Follow along with the video below to see how to install our site as a web app on your home screen.
Note: this_feature_currently_requires_accessing_site_using_safari
They can get the main administrator username password. Then they can get every users email and any other personal information they have given (for example, birthdate).The flaw in a specific version of the vBulletin software allows anyone to easily access the main administrator username and password for a site.
This would also allow hackers to access data, such as e-mail addresses, and edit the site at will.
The flaw affects version 3.8.6 of the software, which was released on 13 July.
The simple hack, which the BBC has confirmed, allows even unskilled people to access many websites.
With a few key strokes the person can obtain the administrator's username and password for the website.
This can be used to log in to the site and modify and delete elements at will.
David Ross, founder of Hexus.net, a technology news and reviews website, said the flaw was a "potential nightmare".
"It could allow someone to access all of the user accounts for the site," he said.
This would be useful to a hacker, he said, because it was "good quality information" that had already been verified.
I don't think there is anything to worry about, unless Munro or Pi hasn't been here to see the notice.Internet Brands announced a patch for the problem at 1900 BST on 21 July on its website.
It also sent e-mails to its customers and sent out a message that appeared on the main control panels of individual customers' software.
The article said they can get the raw username and password of the database user, not the administrator account (unless Im missing something)
The flaw in a specific version of the vBulletin software allows anyone to easily access the main administrator username and password for a site.
You're asking the wrong person.But how do they get the admin username and password when the password is hashed using MD5?
It has come to our attention that 3.8.6 contains a security exploit related to the FAQ
You're missing the second paragraph.
"The exploit allows a malicious user to retrieve a forum's database credentials."
"The flaw affects version 3.8.6 of the software, which was released on 13 July."
It's ok. Pi and Munro would never keep the forum code that up to date.
"The flaw affects version 3.8.6 of the software, which was released on 13 July."
It's ok. Pi and Munro would never keep the forum code that up to date.
You'll have noticed you needed to log in again today, all your cookies were stolen from the cookie jar by the cookie monster.
And also Munro installed the security patch.