PDA

View Full Version : 3.8.4 PL 1 username exploit?


Duncan
11-25-2009, 06:16 AM
Hi,

I have (mostly) default setting for my vBulletin. However, someone just registered a username with no name? It's blank- there's not even a space. The requirement for new usernames is the vbulletin default 3 to 20 characters. How did this happen?

When I search his User ID and look him up he shows up but, again, with no username.

Any ideas?:confused:

EDIT: here is the user- http://www.topictown.com/showthread.php?t=403

CarlitoBrigante
11-25-2009, 06:20 AM
https://vborg.vbsupport.ru/showthread.php?t=228692

You are the second one reporting this.

http://www.vbulletin.com/forum/project.php?issueid=6099

Maybe it is a character encoding issue?

--------------- Added 1259137365 at 1259137365 ---------------

Just checked your link. The username is not empty, it contains characters not supported by your OS; I do not have multilingual support installed, but I suppose it is something from an asian charset.

Duncan
11-25-2009, 06:22 AM
This is nuts. I'll create a support ticket.

wacnstac
11-25-2009, 01:05 PM
I'm watching this thread very closely. Hopefully we will get a root cause soon. Do you run vbSEO?

Thierry Martin
09-26-2010, 01:19 AM
<a href="https://www.exploit-db.com/exploits/14833/" target="_blank">http://www.exploit-db.com/exploits/14833/</a>

BirdOPrey5
09-26-2010, 05:29 PM
very likely the same exploit.