• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
    • Forum
    • Wiki
    • Support
      • Manage Subscriptions
      • FAQ
      • Support For
        • VaultWiki 4.x Series
        • VaultWiki.org Site
    • What's New?
    • Buy Now
    • Manual
    • 
    • Support
    • VaultWiki 4.x Series
    • Feature
    • VB4 Suspect File Versions

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    Issue: VB4 Suspect File Versions

    • Issue Tools
      • View Changes
    1. issueid=2575 January 11, 2012 2:39 PM
      Rick Rick is offline
      New Member
      VB4 Suspect File Versions

      Is there any chance you are going to integrate/add a "Suspect File Versions" for Vaultwiki?
      With the rampaging hacking, it would be a great help.

      Thank you!
      Rick
    Issue Details
    Issue Number 2575
    Issue Type Feature
    Project VaultWiki 4.x Series
    Category Permissions / Security
    Status Implemented
    Priority 1 - Security / Login / Data Loss
    Suggested Version 3.x
    Implemented Version 4.0.0 Gamma 4
    Milestone VaultWiki 4 Beta X
    Software DependencyAny
    License TypePaid
    Votes for this feature 0
    Votes against this feature 0
    Attachments 0
    Assigned Users (none)
    Tags (none)




    1. January 11, 2012 5:39 PM
      pegasus pegasus is offline
      VaultWiki Team
      The problem with Suspect File Versions is that it reports false positives when you are upgrading using a patch rather than a full overwrite. This has occurred for me twice now with vBulletin upgrades, and it is somewhat annoying and could be unsettling for non-technical users.

      Due to the variety of download options available for VaultWiki, it would be difficult to implement a Suspect File Version system that is capable of telling the difference between that and hacking attempts, but not impossible.

      This is something we could implement in version 4, but I would be concerned about the potential size of the md5_sums_file going forward. We already have close to 1500 files in version 4, and for patches to be supported, historical sums would also need to be accepted. The file could easily exceed 1 MB on its own in just a few versions -

      Because sums typically need to be generated at download time rather than being static, this poses an additional challenge where patches and historical sums are concerned.

      We'll solve it...
      Reply Reply  
    2. October 15, 2013 11:18 AM
      pegasus pegasus is offline
      VaultWiki Team
      Originally suggested for 3.0.16.
      Reply Reply  
    3. March 3, 2014 6:49 PM
      pegasus pegasus is offline
      VaultWiki Team
      Implemented in the next release. This ties into vB's Suspect File Versions function, as well as XenForo's File Health Check.

      I was worried about the speed implications building the sums on each download, but the time is negligible since all file contents are already available in memory when we build the download file. Simply adding an md5 at each step doesn't really make a noticeable difference, but I've gone ahead and also added an md5 cache to speed it up on our end.
      Reply Reply  
    + Reply

    Assigned Users
    Loading Please Wait
    Tags
    Loading Please Wait
    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 3:09 PM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2023 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2023 DragonByte Technologies Ltd.
    Copyright © 2008 - 2013 VaultWiki Team, Cracked Egg Studios, LLC.