Influx and Lustrous Upgraded to vBulletin 4.1.4

Support Forum

vBulletin Skins, IPB Skins, phpBB Skins and SMF Skins Support Forum


Go Back   ForumThemes Forums > ForumThemes News & Announcements > Industry News

Follow ForumThemes on Twitter!
Acquiring Tweets
Follow us on Twitter!

Reply
 
LinkBack Thread Tools Display Modes
Old 09-08-2010, 06:37 PM   #1 (permalink)
Customer
  • Join Date: Jan 2009
  • Location: Canada
  • Posts: 1,949
  • User Status: Offline
  • Contact this user:

    Send a message via AIM to william Send a message via MSN to william


Exclamation Issue with the ability to "impersonate" a user

Over the past weekend, an issue was reported with vBulletin that may enable a user to "impersonate" another forum user.
  • The issue occurs if a user elects to register on a site with a username that mimics an existing username on the site but also contains "&" or "#" characters.
  • The possible implication is that it presents a possibility of this new username accidentally being the recipient of new PM's that are sent that were intended for the original user.
  • Testing has indicated that it is not possible for the new user to gain the original users password, access credentials, nor have access to any of their permissions, as a result we do not believe this issue to be a security concern.
  • The issue affects all versions of vBulletin prior to 3.8.5 and as we understand, has been reported previously, but we understand was not actioned on by vBulletin's development team at that point in time.
  • The issue's existence was unintentionally fixed as a result of this bug fix. This fix is not the permanent fix for this issue, however if you are operating a version 3.8.6 and newer, you are not affected by this concern.
  • We will be creating a more permanent fix via a patch that will prevent future creation of accounts that contain special Unicode characters and imitate an existing user account for vBulletin 3.7.7 and 3.8.6
  • Additionally you may prevent any issue arising by entering the following expression into the User Registration Options:
    vBulletin Options > vBulletin Options > User Registration Options > Username Regular Expression: ^[A-Za-z0-9 ]+$
    As a cautionary note, this will limit usernames to just containing alpha-numeric English characters, if you would like your userbase to utilize non-English characters, you may need to edit this regex appropriately.
    The permanent solution we will develop will not have this restriction on characters.
Thanks,
Adrian
  Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Privacy Issue with 4.0.4 and the Recent Threads Widget william Industry News 0 06-20-2010 09:48 PM
Now Testing the New vBulletin Issue Tracking System william Industry News 0 05-24-2010 07:43 PM
Migration of issue management to JIRA from project tools william Industry News 0 05-21-2010 12:35 AM

Powered by: vBulletin Versio3.8.7
Copyright ©2000 - 2012, Jelsoft Enterprises Limited.

SEO by vBSEO 3.3.0

1 2 3 4 5 6 7 8 9 10 11 12