also, although you claim your forum is 'under attack due to alleged YaBB security inadequacies', sites (not just YaBB) do get slammed by bots trying to get through 403 restrictions AND just trying to cause trouble.

1) - check your RAW server access logs and the server error logs to see if bots are slamming YaBB.pl - evidence if this will be repeated (as in 100s of) 403 errors from the same IP close together in time.

If this is happening, the access log should give you the name of the bot to put into your robots.txt file. (see http://www.robotstxt.org/robotstxt.html.)

Also make sure that, if your server is running Apache 2.4, you've installed the Apache 2.4 mod.

2) Copy your .htaccess file from cgi-bin/yabb2 to your html root folder and make sure the offending bot's IP address is included in the .htaccess file.

While reputable bots, like Google and Bing, stop when they hit a 403, some, like Semrushbot, keep slamming those addresses, creating excessive resource use situations.


  

Perfection is not possible. Excellence, however, is excellent.
Back to top
WWW  
IP Logged
 
Paste Member Name in Quick Reply Box Rucola
Senior Member
****
Offline



Posts: 286
Location: Country Children Song
Joined: Aug 9th, 2017
Gender: Male
Mood: Adventurous
Zodiac sign: Taurus
Re: New RSS problem
Reply #13 - Jan 15th, 2018 at 11:32am
Mark & QuoteQuote  

robots.txt where to put and what should be the file permissions?
  
Back to top
 
IP Logged
 
Paste Member Name in Quick Reply Box Dandello
Forum Administrator
YaBB Modder
*****
Offline


I love YaBB 2.7!

Posts: 2234
Location: The Land of YaBB
Joined: Feb 12th, 2014
Gender: Female
Mood: Annoyed
Zodiac sign: Virgo
Re: New RSS problem
Reply #14 - Jan 15th, 2018 at 3:45pm
Mark & QuoteQuote  
robots.txt is a plain ASCII only text file. it just needs to be read (644)

It needs to be placed in your server document root.
  

Perfection is not possible. Excellence, however, is excellent.
Back to top
WWW  
IP Logged
 
Page Index Toggle Pages: 1
ReplyAdd Poll Send Topic
Bookmarks: del.icio.us Digg Facebook Google LinkedIn reddit Twitter Yahoo
New RSS problem

Please type the characters exactly as they appear in the image,
without the first 2 and last 2 characters.
The characters must be typed in the same order,
and they are case-sensitive.
Open Preview Preview

You can resize the textbox by dragging the right or bottom border.
Off Topic Comment Insert Spoiler
Insert Hyperlink Insert FTP Link Insert Image Insert E-mail Insert Media Insert Table Insert Table Row Insert Table Column Insert Horizontal Rule Insert Teletype Insert Code Insert Quote Edited Superscript Subscript Insert List /me - my name Insert Marquee Insert Timestamp No Parse
Bold Italicized Underline Insert Strikethrough Highlight
                       
Change Text Color
Insert Preformatted Text Left Align Centered Right Align
resize_wb
resize_hb







Max 5000 characters. Remaining characters:
Text size: %
More Smilies
View All Smilies
Collapse additional features Collapse/Expand additional features Smiley Wink Cheesy Grin Angry Sad Shocked Cool Huh Roll Eyes Tongue Embarrassed Lips Sealed Undecided Kiss Cry