Originally posted by malvolio
View Post
I'm tempted to buy vBulletin® to hunt around for this security hole, so I can report back to the owners of the code and get it closed ASAP - but if you are aware of such an issue, you really ought to report it yourself, as a responsible Internet citizen.
Of course you could be a wind-up merchant, or a scaremonger, in that there is no such security issue, and you're just trying to sow fear, uncertainty and doubt. That's not actually a very clever thing to do.
If there is such an issue, please PM me about it and I'll buy the source code, determine the origin of the problem, then get on to the vBulletin developers and have it fixed (or have my fix accepted).
Just to be clear, none of the matters discussed in this thread affect me personally, but security issues of the kind you suggest affect us all, and I am happy to expend both personal effort and personal money to get them fixed.
This benefits not only this, but all other, online communities that use the vBulletin software.
UPDATE: no, not a security problem it turns out

Comment