![]() |
new vb exploit! :S
there is a new vb exploit problem!
im not sure if it was already fixed in verison 3.8.2, but is still available under 3.8.1 and 3.8.2 picture:: https://vborg.vbsupport.ru/external/2009/04/63.jpg cheers ahh sorry about the double post... pls delete the other post |
how did u use the same name????
|
is a name exploit ! all vb 3.8.* has it
|
It results from a bad import of data, it's not an exploit - it's bad administration.
|
Quote:
|
an Exploit is something that can help a hacker insert or extract data from the engine, not changing username of a member post...
and from what i see from the screeny, if it's not a very modified vBulletin *(with possible flaws due to modifications) it's a phpBB forum. |
Quote:
Anyway, after importing data the admin should always check for username duplication. Quote:
Quote:
|
is not PHPBB
is not a bad merge since this forum has been using vb since ages, and is not a databese backup , since this is posible to do in other vb forums cheers i dont think the other vb forums have the same problem of bad import data but this forum is since 2007 or older.. and they always have used vb |
It could be a database backup, do you host this website yourself or do you have a hosting provider? Because I've known hosting providers to lose servers and restore backups only to have a hitch in the backup or in the restoration of the backup.
EDIT: Nevermind, I figured this one out. Instead of using a standard "M" in the username, this person used the greek letter Mu html character code "Μ" or "Μ". This allows for a completly new user with the name that looks just like someone else's since the character "Mu" is not the same as M. Here's a list of some other greek symbols that can be used for registration fake outs: http://www.w3schools.com/tags/ref_symbols.asp Alpha, Beta, Epsilon, Zeta, Eta, Iota, Kappa, Mu, Nu, Omicron, Rho, Tau, Upsilon, Chi To fix it, add these to your illegal user names AdminCP -> vBulletin Options -> User Registration Options -> Illegal User Names Code:
Α Β Ε Ζ Η Ι Κ Μ Ν Ο Ρ Τ Υ Χ ν ο Code:
Α Β Ε Ζ Η Ι Κ Μ Ν Ο Ρ Τ Υ Χ ν ο |
Nevermind, didn't see your edit.
|
---------------------
|
Quote:
Quote:
|
thanks for telling me this that well help me alot :)
|
thread title should be changed so as to avoid confusion...
|
All times are GMT. The time now is 05:22 PM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|