PDA

View Full Version : IMPORTANT: CRITICAL SECURITY BUG FIX FOR vB3 RC1!


Erwin
04 Jan 2004, 23:01
Critical Security Bug & Fix

vB3 RC1 downloads have just been suspended.

Please download and upload register.php and login.php here if you have upgraded to vB3 RC1.

http://www.vbulletin.com/forum/showthread.php?p=586786&postcount=4

NTLDR
04 Jan 2004, 23:13
This also effects vB3 Gamma.

filburt1
04 Jan 2004, 23:16
Goes to show you that you should only run the latest stable versions of a product :)

corsacrazy
04 Jan 2004, 23:31
what was the issue ? any one know more information

NTLDR
04 Jan 2004, 23:33
It was related to checking the password that was entered, there are two lines to change in register.php and one in login.php.

Koutaru
04 Jan 2004, 23:38
I was wondering where that bug went in the bug tracker .. good thing my vb3 board isn't public yet

Erwin
04 Jan 2004, 23:41
This also effects vB3 Gamma.
Really??? I didn't realize that...

NTLDR
04 Jan 2004, 23:47
Well not knowing what the bug is, and just looking at the changes bettween RC1 which I downloaded and the patched files, and then looking at my vB3 Gamma files, the lines that changed were the same in vB3 Gamma as they were in the origional RC1, so I've edited them to be safe as I'm not planning on upgrading yet.

Erwin
05 Jan 2004, 00:27
The sad thing is that this is going to delay me releasing my hacks. I am about to release my massive admin/ warn/ suspend/ ban hack... but can't do it without RC1. GAH!

Convergys
05 Jan 2004, 00:42
You just said that to tease us;) lol.. jk...

deathemperor
05 Jan 2004, 00:52
The sad thing is that this is going to delay me releasing my hacks. I am about to release my massive admin/ warn/ suspend/ ban hack... but can't do it without RC1. GAH!
does this mean RC1 will not be RC1 anymore ?
a critical bug fix, don't know wether I have to feel happy or sad

TouchingVirus
05 Jan 2004, 01:10
[delicate security information removed by Erwin - sorry :) ]

It was being investigated while i was browsing the bug forusm...now its not there :)

[sorry, I edited your message, just in case hackers are reading it. :)]

Floris
05 Jan 2004, 01:28
It is in gamma, but it won't work in gamma.

Erwin
05 Jan 2004, 02:31
RC1 is back for download in the member's area. :)

SmEdD
05 Jan 2004, 02:36
The sad thing is that this is going to delay me releasing my hacks. I am about to release my massive admin/ warn/ suspend/ ban hack... but can't do it without RC1. GAH!

Can't wait for it :)

You should also do a red and yellow flag hack for post to allow them and everyone else to know when they are pushing it or hit the edge.

Erwin
05 Jan 2004, 02:59
I'm upgrading my private forums now, and will be releasing all my hacks sometime today. ;)

deathemperor
05 Jan 2004, 03:49
I'm upgrading my private forums now, and will be releasing all my hacks sometime today. ;)
love to hear that, wait for your hacks, Erwin.

Floris
05 Jan 2004, 14:03
I advice users to just upload those 2 files from the rc1 one
and wait for rc2 later today.

PixelFx
05 Jan 2004, 15:43
I cant' even access vb.com with out gateway error. :'(

weewilly
06 Jan 2004, 18:58
I can't either pixel. For the last five days, I get a "Page cannot be Found" error when I try to access anything on Vbulletin.com.

Does anyone know why this is happening and what is going on with them? I have even tried accessing the link from Google and get the same thing.

MindTrix
06 Jan 2004, 19:15
It is because of ddos attacks, chance is your IP has accidently been banned. Email support@vbulletin.com about your problem also stating your IP address and they will help you out.


Note RC2 is out