Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - v-bulletin sites hacked
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

v-bulletin sites hacked

 Post Reply Post Reply
Author
alabamatoy View Drop Down
Groupie
Groupie


Joined: 04 February 2006
Location: United States
Status: Offline
Points: 143
Post Options Post Options   Thanks (0) Thanks(0)   Quote alabamatoy Quote  Post ReplyReply Direct Link To This Post Topic: v-bulletin sites hacked
    Posted: 15 October 2013 at 1:27am
http://krebsonsecurity.com/2013/10/thousands-of-sites-hacked-via-vbulletin-hole/

Slightly off topic, but related.  Apologies if this is not in keeping with this forum's intent.....
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (1) Thanks(1)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 16 October 2013 at 12:46am
Looks like people who did not read the install instructions for vBulletin and remove the install folder after setting up vBulletin are vulnerable to this.

Web Wiz Forums uses a simple check in our install files to see if Web Wiz Forums has been setup already and if it has the install files will not run. It's a very simple check to add and means that you do not need to have to remove the install files.

It's such a simple check to add I am surprised that vBulletin overlooked this.

All software has vulnerabilities and if you produce web applications that the source code be read you have to pay extra attention to security.

It is amazing the amount of time hacker spend going through each and every line of code to find even the smallest vulnerabilities.

Security became the one of the major development parts of Web Wiz Forums back in 2002 and since then coding no code is added to Web Wiz Forums without first considering both security and optimization.

Web Wiz Forums has got a good reputation for security which is why it is used on many hacking websites and we have even worked with a few hacking websites challenging them to find security vulnerabilities in Web Wiz Forums.

I don't mind hackers who find vulnerabilities within software as they are providing a free service to software developers. As long as they work with the software developers reporting the issue first to the developers and allowing enough time for the vulnerability to be patched before they go public.
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.