Page 9 of 12 FirstFirst 1 2 3 4 5 6 7 8 9 10 11 12 LastLast
Results 121 to 135 of 170
Like Tree173Likes

*vBSEO Security Bulletin* All Supported Versions: Patch Release

This is a discussion on *vBSEO Security Bulletin* All Supported Versions: Patch Release within the vBSEO Announcements forums, part of the Announcements & Pre-Sales category; Originally Posted by Brian Cummiskey The download package is NOT infected. It's more likely that there is something in your ...

  1. #121
    Senior Member
    Real Name
    Matthias
    Join Date
    Mar 2009
    Posts
    376
    Liked
    19 times
    Quote Originally Posted by Brian Cummiskey View Post
    The download package is NOT infected. It's more likely that there is something in your datastore DB table that is re-populating the bad data. try looking in your config.XML file and/or the vb datastore table.
    Code:
     SELECT * 
    FROM datastore
    WHERE title LIKE  '%vbseo%'
    should be able to get the info out.
    Have you read the posts above? I guess we now know there the malicious code is from. http://www.vbseo.com/info/vbseo_checkver.php

    ?

  2. #122
    Junior Member
    Real Name
    Anthony Dragani
    Join Date
    Dec 2010
    Posts
    23
    Liked
    4 times
    Apparently they're so busy looking for the problem that they haven't been keeping up with this thread, and don't realize that the mystery has already been solved. :(

  3. #123
    Junior Member
    Real Name
    Liam
    Join Date
    May 2011
    Posts
    6
    Liked
    3 times
    Quote Originally Posted by Brian Cummiskey View Post
    The download package is NOT infected. It's more likely that there is something in your datastore DB table that is re-populating the bad data.
    I assume you wrote that before the first message was posted with this URL?
    http://www.vbseo.com/info/vbseo_checkver.js?ver=3.6.0

    As others have already noted, check the bottom of that page. The download package is fine. What's wrong is that the vBSEO control panel, when we access it on our forums, enables this code injection to happen from code on your own servers.

  4. #124
    Member
    Real Name
    afx1
    Join Date
    Sep 2006
    Posts
    54
    Liked
    0 times
    http://www.vbseo.com/info/vbseo_checkver.js?ver=3.6.0 is now blank, so they're obviously working on the issue now

  5. #125
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    A whole page happened while I was writing that. Sorry.

    The above has already been patched up on our site. That should show nothing now. We are looking in more detail into the cause of that issue.
    Kolbi likes this.
    Brian Cummiskey / Crawlability Inc.
    Security vbulletin - Patch Level for all supported versions released!

    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  6. #126
    vBSEO.com Webmaster Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,111
    Liked
    622 times
    Blog Entries
    4
    The issue about vBSEO version Check was fixed before me or Brian posting. Just clear your browser cache please.
    Kolbi likes this.
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  7. #127
    Junior Member
    Real Name
    Mark
    Join Date
    Aug 2008
    Posts
    13
    Liked
    15 times
    Quote Originally Posted by Kolbi View Post
    Have you read the posts above? I guess we now know there the malicious code is from. http://www.vbseo.com/info/vbseo_checkver.php

    ?
    They removed all content from the js file so nothing should be submitted to that php file anymore (hopefully). They should make an announcement and not try to stay silent about it, after all this was their fault and I spent hours trying to tell everyone that this vulnerability was still active, what did I get back? "clear your cookies, apply the patch, no you haven't applied the patch, change your passwords", god damnit, the patch was already applied on my forums since I first upgraded to 3.6.0 a very long time ago. What really surprises me is that the code snippet had been in their js file for months. My friend and I started looking into it, and when we were able to reproduce it by simply visiting vbseocp.php while being logged in as an administrator on the forum it became easier to track down. Nothing in the PHP files, the IP in webserver logs were our own (indicated that it was client-sided). Must say I was really surprised when find I found that in the javascript hosted on vbseo.com.

  8. #128
    Junior Member
    Real Name
    Drew
    Join Date
    Aug 2008
    Posts
    9
    Liked
    7 times
    Quote Originally Posted by Riverwire View Post
    Im sure people would rather the VBSEO guys spent their time to actually fix it rather than posting in the forums trying to reassure everyone. Let them get on with it and im sure everyone will be notified when they resolve the problem and let us know if there has been other damage done.
    You say "im sure" twice and they'll "let us know", but you don't know that. The thing is, a lot of companies don't unless they get caught or called out.

    As their customer, I am just requesting that they handle this professionally and they are not doing that.

    If you read my post, you'd see one at least one user was being passed off to vBulletin.com when it's obviously a vBSEO issue and they've known about it for a year. Although, in their defense, they thought it had been fixed.

