Go Back   vb.org Archive > Community Central > vBulletin.org Site Feedback
FAQ Community Calendar Today's Posts Search

Closed Thread
 
Thread Tools Display Modes
  #1  
Old 07-24-2007, 05:00 AM
Clayton Clayton is offline
 
Join Date: Nov 2004
Posts: 216
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Sending of Hacks to the Graveyard

Hi there, has there been a sudden surge of attacks that a number of hacks have been sent to the graveyard, please?

this is the notice in the email

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
This modification currently contains a vulnerability. It is recommended you uninstall it until further notice.
- vBulletin.org Staff
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

this reason has been given for a number of hacks
is there a place where we can get further feedback on this, because certain hacks are an integral part of the various sites that have these hacks, please?

Thank you in advance
  #2  
Old 07-24-2007, 05:12 AM
AScherff AScherff is offline
 
Join Date: May 2007
Location: Frankfurt / Germany
Posts: 33
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yes please - the same...

can not find a reason nor solution than uninstall...
  #3  
Old 07-24-2007, 05:14 AM
da420 da420 is offline
 
Join Date: Nov 2005
Posts: 1,232
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by AScherff View Post
Yes please - the same...

can not find a reason nor solution than uninstall...
My suggestion if it's something you need on your forum either wait for the author to update it fixing the vulnerability, fix it yourself, or hire someone to fix it.
  #4  
Old 07-24-2007, 05:31 AM
Clayton Clayton is offline
 
Join Date: Nov 2004
Posts: 216
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

If we could have a little further feedback regarding the problems, such as the attacks that these hacks have been receiving, then we know a little more.

currently it seems as though this has been a blanket reason/approach given for a number of hacks, is this true?

is it a coincidence that this has taken pace, after

1 .. Jelsoft takeover and 2. new sheriffs in town ?

As a user of a number of hacks on a number of forums developed, it would be appreciated that an impression is not being created that the vulnerabilities have occurred due to the 2 points mentioned and questioned above

whereas we may not want to publicly display the vulnerabilities etc, it would also go a long way in reassuring users that what has taken place is not because of over zealous new Mods etc?

or so as not to start a conspiracy theory .. that this is not a policy to prepare users for the new Add-ons that vbulletin.com will be releasing in the future, so kill off any opposition in good old Microsoft style. This is not the case, right?

in mentioning this you can see our concern as users
  #5  
Old 07-24-2007, 07:26 AM
Marco van Herwaarden Marco van Herwaarden is offline
 
Join Date: Jul 2004
Posts: 25,415
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

No, we will not be giving out the details of the exploit to anyone other then the author of the modification. This is to protect those that still have such a modification installed.

Your insinuations really don't make sense. Because Jelsoft was acquired and we have a few new staff members, there suddenly are vulnerable modifications?? Either a modification is vulnerable or not, no company take-over or new staff can change that.

There have been a large number of (valid) reports by members on vulnerable modifications lately, once reported staff will investigate and if correct take actions. That is all that is to it.
  #6  
Old 07-24-2007, 07:29 AM
MaryTheG(r)eek MaryTheG(r)eek is offline
 
Join Date: Sep 2006
Location: Greece
Posts: 1,340
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Just some questions to Moderators:
  1. I bought my first vB licence at Oct 2003. Since then, there are lots of patches for vulnerabilities in vBulletin itself. Why I never got a similar type of email saying "....uninstall vBulletin till future notice"? And why I never informed as client at the time that the vulnerability found, but only when you had ready the patch?
  2. Do you count as fair to inform members (now I'm talking for mods) who have installed it by email (faster) and the author by ...PM?? What should happen if the author has to visit your site for days?
That's for the history. Could you please remove my other mods too?

Thank you
Maria Avlatzi
Loutron 41
57200 Lagadas
Tel +30-23940-20117
Greece
Just to avoid sayings that I'm talking in anonymous mode.
  #7  
Old 07-24-2007, 07:37 AM
Clayton Clayton is offline
 
Join Date: Nov 2004
Posts: 216
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Hi Marco

this is certainly not a case of insinuations, it has a great deal to do with someone using a product which is related to work and clients. This is not a game for some of us but a livelihood

when all of a sudden certain things start occurring we as users of hacks need to be a reassured that what is taking place does not coincide with the 2 points mentioned, maybe I should have placed question marks (will edit post) as then it is a question and will not be seen as an insinuation which obviously has negative connotations attached to it

Thank you
  #8  
Old 07-24-2007, 07:41 AM
MaryTheG(r)eek MaryTheG(r)eek is offline
 
Join Date: Sep 2006
Location: Greece
Posts: 1,340
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Clayton View Post
Hi Marco

this is certainly not a case of insinuations, it has a great deal to do with someone using a product which is related to work and clients. This is not a game for some of us but a livelihood

when all of a sudden certain things start occurring we as users of hacks need to be a reassured that what is taking place does not coincide with the 2 points mentioned, maybe I should have placed question marks (will edit post) as then it is a question and will not be seen as an insinuation which obviously has negative connotations attached to it

Thank you
I think that I've put questionmarks. Also at the top I'm talking about "questions". Or I misunderstood you post??
  #9  
Old 07-24-2007, 07:47 AM
Clayton Clayton is offline
 
Join Date: Nov 2004
Posts: 216
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yes, these are concerned questions put to the community and vBulletin.org

I have seen the forums go through many swings and changes over the years
  #10  
Old 07-24-2007, 07:57 AM
Marco van Herwaarden Marco van Herwaarden is offline
 
Join Date: Jul 2004
Posts: 25,415
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

@MicroHellas

1. vB.org staff does not have control over the procedures used when a vulnerability is found in vBulletin itself. If you want to discuss the Jelsoft procedures, then please post it as a suggestion at vbulletin.com.

2. With our current procedures we will inform both the users that have installed a modification and the author at the same time if the vulnerability found is serious. The reason members are notified by email and the author by PM is merely using the tools we have available. The author is also informed on the details of the vulnerability found. We have no way of knowing if an author will read his email faster then a PM, and he/she could have email notifications of a PM. Also the author could have disabled Email as contact method, so the best way to contact them (that will always work) is by PM.

We are however at this time prepairing new procedures making it easier to communicate with the author when a vulnerability is found.

Also please note the even though we are a community that is build upon the input of many coders, if a vulnerability is found our primary goal is to protect the members.
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 05:47 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04067 seconds
  • Memory Usage 2,257KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)pagenav_pagelinkrel
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete