View Full Version : Mobile version of site keeps giving me a security error.


capt_bugaloo
May 26th, 2010, 09:03 AM
I often read the web-site with my iPod Touch. I find that when I select "Mark Forums Read" I always get the following error message:

http://i122.photobucket.com/albums/o272/LS650/NJ_error.jpg

What does this mean, exactly? I have no issues when I view the web-site with my Windows computer and mark all forums as 'read'.

Alex
May 26th, 2010, 09:57 AM
The mobile version is using templates and code from an older codebase for vbulletin. Most things will work fine, but some won't. The one you're running into is because vBulletin fixed a security bug in their main code, that allowed people to send in inappropriate commands to the software and have the commands actually work. An example could be someone being able to send in a mark forums read command for another user. They upped the security around the handling of security tokens to prevent this. But the mobile code template (which is an aftermarket add-on), doesn't have any of these updates, so it now fails when you try and use the feature that used to work fine.

At some point I'll have to consider disabling the mobile version entirely if I feel the security issues get too great with the old code, but I don't think we're there yet. The best option would be if vBulletin came out with a mobile version of the templates themselves so it worked seamlessly and didn't require this hack.

Sorry for the trouble, but I don't think I can do anything to address it in the near-term.

capt_bugaloo
May 26th, 2010, 12:36 PM
Interesting - thanks for the explanation!

CZroe
May 26th, 2010, 06:03 PM
Search has never worked on my iPhone.

Alex
May 26th, 2010, 08:20 PM
Bruce - try to mark all forums read now on the mobile site. I updated the code just for that line on the mobile version, not sure if it works until someone seeing that version can try it.

capt_bugaloo
May 27th, 2010, 07:48 AM
Nope - it's the same as before.

It's not that big of a deal for me as I also check out the site on my PC.
Posted via Mobile Device