Page 2 of 2 FirstFirst 12
Results 11 to 13 of 13

Thread: Does Ubuntu Forum is still safe?

  1. #11
    Join Date
    Sep 2006
    Location
    France.
    Beans
    Hidden!
    Distro
    Ubuntu Mate 16.04 Xenial Xerus

    Re: Does Ubuntu Forum is still safe?

    samiux, we have already discussed this. Your concerns have been heard, so will you please stop here now ? Continuing pushing wont help much. Thanks.
    | My old and mostly abandoned blog |
    Linux user #413984 ; Ubuntu user #178
    J'aime les fraises.
    Nighty night me lovelies!

    | Reinstalling Ubuntu ? Please check this bug first ! |
    | Using a ppa ? Please install ppa-purge from universe, you may need it should you want to revert packages back |
    | No support requests / username changes by PM, thanks. |
    [SIGPIC][/SIGPIC]

  2. #12
    Join Date
    Jan 2011
    Beans
    117
    Distro
    Ubuntu

    Re: Does Ubuntu Forum is still safe?

    Quote Originally Posted by samiux View Post
    Hi Miguel,

    I will not test the Ubuntu Forums as I am not authorized to do so. I hope officials of Ubuntu Forums can assign Penetration Tester(s) to test the Ubuntu Forums in order to find out any potential vulnerabilities.

    The Inj3ct0r Team stated that they responsible to the attacks. They are criminals. One of my friends' web site has been kidnapped by the team last month.

    I am worrying that let's assume Ubuntu Forums admins find the vulnerabilities after the attack and they informed the vBulletin.com. The vBulletin.com fixed accordingly. The patch has been released but Macrumors.com did not fix the flaw(s) in time. So, the Macrumors.com is attacked in the same manner of Ubuntu Forums in July as it stated in facebook of Inj3ct0r Team. It is understandable.

    However, the Inj3ct0r Team stated that vBulletin.com is attacked via an undocumented vulnerability. Therefore, I suspect that Ubuntu Forums may have the same vulnerability of vBulletin.com too.

    The website(s) can be defensed if all the vulnerabilities have been discovered before the bad guy(s). Please refer to OWASP Top 10 2013 for details -- https://www.owasp.org/index.php/Cate...op_Ten_Project and their testing guide -- https://www.owasp.org/index.php/OWASP_Testing_Project

    Samiux
    Samiux
    The question was "inocent" please don't take me wrong...

    If this team is what you say (and I believe in you) I only hoppe people with responsability try to find if the forum soffer of this vulnarability, or if thhey can't do it, talk to some pentesters to do it...

    Regards and thks for the links

  3. #13
    Join Date
    Mar 2006
    Location
    Williams Lake
    Beans
    Hidden!
    Distro
    Ubuntu Development Release

    Re: Does Ubuntu Forum is still safe?

    Quote Originally Posted by miguelpires View Post
    Samiux
    The question was "inocent" please don't take me wrong...

    If this team is what you say (and I believe in you) I only hoppe people with responsability try to find if the forum soffer of this vulnarability, or if thhey can't do it, talk to some pentesters to do it...

    Regards and thks for the links
    Please read coffeecat's post here.

    If samiux wants to offer his services, he should contact Canonical, as posting here won't do any good.

    Thread Closed.

Page 2 of 2 FirstFirst 12

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •