can old disabled plugins be a security risk?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • sross
    Senior Member
    • Mar 2004
    • 660

    [Forum] can old disabled plugins be a security risk?

    Hi, just curious of the implications of old disabled plugins or products being a security risk. If the plugin has old files on the server can these files be used to compromise security? I have several old plugins that are disabled. I am hesitant to "uninstall" some products as this once crashed my database. So I am thinking the best move it to leave the products and plugins disabled but remove any files related to them in the filesystem. Is this advisable or a waste of time? Thanks
  • zascok
    Senior Member
    • Jul 2012
    • 205
    • 3.8.x

    #2
    could, would and probably will. Clean those things if not used. What was the plugin that crashed ? Is it one of those "Mark thread as ..." ? If so I can help do uninstall

    Comment

    • sross
      Senior Member
      • Mar 2004
      • 660

      #3
      the crash was a while ago and it put me off wanting to do anymore uninstalls. I'll definitely go through and clean out the filesystem though, and I guess instead of uninstall it is safest to just delete the old plugins from the plugins view? This way the database will not be touched and the plugin will be removed? Thanks

      Comment

      • zascok
        Senior Member
        • Jul 2012
        • 205
        • 3.8.x

        #4
        yeah remove the it from plugin view it will uninstall the product as well

        Comment

        • sross
          Senior Member
          • Mar 2004
          • 660

          #5
          thanks for the info, i am cleaning old stuff out as fast as i can but what is considered more of a risk? old plugin files in the file system or old plugins in the vbulletin forum plugins system?

          Comment

          • Hartmut
            Senior Member
            • Nov 2007
            • 2870
            • 4.2.x

            #6
            It's always nice to have cleaned up software thou... Disabled plugins and products can be a security risk it's not supported anymore and files of it are left on ftp. Disabled plugins not using any files should be no risk at all.
            No private support, only PM me when I ask for it. Support in the forums only.

            Comment

            • sross
              Senior Member
              • Mar 2004
              • 660

              #7
              so to clarify if for example i had 10 vulnerable plugins that used 80 files on ftp, and i deleted the 80 files but left the plugins disabled it should not be a risk? Thanks

              Comment

              • liamwli
                Senior Member
                • Feb 2012
                • 129
                • 4.2.X

                #8
                Originally posted by sross
                so to clarify if for example i had 10 vulnerable plugins that used 80 files on ftp, and i deleted the 80 files but left the plugins disabled it should not be a risk? Thanks
                Correct.

                Comment

                • soniceffect
                  Senior Member
                  • Feb 2005
                  • 938
                  • 4.2.X

                  #9
                  Originally posted by sross
                  so to clarify if for example i had 10 vulnerable plugins that used 80 files on ftp, and i deleted the 80 files but left the plugins disabled it should not be a risk? Thanks
                  That would depend on the security risk IMO. If these files can be accessed/run directly then they may well be a security risk. IMO if something is a vulnerable plugin, unless you know what exactly is vulnerable you should uninstall the plugin and remove all files related to it.

                  This said however, you should remove all files related to plugins that are no longer used as a matter of cause.
                  Husky Owners Forum - For all Siberian Husky Owners

                  Comment

                  • sross
                    Senior Member
                    • Mar 2004
                    • 660

                    #10
                    are .js files a risk? thanks for all the info guys

                    Comment

                    • Hartmut
                      Senior Member
                      • Nov 2007
                      • 2870
                      • 4.2.x

                      #11
                      Originally posted by sross
                      are .js files a risk? thanks for all the info guys
                      They could be, yes.
                      Originally posted by soniceffect
                      That would depend on the security risk IMO. If these files can be accessed/run directly then they may well be a security risk. IMO if something is a vulnerable plugin, unless you know what exactly is vulnerable you should uninstall the plugin and remove all files related to it.

                      This said however, you should remove all files related to plugins that are no longer used as a matter of cause.
                      Of coz that should be removed, but a disabled plugin doesnt effect the code as it's not using the hook of the specific file anymore. Where would you start an exploit then when there is no code for it left?
                      Originally posted by sross
                      so to clarify if for example i had 10 vulnerable plugins that used 80 files on ftp, and i deleted the 80 files but left the plugins disabled it should not be a risk? Thanks
                      That's correct.
                      No private support, only PM me when I ask for it. Support in the forums only.

                      Comment

                      widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                      Working...