vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Community Lounge (https://vborg.vbsupport.ru/forumdisplay.php?f=13)
-   -   PM How Secure ? (https://vborg.vbsupport.ru/showthread.php?t=33838)

01-05-2002 10:06 PM

A user at a site that uses VB 2.2.1 claims that he was able to acess other users's PMs. He is neither a computer professional nor hacker. Apparently he was able to do this from message links sent from the Bulletin Board to his email. This user is a reliable source and I believe his story to be true.

My question is - if true how is this possible ? Could this be due to some flaw in the the way the board was set up or some other bug in Vbulletin ?

Appreciate any help/comments. I am not a geek and some of my members are really concerned about these rumours.

Steve Machol 01-05-2002 10:48 PM

I don't belive this is possible and I've never seen this problem proven to be true. If this source is so reliable then simply ask him how he did it.

01-05-2002 11:07 PM

Just got an email from that user, he swears he was able read the
PMs from the links sent to his hotmail and adds:

"if the links have the password embedded in them then anyone can access them [ PMs ] which is what happened. "

As the board in affected was not mine, I will try to get more details but thanks a lot for responding.

Steve Machol 01-05-2002 11:33 PM

Links in vB don't have the password embedded in them. Your user is mistaken.

Steve Machol 01-06-2002 12:03 AM

Just out of curiousity, why are you still running vB 2.0 RC3? This version is very insecure and terribly out of date.

01-06-2002 12:19 AM

Thanks. That's the version that we were sent when we purchased the Vbulletin licence about 5 months ago. As you have probably figured out, I'm no Webmaster, just the site owner. My Webmaster didn't seem to think there was any rush to upgrade but now that you tell me this, I will ask him to upgrade to 2.2.1 asap. Thanks again.


All times are GMT. The time now is 10:06 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.00947 seconds
  • Memory Usage 1,709KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (6)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete