vBulletin Modifications

vBulletin 3.6.5 released

Welcome to vBHackers.com! - vBHackers Updates:

Go Back   vBulletin Modifications > vBHackers.com > Announcements

Reply
 
LinkBack Thread Tools
Old 03-01-2007, 01:40 PM   #1
Advanced Coder
Mikeyodesigns's Avatar
Join Date: May 2006
Real Name: Mike
Location: Scotland
Mikeyodesigns is on a distinguished road

Default vBulletin 3.6.5 released

From Vbulletin.com

vBulletin 3.6.5

This morning, an exploit was reported, which affects vBulletin versions 3.5.x and 3.6.x. Although the report is inaccurate and the published exploit does not work as claimed unless a highly unlikely set of circumstances exist, it has highlighted a potential security issue in these vBulletin versions.

Therefore, we have decided to release updated versions, these being vBulletin 3.5.8 and 3.6.5. We recommend that all customers running vBulletin 3.5.x or 3.6.x upgrade to the appropriate version or apply the supplied patch as soon as possible.

It is worth noting that in order to exploit the problem highlighted by the report, the attacking user must satisfy the following conditions:
  • Must already have moderator privileges
  • Must share the same IP address (or the number of IP octets specified in the Admin Control Panel for IP address matching) with an existing administrator who is currently logged in to the Admin Control Panel
  • Must know the Alt-IP and user agent (exact browser identification) of the administrator
  • OR must know the license number of the site being attacked
Given these requirements, the privilege escalation exploit claimed by the report is almost impossible to achieve.



Bugs Fixed in vBulletin 3.6.5

The Security Flaw
The reported security flaw described in this announcement, which could potentially allow a SELECT query to be hijacked, has been addressed.
Safari Cookies
A problem where users of the Apple browser Safari would be logged off the system prematurely when vBulletin runs on specific servers has been resolved.
More info...
Internet Explorer 7 Compatability
Much has been said about Microsoft's decision to make the Javascript prompt() function throw a security warning whenever it is called. This change resulted in vBulletin's text editor system throwing security warnings whenever a user tried to insert an image or an email link. The use of prompt() for Internet Explorer 7 users has now been discontinued in favour of an alternative method of collecting user input.
More info...

Additionally, improvements in Internet Explorer 7 mean that certain aspects of the vBulletin pop-up menu system, which were previously required to circumvent rendering issues, can now be bypassed. Most notable amongst these is the code that hides all <select> elements that would intersect with the menu when opened.
Fix for Infractions Bug
A problem where infraction expiration was not cleaned-up properly has been addressed.
More info...
Workaround for a FreeBSD Regular Expression Error on Login
Some users running recent versions of PHP running on FreeBSD have encountered a bug in the regular expression engine that caused an error to be shown when logging in. We have worked around this problem. However, it may still appear in other areas, so we are trying to find a proper fix for the issue.
Updating your vBulletin to Fix the Potential Exploit

There are two ways in which you can fix the potential exploit in your version of vBulletin:
  1. Full Upgrade: The best way to fix the problem is to perform a full upgrade by downloading the complete 3.6.5 package from the vBulletin Members' Area and following the regular upgrade instructions.
  2. Patch: A second option is to download the patch files discussed in this thread and upload them to your web server, overwriting the existing files. The patch is available from the Members' Area patch page or you can find it attached to this thread.
Please note that vBulletin 3.6.5 requires at least PHP 4.3.3 and MySQL 4.0.16 or later.



A Note Regarding vBulletin 3.6.6

The publication of this exploit has required a swift release of an updated version to fix the published problem. The original intention for vBulletin 3.6.5 had been to include a number of other bug fixes and improvements that have been reported since 3.6.4.

Unfortunately, the necessity of bringing out a version quickly to fix the exploit has meant that many of these fixes have not had sufficient time to be fully tested to the extent that we would like and have therefore been kept back for vBulletin 3.6.6.

We understand that this may be frustrating to our customers, and in order to minimize the inconvenience, we have ensured that this vBulletin 3.6.5 release contains no template or phrase changes, which will hopefully make upgrading as painless as possible.
__________________
TheUKForums




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Old 03-01-2007, 01:45 PM   #2
vBulletin Guru
Nick R's Avatar
Join Date: May 2006
Real Name: Nick
Location: Cyberspace, UK
Nick R is on a distinguished road

Default

Interesting. I'm upgrading my boards now.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 03-01-2007, 02:06 PM   #3
Michael Biddle
Administrator
Michael Biddle's Avatar
Join Date: Feb 2005
Real Name: Michael Biddle
Location: Anaheim
Michael Biddle is on a distinguished road

Default

Already upgraded my development board now off to do it on my car one
__________________
Support will ONLY be offered through forums
Michael Biddle / vBHackers.com
vBSEO 3.2.0 Launched - Maximum Overdrive for Your Web Traffic! Over 100 Instant SEO Optimizations

vBSEO Google Sitemap Generator - Version 2.2 Released Mandatory Upgrade for vBSEO 3.2.0 GOLD

6X Traffic - $1400 in One Day with vBSEO! Imagine What the vBSEO Patent Pending Technology Can Do For You.

Crawlability Network: vBulletin SEO | vBulletin Hackers




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 03-01-2007, 02:18 PM   #4
Psih
Join Date: Feb 2007
Real Name: Alexandr Zaguzin
Location: Russia
Ateist is on a distinguished road

Default

Thank You! I m go to upgrade...




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 03-01-2007, 03:34 PM   #5
Banned
Join Date: Jan 2007
Likenota is on a distinguished road

Default

thanks. hey if i upgrade do i have to re apply all the hacks and whatnot ?




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 03-01-2007, 03:43 PM   #6
vBulletin Guru
Nick R's Avatar
Join Date: May 2006
Real Name: Nick
Location: Cyberspace, UK
Nick R is on a distinguished road

Default

if your going from 3.6.4 to .5 then there are no changes to the templates. Just a few files. aka; All your templates and hacks should work and stay the same.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 03-01-2007, 04:29 PM   #7
Psih
Join Date: Feb 2007
Real Name: Alexandr Zaguzin
Location: Russia
Ateist is on a distinguished road

Default

I do not download 3.6.5 - Errors, 90%.... ??? 10 attempts... Support - sleep?




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 03-01-2007, 04:49 PM   #8
Michael Biddle
Administrator
Michael Biddle's Avatar
Join Date: Feb 2005
Real Name: Michael Biddle
Location: Anaheim
Michael Biddle is on a distinguished road

Default

what...? what do u mean? it went pretty clean for me, had one error, but i just deleted that row in database
__________________
Support will ONLY be offered through forums
Michael Biddle / vBHackers.com
vBSEO 3.2.0 Launched - Maximum Overdrive for Your Web Traffic! Over 100 Instant SEO Optimizations

vBSEO Google Sitemap Generator - Version 2.2 Released Mandatory Upgrade for vBSEO 3.2.0 GOLD

6X Traffic - $1400 in One Day with vBSEO! Imagine What the vBSEO Patent Pending Technology Can Do For You.

Crawlability Network: vBulletin SEO | vBulletin Hackers




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 03-01-2007, 05:06 PM   #9
loco.m
vB SEO Nutcase
loco.m's Avatar
Join Date: Nov 2005
Real Name: Brandon Sheley
Location: Kansas
loco.m is on a distinguished road

Default

I'll just patch until the real update occurs ;)

no reason to do full upgrades when another release will likely be soon.

-Bs
__________________
Brandon Sheley / vBHackers.com
vBSEO 3.2.0 Launched - Maximum Overdrive for Your Web Traffic! Over 100 Instant SEO Optimizations

vBSEO Google Sitemap Generator - Version 2.2 Released Mandatory Upgrade for vBSEO 3.2.0 GOLD

6X Traffic - $1400 in One Day with vBSEO! Imagine What the vBSEO Patent Pending Technology Can Do For You.

Crawlability Network: vBulletin SEO | vBulletin Hackers


We offer vBulletin Services @ vBulletin Setup - = - Barcode Signature
I run a few Directories, submit your sites: Quality Link Directory, Link Directory, Link Directory
Have you seen Crowdgather yet? it's where you can Find it on Forums




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 03-01-2007, 05:20 PM   #10
Ken Iovino
Founder
Ken Iovino's Avatar
Join Date: Mar 2004
Real Name: Ken Iovino
Location: Miami, Florida
Ken Iovino is on a distinguished road

Default

errrr, I hate upgrades!
__________________
Earnersforum.com - Learn how to make money online! New Look!

Ken Iovino / vBHackers.com
vBSEO 3.2.0 Launched - Maximum Overdrive for Your Web Traffic! Over 100 Instant SEO Optimizations

vBSEO Google Sitemap Generator - Version 2.2 Released Mandatory Upgrade for vBSEO 3.2.0 GOLD

6X Traffic - $1400 in One Day with vBSEO! Imagine What the vBSEO Patent Pending Technology Can Do For You.

Crawlability Network: vBulletin SEO | vBulletin Hackers




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Tags
vbulletin



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
vBulletin 3.6.4 Released Mikeyodesigns Announcements 3 11-28-2006 03:09 AM
vBulletin 3.6.0 Gold Released Rex Announcements 11 10-18-2006 06:18 PM
vBulletin 3.6 Release Candidate 1 Released Ken Iovino Announcements 3 07-11-2006 05:32 PM
vBulletin 3.6 Beta 3 Released Ken Iovino Announcements 9 06-24-2006 05:58 PM
vBulletin 3.0.2 Released Ryan Ashbrook Announcements 8 07-06-2004 12:51 PM


All times are GMT -3. The time now is 07:38 PM.


SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc. (Patent Pending)