PDA

View Full Version : Board Security


wolfy834
Mon 11th Jul '05, 3:29pm
A few days ago my website's forums, running Invision Board 1.3.1, were hacked into. The hacker used SQL injection to delete me and give himself administration rights. From there he went and messed a bunch of other things as well.

I would like to make the move to vBulletin, but I really cannot afford another problem like this, and would like to ask if there is any possibility that someone could do this through this software?

I know vB (and the newer IPB version, although less credible) is a lot more secure, but I just need to be 100% sure that something like this just isn't exploitable before I go and purchase. Also, will you take any responsibility if the forums are hacked through SQL injection (if the software is up-to-date, etc. as well)?

Colin F
Mon 11th Jul '05, 3:34pm
vBulletin doesn't have any known security issues to date. If security issues are found, the developers usually try to post a fix within 24 hours.
So, if you keep your software up to date, you shouldn't have any problems.

I don't think Jelsoft will take any responsibility though.

Steve Machol
Mon 11th Jul '05, 3:44pm
In all fairness to IPB, it's imperative to keep your versions up-to-date since it's not uncommon to have security holes in older versions that have been fixed in the latest version.