Activity Stream
48,167 MEMBERS
6682 ONLINE
besthostingforums On YouTube Subscribe to our Newsletter besthostingforums On Twitter besthostingforums On Facebook besthostingforums On facebook groups

Page 1 of 2 12 LastLast
Results 1 to 10 of 11
  1.     
    #1
    Super Member

    Default Redirection hack - turkish hackers exploiting vbulletin

    Okay, my host emailled me today assuring it was nothing to do with the host

    here is the fix:

    Just to help out other forums in need (our forum threads end up high in google, so someone else might stumble across it with the same issue we had).

    Vbulletin 3.54 and higher contains a html exploit. Malicious html code can be inserted in a thread title if the forum has not been patched with the following fix (note: Other versions haven't been tested yet).

    Open up newthread.php
    Find 'subject' => TYPE_STR,
    Replace it with
    'subject' => TYPE_NOHTML,

    Top X stats also seems to contain an issue allowing a similar exploit. It does not filter out html from thread titles.

    A fix can be found here.

    Note that no real harm can be done to your server when someone used the above exploit.




    source:


    http://www.c4dportal.com/forum/showthread.php?t=560
    Sp32 Reviewed by Sp32 on . Redirection hack - turkish hackers exploiting vbulletin Okay, my host emailled me today assuring it was nothing to do with the host here is the fix: Just to help out other forums in need (our forum threads end up high in google, so someone else might stumble across it with the same issue we had). Vbulletin 3.54 and higher contains a html exploit. Malicious html code can be inserted in a thread title if the forum has not been patched with the following fix (note: Other versions haven't been tested yet). Open up newthread.php Find Rating: 5

    So kiss me and smile for me, say that you'll wait for me <'3

  2.   Sponsored Links

  3.     
    #2
    Member
    Website's:
    ibymegaupload.com
    Thanks for sharing
    Inside of each man lives a muscle-bound ape who can lift mountains in the weight room, please a dozen women at a time, then sleep like a bear during its hibernation for 8 hours and be ready to do it all again the next day.

  4.     
    #3
    Banned
    Website's:
    hd-eroticpictures.com
    ipb > vb nuff said

  5.     
    #4
    Member
    kl ty.


  6.     
    #5
    Member
    Website's:
    WareztheDDL.com GTFO.ws
    dude... this is from 2006 lmao
    ' 09-06-2006, 05:07 PM'

    im pretty sure releases of vb since then have made sure this vulnerability does not happen.


  7.     
    #6
    Super Member
    Open up newthread.php
    Find 'subject' => TYPE_STR,
    Replace it with
    'subject' => TYPE_NOHTML,

    They still didn't change it to nohtml

    and its still happening, so might as well post it here :-)

    So kiss me and smile for me, say that you'll wait for me <'3

  8.     
    #7
    Member
    Website's:
    WareztheDDL.com GTFO.ws
    oh ok, if its still a vun, thanks sp


  9.     
    #8
    Banned
    hmm just noticed typing "&" in a title you get "&amp;" if you use this patch

  10.     
    #9
    Super Member
    yeah I noticed that today as well

    So kiss me and smile for me, say that you'll wait for me <'3

  11.     
    #10
    Banned
    hmm im lost

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. vBulletin 3 Login redirection page help
    By tractor3231 in forum vBulletin
    Replies: 2
    Last Post: 23rd Sep 2011, 05:29 AM
  2. Replies: 6
    Last Post: 20th Jun 2011, 05:50 PM
  3. Hackers start exploiting Patch Tuesday vulnerability
    By ShareShiz in forum News & Current Events
    Replies: 0
    Last Post: 19th Jun 2011, 05:55 PM
  4. about hide hack in Vbulletin
    By mastercho in forum vBulletin
    Replies: 7
    Last Post: 4th Mar 2011, 08:44 PM
  5. Redirection Hack:: Protect urself
    By deepakblr in forum Webmaster Discussion
    Replies: 2
    Last Post: 24th Sep 2009, 11:46 PM

Tags for this Thread

BE SOCIAL