View Full Version : vBulletin 3.6.3 Release Discussion
Mike Sullivan
Wed 8th Nov '06, 9:41am
This thread is for discussing the release of vBulletin 3.6.3.
Please use this thread to talk about things you like or installation experiences etc., but please do not use this thread to post troubleshooting queries or bug reports. These threads tend to grow very large and bug reports etc. tend to become lost and will not get attention from the support or development teams.
Mazinger
Wed 8th Nov '06, 10:02am
Nice job. I'm happy that the bug I reported (http://www.vbulletin.com/forum/bugs36.php?do=view&bugid=1156) has been fixed too. :)
Serkan Yılmaz
Wed 8th Nov '06, 10:07am
Thank you ne gibi degişilikler var arkadaşlar.
wii
Wed 8th Nov '06, 10:10am
Thanks
DJ PİSAGOR
Wed 8th Nov '06, 10:13am
Thanks Staff.
Mazinger
Wed 8th Nov '06, 10:15am
Wow!!! 4 versions released in one time. :D
rknight111
Wed 8th Nov '06, 10:16am
In the upgrade, can I leave my hacks in and just install the patch, I just spent countless hours setting the site up..
Ron
andy-ch
Wed 8th Nov '06, 10:27am
Thank you for the release, time to upgrade :)
I hope in this version all bugs has been eliminated :D
Zachariah B
Wed 8th Nov '06, 10:35am
Groovy :)
Colin F
Wed 8th Nov '06, 10:39am
Yes, uploading the patch file will suffice to protect your forum.
rnmcd
Wed 8th Nov '06, 10:45am
Yes, uploading the patch file will suffice to protect your forum.
What is a "a potential cross-site scripting flaw (XSS)"? What kind of 'damage' can it cause?
Will the patch fix the other bugs too?
If I patch instead of doing a full upgrade, and at a later do the full upgrade, does that cause a problem?Thanks.
Scott MacVicar
Wed 8th Nov '06, 10:49am
The problem was to do with IE handling malformed images incorrectly, it would treat them as HTML instead of erroring out and showing a red cross like every other browser on the planet.
The patch only fixes the security issue.
You'll be overwriting the patch when you do a full upgrade so you should have no problems.
feldon23
Wed 8th Nov '06, 10:50am
What is a "a potential cross-site scripting flaw (XSS)"? What kind of 'damage' can it cause?
Cross-site scripting flaws can allow someone to gain control of your forum. So they are rather serious. ;)
Will the patch fix the other bugs too?
The patch covers the security flaw, not the dozens of bugs fixed since 3.6.2 or 3.5.4.
If I patch instead of doing a full upgrade, and at a later do the full upgrade, does that cause a problem?No, the patch will automatically be uninstalled during the next "real" upgrade.
Bad Bunny
Wed 8th Nov '06, 10:53am
Cool. I am smiling on the inside. It may not be evident by my outward composure, but I am actually you guys take securuty seriously.
feldon23
Wed 8th Nov '06, 10:54am
The problem was to do with IE handling malformed images incorrectly, it would treat them as HTML instead of erroring out and showing a red cross like every other browser on the planet.
Not the first time IE has allowed an image file to wreak havoc. Wouldn't it be nice if IE would stop handing the keys to the store over to any website that asks?
<EFSANE>
Wed 8th Nov '06, 11:02am
Thank you for the update.
rnmcd
Wed 8th Nov '06, 11:10am
The problem was to do with IE handling malformed images incorrectly, it would treat them as HTML instead of erroring out and showing a red cross like every other browser on the planet.
What is a malformed image? Is it when someone uploads an image that is not acutally an image?
JamieLee2k
Wed 8th Nov '06, 11:13am
So let me get this straight, if I upgrade all the mods I put in will all go? I ain't very clued up on these sorts of things.
I have vbPlaza/vbBux, ibproarcade, vbsupport, global announcement, sig resizer, few others. I have 6 styles installed too
|Norman|
Wed 8th Nov '06, 11:22am
Thank you guys. I update right now.
punch
Wed 8th Nov '06, 11:26am
Thanks again for the updates, you guys rule!
Marco van Herwaarden
Wed 8th Nov '06, 11:30am
What is a malformed image? Is it when someone uploads an image that is not acutally an image?
Instead of relying on the provided document type, IE tries to look at the contents of an attachment and then decides how to handle it. So if you for example have a file with the .jpg extension then IE might still decide that it is actually JavaScript and try to execute that as such :eek:
Dave Alcock
Wed 8th Nov '06, 11:31am
My server crashed on Monday - total destruction of the RAID. Is this problem related?
ThorstenA
Wed 8th Nov '06, 11:32am
Thanks for releasing ;)
Zachery
Wed 8th Nov '06, 11:39am
My server crashed on Monday - total destruction of the RAID. Is this problem related?
No.
Dave Alcock
Wed 8th Nov '06, 11:44am
No.Thank goodness. It's been a disaster and I've been slaying my hosting provider.
Upgrading now anyway (just in case....) :)
forumbeat
Wed 8th Nov '06, 12:20pm
Successfully upgraded. I uploaded all the new files and my board was still powered by 3.6.2, I had only just installed yesterday so I was gonna re-install and empty the database when it asks but it said I could upgrade, I assume because the new files.. so I did that :)
Joe Siegler
Wed 8th Nov '06, 12:21pm
Is there a changelog? I don't see one anywhere.
Darkblade
Wed 8th Nov '06, 12:24pm
Thanks for the release. I shall upgrade my forums right away! :)
Scott
Wed 8th Nov '06, 12:32pm
Thanks for the upgrade and support.
MaviJean
Wed 8th Nov '06, 12:42pm
Thank you for the release.
wbear
Wed 8th Nov '06, 12:48pm
Thanks for staying on top of security, as usual. Probably the best upgrade process I've ever used, hands down. Did 4 forums in under half an hour including download/upload, and even get notified about templates that need looking at once it completes.
Couldn't be happier. :D
|Norman|
Wed 8th Nov '06, 12:50pm
Upgraded succesfully. :)
I have seen there is a file, in the upload directory, called "LICENSE". What is it?
Marco van Herwaarden
Wed 8th Nov '06, 12:55pm
Upgraded succesfully. :)
I have seen there is a file, in the upload directory, called "LICENSE". What is it?
