v-bulletin sites hacked
Printed From: Web Wiz Forums
Category: Web Wiz Web App Support Forums
Forum Name: Web Wiz Forums
Forum Description: Support forum for Web Wiz Forums application.
URL: https://forums.webwiz.net/forum_posts.asp?TID=30858
Printed Date: 30 March 2026 at 11:43am Software Version: Web Wiz Forums 12.08 - https://www.webwizforums.com
Topic: v-bulletin sites hacked
Posted By: alabamatoy
Subject: v-bulletin sites hacked
Date Posted: 15 October 2013 at 1:27am
http://krebsonsecurity.com/2013/10/thousands-of-sites-hacked-via-vbulletin-hole/
Slightly off topic, but related. Apologies if this is not in keeping with this forum's intent.....
|
Replies:
Posted By: WebWiz-Bruce
Date Posted: 16 October 2013 at 12:46am
Looks like people who did not read the install instructions for vBulletin and remove the install folder after setting up vBulletin are vulnerable to this.
Web Wiz Forums uses a simple check in our install files to see if Web Wiz Forums has been setup already and if it has the install files will not run. It's a very simple check to add and means that you do not need to have to remove the install files.
It's such a simple check to add I am surprised that vBulletin overlooked this.
All software has vulnerabilities and if you produce web applications that the source code be read you have to pay extra attention to security.
It is amazing the amount of time hacker spend going through each and every line of code to find even the smallest vulnerabilities.
Security became the one of the major development parts of Web Wiz Forums back in 2002 and since then coding no code is added to Web Wiz Forums without first considering both security and optimization.
Web Wiz Forums has got a good reputation for security which is why it is used on many hacking websites and we have even worked with a few hacking websites challenging them to find security vulnerabilities in Web Wiz Forums.
I don't mind hackers who find vulnerabilities within software as they are providing a free service to software developers. As long as they work with the software developers reporting the issue first to the developers and allowing enough time for the vulnerability to be patched before they go public.
------------- https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting
|
|