The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#11
|
||||
|
||||
Yeah we went through this with another member yesterday, https://vborg.vbsupport.ru/showthread.php?t=301892
|
#12
|
|||
|
|||
a lot of vb clients don't even know he is on there forum as administrator. it's kinda sad that people despite of the warnings to remove there install directory still have that on there server(s).
|
Благодарность от: | ||
CAG CheechDogg |
#13
|
||||
|
||||
Well, it's kind of sad it took IB a week to send out security bulletins by mail. Not everyone checks their admincp or the announcement forum on vb.com every day (the latter can't even be subscribed, since that - surprise - does not work in vB5). It's probably not the fault of the support staff, but I imagine they need to get approval from the IB high command to send out such things.
|
#14
|
|||
|
|||
Despite who reads things on the announcements, it shouldn't matter. People are urged to delete install folders on their server after a successful install, therefore it's their own fault if they've been hacked. It does state that leaving precious files and folders on the server can cause people to "hack" or "attack" the forum.
|
#15
|
||||
|
||||
Quote:
You should at least get your facts straight before you tell people it's their own fault. |
7 благодарности(ей) от: | ||
adnedarn, blackberry, CAG CheechDogg, dawges, socialteenz, synseal, WildRover |
#16
|
|||
|
|||
Quote:
|
#17
|
||||
|
||||
Quote:
*Please note: Renaming it to /..install../ OR /old_install/ OR anything honestly is not doing you any good, delete the entire directory to be 100% sure you're not able to be exploited by that ftard . Any script kiddie can become famous, it only takes a tutorial on a supposed "hacker" site and someone without a life to spend time defacing your site or worse. Its your job as the site owner to stay up to par on vB announcements and current security issues. Before the exploit was "known" you had an excuse when hacked, now that we know one is present if leaving the /install/ folder up its silly to come online one morning to find your site defaced or worse when you could have prevented it by simply reading an announcement and taking action. Shoot I emailed a few old clients just to remind them about this, be sure if your running email filters and folders that you still check the folder for the announcement emails and eBulletin's from vBulletin as its easy to overlook mail when its not right in front of you inside your inbox . Edit: Also vBulletin did tell people to delete the entire /install/ folder, this was up letting everyone know of a possible exploit and what actions to take: http://www.vbulletin.com/forum/forum...-1-vbulletin-5 This was a completely unrelated exploit found and the announcement clearly states that, furthermore it also states to delete the /install/ directory near the bottom: http://www.vbulletin.com/forum/forum...d-all-versions So I'm not sure who was telling people to delete just install.php but it was not vBulletin themselves unless I'm missing something entirely and my wife says I do that from time-to-time laugh at me not with me on that one . |
#18
|
|||
|
|||
Quote:
This all changed last week, now we MUST DELETE THE INSTALL DIRECTORY ! |
2 благодарности(ей) от: | ||
cellarius, TheLastSuperman |
#19
|
||||
|
||||
Ahh now I see what you and others meant by that. Although for years this exploit may not have been present, it could be related to recent code changes/inclusions we still do not know the specifics however we do know that from here on out you delete the /install/ directory after installation.
|
2 благодарности(ей) от: | ||
blackberry, CAG CheechDogg |
#20
|
|||
|
|||
Would it be enough to just rename it?
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|