    I don't want to clog up this thread, so feel free to disagree with me and we can talk in PMs or another thread if you want. I'll even edit my post and put a link to the thread if you'd like.

  9. #129
    Junior Member
    Real Name
    Drew
    Join Date
    Aug 2008
    Posts
    9
    Liked
    7 times
    Quote Originally Posted by Mert Gökçeimam View Post
    Without going further i can say that we as a team are extremely unhappy about the situation and trust us we are doing our best to identify the issue. It may not be an excuse but right now i have over 39 degrees body heat and i am working on this with the rest of the team to identify what happened. We will ask our CEO Juan Muriente to create an announcement and publish all details that we will identify.

    I also will like to apologize everyone in behalf of our team.
    Thank you for the update and apology. I hope you guys can get this worked out soon for everyone's sake.

  10. #130
    Junior Member
    Real Name
    Anthony Dragani
    Join Date
    Dec 2010
    Posts
    23
    Liked
    4 times
    Quote Originally Posted by Talaturen View Post
    They removed all content from the js file so nothing should be submitted to that php file anymore (hopefully). What really surprises me is that the code snippet had been in their js file for months.
    Talaturen,

    Thanks for figuring out this mess.

    Could you explain how this exploit was getting from the vbseo.com servers onto our sites?

    Thanks!

  11. #131
    Junior Member Riverwire's Avatar
    Real Name
    Adam
    Join Date
    Apr 2008
    Posts
    25
    Liked
    0 times
    Quote Originally Posted by neowave View Post
    You say "im sure" twice and they'll "let us know", but you don't know that. The thing is, a lot of companies don't unless they get caught or called out.

    As their customer, I am just requesting that they handle this professionally and they are not doing that.

    If you read my post, you'd see one at least one user was being passed off to vBulletin.com when it's obviously a vBSEO issue and they've known about it for a year. Although, in their defense, they thought it had been fixed.

    I don't want to clog up this thread, so feel free to disagree with me and we can talk in PMs or another thread if you want. I'll even edit my post and put a link to the thread if you'd like.
    I agree with you and being a holder of 13 licences in a couple of different accounts i have put my fare share into VBSEO, However my point is that with everyone demanding responses its not going to get this solved any quicker.

  12. #132
    Junior Member
    Real Name
    Mark
    Join Date
    Aug 2008
    Posts
    13
    Liked
    15 times
    Quote Originally Posted by DelDrago View Post
    Talaturen,

    Thanks for figuring out this mess.

    Could you explain how this exploit was getting from the vbseo.com servers onto our sites?

    Thanks!
    The javascript on vbseo.com is embedded in vbseocp.php, so when you visit that page your web browser will load it, and at the end of that script was the malicious code. It made you submit a request to your own forum that added the plugin, and besides that it also sent your forum URL to http://www.vbseo.com/info/vbseo_checkver.php (which most likely forwarded your forum URL to the hackers, I can't know because that part is server-sided).

  13. #133
    Member
    Real Name
    Tim
    Join Date
    Jan 2012
    Posts
    82
    Liked
    1 times
    Just get it figured out guys, do what you need to do and then let us know what we need to do on this end, especially us newbies. At this point I don't have a clue as to what and how much is compromised, but want to make sure my data and website are protected. So when you get all the pieces of the puzzle put together, you may have to lead me (maybe others) step by step to make sure we are secure.

  14. #134
    kau
    kau is offline
    Senior Member
    Real Name
    Alan
    Join Date
    Aug 2006
    Posts
    104
    Liked
    0 times
    I'm lost.

    Can someone give the cliffnotes on what was found.

    vBSEO had a Javascript file that scanned all our sites for exploits and listed which ones were exploitable?

    Then IT created the plugin or a hacker just used the list?

  15. #135
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    The version checker Js is what does the call back to our servers to generate your license key by domain and to make sure your install is valid at first run. I don't have any more details at the moment. Please be assured that we are doing all we can as fast as we can to get this whole thing sorted.

Page 9 of 12 FirstFirst 1 2 3 4 5 6 7 8 9 10 11 12 LastLast

Similar Threads

  1. Replies: 135
    Last Post: 02-24-2011, 07:45 AM
  2. Security Patch Release 3.8.6 PL1
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 3
    Last Post: 07-23-2010, 06:27 AM
  3. Security Patch Release 4.0.2 PL3
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 0
    Last Post: 03-25-2010, 12:50 PM
  4. JELSOFT SECURITY BULLETIN - vBulletin 3.6.8 Patch Level 1 Released
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 0
    Last Post: 11-08-2007, 02:38 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •