Announcement
Collapse
No announcement yet.
User Profile
Collapse
-
Well, they could do that anyway with any kind of distributed attack, but it is harder to accomplish. By contrast, the session table attack I've discussed requires very few resources or coordination and...
-
I can certainly do that, and probably will, moving forward. However, it is not a standard vBulletin setup to list cron.php in the server's crontab -- that is, it is not in the installation instructions...
Leave a comment:
-
First, the kind of attack we're discussing affects very small hobby and niche forums with low traffic -- I've mentioned that low traffic is required to perform that attack successfully. As soon as non-attackers...Last edited by thincom2000; Tue 6 Jan '15, 1:00pm.
Leave a comment:
-
I'm dealing with 0 real users online at the same time and 50,000 attackers at the same time that have the same user ID and IP address(es). Thus cron.php never runs and they are able to keep creating sessions...Last edited by thincom2000; Tue 6 Jan '15, 9:19am.
Leave a comment:
-
Five legitimate users with the same user ID? That doesn't make sense to me. If you want to account for guest users, you can make two limits, one for guests (higher, maybe 1000) and one for logged in users...Last edited by thincom2000; Tue 6 Jan '15, 9:17am.
Leave a comment:
-
It turns out the vulnerability I noticed was not attempting to cause email SPAM but was instead attempting to cause a Denial of Service. See: http://tracker.vbulletin.com/browse/VBIV-16057
Leave a comment:
-
Had a similar problem. Logged-in SPAM users have been using entry.php?do=sendtofriend&do=sendtofriend to fill up the session table completely. This repeats every couple of days. That seems like a...
Leave a comment:
-
Unfortunately that JIRA link now only shows PERMISSION VIOLATION, and unfortunately after reviewing the code for vB 4.2.1 (implied heavily as the fix release in http://www.vbulletin.com/forum/forum/v...Last edited by thincom2000; Mon 15 Apr '13, 8:25am.
Leave a comment:
-
Facebook App - Does it Support Modifications?
I have been asked by some customers to look into the Facebook app in order to integrate our own third-party vBulletin product VaultWiki into it. However, it will be useless to purchase the Facebook app...
-
You have to upgrade the mod. Old versions of mods are not compatible with vB 4.1.4 because vB changed its WYSIWYG code. They told us when vB came out that it would break mods, I don't know why they didn't...
Leave a comment:
-
Reviewed the code for Cyb - Advanced Forum Rules and this can be the culprit as I see an exploit there: you can inject SQL and modify the database if you tamper with the HTML form when agreeing to the...Last edited by Trevor Hannant; Wed 4 May '11, 5:45am.
Leave a comment:
-
If vbf.php is the backdoor, it's not a default vBulletin file. A simple google search implies it stands for vbFreelancers, which is a group that has made a number of modifications for vBulletin. If all...Last edited by thincom2000; Wed 4 May '11, 12:58am.
Leave a comment:
-
While there may be some browser tools to read web pages in other languages, as mentioned above, services like these will not be perfect.
When you want to switch the forum from one language...
Leave a comment:
-
After downloading the ZIP again, I notice it hasn't been updated since last January. Will there be an update soon for the icons used in the Mobile style?
-
1. I don't believe so, vBulletin doesn't have shopping cart support and leaves it up to the site owner to integrate a third-party cart (except for paid subscriptions). If you are talking about a paid...
Leave a comment:
-
You don't need an extra license for the CMS. Simply create 2 "sections", English and Spanish, and give them the custom URLs /en and /es. Then just create your language content in the appropriate...
Leave a comment:
-
Exported how? You can do a database dump, essentially a backup. There's no way to just "export" because there's not really a standardized format for forum data. So you wouldn't be able to do...
Leave a comment:
No activity results to display
Show More
Leave a comment: