vBulletin Security Flaw Makes BBC News

Jonathan

Seasoned Veteran
Joined
Jul 24, 2009
Messages
2,832
Reaction score
0
FP$
6
Seriously, this is the first time I've seen forum software in the news!

http://www.bbc.co.uk/news/technology-10714192

Shame it's a bad thing 😛

I also got an email about this (I'm a customer,) with high priority. It read:

vBulletin SECURITY BULLETIN
http://www.vbulletin.com/
22nd July 2010

* vBulletin 3.8.6 Patch Level 1 Released
* Patch Levels Explained
* Your License Information
* Contact Us

------- VBULLETIN 3.8.6 Patch Level 1 RELEASED --------------------

vBulletin 3.8.6 Patch Level 1 has been released in order to deal with a security issue related to the vBulletin FAQ.

** ONLY VBULLETIN VERSION 3.8.6 IS AFFECTED BY THIS ISSUE **
Other versions are not affected - if you are running an older version of vBulletin 3 you do not need to do anything. If you have already installed vB 3.8.6, then follow these instructions in order to fix this:


1. First, download the 3.8.6 PL1 patch here:

http://members.vbulletin.com/patches.php

2. Delete the existing vbulletin-language.xml file from your 'install' directory.

3. Next upload the two files in that patch:

includes/version_vbulletin.php
install/vbulletin-language.xml

Make sure to upload these in ASCII mode, overwriting any existing files if necessary.

4. Go into your Admin CP and run this:

Admin CP -> Languages & Phrases -> Download/Upload Languages -> Import Language XML File

Then leave the settings as they are and click on Import.


Also please note that if you have not upgraded to 3.8.6 yet, the download has already been patched.

You MUST follow all of those instruction to fix this.

We strongly recommend that all customers running vBulletin 3.8.6 apply this patch as soon as possible.

Please see this notice for any new instructions:
http://www.vbulletin.com/go/386pl1

------- PATCH LEVELS EXPLAINED --------------------------

In order for the vBulletin team to react even more quickly to the discovery of security flaws, recent versions of vBulletin include a new system that allows the release of special security patch versions, which do nothing except fix the security problem.

This system allows a version number such as 1.0.4 to be altered to 1.0.4 PL1 (PL = Patch Level) so administrators can be sure that they are running the most up-to-date code and are no longer vulnerable to known security problems.

To make use of this system, vBulletin releases that include only security flaws will contain *only* the fixed file(s) plus a new version number file, allowing administrators to simply upload the new files without having to run an upgrade script.

A patch level release contains fixes for only the most critical issues in the previous release. In this case, this means the only changes are to address a security issue.

It is designed to be installed directly over top of your 3.8.6 installation. There is no need to run any upgrade scripts.

------- YOUR LICENSE INFORMATION ------------------------

You can use this information to log into the customer area to download vBulletin, ImpEx and other vBulletin-related support materials:

Your Customer Number: (removed)

If you have misplaced your customer password, you can request that it be re-sent to your registered email address using the following form:
http://www.vbulletin.com/go/lostpw

The customer area is located here:
http://members.vbulletin.com/


-------------------- CONTACT US --------------------------

Please do not respond to this email directly. We will not receive your response. Please use the links below.

Got a vBulletin technical query? Contact support:
http://www.vbulletin.com/go/techsupport

For all other queries, please visit this page:
http://www.vbulletin.com/contact.php

----------------------------------------------------------

This periodic email newsletter is delivered to all current vBulletin customers, and contains information about new software versions and vBulletin.com web site features and content. If you have any questions or comments about this mailing, please contact us via the links above. You can unsubscribe from this newsletter in the customer area at the bottom of the page: http://members.vbulletin.com

This email sent to: ---

Copyright ©2000-2010, vBulletin Solutions Limited
 
Your know it's bad when...

... A security issue in a forum software makes it onto the home page of the BBC News site
A serious flaw in software widely used to power online discussion sites could allow hackers to harvest reams of personal data, the BBC has learned.

The flaw in a specific version of the vBulletin software allows anyone to easily access the main administrator username and password for a site.

This would also allow hackers to access data, such as e-mail addresses, and edit the site at will.

The owner of the program - Internet Brands - released a fix on 21 July.

However, at time of writing, many sites remain vulnerable....
Source
 
Re: Your know it's bad when...

oh yeah I read about this somewhere else.
 
Re: Your know it's bad when...

Interesting that vB 3 is falling as well now that Darby is gone.
 
Re: Your know it's bad when...

Good thing I'm using version 3.8.5.
 
Got the email too. I always wait awhile before I upgrade to the next version.. Glad I did this time because I would have updated the board a few days ago, making it vulnerable to attacks.. Then update today because they missed something in their 1st so-called-update. That would have aggravated me.

Hope this bad press teaches them a lesson to test, re-test, re-re-test, re-re-re-test and re-re-re-re-test their updates before they release them to the world.
 
Re: Your know it's bad when...

Taz said:
Who is Darby?

He was vBulletin's project manager lead throughout the vBulletin 3 series. He quit a month or two before vBulletin 4 came out. He built the dead majority of vBulletin 3 (and subsequently, a lot of the vBulletin 4 code because it wasn't an extensive rewrite). He seemed surprised he was cited in that BBC report, and I'm not surprised, because 3.8.5/3.8.6 were released after he left the company.
 
Re: Your know it's bad when...

Mr. Green said:
Good thing I'm using version 3.8.5.
Same here. Maybe I will wait to see if 3.8.6-Patch-Level-1 is a failure too. :lol:
 
Re: Your know it's bad when...

Wow, I swear I heard this somewhere else too
 
Re: Your know it's bad when...

You probably read the other topic (now merged in with this one) that was posted in the Intellectual Chat forum :roll:

Jonathan, I also removed your customer number from your post aswell 😉
 
Re: Your know it's bad when...

I reported the post for your customer number just to save you from others using your number to install the software under your number. Just a little security flaw that was in the topic. But this is a major issue and glad it has been fixed fast.
 
Re: Your know it's bad when...

I noticed that as well. I thought it was strange he had his personal info up there. 😛
 
Re: Your know it's bad when...

Wow VB is going to lose a lot of customers...
 
Re: Your know it's bad when...

Fowler said:
Jonathan, I also removed your customer number from your post aswell 😉
Ah, crap, didn't double check it. Thanks mate.
 
Back
Top Bottom