The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
So if flashchat 4.7.2 now secure?
I got hacked with an old release and left the un-needed CMS files in my flashchat directory. Is it now safe? Will it ever be? Seems that the flashchat boards are now down too.
My users are screaming for a secure chat room. |
#2
|
|||
|
|||
just remove the unused CMS files - problem solved.
|
#3
|
||||
|
||||
Nothing is ever 100% secure, including vbulletin, and 3rd party add-ons (a hole in two top statistics mods was exploited the other week as well) - the important thing is when someone discovers a hole and exploits it, does it get fixed - in the case of VB, Flashchat (and the stats programs) the answer is/was yes.
JFYI, The insecure Flashchat CMS file(s) were fixed in 4.70 (or 4.62, can't remember which now). I believe their forums being down was/is some sort of hosting issue, the main site was restored from a backup taken last week. |
#4
|
|||
|
|||
Has anyone been running with the upgraded flashchat and the removed CMS files for any length of time without being hacked again?
|
#5
|
||||
|
||||
Quote:
A year and a half ago - when I first noticed flashchat, I naively praised it, but after reinstalling it a half-dozen times because of exploits, I have permanently suspended using it. The last two times my site was defaced, it was due to a flashchat exploit being "exploited," if you will. (I also wasn't using the latest-and-greatest either - therefore I share part of the responsibility for the defacement for failure to fix the exploit). They may eventually make it bug free and more power to them, but my personal view is that I will not use it - I can't afford that chance. Twice down is enough for me. Flashchat does get fixed, and it has been. Sometimes improvements to the core create instability; sometimes improvements to the other areas cause vulnerabilities. It happens. The important thing is to recognize that things do happen and fixes need to be made. |
#6
|
|||
|
|||
Quote:
|
Thread Tools | |
Display Modes | |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|