منتدى استراحات زايد

منتدى استراحات زايد (http://vb.ma7room.com/index.php)
-   منتدى أخبار المواقع والمنتديات العربية والأجنبية (http://vb.ma7room.com/forumdisplay.php?f=183)
-   -   Issue with the ability to "impersonate" a user (http://vb.ma7room.com/showthread.php?t=505908)

محروم.كوم 09-08-2010 07:30 PM

Issue with the ability to "impersonate" a user
 
Over the past weekend, an issue was reported with vBulletin that may enable a user to "impersonate" another forum user.
  • The issue occurs if a user elects to register on a site with a username that mimics an existing username on the site but also contains "&" or "#" characters.
  • The possible implication is that it presents a possibility of this new username accidentally being the recipient of new PM's that are sent that were intended for the original user.
  • Testing has indicated that it is not possible for the new user to gain the original users password, access credentials, nor have access to any of their permissions, as a result we do not believe this issue to be a security concern.
  • The issue affects all versions of vBulletin prior to 3.8.5 and as we understand, has been reported previously, but we understand was not actioned on by vBulletin's development team at that point in time.
  • The issue's existence was unintentionally fixed as a result of this bug fix. This fix is not the permanent fix for this issue, however if you are operating a version 3.8.6 and newer, you are not affected by this concern.
  • We will be creating a more permanent fix via a patch that will prevent future creation of accounts that contain special Unicode characters and imitate an existing user account for vBulletin 3.7.7 and 3.8.6
  • Additionally you may prevent any issue arising by entering the following expression into the User Registration Options:
    vBulletin Options > vBulletin Options > User Registration Options > Username Regular Expression: ^[A-Za-z0-9 ]+$
    As a cautionary note, this will limit usernames to just containing alpha-numeric English characters, if you would like your userbase to utilize non-English characters, you may need to edit this regex appropriately.
    The permanent solution we will develop will not have this restriction on characters.
Thanks,
Adrian


الساعة الآن 12:39 PM

Powered by vBulletin® Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.2 TranZ By Almuhajir


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227