The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Why did YAAS get quarentined?
I just got an email that Yet Another Awards System mod (https://vborg.vbsupport.ru/showthread.php?t=232684) was "quarentined". Why is that? I checked and didn't see anything in the thread about it.
|
#2
|
||||
|
||||
CypherSTL would be the best person to answer that. Perhaps its due to a security flaw found in the mod.
|
#3
|
|||
|
|||
Well would be lovely when a websites does something like this they give a reason why now we no shit and don't know whats wrong. It can be a couple of problems and we don't now the severity of it.
Next time if vb.org does this say in the email at least what for. |
#4
|
|||
|
|||
Quote:
|
#5
|
||||
|
||||
They are probably not telling because it would give a hacker a heads up on how to exploit the security issue with the hack. I am sure it will be fixed, it is a fantastic mod and the author is good.
I would like to know if it was with the recent update, I didn't apply it so I am assuming the previous version is safe. -Jason |
#6
|
|||
|
|||
Quote:
|
#7
|
|||
|
|||
Security by obscurity is not security, if there is something wrong most properly the hackers will know this long before us.
|
#8
|
||||
|
||||
Quote:
In this case it was probably noticed by the coder himeself or another. If a hacker had done anything to get noticed over this I am sure we would have heard about it on the site or from the affected site owner. -Jason |
#9
|
||||
|
||||
A security flaw was reported, and the mod quarantined as per our procedures.
The author has now updated the code and the mod has been restored. Case Closed. |
#10
|
|||
|
|||
Our policy on vulnerabilites can be found at Mod Exploit Guidelines
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|