English | VietNam
Home
About Us
Press Center
Products
Customers
Security Blog
Bkav Forum
Contact Us
Buy Online
Downloads
Virus, Spyware, Rootkit, Security
Critical vulnerability in vBulletin 3.8.6
11:12:10, 26/07/2010

1. General information

 

vBuletin, developed and released by vBulletin Solutions, is the most popular forum software on the Internet. On July 22, 2010, a critical vulnerability was found in this software. The flaw allows hacker to attack and take full control of the targeted forum database.

 

2. Technical details
 
vBulletin supports FAQ feature, which allows forum members to search for their information of interest in forum. The vulnerability is found in this feature.
 

Specifically, searching in FAQ with key words related to word "database" (such as "da",'ba", "se"...), the result will be all the forum database's information including IP address, service port, accounts and passwords. It is because vBulletin stores information related to database and FAQ on the same database table.

Exploiting this vulnerability, hackers are able to take control of forum's database for malicious purposes such as deleting or modifying the information in the forum's database. This vulnerability only exists in vBulletin version 3.8.6.

3. Solutions

Rating this vulnerability as critical, Bkis recommends individuals and organizations using vBulletin 3.8.6 immediately patch the flaw by following one of the two methods below:

Method 1:

1. Open file vbulletin-language.xml (in folder \upload\install), find and delete the following text:

<phrasename="database_ingo" date="1271086009"username="Jelsoft" version="3.8.5">

<![CDATA[

DatabaseName: {$vbulletin-> config['Database']['dbname']}

DatabaseHost: {$vbulletin->config['MasterServer']['servername']}

DatabasePort: {$vbulletin->config['MasterServer']['port']}

DatabaseUsername: {$vbulletin->config['MasterServer']['username']}

DatabasePassword: {$vbulletin->config['MasterServer']['password']}

]]>

</phrase>

2. Then import the edited vbulletin-language.xml as follow:

AdminCP -> Languages & Phrases -> Download/Upload Languages -> ImportLanguage XML File

Method 2:

Connect to database and perform the following SQL query:

DELETEFROM phrase WHERE varname = 'database_ingo' 

Bkis


  Other news:
  • Windows 7: Secure but still require users’ awareness
  • 39,000 computers in Vietnam lose network connection upon virus disinfection
  • Google exploited to spread virus
  • Virus posing as Microsoft to delete users’ data has emerged
  • Metamorphic virus Sality rages because of Shortcut vulnerability
  • Vulerability in Vbulletin 3.8.4 and 3.8.5
  • Microsoft Security Bulletin for March 2010
  • Vulnerability in processing marquee tag causes Firefox to crash
  • Security patches for January 2010
  • Microsoft Security Bulletin for December 2009

     Other news  
        
     News in focus
    Bkav: Want the world to know who we are

    Data of more than 85,000 computers in Vietnam has been stolen

    “We are underestimating cyber warfare”

    Safe Run Technology and Bkav 2011

    How your Yahoo! Accounts are stolen

    Bkav 2011 launching ceremony

    7,500 computers in Vietnam infected with “express” virus

    Bkav Enterprise deployed at Daewoo Hotel

    The definition of “filthy attack” does not exist

    Drop virus, swindle unlicensed Windows users for money

    Read more >>

      © 2010 Bkis - Internet Security
      Hitech Building, 1A Dai Co Viet Str., Hai Ba Trung Dist., Ha Noi, Vietnam  * Contact us
    © Please specify "source: Bkis" when using any information from this website.