vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   ibProArcade Archive (https://vborg.vbsupport.ru/forumdisplay.php?f=174)
-   -   Quarantined? (https://vborg.vbsupport.ru/showthread.php?t=269346)

HenryHank 08-29-2011 03:13 PM

Quarantined?
 
Are there any more details on this and why it was quarantined?

thanks.

Zachery 08-29-2011 03:29 PM

We do not release additional details, no sense having the exploit in the wild without a fix.

souperman 08-29-2011 03:56 PM

If it's quarantine it's for a reason. You should probably disable this modification on your board for the time being.

garyb12001 08-29-2011 04:26 PM

Is the recommendation to disable this mod in effect for all versions of VB? Thanks.

souperman 08-29-2011 07:21 PM

From what I can tell, yes. You should disable it in vb3 and in vb4. You should also remove the actual files from your website (just the php files).

JacquiiDesigns 08-29-2011 07:38 PM

Quote:

Originally Posted by Zachery (Post 2239478)
We do not release additional details, no sense having the exploit in the wild without a fix.

Sorry to say - but I find this comment ridiculous....for this modification.

ibProArcade has it's own section here at vB.org - its' the most downloaded/installed modification here. This being the case - I'm sure the 8400 people who've at least clicked install would feel more secure about their vBulletin paid-product if given a reasoning behind why such modification is quarantined.

This policy about "we do not release additional details" truly could use a bit of transparency as concerns such popular modification(s) as ibProArcade! Even if said transparency takes shape in a little info-note attached to the automated(?) quarantine email.

Meanwhile -congrats vBulletin.org for continually keeping members in the dark!

I sincerely hope that MrZeroPage offers up a fix for this exploit, and QUICKLY!

J.

Hippy 08-29-2011 08:03 PM

I'm sure they will contact MrZeroPage about this but I'm not sure he has the time anymore :(
like Zachery said why exploit

basskiller 08-29-2011 09:02 PM

Quote:

Originally Posted by JacquiiCooke (Post 2239574)
Sorry to say - but I find this comment ridiculous....for this modification.

ibProArcade has it's own section here at vB.org - its' the most downloaded/installed modification here. This being the case - I'm sure the 8400 people who've at least clicked install would feel more secure about their vBulletin paid-product if given a reasoning behind why such modification is quarantined.

This policy about "we do not release additional details" truly could use a bit of transparency as concerns such popular modification(s) as ibProArcade! Even if said transparency takes shape in a little info-note attached to the automated(?) quarantine email.

Meanwhile -congrats vBulletin.org for continually keeping members in the dark!

I sincerely hope that MrZeroPage offers up a fix for this exploit, and QUICKLY!

J.

you have to realize that consequences far outweigh the right to know what the problem actually is/
Say he does mention what the exact exploit is.. This could leave possible thousands of boards out there that maybe haven't received the message about the quarantine, vulnerable to the exploit to many new people that now know what the exploit is. And by people, I mean guys that just want to cause truoble..
so is it better for them not to say and we just disable the mod.. wait for the fix, or let you know and possibly open a bunch of boards up to now a bunch of people that didn't know, but now do ???

the smart move is just disable and wait

Biker_GA 08-29-2011 09:25 PM

The problem is, we were told there was an "issue". That's it. What kind of issue? Copyright? Security? What?

I get an email saying there's an issue with a modification and it's been quarantined. Yeah. That tells me a whole lot. In truth, it tells me absolutely nothing at all.

nighteyes 08-29-2011 10:13 PM

Quote:

Originally Posted by Biker_GA (Post 2239633)
The problem is, we were told there was an "issue". That's it. What kind of issue? Copyright? Security? What?

I get an email saying there's an issue with a modification and it's been quarantined. Yeah. That tells me a whole lot. In truth, it tells me absolutely nothing at all.

Yes exactly. The email notice was useless.

I thought they may have been cryptic because the issue was something different to security this time. I'm pretty sure in the past these quarantine notices have always stated 'for security reasons' and that its advisable to disable the product until such a time that a fix is provided. I obviously don't expect them to publish details of the flaw(s). But just a couple of simple words would suffice in letting us know there are security risks in allowing the software to remain on our servers.


All times are GMT. The time now is 07:20 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01695 seconds
  • Memory Usage 1,738KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete