vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   News and Announcements (https://vborg.vbsupport.ru/forumdisplay.php?f=2)
-   -   vBulletin 3.0.7 released (https://vborg.vbsupport.ru/showthread.php?t=76645)

filburt1 02-19-2005 06:27 PM

vBulletin 3.0.7 released
 
It is directed primarily as a security fix that apparently is caused by enabling debug comments in templates (something production sites should not do anyway). However, it also fixes a slew of other bugs, so as usual, you should always stay up to date.

More: http://www.vbulletin.com/forum/showthread.php?t=130591

Paul M 02-19-2005 06:28 PM

Indeed, https://vborg.vbsupport.ru/showthread.php?t=76641 :)

Deaths 02-19-2005 06:30 PM

Hmm, I'll have a look at it.

I'm just hoping it doesn't make any major changes to the files I use for my hack, as it's almost finished now ~~.

EDIT:
Yes, why not create an almost entirely new attachment.php, when that's one of the most time taking parts of my hack, and I was almost done with it -.-

Geographic2 02-19-2005 08:49 PM

Again? Yuk.

I had just gotten 3.0.6 almost working...
might as well start a fresh merge now...

Merlin_ 02-19-2005 09:29 PM

The exploit code says 3.0.5 and up are immune. Is that not right?

Erwin 02-19-2005 09:31 PM

Quote:

Originally Posted by Merlin_
The exploit code says 3.0.5 and up are immune. Is that not right?

No. Only 3.0.7 is immune but only if you have template name in HTML enabled in your Admin CP, which is off by default and which most sites won't have.

AN-net 02-20-2005 12:49 AM

what is exactly the problem with using the html comments, the posts do not mention what the hole is. if it can not be discussed publically can someone drop me a pm...

Dean C 02-20-2005 11:09 AM

It wouldn't be sensible to mention how it can be exploited in public. So before anyone tries ;)...

Paul M 02-20-2005 12:25 PM

Quote:

Originally Posted by Dean C
It wouldn't be sensible to mention how it can be exploited in public. So before anyone tries ;)...

While that may be partly true - people may pay more attention if the problem is actually known rather than some vague "there is an issue". I must admit that I'm struggling to understand how adding comments poses a security risk, I'm sure many others are as well, and people tend to ignore and dismiss something they can't see or understand.

Dean C 02-20-2005 12:44 PM

I understand that, but if we posted up how it can be exploted in public, then you'd have people going around exploiting people's sites. And there are LOTS of people who don't upgrade and apply patches :)

sim tech 02-20-2005 06:19 PM

Is there going to be a discussion area on which mods will have to be redone if I chose the "upgrade" option over the single file patch? My license with Vbulletin is only a month old, so I can do the full upgrade if I want.

But I have installed - "for members who posted today" hack,
Installed pm.php AND users.php hack - for PMs
Also installed V3Arcade
vbookie installed
ucash and ustore installed

Crud - will I have to redo all of these?? Would it be worth it to upgrade from 3.0.6 to 3.0.7 or is just the patch good enough?

Erwin 02-20-2005 08:03 PM

With only 4-5 hacks, best to upgrade to 3.0.7 which fixes some bugs (albeit minor ones) and reapply the hacks. You will have to do all of them.

Paul M 02-20-2005 08:55 PM

Remember it's only the file edits you need to re-do, not complete hack re-installs.

oldfan 02-20-2005 09:49 PM

I got 27 mods/addons/hacks installed.. :(
I think I may pass this upgrade u..

Lizard King 02-21-2005 01:20 AM

Quote:

Originally Posted by oldfan
I got 27 mods/addons/hacks installed.. :(
I think I may pass this upgrade u..

Why dont you use araxis merge or something like that. You can check this thread and upgrade your forum within 30 minutes.

hendri 02-21-2005 04:56 AM

Quote:

Originally Posted by Lizard King
Why dont you use araxis merge or something like that. You can check this thread and upgrade your forum within 30 minutes.

i have upgraded to 3.07 everything seems fine

Blootix 02-23-2005 05:56 AM

Quote:

Originally Posted by Erwin
With only 4-5 hacks, best to upgrade to 3.0.7 which fixes some bugs (albeit minor ones) and reapply the hacks. You will have to do all of them.

*Sigh* yeah. I had to... Even though I only had about 4 hacks. The AWS hack is extremely loooooong though, so that counts as 2! ;)

Delphiprogrammi 02-23-2005 08:02 PM

1 Attachment(s)
hi,

this is pretty obvious goto your admincp => vbulletin settings => general settings

"add template name in html comments" => no that's all there is to it

for a list of bugs fixed in 3.07 you can go here

offcource if you want the fixes you need the full upgrade ....

SaN-DeeP 02-25-2005 05:10 AM

Upgraded to 3.0.7 quite easily :).

Revan 02-25-2005 10:48 PM

I now know why the "Add Template Name In HTML Comments" are a serious (!) security vulnerability.
With an unpatched board with this feature enabled, a cracker can inject malicious PHP code (yes, ANY PHP code) by the use of a malformed URL.
Of course, I'm not about to state HOW this is done, but let me just say that if *I* could find it (and I wasn't even LOOKING for this info!), then a cracker with a grudge will surely find it.

I hope this helps to make users patch themselves, if some are still in doubt of the severity of this exploit :)


All times are GMT. The time now is 06:35 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03247 seconds
  • Memory Usage 1,751KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (5)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (20)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete