Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | vBulletin 3.8.6 security flaw

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Internet Discussion

vBulletin 3.8.6 security flaw
Reply
 
Thread Tools
Old 22-07-2010, 22:51   #1
danielf
cf.mega poser
 
danielf's Avatar
 
Join Date: Jun 2003
Posts: 16,687
danielf has a golden auradanielf has a golden auradanielf has a golden aura
danielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden aura
vBulletin 3.8.6 security flaw

Quote:
A serious flaw in software widely used to power online discussion sites could allow hackers to harvest reams of personal data, the BBC has learned.

The flaw in a specific version of the vBulletin software allows anyone to easily access the main administrator username and password for a site.

This would also allow hackers to access data, such as e-mail addresses, and edit the site at will.

The owner of the program - Internet Brands - released a fix on 21 July.

However, at time of writing, many sites remain vulnerable.
http://www.bbc.co.uk/news/technology-10714192

Good thing this site uses Vbulleting 3.8.5
__________________
Remember kids: We are blessed with a listening, caring government.
danielf is offline   Reply With Quote
Advertisement
Old 23-07-2010, 09:00   #2
beeman
Inactive
 
Join Date: Jul 2007
Location: cambridgeshire
Age: 44
Services: Virgin VIP package, FREEVIEW
Posts: 466
beeman is a splendid one to beholdbeeman is a splendid one to beholdbeeman is a splendid one to beholdbeeman is a splendid one to beholdbeeman is a splendid one to beholdbeeman is a splendid one to beholdbeeman is a splendid one to beholdbeeman is a splendid one to beholdbeeman is a splendid one to behold
Re: Vbulletin 3.8.6 security flaw

Quote:
Originally Posted by danielf View Post

Good thing this site uses Vbulleting 3.8.5
You'll proberlly find 3.8.5 has the same issue 3.8.6 is just a bug fix update for 3.8.5. So unless the fix caused this issue (possiable but rarly happens) then this site is just as vrunuble.
beeman is offline   Reply With Quote
Old 23-07-2010, 10:24   #3
MovedGoalPosts
Inactive
 
MovedGoalPosts's Avatar
 
Join Date: Jun 2003
Location: 127.0.0.1
Age: 61
Posts: 15,868
MovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny stars
MovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny starsMovedGoalPosts has a pair of shiny stars
Re: Vbulletin 3.8.6 security flaw

The previous versions of vbulletin are not affected by the security issue. It is only vb 3.8.6 that is vulnerable. Thus this board is not compromised. We are in no rush to upgrade to 3.8.6, with 3.8.5 running adequately for our needs.

vb 3.8.6 was primarily a bug release, not a security release. Thus it wasn't dealinig with vulnerabilities. However 3.8.6, only a few days old, did have a serious security problem with the FAQ system. The patch which has now been released fixes that. As a patch, the forum display numbering would not indicate if the upgrade had been added to the forum software it would still display 3.8.6.
MovedGoalPosts is offline   Reply With Quote
Old 23-07-2010, 11:59   #4
MetaWraith
Inactive
 
MetaWraith's Avatar
 
Join Date: Oct 2003
Location: 2nd CPU to the right & past the cache
Posts: 1,949
MetaWraith has a bronzed appealMetaWraith has a bronzed appeal
MetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appeal
Send a message via ICQ to MetaWraith Send a message via AIM to MetaWraith Send a message via MSN to MetaWraith Send a message via Yahoo to MetaWraith
Re: Vbulletin 3.8.6 security flaw

Glad to know that our Forum Admins are on the ball, and that we're not at risk.
WTG Team.
MetaWraith is offline   Reply With Quote
Old 24-07-2010, 17:03   #5
Paul
Dr Pepper Addict
Cable Forum Admin
 
Paul's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 63
Services: IDNet FTTP (1000M), Sky Q TV, Sky Mobile, Flextel SIP
Posts: 30,324
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: vBulletin 3.8.6 security flaw

The issue was actually a debugging phrase that was accidently left in the 3.8.6 release. It could have been used (via the FAQ system) to get the mysql user and password. Which in theory someone could use to connect to the database (not here tho, as we dont allow external access).
__________________

Baby, I was born this way.
Paul is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 19:15.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum