Platinax
Internet: Internet Business and Marketing resources for the online entrepeneur
platinax internet: home internet community platinax business directory about platinax contact platinax

Great Britain and International
UK and International
Business Portal

For Entrepreneurs:

Home Forum Directory News Contact
 

 
 business articles and resources   Business
 marketing articles and resources   Marketing
 e-commerce articles and resources   E-commerce
 online security articles and resources   Security
 webhosting articles and resources   Webhosting
 webmaster articles and resources   Webmastering
 
Community Forums:
Web Resources:
 
Area: Marketing Resources
Chris Cardell

Marketing mistakes

How to destroy your business in five easy steps.

 
Area: SEO Resources
Mark Angelleti

Optimising Flash

Getting your Flash content indexed.

 
Area: Ecommerce Resources
john conde

Merchant Accounts

All about Credit Card Processing and Merchant Accounts.

 
Area: Internet Forum:
phpbb templates

phpbb templates

Resources for phpbb templates.

 
Area: News blog:
Brian Turner

General blog

General news and commentary.

 
Area: Business Directory:
Brian Turner

UK Webmaster

UK Webmaster listings in the business directory.

 
Area: Business Directory:
Brian Turner

Web hosting Directory

Web hosting Directory listings in the business directory.

 
Website Advertising


britecorp internet marketing, link building, SEO and webhosting services
Search Engine Optimisation


Company formation
Company Formation

PMC Office: monitors
Buy your next TFT Monitor from PMC Office


Finance market news
Financial Markets


PMC Telecom: digital telephones
Digital Telephones: special reductions


romantic cards



Advertise on Platinax



 
Dynamic Site Feeds:

Platinax Internet >> Platinax Internet News

Platinax Internet & Business News

Platinax Internet News


Internet and business news for the UK online



« Consumer Electronics Show: Fun in the rain at Las Vegas | Main | Economists expect sharp housing downturn »

January 08, 2005

vBulletin 3.0.5: security patch

In the wake of PHP vulnerabilities, and recent attacks by the Santy Worm, vBulletin have quickly released version 3.0.5 of their popular forum software.

Referring to this as a "critical" update, it is intended to replace all versions up to 3.0.4, which is reported to contain a serious security vulnerability.

PHPBB, a free open-source forum software, was recently targeted by a worm that used search engines to track down phpbb forums, before injecting malicious code into unpatched versions.

Here's a copy of the vBulletin security bulletin:



JELSOFT SECURITY BULLETIN
http://www.vbulletin.com/
January 7th, 2005

This email contains important security-related information.
Please read it carefully.

* vBulletin 3.0.4 / 3.0.5 Released
* Important Warning About Sensitive Data
* Security Issues in PHP 4.3.9, 5.0.2 & Older
* Your License Information
* Contact Us

------------ VBULLETIN 3.0.4 / 3.0.5 RELEASED ------------

The discovery of a serious security vulnerability in
versions of vBulletin 3 up to and including 3.0.4 has
necessitated the immediate release of a version to plug
the hole. This is a CRITICAL update, and we urge all
customers running affected software to upgrade vBulletin
with the utmost urgency.

vBulletin 3.0.5 includes all the updates recently released
as part of vBulletin 3.0.4, including a long list of fixes
for minor annoyances and bugs found since version 3.0.3.

vBulletin 3.0.5 is available for immediate download from
the vBulletin Members' Area.
http://www.vbulletin.com/members/

If you are unable to upgrade immediately, you should at
least download the patched version of includes/init.php
from the release announcement thread and replace your
existing version with it.

Please read the announcement for upgrade and installation
instructions, as well as the list of bugs fixed and other
changes:

http://www.vbulletin.com/forum/showthread.php?t=125480

--------- IMPORTANT WARNING ABOUT SENSITIVE DATA ---------

Due to the nature of the vulnerability discovered in
vBulletin 3, and as part of our ongoing effort to maximize
security, we must assume that one or all of the vBulletin
servers may have been compromised.

Therefore, we would STRONGLY RECOMMEND that any customers
who may have submitted sensitive data; such as vBulletin
admin control panel or server login details, to Jelsoft
staff in the past should take steps to alter these details,
so that any information that may have been accessed by an
unauthorized party could not be used.

We would like to reassure our customers that Jelsoft keeps
NO RECORD of credit card numbers used in transactions,
making it impossible for these details to be discovered or
abused.

Additionally, steps have been taken and are ongoing to
ensure that any potentially leaked data does not contain
sensitive data.

------ SECURITY ISSUES IN PHP 4.3.9, 5.0.2 & OLDER -------

The PHP development team recently released PHP 4.3.10 and
5.0.3 in order to patch serious security issues in previous
versions.

With the emergence of malicious code such as the
Santy/NeverEverNoSanity worms, which are responsible for
defacing and damaging a large number of sites, we join with
the PHP team in advising all customers running PHP versions
older than 4.3.10 or 5.0.3 to upgrade as soon as possible
to one of the patched versions.

Posted by at January 8, 2005 07:19 PM


> Discuss this in the Platinax Business forums



 

September 2005
S M T W T F S
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30  

Monthly Archives

Recent Entries

For comprehensive internet
media coverage:
Platinax News Extra

 

All content © Copyright 2004 Brian Turner. All rights reserved.
(excepting where copyright is indicated as otherwise)