For vBulletin 3.x Boards: Weak Password Hash Decryption Patch

Discussion in 'vBulletin Discussions' started by Mikey, Mar 23, 2010.

  1. Mikey

    Mikey Mikeylicio.us

    Joined:
    Sep 12, 2009
    Messages:
    484
    Likes Received:
    92
    Location:
    United Kingdom
    This is an untested (due to lack of documentation available) patch for board owners of the forum software vBulletin versions 3.7.6 and up, and vBulletin 3.8.x and up. Note please that I have not taken a look at the 4.0.x patch, so no clue if this works for 4.0.x board owners with now an expired license who can't upgrade.

    Disclaimer: As this is untested, it's also not supported, we do what we can. vBulletin will not support this modification, so be smart: Upgrade via the normal path, and/or patch if possible. And for **** sake: BACKUP your database AND your files.

    The wetalk.network grants distribution of these instructions, pending it was asked first, and that a link back to this thread is included for proper credits.

    Original source: For vBulletin 3.x Boards: Weak Password Hash Decryption Patch - vbfans.com
    Original announcement from vBulletin.com: Security Fix Releases 3.7.7 and 4.0.2 PL 2

    Instructions:

    Download: 37_38_security_patch_weak_passwords_hash_decryption.txt

    There we go :) I hope that helps a few people patch a security issue with their 3.7 / 3.8 board that decide or can't upgrade and still care about security. But if you ask me, this does NOT fix the actual issue. If they can decrypt the hash, they need the salt, but it shouldn't matter if this is 3 or 30 characters long. They would then already have it. They just need a larger rainbow table to check against.

    Special note for vBulletin 4 users who haven't patched or upgraded yet: At this point I would hold off, the define I read in the php file is set to 3 still. I suspect "another" fix to follow soon.
     
    2 people like this.
  2. Abomination

    Abomination Zealot

    Joined:
    Jun 1, 2009
    Messages:
    1,514
    Likes Received:
    102
    How is Floris involved? Thought this was downloadable from vb.com?

    :confused:
     
  3. Mikey

    Mikey Mikeylicio.us

    Joined:
    Sep 12, 2009
    Messages:
    484
    Likes Received:
    92
    Location:
    United Kingdom
    This is for people with expired licenses, vb.com didnt patch 3.8.5, only vb4.
     
  4. Abomination

    Abomination Zealot

    Joined:
    Jun 1, 2009
    Messages:
    1,514
    Likes Received:
    102
  5. Nick

    Nick Regular Member

    Joined:
    Jul 27, 2008
    Messages:
    7,441
    Likes Received:
    218
    If 3.8.5 doesn't include the patch, then I wonder why they mentioned this:

    Quite misleading, if you ask me. :shrug:
     
  6. kneel

    kneel Regular Member

    Joined:
    Jun 25, 2009
    Messages:
    612
    Likes Received:
    16
    thats what I was gonna ask...in the nicest way...not trying to sound like a prick...I'm just a huge fan of vb and this sparks my interest.
     
  7. Brandon

    Brandon Regular Member

    Joined:
    Jun 1, 2009
    Messages:
    6,602
    Likes Received:
    1,706
    Location:
    Topeka, Kansas
    First Name:
    Brandon
    looks like inet dropped the ball again
    leave it up to the community to clean up after them ;)
    I'll just upgrade to 3.8.5.
     
  8. Mikey

    Mikey Mikeylicio.us

    Joined:
    Sep 12, 2009
    Messages:
    484
    Likes Received:
    92
    Location:
    United Kingdom
    Copy/paste fail, unintentional, I've attached the patch now.

    Basically, there was a patch to vB3.8.4/5 which IB told no-one about, and expired owned license holders cannot access the patch, so Floris (owner of vbfans), has made his own patch free to all, it isn't the same one INET made, but it does the same job.

    Edit; Floris has gone into greater detail on the companies forums; http://www.vbulletin.com/forum/show...-expiring...&p=1951245&viewfull=1#post1951245
     
  9. MordyT

    MordyT Grand Master

    Joined:
    Dec 6, 2009
    Messages:
    529
    Likes Received:
    50
    First Name:
    Mordy
    Patched, thanks!
     
  10. Paul M

    Paul M Dr Pepper Addict

    Joined:
    Jun 16, 2009
    Messages:
    449
    Likes Received:
    136
    Location:
    Nottingham, UK
    3.8.5 does include this change, and always has. They then ported it to other versions.

    What they apparently didnt consider (or at least didnt mention) is what happens if you have 3.8.4, but no access to 3.8.5 (or indeed, if you have 3.7.6 and no access to 3.7.7 either).
     
  11. Nick

    Nick Regular Member

    Joined:
    Jul 27, 2008
    Messages:
    7,441
    Likes Received:
    218
    That post of mine was in response to post #3:

     

Share This Page