Security issue

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Glock21
    Senior Member
    • Apr 2002
    • 311

    Security issue

    Any particular reason as to why someone was able to run a script that made 2,000 new users in about a minute, and was able to confirm all of the emails? Obviously they aren't all valid so there must be some kind of security bug within vBulletin...
  • LeeCHeSSS
    Senior Member
    • Jan 2002
    • 321

    #2
    Originally posted by Glock21
    Any particular reason as to why someone was able to run a script that made 2,000 new users in about a minute, and was able to confirm all of the emails? Obviously they aren't all valid so there must be some kind of security bug within vBulletin...
    Just recently I saw someone else with the same problem; so it is indeed worrying.

    Comment

    • Glock21
      Senior Member
      • Apr 2002
      • 311

      #3
      Yes, actually it just happened to a sister site also. I'm lucky I was able to see about 2,000 emails coming into my inbox literally and shut it off fast.

      Comment

      • Chen
        Senior Member
        • Jun 2001
        • 8388

        #4
        Originally posted by Glock21
        Yes, actually it just happened to a sister site also. I'm lucky I was able to see about 2,000 emails coming into my inbox literally and shut it off fast.
        What version of vBulletin are you running? Is debug mode on?
        Chen Avinadav
        Better to remain silent and be thought a fool than to speak out and remove all doubt.

        גם אני מאוכזב מסיקור תחרות לתור מוטור של NRG הרשת ע"י מעריב

        Comment

        • Glock21
          Senior Member
          • Apr 2002
          • 311

          #5
          2.2.9, and not that I'm aware.

          Comment

          • Glock21
            Senior Member
            • Apr 2002
            • 311

            #6
            They're trying to do it again to us, not that it really matters, but still highly annoying.

            Comment

            • Glock21
              Senior Member
              • Apr 2002
              • 311

              #7
              The program being used is called "s1te phuk" I believe.

              Comment

              widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
              Working...