Exploit found in Yahoo YUI Uploader affecting VB4 and VB5 forums

Discussion in 'vBulletin Discussions' started by BirdOPrey5, Jan 3, 2014.

  1. BirdOPrey5

    BirdOPrey5 #Awesome

    Joined:
    Jul 16, 2011
    Messages:
    343
    Likes Received:
    105
    Location:
    New York
    First Name:
    Joe
    http://www.vbulletin.com/forum/foru...4388-yui-security-issue-found-in-uploader-swf

    Basically you need to overwrite clientscript/yui/uploader/assets/uploader.swf file with a blank/empty file of the same name.

    This will force VB4 to use the AJAX/JavaScript uploader instead.

    VB5 has the file but doesn't use it so no functionality will be lost in VB5, but VB4 users will lose the flash uploader.

    Yahoo says they will not be fixing the issue.

    VB3 is unaffected.
     
    too_cool_3 and Dan Hutter like this.
  2. AWS

    AWS Administrator

    Joined:
    Feb 1, 2010
    Messages:
    1,616
    Likes Received:
    692
    Location:
    Joliet, IL U.S.A.
    First Name:
    Bob
    Thanks Joe. This should affect a few products. I think others also use this.
     
  3. BirdOPrey5

    BirdOPrey5 #Awesome

    Joined:
    Jul 16, 2011
    Messages:
    343
    Likes Received:
    105
    Location:
    New York
    First Name:
    Joe
    Typo'ed the title- can't seem to fix it. :( Foung = Found, obviously. :oops:
     
    Last edited: Jan 3, 2014
  4. AWS

    AWS Administrator

    Joined:
    Feb 1, 2010
    Messages:
    1,616
    Likes Received:
    692
    Location:
    Joliet, IL U.S.A.
    First Name:
    Bob
    Fixed. Got to check permissions too while I'm at it. You should have edit permissions on the title.
     
    BirdOPrey5 likes this.
  5. zappaDPJ

    zappaDPJ Regular Member

    Joined:
    May 27, 2013
    Messages:
    250
    Likes Received:
    165
    Location:
    London, England
    Does anybody know what effect this will have on the functionality of the asset manager if any?
     
  6. BirdOPrey5

    BirdOPrey5 #Awesome

    Joined:
    Jul 16, 2011
    Messages:
    343
    Likes Received:
    105
    Location:
    New York
    First Name:
    Joe
    The asset manager continues to work, just uploads will be done via the AJAX form rather than the flash uploader.
     
    zappaDPJ likes this.
  7. jmurrayhead

    jmurrayhead Regular Member

    Joined:
    Jun 7, 2012
    Messages:
    153
    Likes Received:
    113
    Location:
    Alexandria, VA
    First Name:
    Jason
    I wonder why Yahoo decided not to fix the issue...are they working on a replacement?
     
  8. BirdOPrey5

    BirdOPrey5 #Awesome

    Joined:
    Jul 16, 2011
    Messages:
    343
    Likes Received:
    105
    Location:
    New York
    First Name:
    Joe
    Yahoo considers YUI 2.x end of life. They have YUI 3.x out but they do longer have a flash based uploader in YUI 3.x.
     
  9. jmurrayhead

    jmurrayhead Regular Member

    Joined:
    Jun 7, 2012
    Messages:
    153
    Likes Received:
    113
    Location:
    Alexandria, VA
    First Name:
    Jason
    Got ya, so basically vBulletin just needs to update to later version.
     
  10. zappaDPJ

    zappaDPJ Regular Member

    Joined:
    May 27, 2013
    Messages:
    250
    Likes Received:
    165
    Location:
    London, England
    OK, thanks, no disruption to my users then.
     
  11. BamaStangGuy

    BamaStangGuy Administrator

    Joined:
    Jun 23, 2009
    Messages:
    769
    Likes Received:
    549
    Location:
    Huntsville, AL
  12. zappaDPJ

    zappaDPJ Regular Member

    Joined:
    May 27, 2013
    Messages:
    250
    Likes Received:
    165
    Location:
    London, England
    That's odd, I'm fairly sure I didn't quote myself in that post.
     
  13. WEfail

    WEfail Regular Member

    Joined:
    Sep 9, 2012
    Messages:
    77
    Likes Received:
    179
    Fixed this yesterday. Not sure why VB doesnt list the exploit in the admincp. Another fail.
     
  14. Dan Hutter

    Dan Hutter aka Big Dan

    Joined:
    Jul 20, 2006
    Messages:
    1,412
    Likes Received:
    515
    Location:
    New York
    Thanks for the post @BirdOPrey5 as I haven't followed the vB.com boards in quite a while. I patched my clients boards.
     
  15. WEfail

    WEfail Regular Member

    Joined:
    Sep 9, 2012
    Messages:
    77
    Likes Received:
    179
    Birdofprey is amazing.
     
  16. Alfa1

    Alfa1 Regular Member

    Joined:
    Jul 24, 2009
    Messages:
    303
    Likes Received:
    196
    Yes, that was in 2009. vb4 & vb5 were released after YUI3.
     
  17. BirdOPrey5

    BirdOPrey5 #Awesome

    Joined:
    Jul 16, 2011
    Messages:
    343
    Likes Received:
    105
    Location:
    New York
    First Name:
    Joe
    YUI 3 beat VB4 by just a couple months... Couldn't throw everything out and change to YUI 3 at that point.
     
  18. NixFifty

    NixFifty Regular Member

    Joined:
    Feb 18, 2013
    Messages:
    4
    Likes Received:
    3
    Weekend? :)
     
  19. Alfa1

    Alfa1 Regular Member

    Joined:
    Jul 24, 2009
    Messages:
    303
    Likes Received:
    196
    I actually warned vbulletin about the issue long before that, as YUI2 beta releases were already flowing and at that time there also was a YUI2 exploit.
    At that time the wisest decision would have been to implement jQuery instead. Back then it was already clear that jQuery was the future.
     
  20. Peace

    Peace Regular Member

    Joined:
    Jul 5, 2013
    Messages:
    100
    Likes Received:
    58
    BirdOPrey5 likes this.

Share This Page