Announcement

Collapse
No announcement yet.

Warning on yilmaz mods!

Collapse
X
Collapse
First Prev Next Last
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Warning on yilmaz mods!

    It has come to my attention that yilmaz has copied some mods from a vB mod developer without permission and claiming them as his own. I investigated and checked his published mods on vb.org and to my surprise, he also stole (at least 2 that I'm aware of) some of my mods! And the GIPHY mod for vB5 is one of them. The other one is an "unreleased-but-installed-here" mod for Customer Testimonial module.

    I recommend you to be cautious in installing yilmaz mods. For the GIPHY mod, he made slight modifications to my code that have security implications. He made use of an unapproved public beta GIPHY API key dc6zaTOxFJmzC (which is provided by Giphy and supposed to be used only for testing) and he used it in Javascript. He should have informed the forum owners to request a production GIPHY API key as I did for my mod instead of taking a shortcut and using and hardcoding a beta key. See below's Giphy's documentation on the use of public beta key:

    Originally posted by Giphy
    Public Beta Key
    The Giphy API is open to the public. We have instituted a simple, single public beta key system to let anyone try it out. The API key is required for all endpoints.

    The public beta key is "dc6zaTOxFJmzC”
    Please use this key while you develop your application and experiment with your integrations. Note: the public key is subject to rate limit constraints and we do not encourage live production deployments to use the public key.
    For more details, please see https://giphy.api-docs.io/1.0/welcom...s-and-api-keys

    Even if you replace the beta key with an approved production API key, it would be a security concern because the API key is exposed in Javascript which means anyone can easily find out the GIPHY API key you're using and use it on their own without your knowledge. API keys should be treated like passwords. Usage of API keys is subject to rate limit constraints so if you're using a public beta key or someone else is also using your exposed production API key, then at some point, the GIPHY mod on your forum will stop working if the rate limit is reached sooner than expected.

    Just to be clear, I'm not saying that all of his mods are not his original work. My point is if you're going to re-publish someone else's work, be sure to credit the original developer instead of claiming other people's hard-earned work as if it's yours.

    Btw, few hours after replying to his 2 mods on vb.org, the 2 mods had been taken down. I don't know who took it down because I also contacted one of the Admins on vb.org.
    Last edited by glennrocksvb; 03-28-2022, 04:25 PM.
    Helpful? Donate. Thanks!
    Buy me a coffeePayPal QR Code
    Fast VPS Host for vBulletin:
    A2 Hosting & IONOS

    #2
    Besides being unethical, taking credit for others hard work as your own is lower than low.
    The Linux Community has given me much. I do what I can to return the favor!

    Comment


      #3
      Originally posted by Snowhog View Post
      Besides being unethical, taking credit for others hard work as your own is lower than low.
      I agree 100%!

      100 Percent Agree GIF by HBO
      Helpful? Donate. Thanks!
      Buy me a coffeePayPal QR Code
      Fast VPS Host for vBulletin:
      A2 Hosting & IONOS

      Comment


        #4
        Yes that is total BS

        Comment


          #5
          I uninstalled the one MOD of Yilmaz we were using, then removed it completely from our server. I purchased your "Visitors in the Last X Hours Module" and installed it instead.

          I don't condone unethical conduct. I won't support it, even if the product is/was free. I will support ethical developers. That's why I'll happily pay for your work glennrocksvb.
          The Linux Community has given me much. I do what I can to return the favor!

          Comment


          • glennrocksvb
            glennrocksvb commented
            Editing a comment
            Thanks for your support!

          #6
          In fairness to him, not all of his mods seems to be stolen. At least not from me. Some I would say were "inspired" from mine which is ok with me as long as it's obviously not a straight up duplicate with just slight modifications.
          Last edited by glennrocksvb; 03-29-2022, 10:52 AM.
          Helpful? Donate. Thanks!
          Buy me a coffeePayPal QR Code
          Fast VPS Host for vBulletin:
          A2 Hosting & IONOS

          Comment


          • Snowhog
            Snowhog commented
            Editing a comment
            I think you're being a bit 'too fair'. Even if his MODs are 'inspired' by someone else's work, he should say so and give credit to those authors.

          • glennrocksvb
            glennrocksvb commented
            Editing a comment
            You're right.

          #7
          I wrote that long before in the mods (especially at your giphy mod ) comments and so many people attack me after this. He stole the logo of my old forum, some of my mods and register my old domain (that is ok in my opinion). That’s the reason I deleted all my work at vb.org! Just take a look at my old forums domain and you will see what type of a guy he is.
          My forum closed !

          Comment


            #8
            Yeah when I saw the .de domain in his signature, I knew it looked familiar.
            Helpful? Donate. Thanks!
            Buy me a coffeePayPal QR Code
            Fast VPS Host for vBulletin:
            A2 Hosting & IONOS

            Comment


              #9
              It came to my attention that this same guy re-published "his" version of the GIPHY mod recently. He initially took down it per my request on March 2022. But as of October 2022, he re-published it and I can see his code (JS and CSS) is still using mine!

              I compared our code side-by-side and the only differences are the phrase variables used. The rest (including Javascript variable names are exactly the same. Look at the screenshot below and you be the judge. The left column is my code and the right column is his. The differences are highlighted in gold.



              I wrote this script from scratch when I released the GIPHY mod on Sep 2018. Having the 2 codes the same as coincidence is impossible to happen. Since the GIPHY mod is installed on this site (since the mod was released in 2018), anyone knowledgeable could grab the JS code downloaded in the browser.

              I contacted him and told him if he wants to keep his own version of the GIPHY mod, then I'm fine with it but I told him to not use my code and create it himself from scratch. Otherwise, I respectfully requested him to take it down once again. I haven't received a response from him yet.

              So if you are using his GIPHY mod, be aware that it is using stolen code from mine. I'm not telling you to stop using it but it's just FYI.
              Helpful? Donate. Thanks!
              Buy me a coffeePayPal QR Code
              Fast VPS Host for vBulletin:
              A2 Hosting & IONOS

              Comment

              Users Viewing This Page

              Collapse

              There is 1 user viewing this forum topic.

              • Guest Guest

              Latest Posts

              Collapse

              Working...
              X
              Searching...Please wait.
              An unexpected error was returned: 'Your submission could not be processed because you have logged in since the previous page was loaded.

              Please push the back button and reload the previous window.'
              An unexpected error was returned: 'Your submission could not be processed because the token has expired.

              Please push the back button and reload the previous window.'
              An internal error has occurred and the module cannot be displayed.
              There are no results that meet this criteria.
              Search Result for "|||"