It contains the license agreement as you have accepted when you downloaded vBulletin from the Members' Area.
feldon23
Wed 8th Nov '06, 12:57pm
So let me get this straight, if I upgrade all the mods I put in will all go? I ain't very clued up on these sorts of things.
I have vbPlaza/vbBux, ibproarcade, vbsupport, global announcement, sig resizer, few others. I have 6 styles installed too
I would strongly recommend that you download and install the 3.6.2 -> 3.6.3 patch and hold off on upgrading your forum until you have time to dedicate to properly upgrading the entire forum to 3.6.3 and make sure that vBPlaza/vbBux, and all your other add-ons will still work with no problems.
Mike Sullivan
Wed 8th Nov '06, 12:58pm
It contains the license agreement as you have accepted when you downloaded vBulletin from the Members' Area.
It's also there to prevent Google code search from indexing any zips that happen to contain vB. :)
feldon23
Wed 8th Nov '06, 12:58pm
It contains the license agreement as you have accepted when you downloaded vBulletin from the Members' Area.
So we can go to http://www.bobsforum.com/forum/LICENSE and see people's details?
feldon23
Wed 8th Nov '06, 1:00pm
Is there a changelog? I don't see one anywhere.
All the bugs in the bug tracker reported for 3.6.2 marked as "Closed (Fixed)".
jimandbob
Wed 8th Nov '06, 1:02pm
Having a lot of add ons installed and a custom template...Would there be a lot of changes to make upgrading from 3.6.2 to 3.6.3?
Thanks
Marco van Herwaarden
Wed 8th Nov '06, 1:10pm
Having a lot of add ons installed and a custom template...Would there be a lot of changes to make upgrading from 3.6.2 to 3.6.3?
Thanks
See this Why Can't I Post or Download Files? (http://www.vbulletin.com/forum/showthread.php?t=79557) and after that post in the appropriate Support Forum.
WurkAnimal
Wed 8th Nov '06, 1:13pm
Thanks vBulletin :)
Mike Sullivan
Wed 8th Nov '06, 1:14pm
So we can go to http://www.bobsforum.com/forum/LICENSE and see people's details?
It's just the text from here: http://www.vbulletin.com/order/license_agreement.php
Dream
Wed 8th Nov '06, 1:26pm
Thanks for the patch option! Not feeling like updating templates and modifications.
rasun
Wed 8th Nov '06, 1:34pm
Hmm I am still on 3.6.0. Will this patch also work for me, or do I have to upgrade? I have a lot of modifications to prepare before can upgrade, so a patch would be very useful for me. :confused:
Mr Max
Wed 8th Nov '06, 1:35pm
thanx alot
Warlock40
Wed 8th Nov '06, 1:42pm
Is this going to require a revert of style templates??
Ronak
Wed 8th Nov '06, 1:53pm
Thanks again for the updates, you guys rule!
already updated :D to vBulletin 3.6.3 :p
ambele
Wed 8th Nov '06, 2:01pm
where can i see the list of 50 bugs fixed ? i want to know them.
Arvind™
Wed 8th Nov '06, 2:03pm
thanks guys i hope people come up with sum very kool skins
jimandbob
Wed 8th Nov '06, 2:06pm
See this Why Can't I Post or Download Files? (http://www.vbulletin.com/forum/showthread.php?t=79557) and after that post in the appropriate Support Forum.
Right OK
Sorry for not quite understanding you?
feldon23
Wed 8th Nov '06, 2:06pm
where can i see the list of 50 bugs fixed ? i want to know them.
Bugs fixed in 3.6.3 (http://www.vbulletin.com/forum/bugs36.php?do=list&status=20&vbversion=3.6.2)
feldon23
Wed 8th Nov '06, 2:07pm
Well you have lost me all together.....Is this thread not about the release of 3.6.3....? And was it not a relevant question about upgrading to the release? And what
does it have to do with posting or downloading files??
Sorry for not quite understanding you?
Support is not provided unless you have purchased vBulletin.
If you have purchased vBulletin, please visit the link provided to associate your forum account here with your customer account.
feldon23
Wed 8th Nov '06, 2:10pm
Hmm I am still on 3.6.0. Will this patch also work for me, or do I have to upgrade? I have a lot of modifications to prepare before can upgrade, so a patch would be very useful for me. :confused:
There are hundreds of bugs fixed from 3.6.0 -> 3.6.3. You should consider upgrading very soon.
The patch for 3.6.3 is a replacement for includes/class_image.php. Replacing this file on 3.6.0 has NOT been tested and may give you problematic results!
nikki712
Wed 8th Nov '06, 2:19pm
I'm running 3.6.1. If I just download 3.6.3, and upload all the files in the upload folder, and then run www.mysite.com/forum/install/upgrade.php (http://www.mysite.com/forum/install/upgrade.php), will it be a simple upgrade, or will I have to empty my database first, and then dump the contents back into it after upgrading? (I REALLY don't want to have to do that if I don't have to. Just want to know what to expect. I'm very new to VB, and have never upgraded.) Any help or info would be appreciated. Thanks!
amnesia623
Wed 8th Nov '06, 2:23pm
good times, good times!
|Norman|
Wed 8th Nov '06, 2:32pm
It contains the license agreement as you have accepted when you downloaded vBulletin from the Members' Area.
It's also there to prevent Google code search from indexing any zips that happen to contain vB. :)
Thank you. :)
Joey805
Wed 8th Nov '06, 2:38pm
Where can I dowload the patch from? In the members area, I only see the full package to download.
Mazinger
Wed 8th Nov '06, 2:54pm
From here: http://www.vbulletin.com/forum/showpost.php?p=1247457&postcount=2
carolem
Wed 8th Nov '06, 2:57pm
I'm running 3.6.1. If I just download 3.6.3, and upload all the files in the upload folder, and then run www.mysite.com/forum/install/upgrade.php (http://www.mysite.com/forum/install/upgrade.php), will it be a simple upgrade, or will I have to empty my database first, and then dump the contents back into it after upgrading? (I REALLY don't want to have to do that if I don't have to. Just want to know what to expect. I'm very new to VB, and have never upgraded.) Any help or info would be appreciated. Thanks!
Just make a backup of your database before you upgrade - you don't need to touch anything in your database - the upgrade procedure does whatever it does to your database for you.
Carolem
Chroder
Wed 8th Nov '06, 2:57pm
I'll apply the patch tonight, a bit too busy for the full upgrade :D Thanks for the release :cool:
rasun
Wed 8th Nov '06, 3:04pm
There are hundreds of bugs fixed from 3.6.0 -> 3.6.3. You should consider upgrading very soon.
The patch for 3.6.3 is a replacement for includes/class_image.php. Replacing this file on 3.6.0 has NOT been tested and may give you problematic results!
I know, but I have read the bug-fixes everytime very carefully when a new version was released, and all the bugs were mostly in functions that I don´t use anyway...so there wasn´t really a need for me to upgrade in the past....
This is now the first really security danger since 3.6.0 and so I would like to see a patch also for 3.6.0.
I will upgrade in the future, but like I have said above, a patch would be really useful for me, because have a lot of modifications for which I will have to change a lot of templates. This will take some time, but now I am a little too busy to make this all...
Calibre_k
Wed 8th Nov '06, 3:26pm
Im using 3.6.0 should I upgrade to 3.6.3?
Mazinger
Wed 8th Nov '06, 3:29pm
Yes.
telc
Wed 8th Nov '06, 3:59pm
How can I see a list of bugs fixed between 3.6.2 and 3.6.3. The bugs marked as "Fixed" in the bug tracker do not specify a version.
Mazinger
Wed 8th Nov '06, 4:10pm
It's only displayed in the bug page.
Moparx
Wed 8th Nov '06, 4:13pm
Keep up the good work guys :)
Calibre_k
Wed 8th Nov '06, 4:24pm
phpMyAdmin
how do I backup my database using that?
KASHANWEB
Wed 8th Nov '06, 4:24pm
Install patch = Upgrade to 3.6.3 ro We should do upgrade after install patch ?
KASHANWEB
Wed 8th Nov '06, 4:25pm
phpMyAdmin
how do I backup my database using that?
Here Is Discussion for 3.6.3 , You can Open a new thread in problem sections . ;)
Endurer
Wed 8th Nov '06, 4:26pm
I'm using 3.6.1. and I am not sure if this patch would work for me? I am just caught in the middle of too many assignments at the moment and upgrading to 3.6.3. straightaway is not possible.
Icy
Wed 8th Nov '06, 4:26pm
Upgraded flawlessly.. Thanks vB team for the release :D..
DinamikNet
Wed 8th Nov '06, 4:34pm
Updated successfully..
Thanks vBulletin® Team...
Zachery
Wed 8th Nov '06, 4:36pm
Install patch = Upgrade to 3.6.3 ro We should do upgrade after install patch ?
No, installing the patch is patching, upgrading is upgrading.
If you are going to upgrade, just follow the upgrade steps.
anthoneezy
Wed 8th Nov '06, 5:00pm
Full upgrade vs patch. I'm not sure what the difference is. Can someone explain this?
Mazinger
Wed 8th Nov '06, 5:02pm
I only know that patching doesn't change the version name.
DinamikNet
Wed 8th Nov '06, 5:03pm
Full upgrade vs patch. I'm not sure what the difference is. Can someone explain this?
Patch will just fix new bug (1)...
Full upgrade will fix nearly 50 bugs and contains new Vbulletin Logos etc...
anthoneezy
Wed 8th Nov '06, 5:06pm
Patch will just fix new bug (1)...
Full upgrade will fix nearly 50 bugs and contains new Vbulletin Logos etc...
thanks.
PitchouneN64ngc
Wed 8th Nov '06, 5:08pm
Thanks for this release, as we know IE is a big sh*t :p
Zidane007nl
Wed 8th Nov '06, 5:22pm
Thanks for the release! I just upgraded to vB 3.6.3! :D
Onimua
Wed 8th Nov '06, 5:50pm
Will upgrade soon. :D
Sc®iPt
Wed 8th Nov '06, 6:27pm
thanx For Edit :)
Onimua
Wed 8th Nov '06, 6:33pm
Do we need to include the new LICENSE file? Or can it be left out from the server?
Reverend
Wed 8th Nov '06, 6:38pm
what was changed with these images?
buttons/
edit.gif
email.gif
find.gif
sendpm.gif
feldon23
Wed 8th Nov '06, 6:50pm
Is this going to require a revert of style templates??
In the announcement, it says that 3.6.3 contains no new templates or template changes.
How can I see a list of bugs fixed between 3.6.2 and 3.6.3. The bugs marked as "Fixed" in the bug tracker do not specify a version.
http://www.vbulletin.com/forum/bugs36.php?do=list&status=20&vbversion=3.6.2
I'm using 3.6.1. and I am not sure if this patch would work for me? I am just caught in the middle of too many assignments at the moment and upgrading to 3.6.3. straightaway is not possible.
The patch replaces 1 file. Worst case scenario, your users cannot upload or download images until you do the full upgrade to 3.6.3.
zappsan
Wed 8th Nov '06, 7:18pm
I hope this hasn't been asked yet:
I'm currently running 3.6.1
Will the patch work (it's for 3.6.2) ?
hornstar6969
Wed 8th Nov '06, 7:41pm
Updated perfectly. I had only one template to revert which was good to see as well :D
Chousho
Wed 8th Nov '06, 7:47pm
Upgrade went flawless (as far as I can tell). Thanks for looking out for your customers as usual!
Calibre_k
Wed 8th Nov '06, 7:50pm
Thank you very much UPgraded without any problems at all. Keep up the good work vBulletin staff.
Intimidator
Wed 8th Nov '06, 8:21pm
Thanks for looking out for us all, I'll have to patch for now and upgrade this weekend :)
harmor
Wed 8th Nov '06, 8:22pm
Ugrade too around 18 minutes.
Thanks Jelsoft.
mjp
Wed 8th Nov '06, 8:29pm
what was changed with these images?
buttons/
edit.gif
email.gif
find.gif
sendpm.gif
I was wondering the same thing...
spiffware
Wed 8th Nov '06, 8:46pm
The patch covers the security flaw, not the dozens of bugs fixed since 3.6.2 or 3.5.4.
No, the patch will automatically be uninstalled during the next "real" upgrade.
that is not what it says in the forum news posted in the admincp here is what is says:
3.6.3 also includes fixes for approximately 50 bugs that were discovered in 3.6.2. For this reason, we recommend all customers upgrade to 3.6.3 as soon as possible. If this is not possible and you are currently running 3.6.2, you may use the patch method discussed here (http://www.vbulletin.com/forum/showthread.php?p=1247457).
conqsoft
Wed 8th Nov '06, 8:51pm
what was changed with these images?
buttons/
edit.gif
email.gif
find.gif
sendpm.gif
http://www.vbulletin.com/forum/bugs36.php?do=view&bugid=1060
feldon23
Wed 8th Nov '06, 9:27pm
that is not what it says in the forum news posted in the admincp here is what is says:
3.6.3 also includes fixes for approximately 50 bugs that were discovered in 3.6.2. For this reason, we recommend all customers upgrade to 3.6.3 as soon as possible. If this is not possible and you are currently running 3.6.2, you may use the patch method discussed here (http://www.vbulletin.com/forum/showthread.php?p=1247457).
The patch doesn't upgrade you to 3.6.3. You are still running 3.6.2 with 1 changed file.
what was changed with these images?
buttons/
edit.gif
email.gif
find.gif
sendpm.gif
They still have a lot of white fuzzies on dark backgrounds. I don't see how it can be called "fixed" but I digress. It's possible to make buttons that work well on all colors of background. It has just been decided not to. The worst offender is the New Thread button. It's evident even on vBulletin.com in the default Grey style. Then again, all of the graphics used in vB3 style should be re-saved in Photoshop at the maximum optimization which will save about 40% in download size with no loss of quality. Hopefully we get a new button set in vB4.
Forum Dude
Wed 8th Nov '06, 9:30pm
I keep asking this...but what template changes are required?
harmor
Wed 8th Nov '06, 9:36pm
I keep asking this...but what template changes are required?
http://www.vbulletin.com/forum/showpost.php?p=1247458&postcount=3
Viper007Bond
Wed 8th Nov '06, 10:56pm
Yay! :D
mac27
Thu 9th Nov '06, 12:24am
I upgraded from 3.6.0 > 3.6.3 and everything ran very smooth. My question is It says that I have some templates that need reverting. I went and checked my forum and everything runs and works just fine. So do I need to do the reverts or can I leave it as is?
1996 328ti
Thu 9th Nov '06, 1:14am
I upgraded from 3.6.0 > 3.6.3 and everything ran very smooth. My question is It says that I have some templates that need reverting. I went and checked my forum and everything runs and works just fine. So do I need to do the reverts or can I leave it as is?
Just what I was looking for. I see that several templates need to be reverted but they are already reverted. Is that because it was a non-modified template in the previous version?
Zachery
Thu 9th Nov '06, 1:18am
Yes, requires revert only applies to tempaltes that have been customized.
persianforum
Thu 9th Nov '06, 1:20am
Thank you for the release
Updated successfully..
__________________
www.persianforum.org (http://www.vbulletin.com/forum/www.persianforum.org)
SloppyGoat
Thu 9th Nov '06, 1:48am
Went smooth for me. Thanks.
gsm4arab
Thu 9th Nov '06, 2:49am
Thanks ...
updated Successfully
navjotjsingh
Thu 9th Nov '06, 3:17am
Applied the Patch...Will Upgrade later as I get time.
vitnuce
Thu 9th Nov '06, 3:44am
Updated, thanks :)
shels
Thu 9th Nov '06, 5:54am
What will happen to current style 3.6.2 if upgraded to 3.6.3? Will I need to redo the style. Please help:)
malmazan
Thu 9th Nov '06, 6:06am
I do not seem to find $announcementinfo[title_safe] (typo on announcement says $announcementino[title_safe])
Do i need to translate it ?
towersl
Thu 9th Nov '06, 6:34am
all working here after upgrade, cheers guys! :)
mikaelweb
Thu 9th Nov '06, 8:33am
After upgrade to 3.6.3 i get this info
You have been banned for the following reason:
No reason was specified.
Date the ban will be lifted: Never
The Chief
Thu 9th Nov '06, 9:16am
Could a vBulletin coder take a look at this?
http://www.vbulletin.com/forum/showthread.php?t=207718
rknight111
Thu 9th Nov '06, 9:47am
If I have alot of customizing installed on my site do I install the patch or the full file?? If the whole file is installed will I have to reinstall the skins, and customizing??
RON
oJqJI
Thu 9th Nov '06, 9:53am
Thank you
Rocol
Thu 9th Nov '06, 9:56am
Another smooth upgrade, all went well, without any problems .... nice work and thanks,vB Team :cool:
feldon23
Thu 9th Nov '06, 10:25am
What will happen to current style 3.6.2 if upgraded to 3.6.3? Will I need to redo the style. Please help:)
You do not need to redo the style. If you have customized any of the templates listed in the Announcement, then you will at some point need to integrate those changes into your changes, otherwise certain forum functionality may be problematic.
If I have alot of customizing installed on my site do I install the patch or the full file?? If the whole file is installed will I have to reinstall the skins, and customizing??
RON
If you have no time to dedicate to the upgrade, install the patch.
A proper upgrade will not damage your skins, color schemes, or modifications. However you should check with the websites of each of the modifications you've installed at vBulletin.org to make sure that they all work with 3.6.3. Any templates that you have customized are "frozen in time" at the 3.6.2 state and will not integrate any bugfixes included in the 3.6.3 update. See the announcement to see which templates that THEY changed and compare them with any templates YOU changed. When you upgrade to 3.6.3, it will give you a report of all templates which are now out-of-date and should be updated at your earliest convenience.
feathers
Thu 9th Nov '06, 12:38pm
I assume the minimum PHP version remains as for previous 3.6.x releases?
Mike Sullivan
Thu 9th Nov '06, 12:47pm
I assume the minimum PHP version remains as for previous 3.6.x releases?
Yes, that won't change between patch releases.
wtrk
Thu 9th Nov '06, 1:33pm
if youve changed the default style, does the upgrade overwrite the default style changes?
Zachery
Thu 9th Nov '06, 1:36pm
No, any changes made to styles will remain intact, you may however need to reveiw your changed and update templates.
toby06
Thu 9th Nov '06, 2:29pm
Can I ask a few really stupid questions... I'm running 3.6.0 and want to go ahead and upgrade to 3.6.3. I have made a number template changes, installed about 11 hacks and foresee this upgrade taking a significant amount of time being that it will be my first. So with that said...here we go...
I'm a bit confused with the "revert templates" phrase I keep reading. Am I assuming correctly that upgrading from 3.6.0 to 3.6.3 cause all my templates to revert back to their "original" form/layout?
The Find Updated Templates option in the AdminCP will show me exactly which templates I previously modified were changed? What exactly is this?
All installed hacks will have to be reinstalled...correct?
TIA!
baraban
Thu 9th Nov '06, 2:31pm
Our support for a purchased license expired at the end of September / begining of October. We never launched the site with our purchased license and are currently experimenting with verion 3.6.0 (the latest one we have available for download). We would like to take advantage of the security patch, but it appears to only work for version 3.6.2. What is the proper procedure for getting past this problem? We do not want to pay for support again until we are fully confident that we will be going live with your software.
Zachery
Thu 9th Nov '06, 2:32pm
I'm a bit confused with the "revert templates" phrase I keep reading. Am I assuming correctly that upgrading from 3.6.0 to 3.6.3 cause all my templates to revert back to their "original" form/layout? No, no customized templates will be touched, you must manually make updates to them if its required. You can read over the release announcements to see if any of your customized templates will need to be redone.
The Find Updated Templates option in the AdminCP will show me exactly which templates I previously modified were changed? What exactly is this? It shows you what templates are now out of date because there is a new version of it compared to when it was modified.
All installed hacks will have to be reinstalled...correct? Theres no yes or no for this, file based modifications will need to be redone. Plugins, should still be active, they may need to be updated to work with the current version that you are running. No database changes are removed.
Zachery
Thu 9th Nov '06, 2:32pm
Our support for a purchased license expired at the end of September / begining of October. We never launched the site with our purchased license and are currently experimenting with verion 3.6.0 (the latest one we have available for download). We would like to take advantage of the security patch, but it appears to only work for version 3.6.2. What is the proper procedure for getting past this problem? We do not want to pay for support again until we are fully confident that we will be going live with your software.
You're not paying for support, you're paying for access to new versions of the software.
Silvio
Thu 9th Nov '06, 2:41pm
ty guys
toby06
Thu 9th Nov '06, 2:43pm
Perfect. Thanks for that quick answer, Zachery!
webtodd
Thu 9th Nov '06, 2:47pm
In the upgrade, can I leave my hacks in and just install the patch, I just spent countless hours setting the site up..
Ron
i have a similar issue...will the patch affect any of the minor tweaks/customizations i have made?
ecrispen
Thu 9th Nov '06, 2:51pm
how do i get an updated copy (3.6.3)?
i have an owned license (3.6.1), however it expired in sept 2006. i would truely like to update my version since the one i have is has a major security flaw in it that i was just notified about.
Zachery
Thu 9th Nov '06, 2:53pm
You'll need to renew your access to downloads. This can be done in the members area, it costs 30 USD.
ecrispen
Thu 9th Nov '06, 2:55pm
You'll need to renew your access to downloads. This can be done in the members area, it costs 30 USD.
so i paid for flawed software and your offering no way for me to fix it other than giving you more money?
Rob B
Thu 9th Nov '06, 3:10pm
so i paid for flawed software and your offering no way for me to fix it other than giving you more money?
Patches are available without access to the members area. These will fix the flaw but you will still be on the same version. They are in attachments on the concerning announcement threads.
rogersnm
Thu 9th Nov '06, 3:15pm
Does the 3.6.2 version work ok for 3.6.0?
ecrispen
Thu 9th Nov '06, 3:17pm
Patches are available without access to the members area. These will fix the flaw but you will still be on the same version. They are in attachments on the concerning announcement threads.
found them, thank you. :)
DjiXas
Thu 9th Nov '06, 3:18pm
So is there a full list of fixed bugs?: confused:
1996 328ti
Thu 9th Nov '06, 3:34pm
so i paid for flawed software and your offering no way for me to fix it other than giving you more money?
Oh please. I believe you can still install the patch.
http://www.vbulletin.com/forum/showpost.php?p=1247457&postcount=2
feldon23
Thu 9th Nov '06, 3:37pm
So is there a full list of fixed bugs?: confused:
I have already twice posted a link to the list of bugs fixed in 3.6.3. Please find them on pages 2-3 and of this thread.
sinjix_media
Thu 9th Nov '06, 4:27pm
so i can use 3.6.2 styles for this?
Zachery
Thu 9th Nov '06, 4:36pm
Yes, however styles made for 3.6.2 might need some things changed/fixed/reverted before they will work fully.
smoknz28
Thu 9th Nov '06, 7:34pm
If you have no time to dedicate to the upgrade, install the patch.
A proper upgrade will not damage your skins, color schemes, or modifications. However you should check with the websites of each of the modifications you've installed at vBulletin.org to make sure that they all work with 3.6.3. Any templates that you have customized are "frozen in time" at the 3.6.2 state and will not integrate any bugfixes included in the 3.6.3 update. See the announcement to see which templates that THEY changed and compare them with any templates YOU changed. When you upgrade to 3.6.3, it will give you a report of all templates which are now out-of-date and should be updated at your earliest convenience.
There ya go. ;) That answers the mail for me.
Thanks Feldon,
Mark
indie
Thu 9th Nov '06, 8:01pm
Can we skip the image folder? Or were new images added?
baraban
Thu 9th Nov '06, 8:58pm
You're not paying for support, you're paying for access to new versions of the software.
This did not answer my question on how I could patch version 3.6.0. to fix the security problem.
greersfos
Thu 9th Nov '06, 9:29pm
3.6.3 is my third flawless upgrade since purchasing vBulletin. I was always chasing spam and intruders before I made the switch to vBulletin.
Thanks for the great software and support.
fos....
TomJames
Thu 9th Nov '06, 9:48pm
Another perfect upgrade without a hitch and very fast. I am always reluctant to upgrade because of the hassle on previous forum software I have used before I went with vBulletin. The security risk pushed me on and it went without a hitch.
Thanks for the hard work Jelsoft.
PossumX
Thu 9th Nov '06, 10:08pm
EZ...That's all I have to say. Security flaws always spark my concern, and after researching this one last night and performing the upgrade on my test board, it was a no brainer.
15 minutes total
06:45 : Close vB and post message (admincp) : 1 Minute
06:46 : Export DB files (myphpAdmin) : 5 Minutes
06:51 : Upload 3.6.3 (cuteFTP Pro) : 7 Minutes
06:58 : Upgrade from 3.6.2 > 3.6.3 (upgrade.php) : 2 Minutes
07:00 : Open vB back up (admincp) : FLAWLESS !!The more I do with vB the more I like it. I have used the others in the past, both free and purchased. vBulletin, hands down, is the best around.
Granted, I am not heavily modified, and my mods can be reinstalled and configured within 30 minutes, but upgrades are easy. I'll be keeping it clean ... waiting for the next major upgrade version ... 4.x, whenever that comes.
Cot-BC
Thu 9th Nov '06, 11:16pm
Maybe this is a known problem:
If for some reason, you happen to add an extra vertical whitespace at the end of your config.php, then you may see the following:
*images in the DB (attachments, avatars) as well as file-based avatar stop showing up.
*Clicking the "edit" button on a post, requires a second click of the edit button
*more
Fun, fun, fun!
Thanks for the update.
axinos
Fri 10th Nov '06, 2:13am
I have installled Googlemap, vbshout and Image Hosting Hacks in my forums.
Do you think that there will be any problem with the patch?
Thnx
Firat_Kardeş
Fri 10th Nov '06, 3:28am
ben 3.6.1. kullaniyorum ne yapmam lazim simdi. :(
Ferrarislave
Fri 10th Nov '06, 3:30am
What if I am already on 3.6.2? Do I still need this new security fix?
Scormen
Fri 10th Nov '06, 5:05am
What if I am already on 3.6.2? Do I still need this new security fix?
Yes :)
I updated yesterday one of my two boards without any problem. Tonight I will update the other to.
Thanks!
Kris
express
Fri 10th Nov '06, 6:13am
When we login to the members area we see 3.6 availabe for download but nothign else we already had version 3.6.2 installed but it does not show either, no 3.6.2 and no 3.6.3 only version 3.6
Any ideas?
Joey
Colin F
Fri 10th Nov '06, 6:33am
You can select the appropriate version from the dropdown menu.
express
Fri 10th Nov '06, 6:34am
I know this, it only shows 3.6
express
Fri 10th Nov '06, 6:39am
http://www.realwebhost.net/version.jpg
express
Fri 10th Nov '06, 6:41am
Sorry I see it, expired in Sept, got to renew it, sorry for wasting your time and clouding up the thread.
Works great when you have a valid license.
Dbreh
Fri 10th Nov '06, 6:51am
Thanks and well done
acegames
Fri 10th Nov '06, 7:45am
All upgraded and running fine :)
wbear
Fri 10th Nov '06, 7:51am
How is it that Google is finding these zip files on the server if they're not publicly linked? Can this be prevented (for other zip files) using robots.txt or something?
fusion2
Fri 10th Nov '06, 8:04am
I just purchased 3.6.2 last week, so this is my first upgrade experience.
I have customized my website by integrating advertising, color schemes, menu bar and logos.
How will this upgrade impact my customizations? If it will impact these customizations, how do i upgrade and keep those changes or does this mean i have to redue everything over?
See my site as an example of what i am talking about South Florida Fusion (http://forum.southfloridafusion.com)
Gaia
Fri 10th Nov '06, 9:30am
Thanks, upgraded fine with no problems :).
rnmcd
Fri 10th Nov '06, 10:09am
What ebulletin post is Steve talking about here:
http://www.vbulletin.com/forum/showpost.php?p=1248377&postcount=6
Lumina
Fri 10th Nov '06, 10:17am
Oh, I knew about this IE XSS issue for a long time now, but I didn't knew I had to report it to Jelsoft. I thought it was a Microsoft problem only. You can test your browser here:
http://moritz-naumann.com/tests/xss2.jpg
rnmcd
Fri 10th Nov '06, 10:25am
Oh, I knew about this IE XSS issue for a long time now, but I didn't knew I had to report it to Jelsoft. I thought it was a Microsoft problem only. You can test your browser here:
http://moritz-naumann.com/tests/xss2.jpg
How does the test work?
feldon23
Fri 10th Nov '06, 10:28am
rnmcd,
Your web browser has NO BUSINESS trying to interpret a file that ends in .jpg as an HTML file. Yet that's exactly what that test exhibits on unpatched copies of Internet Explorer.
Internet Explorer needs to quit trying to interpret and "help" files and just handle them as the specifications set out. ESPECIALLY when the content-type directive has been set (Which Jelsoft does but IE ignores). JPG is an image file. Plain and simple. If there is no image inside it, don't display it.
For board administrators, you can go to a great effort to block people from posting HTML, Javascript, etc. and then all they have to do is write some HTML or Javascript into a JPG and upload it and Microsoft has decided to ignore your wishes and execute the Javascript in that JPG.
Most of the security problems for Microsoft products are the software either trying to do more than it's supposed to, or allowing simple tasks to have huge amounts of access to your computer. For instance, you bring up Microsoft Help. Did you know that is an instance of Internet Explorer? So a bad Help file you download off the internet can compromise your computer. A help file should be a help file. It should not have access to the entire PC. The reason Linux is so secure is that every application doesn't have God control over the whole computer. Each application is walled off from each other and only does what it's told.
rnmcd
Fri 10th Nov '06, 10:38am
feldon23, that is a very informative and interesting post. Thank you.
Hopefully more people start to use other browsers or Microsoft changes its ways. My guess is the latter won't happen.
Thanks.
Pyro™
Fri 10th Nov '06, 2:15pm
Awesome, I Will Be Upgrading Mine Right Away.
JBAqua
Fri 10th Nov '06, 3:47pm
i have a similar issue...will the patch affect any of the minor tweaks/customizations i have made?
Still looking for a definititive answer to this question. Will installing just the patch impact any customizations? ie. changes to the default style, images, etc.?
Onimua
Fri 10th Nov '06, 3:51pm
Still looking for a definititive answer to this question. Will installing just the patch impact any customizations? ie. changes to the default style, images, etc.?
No; the patch just fixes the security issue. Only a full upgrade may require you to change your templates or any other customizations.
If you have made file edits, however, those may need to be put back in depending on which files have been changed that need to be overwritten.
JBAqua
Fri 10th Nov '06, 4:16pm
No; the patch just fixes the security issue. Only a full upgrade may require you to change your templates or any other customizations.
If you have made file edits, however, those may need to be put back in depending on which files have been changed that need to be overwritten.
As in edits to which types of files? Does this include jpg or gif files?
Onimua
Fri 10th Nov '06, 5:58pm
As in edits to which types of files? Does this include jpg or gif files?
Nope, the images would be fine. It's more of the core files that vBulletin uses to operate. :)
Dr_HUS
Fri 10th Nov '06, 9:07pm
by the way vb3.6.3 config.php.new need "?>" at the end
Zachery
Fri 10th Nov '06, 9:52pm
No it doesn't.
Delw
Sat 11th Nov '06, 5:08am
Just upgraded to 3.6.2 from 3.07 last week, had no problems( other than the one I caused :). I was hesitant about upgrading to 3.6.3 so soon and worried about the mods and hacks. but at 2am and a little vodka, It makes you cocky ;)
Like someone said in another post on this thread I was done in less than 30 mins with no problems that I can see. Cleared cookies and rebooted 2 and check it on my daughters pc also. I would have been done faster but I had to go grab something to drink and the cat wanted in, then of course the fish needed to be fed:D
I have quite a few mods and Hacks along with custom templates.
Nice job Vbulletin.
Delw
Bob Isaac
Sat 11th Nov '06, 10:39am
I downloaded some gold coloured buttons from this forum some time ago, and now that some have been changed for 3.6.3 (edit.gif, email.gif, find.gif, sendpm.gif) should I not use these gold buttons?
Bob
feldon23
Sat 11th Nov '06, 10:49am
I downloaded some gold coloured buttons from this forum some time ago, and now that some have been changed for 3.6.3 (edit.gif, email.gif, find.gif, sendpm.gif) should I not use these gold buttons?
Bob
The differences in the edit, email, find, and sendpm buttons are trivial and don't affect the programming or operation of the forum in any way. Stick with your gold buttons. :)
Bob Isaac
Sat 11th Nov '06, 11:02am
Thanks.
Bob
Drago911
Sat 11th Nov '06, 4:23pm
I just did a complete upgrade by uploading all the php files with the exception of the install.php file.......the upgrade went flawlessly but after Im done and I log into the admincp it still shows me at 3.6.2........any ideas?
Onimua
Sat 11th Nov '06, 4:29pm
I just did a complete upgrade by uploading all the php files with the exception of the install.php file.......the upgrade went flawlessly but after Im done and I log into the admincp it still shows me at 3.6.2........any ideas?
Make sure you actually ran the upgrade script and didn't just upload the files.
Ohter than that, post in the appropriate forums or submit a ticket to get proper support. :)
GearTripper
Sat 11th Nov '06, 7:16pm
what's this new LICENSE file that in the root folder... and is it necessary?
conqsoft
Sat 11th Nov '06, 7:23pm
what's this new LICENSE file that in the root folder... and is it necessary?
It's just the License Agreement. Open it in notepad if you want to read it... It's not needed though.
GearTripper
Sat 11th Nov '06, 7:32pm
yea, i did open it and read it, but just was curious why it was put there in the download. wasn't sure if 3.6.3 calls for it somewhere for whatever reason.
Mike Sullivan
Sat 11th Nov '06, 8:03pm
This was noted earlier in the thread, but it should keep Google Code Search from indexing any zip that inadvertently contains vB.
GearTripper
Sat 11th Nov '06, 8:07pm
ah - thnx
Scormen
Sun 12th Nov '06, 11:34am
This was noted earlier in the thread, but it should keep Google Code Search from indexing any zip that inadvertently contains vB.
Maybe a stupid question, Mike, but how does google knows when reading that file he may not download a zip that inadvertently contains vB?
Thanks,
Kris
coolfire18x
Sun 12th Nov '06, 12:26pm
Thanks all went great :D
feldon23
Sun 12th Nov '06, 12:58pm
Maybe a stupid question, Mike, but how does google knows when reading that file he may not download a zip that inadvertently contains vB?
Thanks,
Kris
Because of the LICENSE file. ;)
Google Code Search looks for and respects the LICENSE file.
Scormen
Sun 12th Nov '06, 2:12pm
Yes, feldon, but how does he than know that he may not download a zip of VB? I don't see anything special in that code or something....
Kris
feldon23
Sun 12th Nov '06, 3:44pm
Yes, feldon, but how does he than know that he may not download a zip of VB? I don't see anything special in that code or something....
Kris
Google Code Search isn't a he. It's an it.
Chousho
Sun 12th Nov '06, 4:21pm
Google Code Search isn't a he. It's an it.
Maybe it is a he, I mean... artificial intelligence?
feldon23
Sun 12th Nov '06, 8:34pm
Rofl
dodgeboard.com
Mon 13th Nov '06, 12:01am
We just upgraded our board from 3.6.0 to 3.6.3. We have many styles and tons of hacks; flashchat, Zoints profiles, vBradio, Google Hotspots, vBAdvanced, vBSEO, and many others. Everything went very smooth for us. Downtime was about 7 minutes, no issues. Thanks vBulletin for creating such a comprehensive upgrade script!
minimite
Mon 13th Nov '06, 4:21am
I'm going to upgrade from 3.5.4 to whatever version of 3.6 is around by the end of December.
Questions:
1) I use Flashchat for 3.5.4 - does anybody know if that's going to be a problem? I know it's not supported or whatever the lingo is, I'm just asking if anybody knows. Unofficially, if you like.
2) I know I'll have to redo all my current styles because I edited a lot of templates... is there any way at all of saving just the colors so that I don't have to redo that part anyway? I am talking (I think) about the "Main CSS" portion of the styles.
Thanks very much for any help.
:)
Scormen
Mon 13th Nov '06, 5:26am
Maybe it is a he, I mean... artificial intelligence?
:D :p I think it is a girl
Chousho
Mon 13th Nov '06, 5:48am
:D :p I think it is a girl
Maybe... she's single?
Hmmmm *rubs chin*
1996 328ti
Mon 13th Nov '06, 10:06am
1) I use Flashchat for 3.5.4 - does anybody know if that's going to be a problem? I know it's not supported or whatever the lingo is, I'm just asking if anybody knows. Unofficially, if you like.The one off the tufat site? No problem. Just be sure to use the latest version and remove all unnecessary files in the CMSes directory.
feldon23
Mon 13th Nov '06, 11:16am
2) I know I'll have to redo all my current styles because I edited a lot of templates... is there any way at all of saving just the colors so that I don't have to redo that part anyway? I am talking (I think) about the "Main CSS" portion of the styles.
You don't lose color schemes. Actually, what happens is you upgrade to 3.6.x and all your templates that you edited at 3.5.x will stay "frozen in time" at that state. So some forum functions may not work until you synch up the changes.
I prefer to figure out what Jelsoft changed from 3.5.x -> 3.6.x and then make the same changes in my templates. It's often less work than comparing my 3.5.x templates with their fresh 3.6.x templates since I can't tell what I changed vs. what they changed.
Onimua
Mon 13th Nov '06, 6:35pm
It is saying image verification for search has to be disabled for the DoS to work.
Exactly; enable it and you won't have to worry about it.
Zachery
Mon 13th Nov '06, 6:56pm
I've moved the last few posts out of the public view.
Next time please use the members area for reporting things like this. Thanks.
WireNine.com
Tue 14th Nov '06, 3:07pm
Great release, loving the new features so far :)
Enzo_Cena
Tue 14th Nov '06, 4:22pm
ohhh
i dont know where download skins for this version
=(
Marco van Herwaarden
Wed 15th Nov '06, 7:04am
ohhh
i dont know where download skins for this version
=(
Once you have a valid license, you could download additional (member submitted) Styles from either the vbulletin.com or the vbulletin.org forums.
Stilgar
Wed 15th Nov '06, 5:40pm
I have not upgraded from 3.6.0. Will the new security patch work on v3.6.0? I know I should upgrade to 3.6.3, but until I get the time to do it right, I'd like to make sure my site is safe.
Thanks!
dodgeboard.com
Wed 15th Nov '06, 5:50pm
Not sure if the patch will work. This was a very simple upgrade from 3.6.0 to 3.6.3 I was dreading it too, because of all my custom stuff. Took me about 7 minutes and I have tons of hacks, edits, add-ons and styles. I didn't even have to do anything with my vBSEO, and it all still works fine. CMPS unaffected as well. I spent about 10 minutes doing backups to prepare for the worst, then everything worked with out issues. I reverted the neccesary templates after everything was upgraded and online, being carefull to look them over for any hack changes. The only template I chose not to revert was my navbar, cuase it's heavily moded.
Bite the bullet, wont take long.
Stilgar
Wed 15th Nov '06, 5:54pm
Not sure if the patch will work. This was a very simple upgrade from 3.6.0 to 3.6.3 I was dreading it too, because of all my custom stuff. Took me about 7 minutes and I have tons of hacks, edits, add-ons and styles. I didn't even have to do anything with my vBSEO, and it all still works fine. CMPS unaffected as well.
Bite the bullet, wont take long.
Yeah, I guess I should. Ok, dodgeboard. Thanks for the push. It may be just what I need.
Thanks! :)
bibica
Thu 16th Nov '06, 5:38am
Is there any guide for manual file upgrading? I made some changes in code, therfore if there's no way other than replace the new one, it's very uncomfortable for me to upgrade.
Hope someone could help!
Marco van Herwaarden
Thu 16th Nov '06, 6:59am
Is there any guide for manual file upgrading? I made some changes in code, therfore if there's no way other than replace the new one, it's very uncomfortable for me to upgrade.
Hope someone could help!
Please post your questions in the appropriate support forum.
Makc666
Sat 18th Nov '06, 7:36am
How can I see a list of bugs fixed between 3.6.2 and 3.6.3. The bugs marked as "Fixed" in the bug tracker do not specify a version.
Go here:
http://www.vbulletin.com/forum/bugs36.php
Select:
View bugs with status: Closed (Fixed)
Now go to very bottom of the page and you will see another form to fill :)
Select 3.6.2 and press "Display"
Or you can use this link and just change version number :D
http://www.vbulletin.com/forum/bugs36.php?do=list&status=20&vbversion=3.6.2
http://www.vbulletin.com/forum/bugs36.php?do=list&status=20&vbversion=3.6.2
I do not seem to find $announcementinfo[title_safe] (typo on announcement says $announcementino[title_safe])
Do i need to translate it ?
There was a misprint for the first time the post was made.
Have to read: $announcementinfo[title_safe]
alexisbellido
Sat 18th Nov '06, 12:08pm
Nice and easy upgrade from 3.5.x. Thank you guys!
alhobb
Sat 18th Nov '06, 5:50pm
Thanks
smoknz28
Sat 18th Nov '06, 9:17pm
Upgraded and working well.
Thanks
Aeolian
Tue 21st Nov '06, 9:56am
worked overnight to upgrade to 3.6.1.. and next day i wake up and see 3.6.2 LOL.. and now 3.6.3 .. i will just bit more to see is anymore updates r on the way :s
JakeS
Tue 21st Nov '06, 1:29pm
worked overnight to upgrade to 3.6.1.. and next day i wake up and see 3.6.2 LOL.. and now 3.6.3 .. i will just bit more to see is anymore updates r on the way :sSorry, but that is quite funny to find that after you upgrade to vBulletin 3.6.1 that you then see 3.6.2.
Marco van Herwaarden
Tue 21st Nov '06, 1:33pm
worked overnight to upgrade to 3.6.1.. and next day i wake up and see 3.6.2 LOL.. and now 3.6.3 .. i will just bit more to see is anymore updates r on the way :s
Please tell us when you have finished upgrading to 3.6.3, so we can release 3.6.4 :D
dklassen
Tue 21st Nov '06, 6:17pm
I'm running vBulletin 3.6.2 and vbPortal 3.6.1. Templates are stock with the exception of new header graphics and such.
Any issues upgrading to 3.6.3?
Cromulent
Tue 21st Nov '06, 8:53pm
I'm running vBulletin 3.6.2 and vbPortal 3.6.1. Templates are stock with the exception of new header graphics and such.
Any issues upgrading to 3.6.3?
If your templates are stock it shouldn't take more than 5 minutes (unless you have a really big forum).
feldon23
Wed 22nd Nov '06, 10:57am
I'm running vBulletin 3.6.2 and vbPortal 3.6.1. Templates are stock with the exception of new header graphics and such.
Any issues upgrading to 3.6.3?
You will want to check with the website/author of vBPortal to make sure it works with 3.6.3 and if there are any upgrade steps required. I know vBAdvanced requires steps after every vB upgrade.
Powered by vBulletin™ Version 4.0.0 Beta 4 Copyright © 2009 vBulletin Solutions, Inc. All rights