![]() |
|
vBulletin 0day released - Printable Version +- Sinisterly (https://sinister.ly) +-- Forum: General (https://sinister.ly/Forum-General) +--- Forum: World News (https://sinister.ly/Forum-World-News) +--- Thread: vBulletin 0day released (/Thread-vBulletin-0day-released) Pages:
1
2
|
vBulletin 0day released - Infinity - 09-08-2013 Quote:With a huge string of vBulletin sites being hacked, there is no doubt that a Zero-Day is floating around. The Zero-Day was released publicly on a popular Hacking forum and was posted along with a tutorial on how to exploit a targeted site More: http://zerosecurity.org/security/vbulletin-4-15-upgrade-zero-day-released RE: vBulletin 0day released - w00t - 09-09-2013 Hardly a 0day, VBulletin tells its users to delete the install directory. RE: vBulletin 0day released - Ultimatum - 09-09-2013 Mhm, that's right. It's pretty stupid not to delete the install folder/directory. Administrator's fault, nothing to do with vBulletin. RE: vBulletin 0day released - Oni - 09-09-2013 I had this way before. It's a real shame someone leaked it. RE: vBulletin 0day released - Ultimatum - 09-09-2013 (09-09-2013, 02:51 AM)Oni Wrote: I had this way before. It's a real shame someone leaked it. Well, it's not really a 0day, :3. Also, I would have thought most administrators followed the instructions, when deleting the install directory, so I never thought to look. RE: vBulletin 0day released - Oni - 09-09-2013 (09-09-2013, 02:58 AM)Ultimatum Wrote: Well, it's not really a 0day, :3. Also, I would have thought most administrators followed the instructions, when deleting the install directory, so I never thought to look. Well, not anymore it isn't. Haha. RE: vBulletin 0day released - TechSaavy - 09-09-2013 Hard to say it's a 0day, but whatever :d It should be actually obvious to delete the insstallation files :/ Re: RE: vBulletin 0day released - Oni - 09-09-2013 (09-09-2013, 02:43 PM)CamIce Wrote: Hard to say it's a 0day, but whatever :d No, it was. Reason being, a large portion of people leave the upgrade system there. Notice how vBulletin instructed customers only to delete the upgrade files? What would have normally been perfectly safe has become exploitable, and mainly due to poor practice on their end. While I certainly remove installation files, a lot of people don't. MyBB, for example, has a lock on the installation files. It is also worth noting that vBulletin has left the files there on their own forum (with authentication). I might release a modified script that I have later. You'll see how dangerous it is. RE: vBulletin 0day released - Ultimatum - 09-10-2013 (09-09-2013, 02:56 PM)Oni Wrote: No, it was. Reason being, a large portion of people leave the upgrade system there. Notice how vBulletin instructed customers only to delete the upgrade files? What would have normally been perfectly safe has become exploitable, and mainly due to poor practice on their end. Yes, only error on the administartor's part, not vBulletin, there is no actual vulnerability in the code, it's just silly error, like leaving a .sql backup, named "backup.sql" on the index. This is basically all booter skiddies. Re: RE: vBulletin 0day released - Oni - 09-10-2013 (09-10-2013, 04:48 AM)Ultimatum Wrote: Yes, only error on the administartor's part, not vBulletin, there is no actual vulnerability in the code, it's just silly error, like leaving a .sql backup, named "backup.sql" on the index. This is basically all booter skiddies. It's considered a vulnerability. Unless you disagree with me and the developers of vBulletin, of course. Read: http://www.vbulletin.org/forum/showthread.php?p=2441494#post2441494 |