I run a gaming site, pretty much overrun by stupidity.
Haha! Boy does that ever ring true for gaming forums.
Quote:
Originally Posted by SirAdrian
Considering this is a business site, and not really a public discussion board, they have a public image to maintain. Having hacks here with security holes could hurt thousands of customers, so they treat it with the highest priority to 1) remove the hack, and 2) notify the customers at risk. 3) is a lower priority, and that's notifying the creator of the hack for it to be dealt with.
Normally I wouldn't put my oar in, a person's forum is their own and they can run it how they like. But since this appears to be open for discussion I'll expand on what I said in the locked thread.
vBulletin.org when finding a vulnerability:
- instantly remove the software
- notify all the customers and then allow the author to organise a fix and issue an update to the software
- when it's done the software back in circulation. It could be done at any speed so I can't comment.
vBulletin.com when finding a vulnerability:
- Do Jelsoft remove the vulnerable versions until a fix is released? I don't know.
- organise a fix and issue an update to the software, usually within a day or so
- notify all the customers when it's done, anywhere between instantly via an announcement and the AdminCP message to several days via email.