vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   News and Announcements (https://vborg.vbsupport.ru/forumdisplay.php?f=2)
-   -   vBulletin 3.0.5 Released - Critical Update (https://vborg.vbsupport.ru/showthread.php?t=73934)

assassingod 01-07-2005 06:34 AM

vBulletin 3.0.5 Released - Critical Update
 
http://www.vbulletin.com/forum/showthread.php?t=125480

[high]This is a CRITICAL update[/high]

vBulletin 3.0.5 has been released due to a serious security flaw in all vBulletin 3 versions, including 3.0.4

It is a critical update and is recommended you upgrade immediately .

Important information about the vulnerability can be found in the thread, link at the top of this post:

Quote:


Important Warning About Sensitive Data

Due to the nature of the vulnerability discovered in vBulletin 3, and as part of our ongoing effort to maximize security, we must assume that one or all of the vBulletin servers may have been compromised.

Therefore, we would STRONGLY RECOMMEND that any customers who may have submitted sensitive data; such as vBulletin admin control panel or server login details, to Jelsoft staff in the past should take steps to alter these details, so that any information that may have been accessed by an unauthorized party could not be used.
Discussion about the thread is here

lasto 01-07-2005 08:50 AM

just done the init.php cant be bothered updating again

yep the one for 3.0.5

ManagerJosh 01-07-2005 09:12 AM

Quote:

Originally Posted by assassingod
http://www.vbulletin.com/forum/showthread.php?t=125480

[high]This is a CRITICAL update[/high]

vBulletin 3.0.5 has been released due to a serious security flaw in all vBulletin 3 versions, including 3.0.4

It is a critical update and is recommended you upgrade immediately .

Important information about the vulnerability can be found in the thread, link at the top of this post:



Discussion about the thread is here

When can we expect the update to be performed here? :D

Mark.B 01-07-2005 09:42 AM

This is actually a bit of a poor show.

I've just spent three days rehacking my board for the upgrade to 3.0.4 and now I'm expected to do it all again. And for what? So 3.0.6 can be released days later?

This is the second time in succession that a release of vBulletin has effectively been botched. Everyone is congratulating the team on another release, and I am usually very supportive, but on this occasion there's been a big botch, and for the second time running.

The whole point of purchasing forum software instead of using the free programs is that this sort of messing about should not be neccessary.

zurih 01-07-2005 09:44 AM

Quote:

Originally Posted by Mark.B
This is actually a bit of a poor show.

I've just spent three days rehacking my board for the upgrade to 3.0.4 and now I'm expected to do it all again. And for what? So 3.0.6 can be released days later?

This is the second time in succession that a release of vBulletin has effectively been botched. Everyone is congratulating the team on another release, and I am usually very supportive, but on this occasion there's been a big botch, and for the second time running.

The whole point of purchasing forum software instead of using the free programs is that this sort of messing about should not be neccessary.

especially when u have a lot of hacks installed.

strongy 01-07-2005 10:06 AM

again, but i just finished fiddling with hacks, it'll have to wait *uploads that init.php though*

Creative Suite 01-07-2005 10:34 AM

woow , We are in era of the speed :p

, just wanna ask about 3.0.6 :D

Montadiat.com 01-07-2005 10:36 AM

yeah ,

<<< looking out for 3.0.6 :D

Paul M 01-07-2005 11:01 AM

So, the only difference between 3.0.4 and 3.0.5 is init.php ?

Erwin 01-07-2005 11:13 AM

Quote:

Originally Posted by Mark.B
This is actually a bit of a poor show.

I've just spent three days rehacking my board for the upgrade to 3.0.4 and now I'm expected to do it all again. And for what? So 3.0.6 can be released days later?

This is the second time in succession that a release of vBulletin has effectively been botched. Everyone is congratulating the team on another release, and I am usually very supportive, but on this occasion there's been a big botch, and for the second time running.

The whole point of purchasing forum software instead of using the free programs is that this sort of messing about should not be neccessary.

This is not Jelsoft's fault.

This is a NEW security loophole that is present in ALL vB 3 forums except for the latest version, and is not caused by the release of 3.0.4.

They've just discovered the loophole, that's all. It was already there.

So this has nothing to do with a botched release. It's just coincidental.

strongy 01-07-2005 11:17 AM

Quote:

Originally Posted by Paul M
So, the only difference between 3.0.4 and 3.0.5 is init.php ?

i don't think so theirs more too it than that, i think it just fixes the immediate problem :p

Erwin 01-07-2005 11:18 AM

The init.php update will plug the security hole.

Remember, the security hole is in ALL vBulletin 3 forums. It was always there. It just took someone all this time to discover how to exploit it, hence the need to close it now.

Paul M 01-07-2005 11:23 AM

Quote:

Originally Posted by strongy
i don't think so theirs more too it than that, i think it just fixes the immediate problem :p

Yeah, I just took a look - all minor errors (including at least two that look like they were introduced in 3.0.4 !).

Paul M 01-07-2005 11:24 AM

Quote:

Originally Posted by Erwin
The init.php update will plug the security hole.

Remember, the security hole is in ALL vBulletin 3 forums. It was always there.

Only if you run with register_globals ON, which is a bad idea in the first place. :)

Erwin 01-07-2005 12:02 PM

Quote:

Originally Posted by Paul M
Only if you run with register_globals ON, which is a bad idea in the first place. :)

At least that's what they think. :) But the recommendations from the developers is to update init.php anyway.

Revan 01-07-2005 01:24 PM

Quote:

Originally Posted by Thread title
vBulletin 3.0.5 Released

One thing to say:
Bugger.

:p
No, seriously. I am one of these nerds that are desperate to update their vBulletin IMMEDIATELY, no matter how many hacks I have installed (which is 68 BTW).
Even though I have learned in the past that Jelsoft just loves to torture people like me, I still updated to 3.0.4.

Bwaha nah just kidding, I think it's great that they are so quick with patching
...but don't think for a second I'm gonna update any other file than what they list as changed...
XD


//peace

red_baron2000 01-07-2005 05:40 PM

will wait for vbb 4.0 !!! maybe it is out tomorrow!! :)

Guest190829 01-07-2005 07:17 PM

I'm glad they found the loop hole...no complaints from me. = )

HiDeo 01-07-2005 07:52 PM

Thanks for the information

moethelawn 01-07-2005 09:29 PM

Shoot... I just rehacked my board.... oh well...

Better to be secure and rehack everything than to be lazy and have someone take control of my board....

MissKalunji 01-07-2005 09:32 PM

Quote:

Originally Posted by Mark.B
This is actually a bit of a poor show.

I've just spent three days rehacking my board for the upgrade to 3.0.4 and now I'm expected to do it all again. And for what? So 3.0.6 can be released days later?

This is the second time in succession that a release of vBulletin has effectively been botched. Everyone is congratulating the team on another release, and I am usually very supportive, but on this occasion there's been a big botch, and for the second time running.

The whole point of purchasing forum software instead of using the free programs is that this sort of messing about should not be neccessary.


when you say rehack you mean just the php files or even reinstall sql??

moethelawn 01-07-2005 10:00 PM

Quote:

Originally Posted by MissKalunji
when you say rehack you mean just the php files or even reinstall sql??

Just the php files that have changed from the upgrade...

You shouldn't usually have to worry about the SQL, lol.. that would suck if you do....

Erwin 01-09-2005 01:13 AM

Refer to this for a 3.0.5 security patch involving private.php
https://vborg.vbsupport.ru/showthread.php?t=74035

peterska2 01-09-2005 07:38 AM

D'oh!

My private.php is rather hacked. I guess I'll be patching the file for the first time ever.

Sin City 01-19-2005 04:09 AM

i am with Mark.B on this... not to be rude, but this is a pain in the butt to constantly have to reinstall every hack because there's a new update every week or two

it is already unsatisfactory that every aspect of this particular company has to be paid for (after paying $160 to be able to have an owned license, the last thing i should have to pay for is yearly access to the members' section (which only has one important feature - software updates)... true it is not a lot of money, but that is not the point....

the point is, i am quite sure that everyone would've been more than happy to stick it out on vB2 until vB3 was THOROUGHLY finished and had none of these constant "oops, we found something... get the latest download ASAP" issues :ermm:

filburt1 01-19-2005 04:25 AM

I would take a security fix over a possibly less-well-coded third-party modification any day. However, I do agree in my opinion that they should not charge access to the Member's Area for releases in the same major.minor group (i.e., 3.0.x). I know they usually post fixed files in the announcements, but there are dozens of bug fixes in each release that get left out.


All times are GMT. The time now is 04:47 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01198 seconds
  • Memory Usage 1,790KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (11)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (26)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete