Results 1 to 10 of 16

Thread: Site Status - Important - Please Read

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    PGD Staff code_glitch's Avatar
    Join Date
    Oct 2009
    Location
    UK (England, the bigger bit)
    Posts
    933
    Blog Entries
    45
    Ah... Indeed things have just sped up BIG time.
    I once tried to change the world. But they wouldn't give me the source code. Damned evil cunning.

  2. #2
    You may have a vulnerability, or they may think you still have it. If you haven't patched vBulletin for this, please do so at once, as you could be at risk for a data breach:

    http://www.securityfocus.com/bid/47281
    http://www.vbulletin.com/forum/showt...Security-Patch

    It is only about a month old.

  3. #3
    Quote Originally Posted by code_glitch View Post
    Ah... Indeed things have just sped up BIG time.
    I'm afraid not.
    No signature provided yet.

  4. #4
    PGD Staff code_glitch's Avatar
    Join Date
    Oct 2009
    Location
    UK (England, the bigger bit)
    Posts
    933
    Blog Entries
    45
    On my end they have sped up noticeably since athena posted that... I'm not getting an 404s from time outs and pages' load times now are like usual after a long delay rather than really slow after a long delay...
    I once tried to change the world. But they wouldn't give me the source code. Damned evil cunning.

  5. #5
    It's still slow on this end too. Pages take from 30 secs up to a minute to load.

  6. #6
    Still too slow for me to use. Browsing the forum is just frustrating, so I don't bother until someone fixes this.
    Coders rule nr 1: Face ur bugz.. dont cage them with code, kill'em with ur cursor.

  7. #7
    PGD Staff code_glitch's Avatar
    Join Date
    Oct 2009
    Location
    UK (England, the bigger bit)
    Posts
    933
    Blog Entries
    45
    Oh its frustrating I agree... But look on the bright side for us admins: no SPAM! YAY!
    I once tried to change the world. But they wouldn't give me the source code. Damned evil cunning.

  8. #8
    Yeah, but you could have much bigger problems brewing if vB is not patched to fix the vulnerability. Given the type of attacks you are experiencing, it looks like they are trying to exploit this vulnerability or one like it.

    Usually, the way these things go, a vulnerability is discovered by an automated scanner targeting a specific piece of site software, then, once found, it gets put on a list that gets shared on various hacker underground sites (potentially even sold), then the criminals take over and start attacking the site, looking for private information to exploit. Even if the vulnerability gets patched, the attacks may take a few days to a week to subside. The only thing that can be done is make 100% sure the webserver and associated app software is fully patched, clean/scan the server for rogue processes and rootkits, disable attacked facilities, and block DoSing IP addresses.

  9. #9
    Yeah, but you could have much bigger problems brewing if vB is not patched to fix the vulnerability. Given the type of attacks you are experiencing, it looks like they are trying to exploit this vulnerability or one like it.

    Usually, the way these things go, a vulnerability is discovered by an automated scanner targeting a specific piece of site software, then, once found, it gets put on a list that gets shared on various hacker underground sites (potentially even sold), then the criminals take over and start attacking the site, looking for private information to exploit. Even if the vulnerability gets patched, the attacks may take a few days to a week to subside. The only thing that can be done is make 100% sure the webserver and associated app software is fully patched, clean/scan the server for rogue processes and rootkits, disable attacked facilities, and block DoSing IP addresses.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •