vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   vBulletin Unsafe? (https://vborg.vbsupport.ru/showthread.php?t=207586)

MTGDarkness 03-07-2009 06:55 AM

vBulletin Unsafe?
 
Code:

I doubt Jelsoft is hiring, and I dont know if I want to fix something as broken as vbulletin, its DB performance is horendous, its code implmentation is *cringe*, and I doubt they would like a formal AGILE method, altough I do hear they are adopting AGILE (a microsoft originating project mangement style that rocks)

But yes, VB hacking easy as pie, also there is a way to make users do things invisible, a user remote control if you will.

In my experiance the most I would get out reporting the 71 or so hacks I have found to date is a free copy of VB.

This guy claims he can hack vbulletin in 41 different ways with notepad and opera. How much is he bullshitting me?

RedeemedWarrior 03-07-2009 06:59 AM

Vbulletin is one of the most secure softwares on the net.

MTGDarkness 03-07-2009 07:01 AM

He gave me this example:

Code:

Ok here is a quick one.

Custom Sigs accept code, you could cross script it and send to the admin, that wuld cause the admin to load a page to change his pass and send it to you.

Or you could steal his cookie.

Of you could have him execute delete from on his entire db.

So all you do is mail the ++++ and let your custom kill him.

(code so he can't see it)

Vackrick 03-07-2009 07:02 AM

Man He is a liar man that what i can say what ur msn????

pm me ur msn i help u talk to that guy

MTGDarkness 03-07-2009 07:22 AM

Prolly not worth it. Honestly, I can tell he's probably lying. vBulletin couldn't be that unsafe.

Stifler 03-07-2009 07:51 AM

reverse engineering you to give up your password to someone who could supposedly "hack" you in order to protect you is usually how someone who talks a lot of game obtains 99.9% of their passwords.

TigerC10 03-07-2009 07:54 AM

He's a noob that found a list of the cross site scripting exploits on old versions of vB, pretty much if you're up to date his rants about insecurity are worthless.

The only thing he's somewhat right about is the cookie thing. If you log into your board on a public wireless network, anyone can sniff out your cookie without any problem. Once you that cookie is stolen they can do a lot of stuff without authorization until you change your password.

ragtek 03-07-2009 08:26 AM

And as you see, if a exploit is find, the developers are fixing it very fast => 3.8.1 pl 1

Vackrick 03-07-2009 09:06 AM

ya lor vb rox

mac-warez 03-07-2009 01:40 PM

Code:

Actually in the 4th post i believe. he is correct. You can Use an XSS flaw in some 3.6X versions of vBulletin

TigerC10 03-08-2009 04:06 AM

@mac-warez - Yeah, we know. That's what I was talking about before... Old versions.


All times are GMT. The time now is 04:54 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01127 seconds
  • Memory Usage 1,724KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_code_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (11)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete