Register Members List Search Today's Posts Mark Forums Read

Reply
 
Thread Tools
  #1  
Old 30 Dec 2014, 11:35
thetechgenius's Avatar
thetechgenius thetechgenius is offline
 
Join Date: Jun 2014
vB 4.1.4 - Vulnerable to SQL Injection?

So I have a few enemies online, and a few competitors.

One of them said they are going to hack my site using an SQL Injection Exploit. However, I think they are full of it. But just to be on the safe side, I thought I would post here to see what I can do to make sure it doesn't happen.
  • How would I find out if my vB 4.1.4 is vulnerable to SQL Injection?
  • If so, How would I fix that vulnerability if it is vulnerable?
  • Or maybe vB has nothing to do with SQL Injection?
  • Does it have to do with only my MySQL Server and/or PhpMyAdmin?

I also have an legit SSL Certificate, and have my site running on HTTPS throughout the entire site. I also have a legit wildcard subdomain SSL Certificate running on my PhpMyAdmin sub-domain, so my PhpMyAdmin sessions will be secure through an SSL Connection.

Note: I have my vB 4.1.4 running on my own Dedicated Server.

OS: Windows Server 2008 R2
CPU: Intel Xeon Quad Core CPU
RAM: 12GB ECC RAM
ISP: 90Mbps Download | 90Mbps Upload - Dedicated IP
NIC: 1 Gbps
Webserver: IIS 7.0 (Maybe 7.5, not really sure)
MySQL: Version 5.6
PhpMyAdmin: Version 4.1.9

If you need any more info, just ask. And thank you.
__________________
TheTechGenius.Net Official IRC Network (ONLINE)
Host: irc.thetechgenius.net
Port: 6667
TTG IRC Web Client - http://thetechgenius.net/irc.html
Reply With Quote
  #2  
Old 30 Dec 2014, 16:48
Dave Dave is offline
 
Join Date: Jun 2010
Real name: Dave
As far as I know there are no public exploits for 4.1.4, but you should upgrade to the latest version regardless. It's also possible that one of your plugins are vulnerable or that other software on your website is vulnerable.
__________________
https://technidev.com - security, development, exploits, vBulletin
dave[at]technidev[dot]com

Contact me for custom vBulletin 3/4 work & server/website management.
Reply With Quote
  #3  
Old 30 Dec 2014, 16:55
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Aug 2009
Real name: Chris
Anything below 4.2.2 pl2 has unpatched security vulnerabilitys.
__________________
You can get access to my 180 mods for vB 3.6 - 4.x at The Admin Zone as well as the professional support you are used to. New vBulletin Spider Definitions, vBulletin Spiders List Hits 1000 Spiders! ​ OzzModz down. Site has had a data breach, checking how the intrusion happened. Change your PW if you use the same one on my site and others.
Reply With Quote
  #4  
Old 30 Dec 2014, 17:00
thetechgenius's Avatar
thetechgenius thetechgenius is offline
 
Join Date: Jun 2014
The only problem is, I have a very custom Style installed. I payed EdenWebs for it. But they made it for 4.1.4, if I update to 4.2.2 then I need to also get the style updated for 4.2.2.
__________________
TheTechGenius.Net Official IRC Network (ONLINE)
Host: irc.thetechgenius.net
Port: 6667
TTG IRC Web Client - http://thetechgenius.net/irc.html
Reply With Quote
  #5  
Old 30 Dec 2014, 17:08
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Aug 2009
Real name: Chris
Yeah, that's a part of running a site unfortunately.
__________________
You can get access to my 180 mods for vB 3.6 - 4.x at The Admin Zone as well as the professional support you are used to. New vBulletin Spider Definitions, vBulletin Spiders List Hits 1000 Spiders! ​ OzzModz down. Site has had a data breach, checking how the intrusion happened. Change your PW if you use the same one on my site and others.
Reply With Quote
  #6  
Old 30 Dec 2014, 17:13
Brandon Sheley's Avatar
Brandon Sheley Brandon Sheley is offline
 
Join Date: Mar 2005
Real name: Brandon
You can post in the paid request forum asking if anyone can update the style. It's fairly painless for the most part, it just takes time to do correctly.
__________________

Email me for website help: brandon[at]sheley[dot]org
Reply With Quote
  #7  
Old 30 Dec 2014, 17:14
Dave Dave is offline
 
Join Date: Jun 2010
Real name: Dave
Well if you're very handy you could manually look at the changes of 4.1.4 vs the latest version and replace the code which will not affect the theme/templates. This will take a while and is rather difficult though. Upgrading would be the easiest.
__________________
https://technidev.com - security, development, exploits, vBulletin
dave[at]technidev[dot]com

Contact me for custom vBulletin 3/4 work & server/website management.
Reply With Quote
  #8  
Old 30 Dec 2014, 17:22
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Aug 2009
Real name: Chris
Yeah spending the time to upgrade is the best bet, trying to some half assed patching on your own in not the best solution.
__________________
You can get access to my 180 mods for vB 3.6 - 4.x at The Admin Zone as well as the professional support you are used to. New vBulletin Spider Definitions, vBulletin Spiders List Hits 1000 Spiders! ​ OzzModz down. Site has had a data breach, checking how the intrusion happened. Change your PW if you use the same one on my site and others.
Reply With Quote
  #9  
Old 30 Dec 2014, 17:42
thetechgenius's Avatar
thetechgenius thetechgenius is offline
 
Join Date: Jun 2014
Originally Posted by ozzy47 View Post
Yeah spending the time to upgrade is the best bet, trying to some half assed patching on your own in not the best solution.

Your right. Its better to be safe then sorry.

I think i might install a full backup of my forum on one of my Sub-Domains, and try to update it on a test sub-domain first. Just to see if it will break it or not. If everything is good, I will update on my live site. I will have the Sub-Domain directory setup with a password, because i know vBulletin doesn't allow 2 vBulletin installations with a single License.

If the update does break my forum, then I will have to find a way to update my style to work with 4.2.2.

Thank you Ozzy, your always helpful!

And thanks everyone else too. Its greatly appreciated!!
__________________
TheTechGenius.Net Official IRC Network (ONLINE)
Host: irc.thetechgenius.net
Port: 6667
TTG IRC Web Client - http://thetechgenius.net/irc.html
Reply With Quote
  #10  
Old 30 Dec 2014, 18:17
Dave Dave is offline
 
Join Date: Jun 2010
Real name: Dave
I'm sure it will be fine. Worst case scenario you have to make some minor template/CSS changes.
__________________
https://technidev.com - security, development, exploits, vBulletin
dave[at]technidev[dot]com

Contact me for custom vBulletin 3/4 work & server/website management.
Reply With Quote
  #11  
Old 30 Dec 2014, 18:57
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Aug 2009
Real name: Chris
Well the main thing I can think of you may have issues with the navigation. Pre 4.2.0 did not use the Navigation Manager.
__________________
You can get access to my 180 mods for vB 3.6 - 4.x at The Admin Zone as well as the professional support you are used to. New vBulletin Spider Definitions, vBulletin Spiders List Hits 1000 Spiders! ​ OzzModz down. Site has had a data breach, checking how the intrusion happened. Change your PW if you use the same one on my site and others.
Reply With Quote
  #12  
Old 30 Dec 2014, 19:14
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Real name: Lynne
Set up a test site and do an upgrade there first. Then you can modify your style, export it, and import it to the live site when you do the upgrade.
__________________
Former vBulletin.org Staff Member

Try a search before posting for help. Many users won't, and don't, help if the question has been answered several times before.
W3Schools -
Online vBulletin Manual
If I post some CSS and don't say where it goes, put it in the additional.css template.
I will NOT help via PM (you will be directed to post in the forums for help.)
Reply With Quote
  #13  
Old 30 Dec 2014, 19:24
thetechgenius's Avatar
thetechgenius thetechgenius is offline
 
Join Date: Jun 2014
Originally Posted by ozzy47 View Post
Well the main thing I can think of you may have issues with the navigation. Pre 4.2.0 did not use the Navigation Manager.
Your right. I have all my Nav Tabs coded manually in the navbar template. So when I do upgrade, I probably wont use the Navigation Manager, and just code my Nav Tabs in the navbar template. So I don't run into any issues in the long run, I think if I do it that way, it will be less of a hassle.

What do you guys/girls think?

You have to remember, it took a lot of time, money and A LOT of patience to get my forum exactly the way I want it. I custom coded a lot of the features on my forum, including a lot of the Profile, the entire Postbit Legacy, the user info bar at the top, the sticky user info bar at the top that scrolls with the page, a modified Login Menu, the javascript loading bar at the top that loads with the page, a custom ShortURL System (with another Top Level Domain), a custom coded Anonymous URL System (an updated version from the one I posted on vb.org), and MUCH MUCH more. lol

Like I said, it took a long time, a lot of work, and a lot of patience, to get my forum exactly the way I want it, without errors.
__________________
TheTechGenius.Net Official IRC Network (ONLINE)
Host: irc.thetechgenius.net
Port: 6667
TTG IRC Web Client - http://thetechgenius.net/irc.html

Last edited by thetechgenius; 30 Dec 2014 at 19:31.
Reply With Quote
  #14  
Old 30 Dec 2014, 19:46
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Aug 2009
Real name: Chris
It will take some work, but you are better off in the long run. Cause all the work you have done so far is no good if someone keeps hacking the site, because you did not upgrade.
__________________
You can get access to my 180 mods for vB 3.6 - 4.x at The Admin Zone as well as the professional support you are used to. New vBulletin Spider Definitions, vBulletin Spiders List Hits 1000 Spiders! ​ OzzModz down. Site has had a data breach, checking how the intrusion happened. Change your PW if you use the same one on my site and others.
Reply With Quote
  #15  
Old 30 Dec 2014, 20:15
kh99 kh99 is offline
 
Join Date: Aug 2009
Real name: Kevin
I don't remember what changes were in what version, but I know that there were some template changes made where I believe they got rid of some of the 'bit' templates and instead used a vb:each loop in the main template. But if you do as Lynne suggested then you'll see where you stand before committing to anything.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


New To Site? Need Help?

All times are GMT. The time now is 15:20.

Layout Options | Width: Wide Color: