NamePros
Welcome, Guest! Ready to make a name for yourself in the domain business? We welcome both the hobbyist and professional domainer to join the discussion as part of the NamePros community.

Click here to create your profile to start earning reputation for posting, and trader ratings for buying & selling in our free e-marketplace. Build your trader rating with each successful sale. Our system has tracked over 100,000 sales and counting!
FAQ & TOS Register Search Today's Posts Mark Forums Read

Go Back   NamePros.com > Business & Community Discussion Forums > Community > The Break Room
Reload this Page vBulletin Vulnerability

The Break Room Casual discussion about non-industry related topics.

Advanced Search


Closed Thread
 
LinkBack Thread Tools
Old 01-07-2005, 02:35 PM THREAD STARTER               #1 (permalink)
Senior Member
 
Kodeking's Avatar
Join Date: Jun 2003
Location: Naperville Illinois
Posts: 1,786
Kodeking is just really niceKodeking is just really niceKodeking is just really niceKodeking is just really nice
 



vBulletin Vulnerability


I don't think anyone posted this here yet, but I want to get the word out before something like the PHPBB worm starts up here. I just got this email from Jelsoft:

Quote:
JELSOFT SECURITY BULLETIN
http://www.vbulletin.com/
January 7th, 2005

This email contains important security-related information.
Please read it carefully.

* vBulletin 3.0.4 / 3.0.5 Released
* Important Warning About Sensitive Data
* Security Issues in PHP 4.3.9, 5.0.2 & Older
* Your License Information
* Contact Us

------------ VBULLETIN 3.0.4 / 3.0.5 RELEASED ------------

The discovery of a serious security vulnerability in versions of vBulletin 3 up to and including 3.0.4 has necessitated the immediate release of a version to plug the hole. This is a CRITICAL update, and we urge all customers running affected software to upgrade vBulletin with the utmost urgency.

vBulletin 3.0.5 includes all the updates recently released as part of vBulletin 3.0.4, including a long list of fixes for minor annoyances and bugs found since version 3.0.3.

vBulletin 3.0.5 is available for immediate download from the vBulletin Members' Area.
http://www.vbulletin.com/members/

If you are unable to upgrade immediately, you should at least download the patched version of includes/init.php from the release announcement thread and replace your existing version with it.

Please read the announcement for upgrade and installation instructions, as well as the list of bugs fixed and other
changes:

http://www.vbulletin.com/forum/showthread.php?t=125480

--------- IMPORTANT WARNING ABOUT SENSITIVE DATA ---------

Due to the nature of the vulnerability discovered in vBulletin 3, and as part of our ongoing effort to maximize security, we must assume that one or all of the vBulletin servers may have been compromised.

Therefore, we would STRONGLY RECOMMEND that any customers who may have submitted sensitive data; such as vBulletin admin control panel or server login details, to Jelsoft staff in the past should take steps to alter these details, so that any information that may have been accessed by an unauthorized party could not be used.

We would like to reassure our customers that Jelsoft keeps NO RECORD of credit card numbers used in transactions, making it impossible for these details to be discovered or abused.

Additionally, steps have been taken and are ongoing to ensure that any potentially leaked data does not contain sensitive data.

------ SECURITY ISSUES IN PHP 4.3.9, 5.0.2 & OLDER -------

The PHP development team recently released PHP 4.3.10 and
5.0.3 in order to patch serious security issues in previous versions.

With the emergence of malicious code such as the Santy/NeverEverNoSanity worms, which are responsible for defacing and damaging a large number of sites, we join with the PHP team in advising all customers running PHP versions older than 4.3.10 or 5.0.3 to upgrade as soon as possible to one of the patched versions.
__________________
Quote:
Clan-Forums.com >> $30 BoardingForum.com >> $100
TalkWebHosting.com >> $200 AvoidChapter13.com >> $100
Send PM to make lesser offers on the above names.
Kodeking is offline  
Old 01-07-2005, 03:28 PM   #2 (permalink)
RJ
NamePros Webmaster


 
RJ's Avatar
Join Date: Feb 2003
Posts: 12,930
RJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatness
 



Find Marrow Donors! Cystic Fibrosis Parkinson's Disease
thanks Jason. Just made the init changes here on NP.
__________________
@DomainBuyer facebook
RJ is offline  
Old 01-07-2005, 03:29 PM   #3 (permalink)
Senior Member
 
ZuraX's Avatar
Join Date: Apr 2003
Location: Pennsylvania USA
Posts: 2,683
ZuraX is a name known to allZuraX is a name known to allZuraX is a name known to allZuraX is a name known to allZuraX is a name known to allZuraX is a name known to all
 



Yeah thing is I have well over 10 hacks on my board. This sucks big time.
Guess I have to start adding the hacks all over again.
__________________
Been a NP member for 5 or more years?
PM me to join the Social Group!
ZuraX is offline  
Old 01-07-2005, 03:57 PM   #4 (permalink)
Senior Member
 
Scott's Avatar
Join Date: Jun 2003
Location: UK
Posts: 3,547
Scott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond repute
 

Member of the Month
February 2005

Thanks for the reminder. I just took the leap and upgraded PP although the forum is built into the game, or game built into the forum, whatever. Luckily the game works fine, just need to readd all my hacks to the forums.
Scott is offline  
Old 01-07-2005, 04:12 PM   #5 (permalink)
Senior Member
 
ZuraX's Avatar
Join Date: Apr 2003
Location: Pennsylvania USA
Posts: 2,683
ZuraX is a name known to allZuraX is a name known to allZuraX is a name known to allZuraX is a name known to allZuraX is a name known to allZuraX is a name known to all
 



How did you do it? Just save a back up of the mysql and upgrade then reinstall the hacks?
__________________
Been a NP member for 5 or more years?
PM me to join the Social Group!
ZuraX is offline  
Old 01-07-2005, 08:16 PM   #6 (permalink)
NamePros Member
Join Date: Jul 2004
Location: U.S.A.----- Ohio
Posts: 117
ServeTraffic is an unknown quantity at this point
 



Just updated mine, woowee! Thank goodness for updates.
__________________
ServeTraffic.Com
Make money with your traffic, Join our publisher network click here to find out more.
ServeTraffic is offline  
Old 01-07-2005, 08:35 PM   #7 (permalink)
Senior Member
 
CoolGuy's Avatar
Join Date: Jan 2004
Posts: 1,505
CoolGuy is a jewel in the roughCoolGuy is a jewel in the roughCoolGuy is a jewel in the roughCoolGuy is a jewel in the rough
 



Hackers are really getting bored. now man! They need to stop trying to spoil a great thing. If any are found I suggest serious punishment.
__________________
Social Blurpalicious
Directory Submissions

World Internet Discovery Forums International & Local Political Blog
Domain for sale: salesold.com (expires April 2009)
CoolGuy is offline  
Old 01-07-2005, 09:54 PM   #8 (permalink)
NamePros Member
Join Date: Jul 2004
Location: U.S.A.----- Ohio
Posts: 117
ServeTraffic is an unknown quantity at this point
 



I agree, they have no direction in life, and they fear us this is why they do it.
__________________
ServeTraffic.Com
Make money with your traffic, Join our publisher network click here to find out more.
ServeTraffic is offline  
Old 01-07-2005, 10:27 PM   #9 (permalink)
Senior Member
 
{insert name here}'s Avatar
Join Date: Dec 2004
Posts: 1,304
{insert name here} is a glorious beacon of light{insert name here} is a glorious beacon of light{insert name here} is a glorious beacon of light{insert name here} is a glorious beacon of light{insert name here} is a glorious beacon of light
 


Breast Cancer
I've personaly never understood why hackers feel the need to ruin and destroy others work. And I have never understood the need for someone to have the urge to write a viruse.
{insert name here} is offline  
Old 01-08-2005, 03:00 AM   #10 (permalink)
Senior Member
 
Scott's Avatar
Join Date: Jun 2003
Location: UK
Posts: 3,547
Scott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond repute
 

Member of the Month
February 2005

Originally Posted by ZuraX
How did you do it? Just save a back up of the mysql and upgrade then reinstall the hacks?
cp -R vb vb-backup in SSH and then did the upgrade. Didn't care too much about backing up MySQL, I live on the edge. I haven't reinstalled the hacks yet.
Scott is offline  
Old 01-08-2005, 01:38 PM   #11 (permalink)
Senior Member
 
ZuraX's Avatar
Join Date: Apr 2003
Location: Pennsylvania USA
Posts: 2,683
ZuraX is a name known to allZuraX is a name known to allZuraX is a name known to allZuraX is a name known to allZuraX is a name known to allZuraX is a name known to all
 



Just read over at VB .com that theres a BIG update coming. This will suck, do this upgrade and reinstall the hacks, then in a month or two do it all again...
__________________
Been a NP member for 5 or more years?
PM me to join the Social Group!
ZuraX is offline  
Old 01-08-2005, 04:30 PM   #12 (permalink)
Senior Member
 
Scott's Avatar
Join Date: Jun 2003
Location: UK
Posts: 3,547
Scott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond repute
 

Member of the Month
February 2005

Originally Posted by ZuraX
Just read over at VB .com that theres a BIG update coming. This will suck, do this upgrade and reinstall the hacks, then in a month or two do it all again...
Yup But that's life I guess
Scott is offline  
Old 01-08-2005, 09:36 PM   #13 (permalink)
Senior Member
 
CoolGuy's Avatar
Join Date: Jan 2004
Posts: 1,505
CoolGuy is a jewel in the roughCoolGuy is a jewel in the roughCoolGuy is a jewel in the roughCoolGuy is a jewel in the rough
 



I never really add too many mods, makes life easier.
__________________
Social Blurpalicious
Directory Submissions

World Internet Discovery Forums International & Local Political Blog
Domain for sale: salesold.com (expires April 2009)
CoolGuy is offline  
Old 01-08-2005, 09:41 PM   #14 (permalink)
Senior Member
 
ZuraX's Avatar
Join Date: Apr 2003
Location: Pennsylvania USA
Posts: 2,683
ZuraX is a name known to allZuraX is a name known to allZuraX is a name known to allZuraX is a name known to allZuraX is a name known to allZuraX is a name known to all
 



Yes but MODS help bring in users most of the time...
__________________
Been a NP member for 5 or more years?
PM me to join the Social Group!
ZuraX is offline  
Old 01-08-2005, 09:56 PM   #15 (permalink)
Senior Member
 
CoolGuy's Avatar
Join Date: Jan 2004
Posts: 1,505
CoolGuy is a jewel in the roughCoolGuy is a jewel in the roughCoolGuy is a jewel in the roughCoolGuy is a jewel in the rough
 



You need a few mods, forums with too many mods, load slowly and just look complicated. A few good mods are all you need.
__________________
Social Blurpalicious
Directory Submissions

World Internet Discovery Forums International & Local Political Blog
Domain for sale: salesold.com (expires April 2009)
CoolGuy is offline  
Old 01-19-2005, 02:47 AM   #16 (permalink)
RJ
NamePros Webmaster


 
RJ's Avatar
Join Date: Feb 2003
Posts: 12,930
RJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatnessRJ Has achieved greatness
 



Find Marrow Donors! Cystic Fibrosis Parkinson's Disease
There's another security upgrade, now the current version is 3.0.6. I just completed the upgrade, and so far so good.
__________________
@DomainBuyer facebook
RJ is offline  
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools


Liquid Web Smart Servers  
All times are GMT -7. The time now is 07:53 AM.

Managed Web Hosting by Liquid Web
Domain name forum recommended by Domaining.com Powered by: vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.6.0 Ad Management plugin by RedTyger