Dynadot โ€” .com Transfer

vBulletin Vulnerability

SpaceshipSpaceship
Watch

Kodeking

Established Member
Impact
11
I don't think anyone posted this here yet, but I want to get the word out before something like the PHPBB worm starts up here. I just got this email from Jelsoft:

JELSOFT SECURITY BULLETIN
http://www.vbulletin.com/
January 7th, 2005

This email contains important security-related information.
Please read it carefully.

* vBulletin 3.0.4 / 3.0.5 Released
* Important Warning About Sensitive Data
* Security Issues in PHP 4.3.9, 5.0.2 & Older
* Your License Information
* Contact Us

------------ VBULLETIN 3.0.4 / 3.0.5 RELEASED ------------

The discovery of a serious security vulnerability in versions of vBulletin 3 up to and including 3.0.4 has necessitated the immediate release of a version to plug the hole. This is a CRITICAL update, and we urge all customers running affected software to upgrade vBulletin with the utmost urgency.

vBulletin 3.0.5 includes all the updates recently released as part of vBulletin 3.0.4, including a long list of fixes for minor annoyances and bugs found since version 3.0.3.

vBulletin 3.0.5 is available for immediate download from the vBulletin Members' Area.
http://www.vbulletin.com/members/

If you are unable to upgrade immediately, you should at least download the patched version of includes/init.php from the release announcement thread and replace your existing version with it.

Please read the announcement for upgrade and installation instructions, as well as the list of bugs fixed and other
changes:

http://www.vbulletin.com/forum/showthread.php?t=125480

--------- IMPORTANT WARNING ABOUT SENSITIVE DATA ---------

Due to the nature of the vulnerability discovered in vBulletin 3, and as part of our ongoing effort to maximize security, we must assume that one or all of the vBulletin servers may have been compromised.

Therefore, we would STRONGLY RECOMMEND that any customers who may have submitted sensitive data; such as vBulletin admin control panel or server login details, to Jelsoft staff in the past should take steps to alter these details, so that any information that may have been accessed by an unauthorized party could not be used.

We would like to reassure our customers that Jelsoft keeps NO RECORD of credit card numbers used in transactions, making it impossible for these details to be discovered or abused.

Additionally, steps have been taken and are ongoing to ensure that any potentially leaked data does not contain sensitive data.

------ SECURITY ISSUES IN PHP 4.3.9, 5.0.2 & OLDER -------

The PHP development team recently released PHP 4.3.10 and
5.0.3 in order to patch serious security issues in previous versions.

With the emergence of malicious code such as the Santy/NeverEverNoSanity worms, which are responsible for defacing and damaging a large number of sites, we join with the PHP team in advising all customers running PHP versions older than 4.3.10 or 5.0.3 to upgrade as soon as possible to one of the patched versions.
 
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
GoDaddyGoDaddy
thanks Jason. Just made the init changes here on NP.
 
0
•••
Yeah thing is I have well over 10 hacks on my board. This sucks big time. :(
Guess I have to start adding the hacks all over again. :(
 
0
•••
Thanks for the reminder. I just took the leap and upgraded PP although the forum is built into the game, or game built into the forum, whatever. Luckily the game works fine, just need to readd all my hacks to the forums. :tu: :D
 
0
•••
How did you do it? Just save a back up of the mysql and upgrade then reinstall the hacks?
 
0
•••
Just updated mine, woowee! Thank goodness for updates. :D
 
0
•••
Hackers are really getting bored. now man! They need to stop trying to spoil a great thing. If any are found I suggest serious punishment.
 
0
•••
I agree, they have no direction in life, and they fear us this is why they do it. :gl:
 
0
•••
I've personaly never understood why hackers feel the need to ruin and destroy others work. And I have never understood the need for someone to have the urge to write a viruse. :-/
 
0
•••
ZuraX said:
How did you do it? Just save a back up of the mysql and upgrade then reinstall the hacks?

cp -R vb vb-backup in SSH and then did the upgrade. Didn't care too much about backing up MySQL, I live on the edge. I haven't reinstalled the hacks yet.
 
0
•••
Just read over at VB .com that theres a BIG update coming. This will suck, do this upgrade and reinstall the hacks, then in a month or two do it all again...
 
0
•••
ZuraX said:
Just read over at VB .com that theres a BIG update coming. This will suck, do this upgrade and reinstall the hacks, then in a month or two do it all again...

Yup :( But that's life I guess
 
0
•••
I never really add too many mods, makes life easier.
 
0
•••
Yes but MODS help bring in users most of the time...
 
0
•••
You need a few mods, forums with too many mods, load slowly and just look complicated. A few good mods are all you need.
 
0
•••
There's another security upgrade, now the current version is 3.0.6. I just completed the upgrade, and so far so good.
 
0
•••
Appraise.net
Escrow.com
Spaceship
Rexus Domain
CryptoExchange.com
Domain Recover
CatchDoms
DomDB
NameFit
  • The sidebar remains visible by scrolling at a speed relative to the pageโ€™s height.
Back