Today's Posts Follow Us On Twitter! TFL Members on Twitter  
Forum search: Advanced Search  
Navigation
Marketplace
  Members Login:
Lost password?
  Forum Statistics:
Forum Members: 24,254
Total Threads: 80,792
Total Posts: 566,471
There are 561 users currently browsing (tf).
 
  Our Partners:
 
  TalkFreelance     TalkFreelance Information     Suggestions and Feedback :

3.6.5

Thread title: 3.6.5
Closed Thread    
    Thread tools Search this thread Display Modes  
03-31-2007, 04:05 AM
#1
Vizon is offline Vizon - Click for my Image
Status: R'tard
Join date: Jan 2007
Location: USA
Expertise:
Software:
 
Posts: 2,959
iTrader: 21 / 100%
 

Vizon is an unknown quantity at this point

  Old  3.6.5

vBulletin had an update, due to a HUGE security issue with moderators or something. Check up on that guys

03-31-2007, 04:17 AM
#2
Village Genius is offline Village Genius
Village Genius's Avatar
Status: Geek
Join date: Apr 2006
Location: Denver, CO
Expertise: Software
Software: Chrome, Notepad++
 
Posts: 6,894
iTrader: 18 / 100%
 

Village Genius will become famous soon enough

  Old

the security issues circumstances where near impossible to do, IIRC they had to have the same IP as an admin in the panel.

03-31-2007, 04:44 AM
#3
Vizon is offline Vizon - Click for my Image
Status: R'tard
Join date: Jan 2007
Location: USA
Expertise:
Software:
 
Posts: 2,959
iTrader: 21 / 100%
 

Vizon is an unknown quantity at this point

  Old

Well I read up on it in my vB and didn't see that?

03-31-2007, 07:59 AM
#4
vitalize is offline vitalize
Status: Member
Join date: May 2006
Location: Australia
Expertise:
Software:
 
Posts: 413
iTrader: 7 / 100%
 

vitalize is on a distinguished road

  Old

"and in order to exploit the problem a number of highly unlikely circumstances must exist simultaneously."

Doesn't sound like a big deal weather people upgrade or not.

03-31-2007, 12:44 PM
#5
sketchie is offline sketchie
sketchie's Avatar
Status: Senior Member
Join date: Jul 2005
Location:
Expertise:
Software:
 
Posts: 835
iTrader: 1 / 100%
 

sketchie is on a distinguished road

  Old

3.6.5 has been out for a while now, the post on vBulletins website was made on 1st March...


It is worth noting that in order to exploit the problem highlighted by the report, the attacking user must satisfy the following conditions:
Must already have moderator privileges
Must share the same IP address (or the number of IP octets specified in the Admin Control Panel for IP address matching) with an existing administrator who is currently logged in to the Admin Control Panel
Must know the Alt-IP and user agent (exact browser identification) of the administrator
OR must know the license number of the site being attacked

04-01-2007, 08:58 AM
#6
Matsta is offline Matsta
Matsta's Avatar
Status: Insert Rave Here
Join date: Dec 2006
Location: Auckland, NZ
Expertise:
Software:
 
Posts: 1,426
iTrader: 3 / 100%
 

Matsta is on a distinguished road

Send a message via AIM to Matsta Send a message via MSN to Matsta

  Old

Hmm big forums never update lol, i dont think were goin to get hacked

04-01-2007, 03:45 PM
#7
Freddy is offline Freddy
Status: Junior Member
Join date: Mar 2007
Location: Norway
Expertise:
Software:
 
Posts: 63
iTrader: 2 / 100%
 

Freddy is on a distinguished road

Send a message via MSN to Freddy

  Old

But its the big forums people like to hack?

The big forums do get hacked eventually!

trust me, i now

Freddy

04-01-2007, 04:12 PM
#8
crazyryan is offline crazyryan
Status: I love this place
Join date: May 2006
Location:
Expertise:
Software:
 
Posts: 603
iTrader: 6 / 100%
 

crazyryan is an unknown quantity at this point

  Old

It's the big forums who realise taking backups daily is a good idea.

04-01-2007, 04:19 PM
#9
Freddy is offline Freddy
Status: Junior Member
Join date: Mar 2007
Location: Norway
Expertise:
Software:
 
Posts: 63
iTrader: 2 / 100%
 

Freddy is on a distinguished road

Send a message via MSN to Freddy

  Old

So true so true...

But, people should upgrade their versions even they fell secure enough with their current version. And that they feel secure when they take backup ever day.. But its never fun having their own forums down for several hours because some idiot of an hacker wanted some fun!

Get me?

Freddy!

04-01-2007, 05:49 PM
#10
KewL is offline KewL
Status: OG
Join date: Apr 2006
Location: California
Expertise: Design, Music, Xhtml, Css
Software: Photoshop, Coda, FL Studio
 
Posts: 2,007
iTrader: 11 / 100%
 

KewL is an unknown quantity at this point

  Old

The next update ant until 5.6.7 guys.

Closed Thread    


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

  Posting Rules  
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump:
 
  Contains New Posts Forum Contains New Posts   Contains No New Posts Forum Contains No New Posts   A Closed Forum Forum is Closed