Go Back   vb.org Archive > News and Announcements > vBulletin Pre-Sales Questions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 04-28-2014, 06:49 AM
andrew10 andrew10 is offline
 
Join Date: Apr 2014
Posts: 1
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Found a way to hack vBulletin, have sent email to support

Hi vBulletin,

I've found a way to hack vBulletin and have sent in a report to support@vbulletin.com.
I have yet to receive a response to even state that the email was received.

To put it bluntly this is the sort of attack which could be used to gain access to a forum and masquerade as the user, or worse obtain the users password and use it to hack other systems which that user uses with the same username / password combination.

It would be nice to receive an acknowledgement, whilst I won't use the hack, or tell others how to successfully exploit it, that's not to say there are not others out there who are not as trustworthy as me.

I'm not asking for any monetary compensation, all I'm asking is that the bug report is properly acknowledged and the risk is appropriately mitigated, since I myself frequent several forums powered by vBulletin.

I don't think this is too much to ask.

Andrew
Reply With Quote
  #2  
Old 04-28-2014, 08:30 AM
BirdOPrey5's Avatar
BirdOPrey5 BirdOPrey5 is offline
Senior Member
 
Join Date: Jun 2008
Location: New York
Posts: 10,610
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Whenever our system receives an email from an unknown source you get an email back with instructions you must follow to confirm you are human and not a spammer.

Until those instructions are completed we never get the email. Once we do receive the email you will receive another reply with the ticket number generated so you can reply/track the issue.

Please do not post details here- if you do did receive a ticket number please post that so I can look for your message, I don't immediately see it in our queue this morning.

I caution other people before panicking that more often than not exploits we get emailed about turn out to be with older versions of the software already patched or 3rd party modifications- but in the event it is an exploit with the current VB versions we work very hard to patch it as soon as possible and are very grateful to those that help us find such exploits.
Reply With Quote
Благодарность от:
TheLastSuperman
  #3  
Old 04-29-2014, 05:13 PM
Chris8's Avatar
Chris8 Chris8 is offline
 
Join Date: Nov 2009
Posts: 188
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

What vbulletin version is this about?
Reply With Quote
  #4  
Old 04-30-2014, 02:06 AM
Zachery's Avatar
Zachery Zachery is offline
 
Join Date: Jul 2002
Location: Ontario, Canada
Posts: 11,440
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I haven't seen any tickets from the email you used to register with.

Please feel free to cc me in on the next time you send it.

Zachery.woods@vbulletin.com
Reply With Quote
  #5  
Old 04-30-2014, 08:15 AM
BirdOPrey5's Avatar
BirdOPrey5 BirdOPrey5 is offline
Senior Member
 
Join Date: Jun 2008
Location: New York
Posts: 10,610
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Any off topic / sarcastic / useless posts will be infracted beyond this point. Not the place for it.
Reply With Quote
  #6  
Old 04-30-2014, 02:26 PM
cellarius's Avatar
cellarius cellarius is offline
 
Join Date: Aug 2005
Posts: 1,987
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by BirdOPrey5 View Post
Please do not post details here- if you do did receive a ticket number please post that so I can look for your message.
Ahm, wasn't the ticket id supposed to be confidential, because all that's needed to access a ticket is that id? Has that changed, or do I remember that wrongly?
Reply With Quote
  #7  
Old 04-30-2014, 04:05 PM
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Location: California/Idaho
Posts: 41,180
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by cellarius View Post
Ahm, wasn't the ticket id supposed to be confidential, because all that's needed to access a ticket is that id? Has that changed, or do I remember that wrongly?
You need the ticketid along with a randomly generated hash.
Reply With Quote
  #8  
Old 04-30-2014, 04:42 PM
Zachery's Avatar
Zachery Zachery is offline
 
Join Date: Jul 2002
Location: Ontario, Canada
Posts: 11,440
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by cellarius View Post
Ahm, wasn't the ticket id supposed to be confidential, because all that's needed to access a ticket is that id? Has that changed, or do I remember that wrongly?
As lynne pointed out, without the hash the ticketid is pretty useless.
Reply With Quote
  #9  
Old 04-30-2014, 05:31 PM
BirdOPrey5's Avatar
BirdOPrey5 BirdOPrey5 is offline
Senior Member
 
Join Date: Jun 2008
Location: New York
Posts: 10,610
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

And... Even if you did manage to figure out the random hash we hide sensitive data like passwords and personal details so that they aren't visible even with the hash.
Reply With Quote
  #10  
Old 05-01-2014, 08:05 AM
cellarius's Avatar
cellarius cellarius is offline
 
Join Date: Aug 2005
Posts: 1,987
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Ah, o.k., I stand corrected there. Thanks for clearing this up.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 01:05 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04462 seconds
  • Memory Usage 2,254KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (3)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (10)post_thanks_box
  • (1)post_thanks_box_bit
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete