PDA

View Full Version : Is VBulletin secure


Jap-Club
Sun 10th Sep '06, 7:38pm
Just been doing a search on here and read a few bad points, well not bad but people getting hacked!

What do you guys think. I am just a little concirned as I am no good with the html code and don't wanna be left stranded!

George

Zachery
Sun 10th Sep '06, 7:42pm
The stock vBulletin package is very secure, thats not to say we are perfect, but if there was a security issue with our software it would be patched. The people who have been having problems lately are running third party addons/modifications.

Jap-Club
Sun 10th Sep '06, 7:51pm
Thank you,

Do you do proggramming?

Zachery
Sun 10th Sep '06, 11:06pm
I'm not one of the vBulletin developers if thats what you are asking.

Mark.B
Mon 11th Sep '06, 4:30am
Just been doing a search on here and read a few bad points, well not bad but people getting hacked!

What do you guys think. I am just a little concirned as I am no good with the html code and don't wanna be left stranded!

George

Most of the recent problems have been caused by something called Flashchat, a general Chat program that can be integrated with vB. It is this, not vB, that was insecure.

There was also an issue with an add on called "Top X Stats" which allowed people to post page redirects which redirect users away from your site. Again this is not part of a stock vB instalation.

If you just install the standard, out of the box vBulletin you are not going to have any issues, as there are no known security exploits in it.

feldon23
Mon 11th Sep '06, 11:32am
vBulletin itself doesn't have any known security flaws at this point. Any security flaws that are discovered and found in the wild generally have an XML patch available within hours and it takes 30 seconds to patch/update.

It's really all the other scripts and add-ons you use. FlashChat wouldn't have been a problem if they'd followed best practices and only put the bridges for vBulletin instead of uploading the whole folder no matter which forum you use. Basic rule: Don't install a lot of unnecessary crap. ;)