OT: High-severity vulnerability in vBulletin is being actively exploited

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts
  • caduceus
    Zag for Life
    • Mar 2007
    • 5158

    OT: High-severity vulnerability in vBulletin is being actively exploited

    I thought I posted this in the support forum, but I guess it ended up here. Apologies...mods move if appropriate. Would seem to be a serious issue though that could affect our board though.

    I hope the admins are paying attention:



    Attackers are mass-exploiting an anonymously disclosed vulnerability that makes it possible to take control of servers running vBulletin, one of the Internet’s most popular applications for website comments. Sites running the app should take comments offline until administrators install a patch that vBulletin developers released late Wednesday morning.

    The vulnerability was disclosed through an 18-line exploit that was published on Monday by an unidentified person. The exploit allows unauthenticated attackers to remotely execute malicious code on just about any vBulletin server running versions 5.0.0 up to 5.5.4. The vulnerability is so severe and easy to exploit that some critics have described it as a back door.

    “Essentially, any attack exploits a super simple command injection,” Ryan Seguin, a research engineer at Tenable, told Ars. “An attacker sends the payload, vBulletin then runs the command, and it responds back to the attacker with whatever they asked for. If an attacker issues a shell command as part of the injection, vBulletin will run Linux commands on its host with whatever user permissions vBulletins' system-level user account has access to.” Seguin has more in this technical analysis of the vulnerability.
    GUBoards is running version 4.2.2. Whether that's vulnerable, I don't know.
  • ZagsGoZags
    Zag for Life
    • Nov 2007
    • 4206

    #2
    thanks for bringing this up

    Comment

    • LongIslandZagFan
      Moderator
      • Feb 2007
      • 13951

      #3
      Originally posted by caduceus View Post
      I thought I posted this in the support forum, but I guess it ended up here. Apologies...mods move if appropriate. Would seem to be a serious issue though that could affect our board though.

      I hope the admins are paying attention:





      GUBoards is running version 4.2.2. Whether that's vulnerable, I don't know.

      Not sure if 4.2.2 is vulnerable or not. I am going to try and meet up with the SR folks when I am out next week. Thanks for posting this.
      "And Morrison? He did what All-Americans do. He shot daggers in the daylight and stole a win." - Steve Kelley (Seattle Times)

      "Gonzaga is a special place, with special people!" - Dan Dickau #21

      Foo me once shame on you, Foo me twice shame on me.

      2012 Foostrodamus - Foothsayer of Death

      Comment

      • GrizZAG
        Zag for Life
        • Nov 2009
        • 2395

        #4
        Keep us posted on what you learn LIZF, this is disconcerting for sure. Thanks
        One of the greatest stories in basketball history...Gonzaga!

        Comment

        Working...
        X