PDA

View Full Version : Heartbleed Bug and Vbulletin?


Justinphx
04-08-2014, 06:24 PM
<a href="https://www.cnet.com/news/heartbleed-bug-undoes-web-encryption-reveals-user-passwords/" target="_blank">http://www.cnet.com/news/heartbleed-...ser-passwords/</a>

Is this anything to be concerned about using Vbulletin? I am not sure how much OpenSSL is used and how Vbulletin stores/encrypts passwords. Thanks.

Zachery
04-08-2014, 06:43 PM
By default we use OpenSSL/cURL with SSL for facebook. Its not a vbulletin issue so much as an issue with SSL and you should get your server updated.

xenite
04-09-2014, 12:51 PM
If your server is running older software that is not yet considered to be vulnerable you should be okay. Not every server installation was upgraded to the OpenSSL that has been affected by the bug.

Barcham
04-09-2014, 01:43 PM
Darn! I just posted about this in the Community Lounge. I guess this answers my question.

PartiBoi
04-11-2014, 06:59 AM
<a href="https://filippo.io/Heartbleed/" target="_blank">http://filippo.io/Heartbleed/</a>

enter your Url and it will check your site, of course this is for SSL forums.