Results 1 to 7 of 7

Potential security issue in all vB versions

This is a discussion on Potential security issue in all vB versions within the vBSEO Announcements forums, part of the Announcements & Pre-Sales category; Dear Customers, A possible security issue within vbulletin has been identified. There isn't a patch so to speak, so I ...

  1. #1
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,782
    Liked
    648 times
    Blog Entries
    2

    Potential security issue in all vB versions

    Dear Customers,

    A possible security issue within vbulletin has been identified. There isn't a patch so to speak, so I don't think vb will be making a release notice about this. I just want to make sure all of our customers are aware of the potential risk in leaving user names wide open.

    Floren brought this up here:
    Security flaw found in all vBulletin versions - Axivo Forums

    There is a discussion thread on vb about the issue here along with a regex fix for user names:
    vBulletin Community Forum


    The only fix available is to filter your usernames and allow only alphanumeric characters, when a guest tries to register.
    Go to vBulletin Options and select the User Registration Options menu.
    Into Username Regular Expression field, enter:
    Code:
    ^[a-zA-Z0-9@\._ ]+$



    My article written years ago uses a similar rule, but i allow just spaces instead of . _ and @ along with the space. With vbseo, spaces will turn into "-", and so will "_" in the url, so it's a good idea to not allow both spaces and any other semi-special character if you don't use id's in any member area rewrite settings. Your choice.

    Last edited by Brian Cummiskey; 09-04-2010 at 08:55 PM.
    Brian Cummiskey / Crawlability Inc.
    vBSEO 3.6.0 GOLD Released!
    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  2. #2
    Senior Member TECK's Avatar
    Real Name
    Floren Munteanu
    Join Date
    Apr 2006
    Location
    Canada
    Posts
    788
    Liked
    0 times
    Blog Entries
    2
    Thanks for informing the users, Brian.
    Floren Munteanu @ Axivo Inc.

  3. #3
    vBSEO Staff Andrés Durán Hewitt's Avatar
    Real Name
    Andrés Durán
    Join Date
    Jul 2009
    Location
    Costa Rica
    Posts
    3,152
    Liked
    371 times
    Blog Entries
    1
    Hello Brian,

    Thank you for informing us .

    Spanish customers:

    Riesgo de seguridad encontrado en versiones anteriores a vBulletin 3.8.6 PL1
    Andrés Durán / Crawlability Inc.
    ˇvBSEO 3.6.0 GOLD Liberado!
    Inaugurando el NUEVO vBSEO Sitemap Generator 3.0. - ˇAHORA disponible para Clientes de vBSEO!

    Síguenos en: Facebook | Síguenos en: Twitter


  4. #4
    Junior Member
    Real Name
    George
    Join Date
    Feb 2009
    Location
    Fall River, MA
    Posts
    4
    Liked
    0 times
    Thank you!

  5. #5
    Senior Member
    Real Name
    Jarod
    Join Date
    Oct 2006
    Location
    Italy
    Posts
    183
    Liked
    1 times
    Thank you for the news Brian

  6. #6
    Member
    Real Name
    moddis
    Join Date
    Jan 2008
    Posts
    39
    Liked
    0 times

    Smile

    So how would I turn this
    ^[a-zA-Z0-9@\._ ]+$

    into something that would be more optimal to be used with Vbseo like you said?
    Why is it a bad idea to allow @ and dot? Basically how should the above look if it only allows big small letters, numbers and _'s or space (whichever is better to use).

    Also, what would happen to all the users that already registered with using different types of characters?

    Thank You!

  7. #7
    vBSEO.com Webmaster Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    22,367
    Liked
    542 times
    Blog Entries
    4
    Please post all your questions about this issue on vBulletin.com

    Closing this thread as this discussion should be normally posted on vB.com and it should not exist on vBSEO.com at all.
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

Similar Threads

  1. vBulletin 3.x Security issue
    By Lagaf in forum Bug Reporting
    Replies: 308
    Last Post: 08-02-2010, 12:20 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •