vBulletin Security Patch for vB 4.1.4 and vB 3.8.7 : Low Risk "phishing" patch

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • IBxAnders
    Senior Member
    • Aug 2001
    • 1172
    • 4.0.x

    vBulletin Security Patch for vB 4.1.4 and vB 3.8.7 : Low Risk "phishing" patch

    Announcement and Instructions:

    Earlier last month the vBulletin team was notified of an indirect, low-risk security exploit vector that could potentially be used to maliciously trick users into providing account sensitive information to non-authorized parties. Please see the original notice for more information: https://www.vbulletin.com/forum/show...hishing-Vector

    While the security risk is low, we have taken the report very seriously and incorporated additional security functionality into the vBulletin product to safeguard your site and prevent any attempts at malicious phishing activity.

    After successful installation of the patch, no configuration or activation will be required and the new security check will work automatically to prevent malicious redirection.

    Patched Versions:
    • vBulletin 3.8.7 (download from members area)
    • vBulletin 3.8.7 with Mobile API (download from members area)
    • vBulletin 4.1.4 (download from members area)


    Important Patch Installation Notes:
    • Please check and make sure you are downloading and installing the correct patch.
    • Important; that if you are using vBulletin 3.8.7 with Mobile API product you need the special “vBulletin 3.8.7 MAPI Patch”.
    • Optional: This patch requires you to execute the upgrade process in order to install the additional security features.
    • As always, It is recommended to have a full database backup of your site prior to upgrading.


    Patch Installation Instructions:


    Please note (for Advanced Users Only): These settings and configuration will not affect most vBulletin users. If you have created a custom domain configuration, you can define a domain “whitelist” in your Admin Control Panel. Go to AdminCP -> Settings -> Options -> Site Name / URL / Contact Details -> “Redirect Domain Whitelist”.
    Last edited by Steve Machol; Mon 11 Jul '11, 5:04pm.
    anders | vbulletin team | check out the new vbulletin facebook app
    Proudly vBulletin'ing since 2001
    Please be my friend!
    http://www.twitter.com/inetskunkworks
    vBulletin Performance Articles:
    Click here to read

Related Topics

Collapse

Working...