vBulletin SEO Forums

SEO

vBulletin Search Engine Optimization

Buy vBSEO Now! HACKER SAFE certified sites prevent over 99.9% of hacker crime.
ne nw
vBSEO Total Support Team Launches DeskPro New vBSEO Discount Level for Network Builders vBSEO 3.2.0 GOLD Has Landed Success with vBSEO = 600ore Web Visitors + $1400 in a Day! Crawlability Inc. Files for SEO Technology Patent
se sw

vBulletin 3.7.0 Release Candidate 4

This is a discussion on vBulletin 3.7.0 Release Candidate 4 within the vBulletin.com Announcements forums, part of the Announcements & Pre-Sales category; vBulletin 3.7.0 Release Candidate 4 Yeah, we know... THIS IS PRE-RELEASE SOFTWARE. IT IS UNSUPPORTED. If you are not fully ...

Go Back   vBulletin SEO Forums > Announcements & Pre-Sales > vBulletin.com Announcements

Enhancing 80 million pages.

Register FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read
  #1  
Old 04-23-2008, 02:00 PM
Joe Ward's Avatar
vBSEO Staff
vBSEO Total Customer SupportvBSEO Documenter
 
Real Name: Joseph Ward
Join Date: Jun 2005
Location: Puerto Rico
Posts: 19,746
Blog Entries: 7
vBulletin 3.7.0 Release Candidate 4

vBulletin 3.7.0
Release Candidate 4

Yeah, we know...

THIS IS PRE-RELEASE SOFTWARE.
IT IS UNSUPPORTED.

If you are not fully at home with backing-up and restoring your forum, dealing with bugs and regular upgrades, DO NOT INSTALL THIS VERSION

Last week, I announced that we intended to release the stable, final version of vBulletin 3.7.0 this week. I'm sorry to say that this will not be the case.

A security hole involving a CSRF (cross-site request forgery) vulnerability was reported to us over the weekend, requiring changes to significant numbers of templates and files in all of our products including vBulletin 3.x, Blog and Project Tools. The CSRF problem potentially enabled an administrator who had been lured to a third-party site to unknowingly submit forms located on the forum he or she administers, resulting in potential damage to the forum. Actions performed via the Admin Control Panel are not vulnerable.

Incidentally, this vulnerability is not unique to vBulletin - many web applications are affected and always have been, due to the very nature of the web.

It was decided that rather than push ahead and release 3.7.0, it would be better to roll out a further release candidate containing the fix for this problem, as the changes are widespread and it would not be prudent to label 3.7.0 as 'stable' before it has had at least one outing in pre-release form.

As we release vBulletin 3.7.0 Release Candidate 4, we are simultaneously releasing 3.6.10, which contains various bug fixes back-ported from 3.7.0, and of course the fix for the security problem. New versions of Blog and Project Tools will follow shortly in the coming days.

Unfortunately, due to the number of file and template changes required by the security fix, it is not practical to provide a patch or plugin to resolve the problem - only a full-scale upgrade will be sufficient.

We recommend that all customers upgrade as soon as possible.
Customers running 3.7.x should upgrade to 3.7.0 RC4.
Customers running 3.6.9 or earlier should upgrade to 3.6.10.

To all those who have been expecting to download vBulletin 3.7.0 'Gold' this week, we are sorry. We hope that the fact that we would rather delay a major, pre-announced release than put out software with known vulnerabilities illustrates our commitment to security.

If testing of this release candidate goes well, we will once again be looking at a stable release next week.

PHP and MySQL Recommendations

We recommend that vBulletin 3.7 is run on PHP 5.2.5 with APC (or a similar opcode cache) and MySQL 5.0.51 for best performance and stability.

What does Release Candidate mean?

Release Candidate, or RC for short, means that we believe vBulletin 3.7 will be ready to be declared a "stable" and "supported" supported release once it has undergone some final testing. The only known bugs that may remain are trivial.

RCs will be released until only trivial bugs are being fixed. Once this happens, the next stage is to move on to "gold" or, as it's officially known, 3.7.0.

This is still pre-release software. If you are not fully at home with backing-up and restoring your forum, dealing with bugs and regular upgrades, do not install this version but rather wait for the final, 3.7.0 version.

Customers should bear in mind that this is a release candidate, not a certified 'stable' release so the following caveats apply:
  • Pre-release software is unsupported and you install beta and RC versions at your own risk.
  • Some minor bugs remain unresolved at this time, so pre-release software should not be deployed on production sites.
  • You should always back up your database fully before attempting to install pre-release software.
  • If you choose to install this version, you should be aware that we plan to release new RC versions in rapid succession as bugs are fixed and holes are plugged. Do not install this RC version if you are not willing or able to keep up-to-date with new releases.
  • The ImpEx import system does not support the 3.7 code yet, and will not support it until the release of 3.7.0 (stable).



More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #2  
Old 04-23-2008, 05:54 PM
Mert Gökçeimam's Avatar
vBSEO.com Webmaster
vBSEO Total Customer SupportvBulletin HackerBig Board Administrator
 
Real Name: Lizard King
Join Date: Oct 2005
Location: Istanbul
Posts: 7,817
Blog Entries: 1
Send a message via MSN to Mert Gökçeimam
This is funny Stable version is going to be Rc4
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #3  
Old 04-23-2008, 06:09 PM
Michael Biddle's Avatar
vBSEO Staff
vBSEO Total Customer Support
 
Real Name: Michael Biddle
Join Date: Jan 2007
Location: Southern California
Posts: 3,014
Blog Entries: 5
Safety first...lol
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #4  
Old 04-23-2008, 06:25 PM
Senior Member
 
Real Name: Derek
Join Date: Feb 2007
Location: USA, NJ
Posts: 271
Blog Entries: 3
I'd prefer saftey alright. Well, time for me to do a backup and upgrade. This is already a long day and to end it i'll upgrade to RC4.

Any bet's on a RC5?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #5  
Old 04-23-2008, 06:29 PM
Michael Biddle's Avatar
vBSEO Staff
vBSEO Total Customer Support
 
Real Name: Michael Biddle
Join Date: Jan 2007
Location: Southern California
Posts: 3,014
Blog Entries: 5
Doubt the RC5. Then again I doubted RC4, but this one is understandable.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #6  
Old 04-23-2008, 06:32 PM
Senior Member
 
Real Name: Derek
Join Date: Feb 2007
Location: USA, NJ
Posts: 271
Blog Entries: 3
I'm glad someone caught this before the final. I'd rather have a perfect final release then to have a security risk sitting on thin ice.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #7  
Old 04-23-2008, 06:55 PM
briansol's Avatar
Senior Member
vBSEO Pre-Release TeamDesign for SEOBig Board Administrator
 
Real Name: Brian
Join Date: Apr 2006
Location: Central CT, USA
Posts: 5,538
from what i can gather, this isn't a very serious exploit... i'm not even bothering.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #8  
Old 04-25-2008, 04:16 AM
Member
 
Real Name: LinkHunter
Join Date: Dec 2007
Posts: 52
The new RC4 with its security features doesn't affect anything in vbseo right??

Yeah, it was a lot of work but you have to do the upgrade!!!

No biggie!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #9  
Old 04-25-2008, 06:40 AM
Senior Member
 
Real Name: Derek
Join Date: Feb 2007
Location: USA, NJ
Posts: 271
Blog Entries: 3
It doesn't affect VBSEO. The only thing this effected was my template(might happen with your template also). I need to get a few template files updated in which will get done this weekend. My url structure and vbseo settings didn't change at all after upgrading to RC4.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
vBulletin 3.7.0 Release Candidate 3 Joe Ward vBulletin.com Announcements 12 04-12-2008 11:44 AM
vBulletin 3.7.0 Release Candidate 2 Joe Ward vBulletin.com Announcements 17 04-04-2008 11:29 PM
vBulletin 3.7.0 Release Candidate 1 Joe Ward vBulletin.com Announcements 14 03-25-2008 06:00 AM
vBulletin® 3.7.0 Release Candidate 1 NeutralizeR Off-Topic & Chit Chat 6 03-23-2008 12:13 AM
vBulletin 3.6 Release Candidate 1 Available Joe Ward SEO Buzz 13 07-27-2006 03:36 AM


All times are GMT -4. The time now is 10:25 PM.


Powered by vBulletin Version 3.8.0 Beta 4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.5 ©2008, Crawlability, Inc.