Go Back   vb.org Archive > Community Central > vBulletin.org Site Feedback
FAQ Community Calendar Today's Posts Search

Closed Thread
 
Thread Tools Display Modes
  #1  
Old 06-29-2007, 03:54 PM
hambil's Avatar
hambil hambil is offline
 
Join Date: Jun 2004
Location: Seattle
Posts: 1,719
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default What happened to respect?

I thought the policy was to contact an author if a vulnerability was discovered in one of their hacks, and give them a reasonable amount of time to fix the issue before publicly flogging them. I believe the PM telling me about the issue was actually sent AFTER the hack was pulled and every user alerted via an update email. Gee, thanks.

It's a hack that's been around for a couple years, too. Still, I guess it just had to be removed INSTANTLY.
  #2  
Old 06-29-2007, 03:56 PM
Princeton's Avatar
Princeton Princeton is offline
 
Join Date: Nov 2001
Location: Vineland, NJ
Posts: 6,693
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It's nothing against the coder ... we just have to do with what's best for the community.
  #3  
Old 06-29-2007, 04:00 PM
hambil's Avatar
hambil hambil is offline
 
Join Date: Jun 2004
Location: Seattle
Posts: 1,719
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Princeton View Post
It's nothing against the coder ... we just have to do with what's best for the community.
Well let me know when you start doing that. I've been waiting for three years.
  #4  
Old 06-29-2007, 04:02 PM
nexialys
Guest
 
Posts: n/a
Default

for the best of the community, when a tool is having a bug, 99% of the time, people are reporting the bug in the thread related to the hack... then the author can fix the bug...

an insert or a exploit is a bug, so it have to be reported in the thread, contacting the author, and wait for a certain time for a result...

for the best of the community, if you really want to protect the members and the people using these codes, you'd be better test each release before they go public... but you don't... so give a chance to the coder first.
  #5  
Old 06-29-2007, 04:05 PM
RedTyger's Avatar
RedTyger RedTyger is offline
 
Join Date: Nov 2006
Location: UK
Posts: 1,310
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It's not what Jelsoft do for their own product, so I would say it's only fair that what's good for the goose is good for the gander.
  #6  
Old 06-29-2007, 04:07 PM
Princeton's Avatar
Princeton Princeton is offline
 
Join Date: Nov 2001
Location: Vineland, NJ
Posts: 6,693
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by hambil View Post
Well let me know when you start doing that. I've been waiting for three years.
if that was the case .. I have no idea why you're still here.

Quote:
Originally Posted by nexialys View Post
for the best of the community, when a tool is having a bug, 99% of the time, people are reporting the bug in the thread related to the hack... then the author can fix the bug...

an insert or a exploit is a bug, so it have to be reported in the thread, contacting the author, and wait for a certain time for a result...

for the best of the community, if you really want to protect the members and the people using these codes, you'd be better test each release before they go public... but you don't... so give a chance to the coder first.
if an exploit is found .. mod will be removed - no ands, ifs, or buts

coder is always contacted and they are free to fix .. once fixed, we will gladly return the mod to it's proper location
  #7  
Old 06-29-2007, 04:39 PM
hambil's Avatar
hambil hambil is offline
 
Join Date: Jun 2004
Location: Seattle
Posts: 1,719
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Princeton View Post
if that was the case .. I have no idea why you're still here.
That's a pretty good question, actually.
  #8  
Old 06-29-2007, 07:14 PM
Paul M's Avatar
Paul M Paul M is offline
 
Join Date: Sep 2004
Location: Nottingham, UK
Posts: 23,748
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

<a href="https://vborg.vbsupport.ru/info.php?do=security" target="_blank">https://vborg.vbsupport.ru/info.php?do=security</a>

SQL injections are always considered severe.

As for 'respect' - perhaps you need to review your posts in this thread. Sarcastic remarks are not generally considered very respectful.
  #9  
Old 06-29-2007, 07:53 PM
nexialys
Guest
 
Posts: n/a
Default

i think it is more frustration than missrespect from hambil... his age and experience make him easily iritated... LOL...
  #10  
Old 06-29-2007, 11:22 PM
hambil's Avatar
hambil hambil is offline
 
Join Date: Jun 2004
Location: Seattle
Posts: 1,719
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

My guess is a serious review of the hacks on this board would result in over half of them being taken down for security reasons. I have no issue with dealing seriously with a security issue, but over-reactions bother me. Not contacting the author giving them a chance to fix it. Moving the hack to the graveyard so the author can't even download it themselves (to insure the fix they are making is to the same files everyone else has downloaded - especially when the hack is two years old).

As I said, this issue has been in that code for two years. To my knowledge nobody has ever had a problem, and nobody has reported it in the hack thread. This doesn't mean it isn't serious and doesn't need to be urgently addressed, but come-on. Next time Jelsoft has a serious security issue can I expect my forum software to be immediately shut down without my consent or any pre-notification and not run again until Jelsoft fixes the issue?

Call it what you want, spin it however you want, this was a disrespectful and unnecessary act that can only make sense if you have a very exaggerated sense of self importance and your place in the world. My hack wasn't running the Mars lander, or keeping Nuclear missiles from launching, and neither is vb itself.
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 06:59 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04206 seconds
  • Memory Usage 2,250KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (4)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (8)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete