Welcome to WebmasterWorld Guest from 54.196.208.6

Forum Moderators: rogerd

Message Too Old, No Replies

Report: 35,000 vBulletin Sites Easily Hacked Through Failure To Follow Security Advice

     
2:11 pm on Oct 15, 2013 (gmt 0)

Administrator from GB 

WebmasterWorld Administrator engine is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month

joined:May 9, 2000
posts:22300
votes: 238


Attackers appear to have compromised tens of thousands of Web sites using a security weakness in sites powered by the forum software vBulletin, security experts warn.Report: 35,000 vBulletin Sites Easily Hacked Through Failure To Follow Security Advice [krebsonsecurity.com]
Internet Brands Inc. warned users that failing to remove the “/install” and “/core/install” directories on sites running 4.x and 5.x versions of the forum software could render them easily hackable.
3:57 pm on Nov 13, 2013 (gmt 0)

Senior Member

WebmasterWorld Senior Member 10+ Year Member

joined:Mar 4, 2004
posts:877
votes: 0


Certainly people not taking advice are not blameless but why not a simple check to see if the folder exists if it's that vulnerable?

You can't run a phpBB forum with the install folder present.