Go Back   vb.org Archive > Community Central > vBulletin.org Site Feedback
FAQ Community Calendar Today's Posts Search

Closed Thread
 
Thread Tools Display Modes
  #141  
Old 07-27-2007, 10:36 AM
MaryTheG(r)eek MaryTheG(r)eek is offline
 
Join Date: Sep 2006
Location: Greece
Posts: 1,340
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Zachery View Post
How do you figure someone who reviewed your code from our site is breaking copyright laws?
First of all someone who reviewed my code (or revied anything, not only code) is not only breaking copyright laws. He is breaking the law about reviews, which is saying that to perform a review (in anything) and to post somewhere the results of this review is prohibited without the written permission of the author (in case for code) or the owner (in case of a product).

Make a simple google search for "reporting vulnerabilities" and you'll find it as many other useful information. Among the others (there are real examples there) the Reporter (who can never been anonymus) must give details like:
  • Why he decided to make the review
  • Why he choosen especially this software (if its about code)
  • To prove that he founds only this vulnerability and that he hasn't hide in the past vulnerabilities that he found and didn't reported.
  #142  
Old 07-27-2007, 10:40 AM
Dismounted's Avatar
Dismounted Dismounted is offline
 
Join Date: Jun 2005
Location: Melbourne, Australia
Posts: 15,047
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by AScherff View Post
as a Member or User:

i wish to be informed of a vulnerabilty... please

and also i wish a little more information about the vulnerabilty:

will it destroy the Server ?
will it destroy the database ?
will it destroy then vBulletin ?
will it destroy the mod ?
will it ..... ?


or ist there only a theoretical chance that some one can inject or whatever

without showing the real vulnerability.


So i have a better chance to deside to deactivate, deinstall, or close my whole system

thanks

Alfred
We will NEVER send out details of any vulnerability as this can cause people to abuse that information and exploit it.
  #143  
Old 07-27-2007, 10:44 AM
MaryTheG(r)eek MaryTheG(r)eek is offline
 
Join Date: Sep 2006
Location: Greece
Posts: 1,340
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Just a random article as an example:
http://www.cerias.purdue.edu/weblogs...s-law/post-38/
  #144  
Old 07-27-2007, 11:36 AM
Paul M's Avatar
Paul M Paul M is offline
 
Join Date: Sep 2004
Location: Nottingham, UK
Posts: 23,748
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by MicroHellas View Post
First of all someone who reviewed my code (or revied anything, not only code) is not only breaking copyright laws. He is breaking the law about reviews, which is saying that to perform a review (in anything) and to post somewhere the results of this review is prohibited without the written permission of the author (in case for code) or the owner (in case of a product).
You released the modification here (to the public) for anyone to download. Therefore anyone can look at it and find any exploits it may have. No laws are broken doing this. Copyright laws are about stopping people from copying code and releasing it as their own (hence their name).

As for reviews - please show us this "review" law you refer to, becasue there is no such thing I know of (apart from which no review has been published anyway).
  #145  
Old 07-27-2007, 11:42 AM
MaryTheG(r)eek MaryTheG(r)eek is offline
 
Join Date: Sep 2006
Location: Greece
Posts: 1,340
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Paul M View Post
You released the modification here (to the public) for anyone to download.
to download for use.. For nothing more....

Quote:
Originally Posted by Paul M View Post
As for reviews - please show us this "review" law you refer to, becasue there is no such thing I know of (apart from which no review has been published anyway).
I wrote it above. Actually is the perfect example for this topic. Also don't forget to follow the links in article's body. There are much more interesting facts to read there.
  #146  
Old 07-27-2007, 12:01 PM
AScherff AScherff is offline
 
Join Date: May 2007
Location: Frankfurt / Germany
Posts: 33
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Dismounted View Post
We will NEVER send out details of any vulnerability as this can cause people to abuse that information and exploit it.
Thanks, and the affected is standing in the rain.

So, if a vulnerability of an mod is reported and i receive a e-mail to deinstall the mod,
my decision must be, to deinstall the whole vBulletin itself ! Because i do not know and can not decide if the vulnerability of the mod also breaks (or has broken) a leak in vBulletin itself

So, if you are not willing to give any (also low) detail to vulnerability of a modification - so as a part of informing the customers i appreciate to hear a loud and clear opinion that after deinstalling the mod (or what ever is to do) it has no harm to vBulletin and the system itself.

Thats only a point of view from a customer...
  #147  
Old 07-27-2007, 12:04 PM
hambil's Avatar
hambil hambil is offline
 
Join Date: Jun 2004
Location: Seattle
Posts: 1,719
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by MicroHellas View Post
to download for use.. For nothing more....



I wrote it above. Actually is the perfect example for this topic. Also don't forget to follow the links in article's body. There are much more interesting facts to read there.
That's someone's blog, not a law.
  #148  
Old 07-27-2007, 12:15 PM
MaryTheG(r)eek MaryTheG(r)eek is offline
 
Join Date: Sep 2006
Location: Greece
Posts: 1,340
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by hambil View Post
That's someone's blog, not a law.
Finally it became a word's game. I wrote to follow the links. Especially one links to a newspaper. Read the article from the news.
  #149  
Old 07-27-2007, 12:18 PM
hambil's Avatar
hambil hambil is offline
 
Join Date: Jun 2004
Location: Seattle
Posts: 1,719
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by MicroHellas View Post
Finally it became a word's game. I wrote to follow the links. Especially one links to a newspaper. Read the article from the news.
I'm not trying to play word games. That would be especially pointless since English isn't your first language, and we'd only end up misunderstanding each other even worse. I'm just trying to understand where you are coming from, and what you want to accomplish here. You're angry, I get that (I'm obviously occasionally hot headed myself). But we seemed to have moved past anger into other more confusing things.
  #150  
Old 07-27-2007, 03:00 PM
Paul M's Avatar
Paul M Paul M is offline
 
Join Date: Sep 2004
Location: Nottingham, UK
Posts: 23,748
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by MicroHellas View Post
to download for use.. For nothing more....
If you allow it to be downloaded, and it's visible source, then people can read it. This is not against copyright law (or any other law).
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 09:25 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04801 seconds
  • Memory Usage 2,265KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (10)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (3)pagenav_pagelink
  • (1)pagenav_pagelinkrel
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete