Massive PSAUX ransomware attack targets 22,000 CyberPanel instances

Maybe old news to some, but unfortunately I only heard about it after my server was knocked offline - six hours ago and counting. If you're using CyberPanel and haven't updated to 2.3.8+, and are lucky enough not to have been impacted by this yet, get busy.

www.bleepingcomputer.com

Massive PSAUX ransomware attack targets 22,000 CyberPanel instances

Over 22,000 CyberPanel instances exposed online to a critical remote code execution (RCE) vulnerability were mass-targeted in a PSAUX ransomware attack that took almost all instances offline.
www.bleepingcomputer.com
www.bleepingcomputer.com

Читать далее...

Приветствуем нового пользователя, Александр Синицын

@Александр Синицын, Добро пожаловать на наш форум! Территория возможностей 💥 😉

Зарегистрированный пользователь не может скачивать ресурсы ознакомившись с условиями на странице с повышениями групп или в личном профиле!


Описания платных групп:

Approval mode: Manual, Auto:Timer, Auto:Analysis

The objective is to make it difficult for extremely inconvenient people to access it, generally they are part of a group where you have advertised your group.

1 - Admin > Setup > Options > User registration
Registration setup:
[ ] Approval mode
( * ) Enable manual approval
( ) After n hours (24 is default)
( ) Automatic, trivial rules.
[ ] If invalidated, User state {......}

2 - Admin > Users > Custom user fields
In user custom fields, include a new...

Read more

Читать далее...

[Xen-Soluce] Information Page Management [Paid]

XenSoluce submitted a new resource:

[Xen-Soluce] Information Page Management - Create new pages in your help pages, like rules, informations, FAQs.

Description :
  • This add-on allows you to create new pages in your help pages, like rules, informations, FAQs.
Feature summary :
  • Information Page Management :
    • Help pages :
      • Add help pages :
        • Default
        • Information group
    • Information groups
      • Add...
Click to expand...

Read more

Читать далее...

Lost Access to Most Tools as a Non-Super Admin

I'm a regular admin on a forum, not a super admin. I'm also its technical admin, and handle all technical affairs. I upgraded the forum from 2.3.3 to 2.3.4. However, after doing so, I lost access to most tools in the admin control panel. For instance, I can no longer check for upgrades, nor run a file health check. Everything else appears to be the same. When I attempt to access these pages by the URL directly, I get an error stating that I do not have permission. Is this intended?

Читать далее...

Attachments unassociated since 2.3.4

Yesterday I upgraded to 2.3.4. Since then attachments weren't displaying, not in posts, articles, link directory, nothing.

At first I thought it had to do with a 3rd party add on, since the admin panel would show this:

Screenshot_1.webp

After uninstalling the job add on, the problem still persists. No attachment is displayed. The admin panel now shows this:

Screenshot_7.webp

(At the time of uploading these screenshots on XF, I even had a problem where it said:

1730307870817.webp

So, I'm guessing...

Read more

Читать далее...

Flag Loggedin-only permissions

XenForo treats logged out visitors ("Guests") and logged in but unconfirmed visitors ("Members") somewhat equal - they both get their permissions from usergroup Unregistered / Unconfirmed.

So when editing this usergroup there are many permissions like
  • Use push notifiations
  • Upload an avatar
  • Upload a profile banner
  • ...
that can (currently) only be applied to Members - they have no effect on Guests.

While it may be "logical" that some permissions can't be applied to...

Read more

Читать далее...

Can admins sort 'Current Visitors' list by IP address

In order to check for abuse and unidentified bots, I often peak through the 'Current Visitors' (guests) pages to see whose online. But what would be really handy is if this list could be sorted / ordered by IP address, which would make it easier to spot multiple loads from a similar pool of IP addresses (a common aspect of bot traffic). Is there any way to do this?

Читать далее...

Приветствуем нового пользователя, firedragoq

@firedragoq, Добро пожаловать на наш форум! Территория возможностей 💥 😉

Зарегистрированный пользователь не может скачивать ресурсы ознакомившись с условиями на странице с повышениями групп или в личном профиле!


Описания платных групп:

Limit fields in returned entity

Hello
I'm working on an API endpoint which returns posts from a specific thread, with an option to limit results and order them with orderByDate('...').

My problem is with the result returned:
As I'm returning a XF entity, the results contain many unwanted fields (mainly user data and node data that should not be shown to the world)

I saw this thread: https://xenforo.com/community/threa...f-columns-from-an-entity-using-finder.160806/

and understand this...

Read more

Читать далее...

Custom purchasable - Stripe error "You must specify either `product` or `product_data` when creating a price"

I'm trying to implement my own purchasable to allow members on one of my private sites to order photo prints.

I'm receiving the following error when I submit the purchase using the Stripe payment profile:
  • Stripe\Exception\InvalidRequestException: You must specify either product or product_data when creating a price.
  • src/vendor/stripe/stripe-php/lib/Exception/ApiErrorException.php:38
Code:

#0 src/vendor/stripe/stripe-php/lib/Exception/InvalidRequestException.php(35)...

Read more

Читать далее...

Приветствуем нового пользователя, sadmansomewhere

@sadmansomewhere, Добро пожаловать на наш форум! Территория возможностей 💥 😉

Зарегистрированный пользователь не может скачивать ресурсы ознакомившись с условиями на странице с повышениями групп или в личном профиле!


Описания платных групп:

Приветствуем нового пользователя, fonikov

@fonikov, Добро пожаловать на наш форум! Территория возможностей 💥 😉

Зарегистрированный пользователь не может скачивать ресурсы ознакомившись с условиями на странице с повышениями групп или в личном профиле!


Описания платных групп:

Binance Pay Widget USDT [Paid]

javakhir submitted a new resource:

Binance Pay Widget USDT - Cryptocurrency USDT

Binance Pay Widget addon for XenForo User Upgrades to accept payments in USDT

Optional:
As Binance website is blocked in many countries, we added Proxy method, you can use your own proxy IP
that will allow Payment work straight on your XenForo website without visiting Binance website.

Addon will automatically generate QR code from your Binance account.
Click to expand...

Read more about this...

Read more

Читать далее...

Фильтровать

Назад
Верх Низ