Forum protection

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • flasher33
    Member
    • Oct 2006
    • 54

    Forum protection

    I am installing the 3.7.3 pl1 upgrade today and a question popped out in my head.

    As far as I know, there is vulnerability in 3.6.x series that was about the spacer_open and spacer_close in regards to installing new skins or self made ones.
    And you have to patch them manually or something like that.

    My question is, are they present with this installment??
    And how about the vulnerability in the global.php that you have to change the template name so that the attacker will be misled is it fixed?
  • Jake Bunce
    Senior Member
    • Dec 2000
    • 46598
    • 3.6.x

    #2
    I am not aware of either of those vulnerabilities. But you can ensure that your forum has the latest security updates by upgrading to the latest stable version (currently 3.7.3 PL1).

    Comment

    • flasher33
      Member
      • Oct 2006
      • 54

      #3
      well there are vulnerabilities in regards to the forum custom made styles where a redirect page code is injected in the SQL DB and also with the offical VB defult style.

      the maine issue is the spacer_open and spacer_close template. Are they protected or not?
      in regards to the 3.7.3 PL1 (functionality) it ok and till now there is no problem with it.

      Comment

      • Jake Bunce
        Senior Member
        • Dec 2000
        • 46598
        • 3.6.x

        #4
        I have never heard of any vulnerabilities relating to those template variables. 3.7.3 PL1 currently has no known security problems.

        Comment

        • clasione
          Member
          • Apr 2004
          • 47
          • 3.0.1

          #5
          My spacer_open table keeps getting hacked with an SQL injection.... I can never find any information on this but I am getting hacked over and over again... http://clasione.blogspot.com/2008/10...lestinian.html
          Long Island Exchange ® Inc. - Searchen Networks ® Inc.

          Comment

          • Jobe1986
            Senior Member
            • Jan 2007
            • 629
            • 4.2.x

            #6
            And I have my usual comment, if this accusation of it being a hole in vBulletin and NOT anything else is true, then why are only small sites getting hit, and not tha majority of vBulletin powered sites suchs as THIS one, my own and mnay thousands of others?
            http://data.collectiveirc.net/status/user/Jobe.png

            Comment

            • clasione
              Member
              • Apr 2004
              • 47
              • 3.0.1

              #7
              How about a recomendation for a solution Jobe.....
              Long Island Exchange ® Inc. - Searchen Networks ® Inc.

              Comment

              • flashgordon
                Senior Member
                • Sep 2006
                • 206
                • 3.5.x

                #8
                Originally posted by clasione
                How about a recomendation for a solution Jobe.....
                Check your server, clasione. You have a security hole, somewhere.

                Comment

                • clasione
                  Member
                  • Apr 2004
                  • 47
                  • 3.0.1

                  #9
                  I had Rackspace check the server and I disabled a function they thought woudl help tighted it up although it happened again.... they are suggesting that it is the software... I have thus found a solution by elliminating that template since it is the same exact one which keeps getting exploited... Hopefully this will enable them from using it...
                  Long Island Exchange ® Inc. - Searchen Networks ® Inc.

                  Comment

                  • flashgordon
                    Senior Member
                    • Sep 2006
                    • 206
                    • 3.5.x

                    #10
                    Originally posted by clasione
                    Hopefully this will enable them from using it...
                    Highly unlikely. If they repeatedly hacked your server, they will do it again.
                    Check the server logs or have your host check them.
                    Also check the server's temporary directories.

                    Comment

                    • clasione
                      Member
                      • Apr 2004
                      • 47
                      • 3.0.1

                      #11
                      I have checked a good number of things lately and the spacer_open template has been the single exploit point this far on multiple forums multiple times... I have disabled the template from being called. I'll know shortly if another entry point can be used. This has happened about 8 times already.
                      Long Island Exchange ® Inc. - Searchen Networks ® Inc.

                      Comment

                      • Jobe1986
                        Senior Member
                        • Jan 2007
                        • 629
                        • 4.2.x

                        #12
                        The next step would be to run the forum, fixed from the hack for a while, with NO plug-ins enabled, using
                        define('DISABLE_HOOKS', true);
                        in config.php
                        http://data.collectiveirc.net/status/user/Jobe.png

                        Comment

                        • clasione
                          Member
                          • Apr 2004
                          • 47
                          • 3.0.1

                          #13
                          Thanks for the advice... Both forums have plug-ins but neither share the same plug in... So I was thinking it is not a plug-in issue as one of them would not have had the vulnerable plugin for them to both get hacked the same way..... Atleast that was what I was thinking.
                          Long Island Exchange ® Inc. - Searchen Networks ® Inc.

                          Comment

                          • Simon Lloyd
                            Senior Member
                            • Apr 2008
                            • 610
                            • 3.7.x

                            #14
                            Are you sure you dont have a public ftp open on your server which allowing them to exploit your php files?
                            Kind regards,
                            Simon
                            Microsoft Office Discussion

                            Comment

                            widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                            Working...