Register Members List Search Today's Posts Mark Forums Read

Reply
 
Thread Tools
  #1  
Old 05 Jan 2002, 23:06
Fred Zed Fred Zed is offline
 
Join Date: Jan 2002
PM How Secure ?

A user at a site that uses VB 2.2.1 claims that he was able to acess other users's PMs. He is neither a computer professional nor hacker. Apparently he was able to do this from message links sent from the Bulletin Board to his email. This user is a reliable source and I believe his story to be true.

My question is - if true how is this possible ? Could this be due to some flaw in the the way the board was set up or some other bug in Vbulletin ?

Appreciate any help/comments. I am not a geek and some of my members are really concerned about these rumours.
Reply With Quote
  #2  
Old 05 Jan 2002, 23:48
Steve Machol's Avatar
Steve Machol Steve Machol is offline
 
Join Date: Nov 2001
I don't belive this is possible and I've never seen this problem proven to be true. If this source is so reliable then simply ask him how he did it.
__________________
Steve Machol, vBulletin Moderator

Please do not email or PM me for vBulletin support. I will try to answer all questions on the vB Forums. Thank you for respecting this request!
Reply With Quote
  #3  
Old 06 Jan 2002, 00:07
Fred Zed Fred Zed is offline
 
Join Date: Jan 2002
Just got an email from that user, he swears he was able read the
PMs from the links sent to his hotmail and adds:

"if the links have the password embedded in them then anyone can access them [ PMs ] which is what happened. "

As the board in affected was not mine, I will try to get more details but thanks a lot for responding.
Reply With Quote
  #4  
Old 06 Jan 2002, 00:33
Steve Machol's Avatar
Steve Machol Steve Machol is offline
 
Join Date: Nov 2001
Links in vB don't have the password embedded in them. Your user is mistaken.
__________________
Steve Machol, vBulletin Moderator

Please do not email or PM me for vBulletin support. I will try to answer all questions on the vB Forums. Thank you for respecting this request!
Reply With Quote
  #5  
Old 06 Jan 2002, 01:03
Steve Machol's Avatar
Steve Machol Steve Machol is offline
 
Join Date: Nov 2001
Just out of curiousity, why are you still running vB 2.0 RC3? This version is very insecure and terribly out of date.
__________________
Steve Machol, vBulletin Moderator

Please do not email or PM me for vBulletin support. I will try to answer all questions on the vB Forums. Thank you for respecting this request!
Reply With Quote
  #6  
Old 06 Jan 2002, 01:19
Fred Zed Fred Zed is offline
 
Join Date: Jan 2002
Thanks. That's the version that we were sent when we purchased the Vbulletin licence about 5 months ago. As you have probably figured out, I'm no Webmaster, just the site owner. My Webmaster didn't seem to think there was any rush to upgrade but now that you tell me this, I will ask him to upgrade to 2.2.1 asap. Thanks again.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
Forum Jump


New To Site? Need Help?

All times are GMT. The time now is 08:32.

Layout Options | Width: Wide Color: