vBulletin SEO Forums

SEO

vBulletin Search Engine Optimization

Buy vBSEO Now! HACKER SAFE certified sites prevent over 99.9% of hacker crime.
ne nw
vBSEO Total Support Team Launches DeskPro New vBSEO Discount Level for Network Builders vBSEO 3.2.0 GOLD Has Landed Success with vBSEO = 600ore Web Visitors + $1400 in a Day! Crawlability Inc. Files for SEO Technology Patent
se sw

vBulletin 3.7.2 PL1 and 3.6.10 PL3 Released

This is a discussion on vBulletin 3.7.2 PL1 and 3.6.10 PL3 Released within the vBulletin.com Announcements forums, part of the Announcements & Pre-Sales category; vBulletin 3.7.2 PL1 / vBulletin 3.6.10 PL3 An XSS flaw affecting the vBulletin control panel logging system has been identified, ...

Go Back   vBulletin SEO Forums > Announcements & Pre-Sales > vBulletin.com Announcements

Enhancing 80 million pages.

Register FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply

 

LinkBack Thread Tools
  #1  
Old 07-07-2008, 12:40 PM
Joe Ward's Avatar
vBSEO Staff
vBSEO Total Customer SupportvBSEO Documenter
 
Real Name: Joseph Ward
Join Date: Jun 2005
Location: Puerto Rico
Posts: 19,746
Blog Entries: 7
vBulletin 3.7.2 PL1 and 3.6.10 PL3 Released

vBulletin 3.7.2 PL1 / vBulletin 3.6.10 PL3

An XSS flaw affecting the vBulletin control panel logging system has been identified, another was found affecting boards running in debug mode. It could allow an attacker to trick an admin into unwittingly performing an action within the control panel that they had not intended. To resolve this issue, it is necessary to release patch level versions of vBulletin 3.7.2 and 3.6.10.

One of the XSS flaws was discovered by Jessica Hope and the other by ourselves.

The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


Upgrading from 3.7.2, 3.6.10 or their patch level versions

If you are already running 3.7.2, 3.6.10 or their patch level versions, the process you will be required to follow to make your board immune to the XSS problem is very simple.

There is no need to run an upgrade script if you are already running 3.7.2, 3.6.10 or their patch level versions.

Visit the Patches section of the vBulletin Members' Area and download either the patch for 3.7.2, or the patch for 3.6.10, according to the version you are currently running, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 or PL3 release respectively.

The 3.6.10 PL3 patch file also includes the PL1 and PL2 fixes.


Upgrading from Versions Earlier than 3.7.2 or 3.6.10

If you are not already running 3.7.2 or 3.6.10, you should download the most latest version from the Members' Area and perform an upgrade as normal.

Full instructions for upgrading vBulletin are available here.


Download vBulletin 3.7.2 PL1 or 3.6.10 PL3

As usual, both versions released today are available for all customers with valid, active licenses to download from the vBulletin Members' Area.

vBulletin Members Area


More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #2  
Old 07-07-2008, 06:02 PM
Senior Member
 
Real Name: Derek
Join Date: Feb 2007
Location: USA, NJ
Posts: 271
Blog Entries: 3
I just got done doing the update. No template changes which is good.

Past 2 days, i've did a lot of updating on my forum. At least VB fixed some bug's that i had on my forum.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #3  
Old 07-07-2008, 06:19 PM
Ace Shattock's Avatar
vBSEO Staff
vBSEO Total Customer SupportCommunity Builder
 
Real Name: Ace Shattock
Join Date: Jul 2005
Location: New Zealand
Posts: 2,923
Who is this Jessica Hope person that keeps getting mentioned as an exploit finder?

Should I know?
__________________
Ace Shattock / Crawlability Inc.
Support Team Launches New DeskPro Powered Tool Enhanced Support at Your Service

vBSEO 3.2.0 Launched - Maximum Overdrive for Your Web Traffic! Over 100 Instant SEO Optimizations

6X Traffic - $1400 in One Day with vBSEO! Imagine What the vBSEO Patent Pending Technology Can Do For You.


My Personal Sites: New Zealand Forum | vBulletin Modifications and Styles | vBulletin Hosting
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #4  
Old 07-07-2008, 06:22 PM
Senior Member
 
Real Name: Lee
Join Date: Sep 2006
Location: Costa Blanca
Posts: 280
Glad I held off doing the last update. Two birds with one stone

Just hope it don't mess up my latest forum efforts
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #5  
Old 07-07-2008, 06:22 PM
Senior Member
 
Real Name: Derek
Join Date: Feb 2007
Location: USA, NJ
Posts: 271
Blog Entries: 3
I have no idea and is this person actually a human or made up character?

Does VB pay people to hack there software to find bugs or something?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #6  
Old 07-07-2008, 06:28 PM
briansol's Avatar
Senior Member
vBSEO Pre-Release TeamDesign for SEOBig Board Administrator
 
Real Name: Brian
Join Date: Apr 2006
Location: Central CT, USA
Posts: 5,538
she's a big wig on security tracker...
SecurityTracker.com Archives - vBulletin Input Validation Hole in 'redirect' Parameter Permits Cross-Site Scripting Attacks
http://www.google.com/search?q=jessi...ient=firefox-a
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #7  
Old 07-07-2008, 06:29 PM
Senior Member
 
Real Name: Lee
Join Date: Sep 2006
Location: Costa Blanca
Posts: 280
I'm sure there are plenty of people biting their lips with an answer to the last question.

I'm waiting to see what Brian says
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #8  
Old 07-07-2008, 07:01 PM
briansol's Avatar
Senior Member
vBSEO Pre-Release TeamDesign for SEOBig Board Administrator
 
Real Name: Brian
Join Date: Apr 2006
Location: Central CT, USA
Posts: 5,538
i don't know what vb does.

there's plenty of 3rd party service out there, like scan alert (now mcaffe secure) etc that will place various tests on your sites. vbseo in fact runs this same service.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #9  
Old 07-07-2008, 08:38 PM
Senior Member
Big Board Administrator
 
Real Name: Matt
Join Date: May 2006
Posts: 580
Upgraded both my sites within minutes.

ps. I hope everyone here is using different admincp and modcp directories on there forums.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #10  
Old 07-07-2008, 08:39 PM
briansol's Avatar
Senior Member
vBSEO Pre-Release TeamDesign for SEOBig Board Administrator
 
Real Name: Brian
Join Date: Apr 2006
Location: Central CT, USA
Posts: 5,538
IMO, these aren't even a big deal. you just need to be careful about what you click and when you click it. XSS are usually easy to detect/notice just by watching the status bar load
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #11  
Old 07-07-2008, 11:52 PM
Senior Member
 
Real Name: Derek
Join Date: Feb 2007
Location: USA, NJ
Posts: 271
Blog Entries: 3
Thanks for the info Brian. I didn't even know this.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #12  
Old 07-08-2008, 05:06 AM
Senior Member
Big Board Administrator
 
Real Name: Alex
Join Date: Mar 2007
Location: Italy
Posts: 163
Quote:
Originally Posted by hornstar6969 View Post

ps. I hope everyone here is using different admincp and modcp directories on there forums.
Hello, what you mean?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #13  
Old 07-08-2008, 05:35 AM
Shadab's Avatar
Senior Member
 
Real Name: Shadab
Join Date: Oct 2007
Location: Bhopal
Posts: 279
Blog Entries: 12
Send a message via ICQ to Shadab Send a message via MSN to Shadab Send a message via Yahoo to Shadab Send a message via Skype™ to Shadab
Quote:
Originally Posted by meonet View Post
Hello, what you mean?
Means changing the directories of Admin Control Panel and Moderation control panel.
The default are : admincp/ and modcp/

Changing them to something obscure like :

admincp-hackers-cant-get-here/
modcp-not-here-too/

should be good
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #14  
Old 07-08-2008, 09:14 AM
Senior Member
Big Board Administrator
 
Real Name: Alex
Join Date: Mar 2007
Location: Italy
Posts: 163
Quote:
Originally Posted by Shadab View Post
Means changing the directories of Admin Control Panel and Moderation control panel.
The default are : admincp/ and modcp/

Changing them to something obscure like :

admincp-hackers-cant-get-here/
modcp-not-here-too/

should be good
Oh ok thanks
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #15  
Old 07-08-2008, 04:23 PM
Michael Biddle's Avatar
vBSEO Staff
vBSEO Total Customer Support
 
Real Name: Michael Biddle
Join Date: Jan 2007
Location: Southern California
Posts: 3,014
Blog Entries: 5
However if you choose to do this, be sure that you update the path in your config.php
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
Reply

Tags
3.7

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
vBulletin 3.7.1 PL1 & 3.6.10 PL1 Released Joe Ward vBulletin.com Announcements 3 06-09-2008 01:31 PM
vBulletin 3.6.10 Released Joe Ward vBulletin.com Announcements 0 04-23-2008 02:00 PM
vBulletin 3.6.2 released Mert Gökçeimam Off-Topic & Chit Chat 9 10-05-2006 09:42 PM
vBulletin 3.6.1 Released 10085998 General Discussion 27 09-15-2006 11:57 PM
vBulletin 3.5.1, 3.0.10 Released Keith Cohen Off-Topic & Chit Chat 5 11-02-2005 12:17 PM


All times are GMT -4. The time now is 11:17 PM.


Powered by vBulletin Version 3.8.0 Beta 4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.5 ©2008, Crawlability, Inc.