Page Index Toggle Pages: 1 [2] 3  Send TopicPrint
Very Hot Topic (More than 25 Replies) A call for AOL users (Read 19454 times)
BillBSET
God Member
*****
Offline


Ignorance can be fixed,
Stupid is Forever

Posts: 698
Location: Monkey Island
Joined: Sep 19th, 2003
Gender: Male
Re: A call for AOL users
Reply #15 - Dec 2nd, 2004 at 8:47am
Print Post  
I seem to be repeating my self.. you and I were just talking about
this in another thread...   Roll Eyes

and bombing all of those civillians..  man...

I hope someone can figure this out..
I hate to wait for sp2....
I doesn't log you out if your IP is different...   

the problem is for those folks who are just now setting up a 1.4 forum... 
they won't understand or realize about this problem...  Undecided

for me it is just academic...



  


After you eliminate all of the possibilities,
whatever is left, no matter how seemingly impossible,
must be the truth.


Back to top
WWW  
IP Logged
 
naitram
New Member
*
Offline


I love YaBB 1G - SP1.2!

Posts: 14
Joined: Dec 2nd, 2004
Re: A call for AOL users
Reply #16 - Dec 2nd, 2004 at 3:11pm
Print Post  
JD_Steele wrote on Dec 2nd, 2004 at 1:57am:
Is there any solution for the AOL problem? Alot of my forum members are complaining about not being able to get further than 1 click before they are auto-logged out. I think the feature is nice, but it takes out ALOT of innocent bystanders as well. Kinda like dropping the nuclear bomb on a small city to kill the 50 or so "bad guys".

Any suggestions? Maybe you could have something where you add user names to a list and if they are on the list, they can browse like before. I don't know.

JD_Steele



i have disabled the function by making everyone use a static value. i know this defeates the purpose of the SID in the first place but it was much eaiser than trying to remove the mod.

changes:

Code
Select All
AdminEdit.pl: $cryptsession = &encode_session($user_ip,$masterseed);
Load.pl: if (&encode_session($user_ip,$slaveseed) ne $decryptsession && $cookiesession ne ""){$validsession = 0;}
LogInOut.pl: $cryptsession = &encode_session($user_ip,$masterseed);
Subs.pl: $formsession = &encode_session($user_ip,$masterseed);
 




to:
Code
Select All
AdminEdit.pl: $cryptsession = &encode_session('12345',$masterseed);
Load.pl: if (&encode_session('12345',$slaveseed) ne $decryptsession && $cookiesession ne ""){$validsession = 0;}
LogInOut.pl: $cryptsession = &encode_session('12345',$masterseed);
Subs.pl: $formsession = &encode_session('12345',$masterseed);
 


  
Back to top
 
IP Logged
 
Duncan
New Member
*
Offline



Posts: 33
Joined: Jul 3rd, 2003
Gender: Male
Re: A call for AOL users
Reply #17 - Dec 2nd, 2004 at 6:42pm
Print Post  
The problem with AOL is there only appear to pass the proxy IP and not the client IP as well - most other ISPs which use transparent proxies pass both (although I notice that YaBB only logs the proxy IP against posts even for those ISPs which do pass both)...

Quote:
over at YaBBForums.. someone recommended only checking the first part of the IP  ie.. 100.100.100.xx


Whether that would work would depend on how AOL handle the load balancing on their proxies. I am aware of at least 5 address ranges for AOL proxies (starting 64.12.xx.xx, 198.81.xx.xx, 205.188.xx.xx, 209.240.xx.xx and 152.163.xx.xx). If each address ranges serves only one part of the country/world covered by AOL then it shouldn't be a problem - but if individual users jump across the different proxy address ranges on successive clicks, then only checking the first couple of numbers wouldn't work.
  
Back to top
WWW  
IP Logged
 
Dam Yankee
God Member
*****
Offline



Posts: 1538
Location: Maryville
Joined: Jun 13th, 2003
Gender: Female
Re: A call for AOL users
Reply #18 - Dec 2nd, 2004 at 7:03pm
Print Post  
I have one member with AOL that has jumped proxy ranges in a single session. These are all from the same member, same visit:

172.201.xx.xx
172.145.xx.xx
172.152.xx.xx
  
Back to top
WWW  
IP Logged
 
Duncan
New Member
*
Offline



Posts: 33
Joined: Jul 3rd, 2003
Gender: Male
Re: A call for AOL users
Reply #19 - Dec 2nd, 2004 at 9:54pm
Print Post  
According to the IP logs on the Member list, I have AOL members whi have accessed my site through more than one completely different proxy range (eg, 65.255.xx.xx, 217.137.xx.xx, and 195.93.xx.xx)

I don't know whether those were in the same session but it certainly shows that a single AOL user can more around completely different proxy ranges and so it is possible that matching only the first number would still result in AOL users being logged out.
  
Back to top
WWW  
IP Logged
 
Kong
God Member
*****
Offline


Is it just me or is my
back hairy???

Posts: 858
Joined: Aug 2nd, 2002
Gender: Male
Re: A call for AOL users
Reply #20 - Dec 2nd, 2004 at 11:00pm
Print Post  
I guess it depends on how many different systems they have to jump through to access whatever it is they are trying to access.
  


Back to top
 
IP Logged
 
BillBSET
God Member
*****
Offline


Ignorance can be fixed,
Stupid is Forever

Posts: 698
Location: Monkey Island
Joined: Sep 19th, 2003
Gender: Male
Re: A call for AOL users
Reply #21 - Dec 2nd, 2004 at 11:45pm
Print Post  
well., that takes care of that...

172.201.xx.xx
172.145.xx.xx
172.152.xx.xx

man,, aol.. how did they buy time/warner anyway... internet scam??

  


After you eliminate all of the possibilities,
whatever is left, no matter how seemingly impossible,
must be the truth.


Back to top
WWW  
IP Logged
 
Dam Yankee
God Member
*****
Offline



Posts: 1538
Location: Maryville
Joined: Jun 13th, 2003
Gender: Female
Re: A call for AOL users
Reply #22 - Dec 3rd, 2004 at 2:58am
Print Post  
Two words... AOL sucks.  Roll Eyes
  
Back to top
WWW  
IP Logged
 
IMOG
New Member
*
Offline


I love YaBB 1G - SP1.2!

Posts: 8
Joined: Dec 4th, 2004
Re: A call for AOL users
Reply #23 - Dec 11th, 2004 at 6:44pm
Print Post  
I am an AOL user (Thanks mom and dad  Roll Eyes ) when I am at home (I compute from many places, occasionally from home - I do a lot of traveling), and I am not clear on where this issue stands currently.

If there is any way I could be of service, let me know.  I have had the good fortune of enjoying some of the generosity of this forum and those who support YaBB, so if I could give a little back, this might be a good oppurtunity.  I will try to check back every so often, but you might want to try to contact me at spamisyummy@gmail.com - this is my public email address and I check this weekly.
  
Back to top
 
IP Logged
 
Boardmodder420
New Member
*
Offline


I love YaBb

Posts: 20
Joined: Dec 16th, 2004
Re: A call for AOL users
Reply #24 - Dec 16th, 2004 at 11:26pm
Print Post  
naitram wrote on Dec 2nd, 2004 at 3:11pm:
i have disabled the function by making everyone use a static value. i know this defeates the purpose of the SID in the first place but it was much eaiser than trying to remove the mod.

changes:

Code
Select All
AdminEdit.pl: $cryptsession = &encode_session($user_ip,$masterseed);
Load.pl: if (&encode_session($user_ip,$slaveseed) ne $decryptsession && $cookiesession ne ""){$validsession = 0;}
LogInOut.pl: $cryptsession = &encode_session($user_ip,$masterseed);
Subs.pl: $formsession = &encode_session($user_ip,$masterseed);
 




to:
Code
Select All
AdminEdit.pl: $cryptsession = &encode_session('12345',$masterseed);
Load.pl: if (&encode_session('12345',$slaveseed) ne $decryptsession && $cookiesession ne ""){$validsession = 0;}
LogInOut.pl: $cryptsession = &encode_session('12345',$masterseed);
Subs.pl: $formsession = &encode_session('12345',$masterseed);
 





ok so wait? is this a line i must edit in my source files? i do not understand how to apply this to my forum? the new security thing has compleatly messed things up for alot of my members is there any way around it? or to turn it off?
  
Back to top
 
IP Logged
 
naitram
New Member
*
Offline


I love YaBB 1G - SP1.2!

Posts: 14
Joined: Dec 2nd, 2004
Re: A call for AOL users
Reply #25 - Dec 17th, 2004 at 3:57pm
Print Post  
you need to edit each of the four files listed

AdminEdit.pl
Load.pl
LogInOut.pl
Subs.pl

find the lines that i listed and change
$user_ip
to
'12345'
or some other static value but it must be the same in all four files
  
Back to top
 
IP Logged
 
justonemore
New Member
*
Offline


I love YaBB 1G - SP1!

Posts: 1
Joined: Oct 30th, 2002
Re: A call for AOL users
Reply #26 - Dec 19th, 2004 at 6:20pm
Print Post  
I'm with Drews.  I see what should get changed.  I just don't know WHAT file the changes need to be made in.
TIA
  
Back to top
 
IP Logged
 
ViperScope
New Member
*
Offline


I love YaBB 1G - SP1.2!

Posts: 22
Location: Saint John
Joined: Jul 31st, 2004
Gender: Male
Re: A call for AOL users
Reply #27 - Feb 10th, 2005 at 3:13am
Print Post  
couldn't u just add
Code
Select All
$user_ip = "12345"; 


above it in those pages or something like
Code
Select All
if ($user_ip eq "") {$user_ip = "12345";}
 


  


viperscope.2ya.com
Back to top
WWW  
IP Logged
 
Spikecity
God Member
*****
Offline


Beer anyone ?

Posts: 2630
Location: New York
Joined: Apr 16th, 2002
Gender: Male
Re: A call for AOL users
Reply #28 - Feb 10th, 2005 at 2:15pm
Print Post  
ViperScope wrote on Feb 10th, 2005 at 3:13am:
couldn't u just add
Code
Select All
$user_ip = "12345"; 


above it in those pages or something like
Code
Select All
if ($user_ip eq "") {$user_ip = "12345";}
 



Won't work as $user_ip as defined always in Subs.pl, one of the first loaded scripts and setting $user_ip to a static value means every user has the same IP address on your board, making IP blocking useless.

Above all $user_ip is a core system variable that should not be tampered with as it will compromise everything secure on your board.
So a very dangerous suggestion that should not be done in this way.

Feeding the session id with a static value instead of the IP is a different thing (this is what the original code change suggested does).
  

Nothing to add here Smiley
Back to top
 
IP Logged
 
ViperScope
New Member
*
Offline


I love YaBB 1G - SP1.2!

Posts: 22
Location: Saint John
Joined: Jul 31st, 2004
Gender: Male
Re: A call for AOL users
Reply #29 - Feb 20th, 2005 at 10:49am
Print Post  
i was thinking why not add an option in the members profiles to not use that part of the forum so say  if this user username ignore ip check  or something alone that line..
  


viperscope.2ya.com
Back to top
WWW  
IP Logged
 
Page Index Toggle Pages: 1 [2] 3 
Send TopicPrint