vBulletin 3.8.6

Discussion in 'vBulletin' started by dynashox, Jul 13, 2010.

  1. #1
    vBulletin 3.8.6, the last "bug fix" release for vBulletin 3 is now available for download. :)

    - Dynashox -
     
    dynashox, Jul 13, 2010 IP
  2. Brandon Sheley

    Brandon Sheley Illustrious Member

    Messages:
    9,721
    Likes Received:
    612
    Best Answers:
    2
    Trophy Points:
    420
    #2
    and....
    have you updated?
     
    Brandon Sheley, Jul 13, 2010 IP
  3. dynashox

    dynashox Premium Member Staff

    Messages:
    8,662
    Likes Received:
    563
    Best Answers:
    3
    Trophy Points:
    335
    #3
    Not yet. But tonight I'll give it a go.

    - Dynashox -
     
    dynashox, Jul 13, 2010 IP
  4. Bohra

    Bohra Prominent Member

    Messages:
    12,573
    Likes Received:
    537
    Best Answers:
    0
    Trophy Points:
    310
    #4
    which bug did they fix ?
     
    Bohra, Jul 13, 2010 IP
  5. dynashox

    dynashox Premium Member Staff

    Messages:
    8,662
    Likes Received:
    563
    Best Answers:
    3
    Trophy Points:
    335
    #5
    dynashox, Jul 14, 2010 IP
  6. Woodcs82

    Woodcs82 Well-Known Member

    Messages:
    2,588
    Likes Received:
    32
    Best Answers:
    0
    Trophy Points:
    150
    #6
    Where is the option to select 3.8.6? I dont see it!
     
    Woodcs82, Jul 16, 2010 IP
  7. inspiroHost

    inspiroHost Peon

    Messages:
    989
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #7
    vBulletin 4 is available to owned 3.x owners now FYI. Just $50 bucks from vbulletin's website.
     
    inspiroHost, Jul 16, 2010 IP
  8. Bohra

    Bohra Prominent Member

    Messages:
    12,573
    Likes Received:
    537
    Best Answers:
    0
    Trophy Points:
    310
    #8
    this is not rite vb3 updates are available for 50$ not vb4
     
    Bohra, Jul 20, 2010 IP
  9. xanth

    xanth Active Member

    Messages:
    328
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    60
    #9
    If you have vb 4, you can download all updates. If you paid $50 to buy 3.8.6, you can download vb 4.0.x until your 3 months runs out. Chances are this is worthless since vb 3.0.5 will change significantly and there are over 1,000 bugs in the tracker. 4.0.6 alone has roughly 50 bugs on its agenda to fix alone.

    Also be aware that if you installed the long awaited 3.8.6 upgrade, you have also installed an embarrassing security exploit in the FAQ that can allow an unscrupulous person to retrieve your user name and password for your forum. There is a patch to remove the offending code. I'd love to know how that could possibly have made it into vBulletin's first upgrade to vBulletin 3 in a year... and supposedly there weren't even a dozen changes/fixes.
     
    xanth, Jul 22, 2010 IP
  10. RectangleMan

    RectangleMan Notable Member

    Messages:
    2,825
    Likes Received:
    132
    Best Answers:
    0
    Trophy Points:
    210
    #10
    This version is exploitable. You have to get the patch from yesterday if you don't want to get pwnd. Great job VB at sucking arse for paid software.
     
    RectangleMan, Jul 22, 2010 IP
  11. bigturnip

    bigturnip Active Member

    Messages:
    71
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    70
    #11
    Not quite, it reveals the details of the mysql database, which as far as I am aware is pretty useless unless you have access to the server or the mysql database has been set up for remote access. Obviously it's not great and I'm sure some people used the same username and password for their mysql database as their admin account on their forum, so it's possible some forums have been compromised, but it's not quite as bad as the reports are making out.
     
    bigturnip, Jul 22, 2010 IP
  12. xanth

    xanth Active Member

    Messages:
    328
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    60
    #12
    I meant mysql info for your forum which is incredibly dangerous and embarrassing. If someone finds even a small hole in your server, which from people having fun it seems to be quite many, your forum data is completely vulnerable. Once you have the mysql access info it's a piece of cake to access the admin account on the forum with just a few steps.
     
    xanth, Jul 22, 2010 IP
  13. Floris

    Floris Peon

    Messages:
    3
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #13
    Pretty useless?

    - db allows remote connections? You're screwed
    - site has phpmyadmin somewhere, or another user on the same box? You're screwed

    I am sure nobody wants their site dump being for sale on flippa or other web sites..
     
    Floris, Jul 23, 2010 IP
  14. digitalpoint

    digitalpoint Overlord of no one Staff

    Messages:
    38,334
    Likes Received:
    2,613
    Best Answers:
    462
    Trophy Points:
    710
    Digital Goods:
    29
    #14
    Of course you can argue that MySQL should not allow any connection from random IPs and that the MySQL username/password shouldn't be used for other things (like admin accounts). But that isn't really the point... exposing *anything* that only the administrator should see is BAD (anything from config.php file for example).

    I could also argue it doesn't affect me since I upgraded to vBulletin 4.x. Also not the point though.
     
    digitalpoint, Jul 23, 2010 IP
  15. Floris

    Floris Peon

    Messages:
    3
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #15
    Almost every 4.0 release has a patch level, so .....
     
    Floris, Jul 23, 2010 IP
  16. Bohra

    Bohra Prominent Member

    Messages:
    12,573
    Likes Received:
    537
    Best Answers:
    0
    Trophy Points:
    310
    #16
    i guess such exploits are bound to happen when we talk about a software with so many multiple functionality.. as long as they are detected fast before damage is done it shouldnt be an issue.. unless offcourse hackers come to know of it first
     
    Bohra, Jul 23, 2010 IP
  17. xanth

    xanth Active Member

    Messages:
    328
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    60
    #17
    This has nothing to do with multiple functionality or an exploit that is discovered by a hacker. There is no reason why (1) this kind of code should have been where it was in the first place - it's the keys to the castle not a creative exploit, and (2) how the QA team didn't catch this before it went out the door.
     
    xanth, Jul 24, 2010 IP