Raised This Month: $51 Target: $400
 12% 

data breach? stop using EOL forum version


Post New Thread Reply   
 
Thread Tools Display Modes
Author Message
maidos
Junior Member
Join Date: Aug 2013
Old 06-12-2014 , 16:18   data breach? stop using EOL forum version
Reply With Quote #1

maybe u could had prevented the hack if u actually didnt use a outdated vbulletin version that is EOL already? vbulletin doesnt support 3.8.7 (which this site is using) so any security exploits posted on net wont be fixed by vbulletin company.

Last edited by maidos; 06-12-2014 at 16:24.
maidos is offline
fysiks
Veteran Member
Join Date: Sep 2007
Location: Flatland, USA
Old 06-12-2014 , 16:30   Re: data breach? stop using EOL forum version
Reply With Quote #2

The fact that an older version of vBulletin is being used has been discussed before and the discussion explains the reasons. I'm not saying that they are the most valid reasons, I'm just saying this has been discussed before. If you can find that thread, you will see the reasons. Just an FYI.
__________________
fysiks is offline
Backstabnoob
Veteran Member
Join Date: Feb 2009
Location: Iwotadai Dorm
Old 06-12-2014 , 16:38   Re: data breach? stop using EOL forum version
Reply With Quote #3

From what I recall, most of the reasons were of the "we don't like change" type.
__________________
Currently busy working on a very large scale anime database project.
Backstabnoob is offline
fysiks
Veteran Member
Join Date: Sep 2007
Location: Flatland, USA
Old 06-12-2014 , 16:41   Re: data breach? stop using EOL forum version
Reply With Quote #4

Quote:
Originally Posted by Backstabnoob View Post
From what I recall, most of the reasons were of the "we don't like change" type.
No, the biggest one was that there are customizations (that are required for our community) that would require significant redevelopment in a new version of vBulletin.
__________________

Last edited by fysiks; 06-12-2014 at 16:41.
fysiks is offline
hleV
Veteran Member
Join Date: Mar 2007
Location: Lithuania
Old 06-12-2014 , 17:35   Re: data breach? stop using EOL forum version
Reply With Quote #5

Considering how big this community is, I believe there should be changes, as in, vBulletin should be upgraded and the customizations redone.
__________________
hleV is offline
fysiks
Veteran Member
Join Date: Sep 2007
Location: Flatland, USA
Old 06-12-2014 , 18:52   Re: data breach? stop using EOL forum version
Reply With Quote #6

Quote:
Originally Posted by hleV View Post
Considering how big this community is, I believe there should be changes, as in, vBulletin should be upgraded and the customizations redone.
I agree but you need to find someone who knows how to do the required customizations first .
__________________
fysiks is offline
Jelle
[b]MOAR CANDY[/b]
Join Date: Aug 2009
Location: Denmark
Old 06-12-2014 , 18:55   Re: data breach? stop using EOL forum version
Reply With Quote #7

Quote:
Originally Posted by hleV View Post
Considering how big this community is, I believe there should be changes, as in, vBulletin should be upgraded and the customizations redone.
I doubt the guys who actually have to do the work feels the same way. For anyone it can be quite hard to pull out a month of work from their calendar.

I know, it's easy as a normal user to have the opinion that stuff should change, but considering it's all free work such thing is likely not to happen.

I would like a change too, it would be nice to see something different, but to be honest the forum does it's job quite well, and people are familiar with it. So with all that work that has to be put into it, the gains are just too small.
__________________
No idea what to write here...
Jelle is offline
Send a message via MSN to Jelle
hleV
Veteran Member
Join Date: Mar 2007
Location: Lithuania
Old 06-12-2014 , 19:04   Re: data breach? stop using EOL forum version
Reply With Quote #8

I never said the staff has to do it.
__________________
hleV is offline
YamiKaitou
Has a lovely bunch of coconuts
Join Date: Apr 2006
Location: Texas
Old 06-12-2014 , 19:22   Re: data breach? stop using EOL forum version
Reply With Quote #9

vBulletin does indeed still support 3.8.x, in fact they just patched it on March 13 2014
__________________
ProjectYami Laboratories

I do not browse the forums regularly anymore. If you need me for anything (asking questions or anything else), then PM me (be descriptive in your PM, message containing only a link to a thread will be ignored).
YamiKaitou is offline
asherkin
SourceMod Developer
Join Date: Aug 2009
Location: OnGameFrame()
Old 06-12-2014 , 19:31   Re: data breach? stop using EOL forum version
Reply With Quote #10

As I replied to you on Reddit:
Quote:
The vBulletin-related things in the attack (PHP code injection from the admin panel, and a less-than-stellar password hashing algorithm) are present in the latest release of vBulletin 5. There was no vBulletin exploit involved here.
We're capable developers and maintain a stack of security and functionality patches on top of vB - no exploit was involved here, it was a simple compromise of an administrator account, as was fully detailed in the email that went out to all members and the announcement at the top of every forum.

We've been evaluating moving away from vB 3.x for a very long time now, we're not ignoring the issues, but spreading FUD like blaming this issue on a vB 3.x security bug doesn't help anyone.
__________________
asherkin is offline
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 16:57.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode