Welcome, Guest. Please login or register.

Author Topic: Vbulletin Bug ......  (Read 2030 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline BoudiccaTopic starter

  • Sr. Member
  • ****
  • Join Date: Jul 2002
  • Posts: 438
    • Show only replies by Boudicca
Vbulletin Bug ......
« on: July 22, 2010, 09:21:34 PM »
was Enterprise Vault (Its an Exchange Fail!), now its EMC Avamar, Dedupe for mostly everything including brain cells.
 

Offline Piru

  • \' union select name,pwd--
  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 6946
    • Show only replies by Piru
    • http://www.iki.fi/sintonen/
Re: Vbulletin Security Vulnerability
« Reply #1 on: July 23, 2010, 09:04:05 AM »
Quote from: Boudicca;571678
Vbulletin bug http://www.bbc.co.uk/news/technology-10714192
Luckily amiga.org is not affected (it isn't running the vulnerable version of the software).
 

Offline Karlos

  • Sockologist
  • Global Moderator
  • Hero Member
  • *****
  • Join Date: Nov 2002
  • Posts: 16879
  • Country: gb
  • Thanked: 5 times
    • Show only replies by Karlos
Re: Vbulletin Security Vulnerability
« Reply #2 on: July 23, 2010, 10:24:50 PM »
Quote from: Piru;571739
Luckily amiga.org is not affected (it isn't running the vulnerable version of the software).

The vbulletin support site actually provides an acid test to ensure the patch has been applied properly. Basically, the patch removes a sensitive item from the database and their test simply looks for it.

I took the liberty of investigating. It seems the item in question does not exist in 3.8.4 regardless, so hopefully you're right. We've had enough bother in recent weeks as it is.
int p; // A