ABXZone Computer  Forums



Welcome to the ABXZone Computer Forums forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Reply
 
LinkBack Thread Tools Display Modes
Old 01-04-2005, 05:25 PM   #1
Banned?
 
Join Date: Jan 2004
Location: New York City
Posts: 8,196
vBulletin 3.0.5

this question is directed more towards CJ (or maybe another mod knows the answer as well)...I was just curious if ABX will be upgrading to the newly released vBulletin 3.0.4...I hear it fixes a lot of bugs that are in the current version

Edit by PCB: Latest version is now 3.0.5, and it is considered a "critical" update. See post #6 in this thread for more info.
__________________
ASUS Maximus Formula (X38) ***** XFX GTX 260 Black Edition Core 216 896MB
Intel E8400
***** Noctua NH-U12P
G.Skill 4 GB (2 X 2 GB) DDR2 800 4-4-4-12 *****
Western Digital Caviar Black 640GB WD6401AALS
Lian Li PC-A70B (black)
***** Corsair HX850W
AuzenTech Auzen X-Fi Prelude 7.1 *****
Creative Inspire P5800 5.1 speakers
Sony Optiarc AD-7240S-0B
***** Sony GDM-F520 21' CRT monitor (19.8' viewable)
Vista Business 64-bit w/SP2 *****
standard 3.5" floppy drive
Microsoft Laser Mouse 6000 ***** Microsoft Wired Keyboard 500 (Black)

Last edited by PCBruiser; 01-18-2005 at 10:25 AM..
(Offline)   Reply With Quote

 
Old 01-18-2005, 09:17 AM   #2
Moderator
 
Join Date: Feb 2001
Location: Below sealevel
Posts: 9,663
I'm not aware of any plans to do this but I'm sure CJ will have a look at the changes. If there are any worthwhile fixes I'm sure we would upgrade.
__________________
Main Rig:
Asus P5K | Intel Core Quad Q6600 | Corsair XMS 6400-4gig
eVGA GeForce 8800 GTX KO ACS3 | X-Fi ExtremeMusic | Z-5500D
OCZ GameXstream 850W | ThermalTake Aguila | Logitech G-15
Logitech MX1000 | Synology DS-207+ NAS (2x500WD-SATA2-RAID0)
(Offline)   Reply With Quote
Old 01-18-2005, 09:18 AM   #3
ABX Public Relations
 
sammy2066's Avatar
 
Join Date: Nov 2003
Location: ABXZone.com
Posts: 8,696
i dont find much bugs in this version .... but in the process though, if we can give the site a new look and actually "implement" the new design contest thingi ... then it would be nice ....
__________________
Most users ever online was 1,377, 04-19-2006 at 10:31 PM.
(Offline)   Reply With Quote
Old 01-18-2005, 09:20 AM   #4
The Shade of Lazarus
 
KingTermite's Avatar
 
Join Date: Jun 2002
Location: PM me to keep in contact
Posts: 26,003
Looks like they are on 3.0.5 now.
http://www.vbulletin.com/forum/showt...?postid=791268
__________________

Bye Bye ABXZone.....Rest In Peace.
(Offline)   Reply With Quote
Old 01-18-2005, 09:21 AM   #5
Banned?
 
Join Date: Jan 2004
Location: New York City
Posts: 8,196
Quote:
Originally Posted by sλmmy2066
if we can give the site a new look and actually "implement" the new design contest thingi ... then it would be nice ....
Wow..I completely forgot about that design contest...what happened with the new design??...there were some nice design submissions if I remember...
__________________
ASUS Maximus Formula (X38) ***** XFX GTX 260 Black Edition Core 216 896MB
Intel E8400
***** Noctua NH-U12P
G.Skill 4 GB (2 X 2 GB) DDR2 800 4-4-4-12 *****
Western Digital Caviar Black 640GB WD6401AALS
Lian Li PC-A70B (black)
***** Corsair HX850W
AuzenTech Auzen X-Fi Prelude 7.1 *****
Creative Inspire P5800 5.1 speakers
Sony Optiarc AD-7240S-0B
***** Sony GDM-F520 21' CRT monitor (19.8' viewable)
Vista Business 64-bit w/SP2 *****
standard 3.5" floppy drive
Microsoft Laser Mouse 6000 ***** Microsoft Wired Keyboard 500 (Black)
(Offline)   Reply With Quote
Old 01-18-2005, 09:22 AM   #6
Banned?
 
Join Date: Jan 2004
Location: New York City
Posts: 8,196
Quote:
Originally Posted by KingTermite
The discovery of a serious security vulnerability in versions of vBulletin 3 up to and including 3.0.4 has necessitated the immediate release of a version to plug the hole.

The vulnerability affects anyone running vBulletin 3 on PHP 4 with register_globals enabled in php.ini.

This is a CRITICAL update, and urge all affected customers to upgrade vBulletin with the utmost urgency.
__________________
ASUS Maximus Formula (X38) ***** XFX GTX 260 Black Edition Core 216 896MB
Intel E8400
***** Noctua NH-U12P
G.Skill 4 GB (2 X 2 GB) DDR2 800 4-4-4-12 *****
Western Digital Caviar Black 640GB WD6401AALS
Lian Li PC-A70B (black)
***** Corsair HX850W
AuzenTech Auzen X-Fi Prelude 7.1 *****
Creative Inspire P5800 5.1 speakers
Sony Optiarc AD-7240S-0B
***** Sony GDM-F520 21' CRT monitor (19.8' viewable)
Vista Business 64-bit w/SP2 *****
standard 3.5" floppy drive
Microsoft Laser Mouse 6000 ***** Microsoft Wired Keyboard 500 (Black)
(Offline)   Reply With Quote
Old 01-18-2005, 10:06 AM   #7
The Shade of Lazarus
 
KingTermite's Avatar
 
Join Date: Jun 2002
Location: PM me to keep in contact
Posts: 26,003
Quote:
Originally Posted by polonyc2
The discovery of a serious security vulnerability in versions of vBulletin 3 up to and including 3.0.4 has necessitated the immediate release of a version to plug the hole.

The vulnerability affects anyone running vBulletin 3 on PHP 4 with register_globals enabled in php.ini.

This is a CRITICAL update, and urge all affected customers to upgrade vBulletin with the utmost urgency.
Yes, I remember that. I posted a news article on it.

Although, I thought the (root) problem was with PHP, although programs that use PHP may be able to plug the hole another way.
__________________

Bye Bye ABXZone.....Rest In Peace.
(Offline)   Reply With Quote
Old 01-18-2005, 10:11 AM   #8
Registered User
 
Join Date: May 2004
Location: Houston, TX
Posts: 204
Quote:
Originally Posted by KingTermite
Yes, I remember that. I posted a news article on it.

Although, I thought the (root) problem was with PHP, although programs that use PHP may be able to plug the hole another way.
Heh - any proggies that use register_globals on in php probably has the vulnerability. Like osc2nuke that I'm running. That's why it is default off now. Of course in vBulletin's forums they were dissing nuke because it was vulnerable (before their fix)
__________________
3500+, 1 Gb G.Skill PC4400 LE's, MSI K8N Neo4 Plat., OCZ Powerstream 520W, Yellow NZXT Guardian, X850 XT PE, Dual 15K SCSI, Maxtor 160GB, Polarflo TT, http://www.fx-57.com/watercool/ - http://www.fx-57.com/myrig/
(Offline)   Reply With Quote
Old 01-18-2005, 10:13 AM   #9
The Shade of Lazarus
 
KingTermite's Avatar
 
Join Date: Jun 2002
Location: PM me to keep in contact
Posts: 26,003
Quote:
Originally Posted by RAINFIRE
Heh - any proggies that use register_globals on in php probably has the vulnerability. Like osc2nuke that I'm running. That's why it is default off now. Of course in vBulletin's forums they were dissing nuke because it was vulnerable (before their fix)
Right....but what I mean is the "root" of the problem is in PHP itself. PHP is a language...so by itself its nothing. That's why "programs" that use it have the problem.
__________________

Bye Bye ABXZone.....Rest In Peace.
(Offline)   Reply With Quote
Old 01-18-2005, 10:16 AM   #10
Registered User
 
Join Date: Nov 2003
Posts: 13,497
polonyc2, I edited the thread title and added a comment in your first post just to highlight that the latest version is 3.0.5. I think this is something we should also do ASAP, but it needs testing first. One of the issues is whether we would have to redo the data base for ABX, I don't know the answer to that personally; but, if we do that is a big job, and ABX might have to be off-line during that process. In any case, it should be done to reduce our vunerabilities and add new bug fixes. I suppose CJ ought to check if a newer version is scheduled for release in the near future also. It would be a shame to go through all the work, only to have to do it again.
(Offline)   Reply With Quote
Old 01-18-2005, 10:17 AM   #11
ABX Public Relations
 
sammy2066's Avatar
 
Join Date: Nov 2003
Location: ABXZone.com
Posts: 8,696
i like new versions ....
__________________
Most users ever online was 1,377, 04-19-2006 at 10:31 PM.
(Offline)   Reply With Quote
Old 01-18-2005, 12:31 PM   #12
I'm gettin' dizzy!
 
Bofinn's Avatar
 
Join Date: Jan 2004
Location: Chicagoland
Posts: 11,078
Quote:
Originally Posted by sλmmy2066
i like new versions ....
we actually have a custom application named versions, that checks what package versions have been installed by SMS...
Attached Images
File Type: jpg versions.jpg (47.0 KB, 10 views)
__________________
---------- JimBo -----------



When in doubt, smack it!
(Offline)   Reply With Quote
Old 01-19-2005, 01:53 AM   #13
Banned?
 
Join Date: Jan 2004
Location: New York City
Posts: 8,196
vBulletin 3.0.6

vBulletin 3.0.6 and 2.3.6 are security and bug fix releases. They fix a recently discovered XSS issue regarding BB code parsing.

All versions of vBulletin prior to 3.0.6 and 2.3.6 are vulnerable. The only workaround is to disable BB code parsing in signatures and all forums where untrusted users can post.

*with all the recent security fixes, it seems like an even better reason for ABX to upgrade...I don't think most members would mind a little downtime to plug some critical security holes...better a little downtime rather then a major shutdown of the site

http://www.vbulletin.com/forum/showthread.php?t=127027
__________________
ASUS Maximus Formula (X38) ***** XFX GTX 260 Black Edition Core 216 896MB
Intel E8400
***** Noctua NH-U12P
G.Skill 4 GB (2 X 2 GB) DDR2 800 4-4-4-12 *****
Western Digital Caviar Black 640GB WD6401AALS
Lian Li PC-A70B (black)
***** Corsair HX850W
AuzenTech Auzen X-Fi Prelude 7.1 *****
Creative Inspire P5800 5.1 speakers
Sony Optiarc AD-7240S-0B
***** Sony GDM-F520 21' CRT monitor (19.8' viewable)
Vista Business 64-bit w/SP2 *****
standard 3.5" floppy drive
Microsoft Laser Mouse 6000 ***** Microsoft Wired Keyboard 500 (Black)

Last edited by polonyc2; 01-19-2005 at 02:01 AM..
(Offline)   Reply With Quote
Old 01-19-2005, 07:22 AM   #14
CJ
Former Site Ruler
 
CJ's Avatar
 
Join Date: Jan 2001
Location: Maryland
Posts: 2,535
FWIW,

I do install the security fixes. I just have not yet installed the full version. It is on my to do list and my goal is to get vb updated by the beginning of February.

CJ
(Offline)   Reply With Quote
Old 01-19-2005, 08:07 AM   #15
ABX Public Relations
 
sammy2066's Avatar
 
Join Date: Nov 2003
Location: ABXZone.com
Posts: 8,696
sounds good CJ .....
__________________
Most users ever online was 1,377, 04-19-2006 at 10:31 PM.
(Offline)   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




Powered by vBulletin® Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.1
vBulletin Skin developed by: vBStyles.com

© 2006 - 2009 ABXZone Forums | About ABX Zone Forums | Advertising Opportunities | Legal | A member of the Crowdgather Forum Community