+ Reply to Thread
Results 1 to 15 of 52
Page 1 of 4
FirstFirst 1 2 3 ... LastLast

Thread: Major Duplicable Security Hole: Is This a Bug?

  1. #1
    Senior Member jminiman is on a distinguished road
    Join Date
    Jul 2001
    Location
    Media, PA USA
    Age
    28
    Posts
    117

    Major Duplicable Security Hole: Is This a Bug?

    Hi all,

    I have brought this up in another thread (http://vbulletin.com/forum/showthrea...&postid=233687), but it looks like vBulletin has a really weird bug going on. Several of my moderators continue to get access to private forums that Moderator group members are locked out of. I keep changing their individual forum permissions to not access these private forums, but they spontaneously keep getting access to all private forums.

    Moderators are locked out of all of these forums, and all my moderators are now in the Moderator group (something that should be done by default--that's silly!). However, random moderators have access to all the private forums, and even after setting things straight, they spotaneously get access to all private forums when I add a new private forum.

    What the heck is going on? We seriously need to get to the bottom of this. This is a major security problem and should be treated seriously.
    Jared Miniman
    -------
    Editor In-Chief
    pocketnow.com -- it's all about portability...
    http://www.pocketnow.com

  2. #2
    Senior Member jminiman is on a distinguished road
    Join Date
    Jul 2001
    Location
    Media, PA USA
    Age
    28
    Posts
    117
    I don't mean to be rude, but shouldn't an issue like this get an immediate official response?
    Jared Miniman
    -------
    Editor In-Chief
    pocketnow.com -- it's all about portability...
    http://www.pocketnow.com

  3. #3
    Senior Member JamesUS is on a distinguished road
    Join Date
    Aug 2000
    Location
    London, England
    Posts
    4,625
    Can you please send your admin logon details to support@vbulletin.com and we will look into this for you
    James Ussher-Smith
    .:.: SideLinks - Make your directory work for you :.:.

  4. #4
    Senior Member jminiman is on a distinguished road
    Join Date
    Jul 2001
    Location
    Media, PA USA
    Age
    28
    Posts
    117
    Sent.
    Jared Miniman
    -------
    Editor In-Chief
    pocketnow.com -- it's all about portability...
    http://www.pocketnow.com

  5. #5
    Senior Member JamesUS is on a distinguished road
    Join Date
    Aug 2000
    Location
    London, England
    Posts
    4,625
    Thanks. I can't promise this will be looked into properly until tomorrow now - as it's quite late on a Sunday. If you don't receive anything today it will definitely be looked at first thing in the morning tomorrow though.
    James Ussher-Smith
    .:.: SideLinks - Make your directory work for you :.:.

  6. #6
    Former vBulletin Developer Scott MacVicar is on a distinguished road
    Join Date
    Dec 2000
    Location
    Reading, UK
    Posts
    13,335
    Blog Entries
    1
    do you have any hacks installed that affect access masks in any way?

    I've sat for about an hour now trying to re-create this problem on a unhacked board.
    Scott MacVicar

    My Blog | Twitter

  7. #7
    Senior Member jminiman is on a distinguished road
    Join Date
    Jul 2001
    Location
    Media, PA USA
    Age
    28
    Posts
    117
    Which files might affect access masks (so I can trace back my MANY installed hacks to the individual files)? All of my hacks have been well commented.
    Jared Miniman
    -------
    Editor In-Chief
    pocketnow.com -- it's all about portability...
    http://www.pocketnow.com

  8. #8
    Former vBulletin Developer Scott MacVicar is on a distinguished road
    Join Date
    Dec 2000
    Location
    Reading, UK
    Posts
    13,335
    Blog Entries
    1
    did you install one of my hacks called "Allow mods to edit access masks?"

    thats one that would definately cause this problem if the mods are misusing it, either that or you could have a corrupt admin

    The hacks could be in many files so I'd try and find as many of them as posibble.

    If you got them from vBulletin.org and clicked the Installed Hack button then it would list all the hacks you installed in your profile.
    Scott MacVicar

    My Blog | Twitter

  9. #9
    Senior Member jminiman is on a distinguished road
    Join Date
    Jul 2001
    Location
    Media, PA USA
    Age
    28
    Posts
    117
    Silly me--I never informed vB.org that I installed more than a few of the hacks. No, I didn't ever install the mod access hack, though.
    Jared Miniman
    -------
    Editor In-Chief
    pocketnow.com -- it's all about portability...
    http://www.pocketnow.com

  10. #10
    Senior Member jminiman is on a distinguished road
    Join Date
    Jul 2001
    Location
    Media, PA USA
    Age
    28
    Posts
    117
    I'm becoming less sure that this is a hack, because only certain mods exhibit this behavior--about 1/3 of them do. Is there any way to see if an individual user has corrupt access masks?
    Jared Miniman
    -------
    Editor In-Chief
    pocketnow.com -- it's all about portability...
    http://www.pocketnow.com

  11. #11
    Senior Member WizyWyg is on a distinguished road WizyWyg's Avatar
    Join Date
    Jul 2001
    Location
    Honolulu, HI
    Age
    35
    Posts
    1,310
    Revert your templates, upload original unhacked php files and see if anything happens that way

    I dont have any problems with any of my mods and even forums bigger than mines with 30+ mods aren't seeing this problem.

    If you have to you can install another instance of vbulletin on your server to test things out (no public access). And you can narrow it down to a problem

    1. double check your access masks for each user group
    2. double check your access masks on each forum. You could have inadvertently turned one on to custom settings.
    There are only 10 types of people in the world: Those who understand binary, and those who don't


  12. #12
    Senior Member jminiman is on a distinguished road
    Join Date
    Jul 2001
    Location
    Media, PA USA
    Age
    28
    Posts
    117
    Here are the PHP files I have edited:

    index.php, member.php, register.php, showthread.php, admin/forum.php, admin/email.php.

    Over 60% of my templates have been modified, but I can't imagine how these problems would have anything to do with templates--all of the template sets have the same access masks, so it wouldn't matter. I guess I could try reverting to the old PHP files, but I'd kinda prefer not to unless it's a last ditch effort. I have a number of hacks that I don't want to reinstall right now.
    Jared Miniman
    -------
    Editor In-Chief
    pocketnow.com -- it's all about portability...
    http://www.pocketnow.com

  13. #13
    Customer Support Manager Steve Machol is a name known to all Steve Machol is a name known to all Steve Machol is a name known to all Steve Machol is a name known to all Steve Machol is a name known to all Steve Machol is a name known to all Steve Machol's Avatar
    Join Date
    Jul 2000
    Location
    Jelsoft InterGalactic HQ
    Posts
    142,702
    Originally posted by jminiman
    I guess I could try reverting to the old PHP files, but I'd kinda prefer not to unless it's a last ditch effort. I have a number of hacks that I don't want to reinstall right now.
    However you have to understand that we can't really provide support on hacked installations. There are just too many unkown variables once a person has hacked their board.
    Steve Machol, vBulletin Customer Support Manager
    "Have Copy, Will Paste" (when appropriate)

    Please do not email or PM me for vBulletin support. I will be more than glad to answer your questions on the vB Forums and in the support system.

    Just remember that what happens in localhost, stays in localhost.


  14. #14
    Senior Member JamesUS is on a distinguished road
    Join Date
    Aug 2000
    Location
    London, England
    Posts
    4,625
    I will look at it when I get home today, but it is beginning to sound like it might be a hack problem. If someone can reproduce it on an unhacked board it would be useful though.
    James Ussher-Smith
    .:.: SideLinks - Make your directory work for you :.:.

  15. #15
    Senior Member WizyWyg is on a distinguished road WizyWyg's Avatar
    Join Date
    Jul 2001
    Location
    Honolulu, HI
    Age
    35
    Posts
    1,310
    Originally posted by jminiman
    Here are the PHP files I have edited:

    index.php, member.php, register.php, showthread.php, admin/forum.php, admin/email.php.

    Over 60% of my templates have been modified, but I can't imagine how these problems would have anything to do with templates--all of the template sets have the same access masks, so it wouldn't matter. I guess I could try reverting to the old PHP files, but I'd kinda prefer not to unless it's a last ditch effort. I have a number of hacks that I don't want to reinstall right now.
    again, you can install another instance of vbulletin for testing purposes that way you can narrow down the problem.

    Though it does definitely sound like one of your hacks messed up.

    You edited many of the "main" php files and it could be anything in them.
    There are only 10 types of people in the world: Those who understand binary, and those who don't


+ Reply to Thread
Page 1 of 4
FirstFirst 1 2 3 ... LastLast

Similar Threads

  1. Security hole in 2.2.8???
    By Rich_Z in forum vBulletin 2 'How Do I' and Troubleshooting
    Replies: 3
    Last Post: Sat 7th Dec '02, 3:13am
  2. Security HOLE!!!
    By toejam789 in forum vBulletin 2 'How Do I' and Troubleshooting
    Replies: 9
    Last Post: Mon 3rd Jun '02, 10:01pm
  3. Replies: 11
    Last Post: Wed 29th May '02, 7:30pm
  4. Major privacy hole in Windows/MSN Messenger
    By Joe Gronlund in forum Chit Chat
    Replies: 4
    Last Post: Wed 6th Feb '02, 6:08pm
  5. Major security bug
    By Funkie in forum vBulletin 2 'How Do I' and Troubleshooting
    Replies: 2
    Last Post: Mon 4th Jun '01, 7:58am

Bookmarks

Posting Permissions

Posting Permissions
  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts