(speculation) Site update warning

Currently reading:
(speculation) Site update warning

Lambie

¯\_(ツ)_/¯
Joined
Feb 15, 2016
Messages
163
Points
35
Location
Stuck in A414 traffic
Hi All.

Now this is speculation, since I can't directly see what version of vBulletin this forum uses (3.8.8 according to the js files, but could be cached). But I follow Troy Hunt, a security expert known for bringing together publically released dumps of stolen data to the site haveibeenpwned.com. This site lets you search to see if your details have been involved with a leak.

Recently a trend has been happening where outdated vBulletin boards are being targeted. So far from what I've seen on the interwebs, Versions 3.8.9, 3.8.10 beta, 4.2.3, 4.2.4 beta, and 5.2.3 are vulnerable to a type of attack that grants hackers access to the caches, and has reportedly been used to steal cached database data.

I see the website is currently at 3.8.8, which I think is deemed not vulnerable, so all is well right now. Just wanted to give the admins a heads up so the bad guys don't try punishing your awesome community. (y)

I may have posted this in the wrong place, if so I'm sorry about that!
 
Last edited:
Cheers buddy - we're not actually on 3.8.8 - but it's always good to know of any latest developments.

The vulnerability I think you are talking about was patched on August 1 and was related to redirecting via a malicious upload/url fetch.

And yes, that gave you full mysql access :eek:

No problem - just didn't want the site to go the way a lot of vBulletin sites are going right now!

Good to hear you guys keep up with the patches that go on, thanks for that! :D
 
Back
Top