View Single Post
  #9  
Old 11-07-2013, 04:41 PM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Digital Jedi View Post
To that point, I think all the hacking that's been going on lately has been a little misleading. It's a mistake to think something's more secure only because it hasn't been hacked a lot lately. vB3 probably has more security vulnerabilities than vB4. It's unsupported, older software that is no longer being patched or developed. That, in of itself, is going to be one of the problems admin experience in the coming years. But it's not a popular target. There are still fewer vB3 boards out than the combined vB4 and 5 boards. Their going to look for the more common vulnerability. The one that will get them into the most sites. The one that will do the most damage. (Which is why WordPress and Joomla are the most hacked scripts out there right now.) vB3 just isn't interesting right now to them, but that doesn't mean it's more secure. Logically, nothing is more secure once development stops. Liken it to anyone trying to use Netscape to browse the web today. You probably won't run into a lot of people targeting Netscape. But you'd be taking a huge risk using it as your main browser. vB3 is not to that point yet. But it will be. And in not too short a time.
But first and foremost, the one which is easiest.

Problem with your missive is, before v4 when v3 was king... It was a rare thing even then to see a v3 site defaced/hacked. It's simply, inherently, more secure than v4.

Side note: I've had a Joomla installation online for almost ten years now, never upgraded it or anything - and it hasn't been touched. It is fronting a v3 installation that's been there for the same amount of time, nothing's happened. I think that one is still a 3.5.4 or some such.

For the script kiddie (which is 99% of this "hacking" that goes on) easy access and vulnerability is key. These aren't actual, black hat hackers here - these are goofs looking for "street cred" and any site will do.

The actual, black hat hacker won't be stopped no matter your security.
Reply With Quote
 
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01418 seconds
  • Memory Usage 1,768KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD_SHOWPOST
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_quote
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_box
  • (1)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit_info
  • (1)postbit
  • (1)postbit_onlinestatus
  • (1)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • reputationlevel
  • showthread
Included Files:
  • ./showpost.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showpost_start
  • bbcode_fetch_tags
  • bbcode_create
  • postbit_factory
  • showpost_post
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • showpost_complete