Quote:
I've some friends using vBulletin and their site were attacked by some hackers, using some shells installed via files/images upload way.
|
this is impossible via vBulletin. for any image uploaded via vBulletin, the server reprocess the image via GD or ImageMagik (your choice), so if it's not a real image, it is rejected. it's not based on a filename, but the content of the file. impossible to cheat.
there will always have some hacker cracking a website. there will always have situations where it's the admin fault if something wrong occur. and when it's the software which is in cause, the guys at Jelsoft are making sure it wont happen again but updating their software with the fix.