إنضمامك إلي منتديات استراحات زايد يحقق لك معرفة كل ماهو جديد في عالم الانترنت ...

انضم الينا
استراحات زايد الصفحة الرئيسية

         :: اسم هيا في المنام (آخر رد :نوران نور)       :: افضل شركة تنظيف منازل بالرياض مجربه | الفتح كلين سيرفيس (آخر رد :layansherief)       :: أهميتها وكيفية تنزيلها وتثبيتها (آخر رد :محمد العوضي)       :: حلمت اني لابسه فستان ابيض (آخر رد :نوران نور)       :: حول الألعاب وطرق تنزيلها (آخر رد :محمد العوضي)       :: افضل قهوجيين بالرياض 30% خصم | (آخر رد :layansherief)       :: رؤية القطط في المنام للمتزوجة لابن سيرين (آخر رد :نوران نور)       :: افضل شركة تركيب ستائر الكويت بخصم 13% | دليل شقردي (آخر رد :layansherief)       :: تفسير حلم المرايا (آخر رد :نوران نور)       :: افضل فني صباغ جدران بالكويت بخصم 20% | دليل شقردي (آخر رد :layansherief)      

إضافة رد
 
LinkBack أدوات الموضوع انواع عرض الموضوع
  #1  
قديم 03-22-2010, 10:00 PM
عضو ماسي
بيانات محروم.كوم
 رقم العضوية : 503
 تاريخ التسجيل : Dec 2007
الجنس : female
علم الدوله :
 المشاركات : 2,100,612
عدد الـنقاط :3341
 تقييم المستوى : 2139

The vBulletin development team has identified a potential issue with the strength of password encryption in vBulletin and we are implementing a patch to address this issue.

In certain rare cases, hackers can exploit a non-vBulletin vector (such as a bad plug-in) to access the vBulletin password database and attempt to decrypt administrator and user passwords.

In the cases we have investigated, if hackers are able to successfully exploit the password database, they focus on administrator usernames and passwords. Since many administrators work on multiple vBulletin sites, the hackers then search all vBulletin sites for a particular administrator username and attempt to log in with the corresponding password. They then access user tables and attempt to repeat the process across multiple vBulletin sites and cause widespread disruptions.

The patch changes the way password hashes are generated to prevent some methods of determining the password from the hash from working. Note that the new hashes are only generated when a password is changed. Therefore, we strongly advise changing all admin passwords immediately once the patch is applied. It is also strongly recommended that all users change their passwords as well.

To protect yourself from the vulnerability, you need to do the following:

If you are running VB 3.7.x, upgrade to version 3.7.7
If you are running VB 3.8.x upgrade to version 3.8.5
If you are running VB 4 version 4.0 or 4.0.1, upgrade to 4.0.2 PL 2

If you are running VB version 4.0.2 and 4.0.2 PL 1, the process is a little different.
1) Download the 4.0.2 PL 2 patch files.
2) Set your site to be offline.
3) Upload the patch files your vbulletin directory.
4) Run the url http://your.site.com/vBdirectory/ins...e_402_salt.php
5) Set your site to be online.


Note: If a user changes their password after the patch is uploaded, but before the upgrade_402_salt.php, then they will be unable to log in. The password will need to be reset after the upgrade_402_salt.php. Setting the site to be offline while the patch is applied will prevent users from changing their passwords during this interval.

The patch will not prevent all methods of obtaining the passwords from the hashes. Passwords that are weak or otherwise easily guessed can still be obtained. You should observe basic rules for password generation:

1) A minimum of 6 characters, with more being better
2) Use upper case, lower case, numbers, and punctuation characters in your password
3) Avoid words found in dictionaries, as these are often used to guess passwords

It is also strongly recommended that administrators who use the same username across multiple sites use different passwords for each site they log in to, because if the site you reuse a password on isn’t secure, the security of your site is still compromised.


The 4.0.2 PL 2, patch also fixes the XSS bug on the search pages. This bug does not exist in vBulletin 3.



Kevin
__DEFINE_LIKE_SHARE__
رد مع اقتباس
إضافة رد

مواقع النشر (المفضلة)


تعليمات المشاركة
لا تستطيع إضافة مواضيع جديدة
لا تستطيع الرد على المواضيع
لا تستطيع إرفاق ملفات
لا تستطيع تعديل مشاركاتك

BB code is متاحة
كود [IMG] متاحة
كود HTML معطلة
Trackbacks are متاحة
Pingbacks are متاحة
Refbacks are متاحة



الساعة الآن 05:01 PM


Powered by vBulletin® Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.2 TranZ By Almuhajir

RSS RSS 2.0 XML MAP HTML