<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Axivo Forums</title>
		<link>http://www.axivo.com/forum/</link>
		<description>This is a discussion forum related to latest products and services offered by Axivo Inc.</description>
		<language>en</language>
		<lastBuildDate>Thu, 09 Sep 2010 16:33:37 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://www.axivo.com/forum/images/misc/rss.jpg</url>
			<title>Axivo Forums</title>
			<link>http://www.axivo.com/forum/</link>
		</image>
		<item>
			<title>Security flaw found in all vBulletin versions</title>
			<link>http://www.axivo.com/forum/showthread.php?t=138&amp;goto=newpost</link>
			<pubDate>Sat, 04 Sep 2010 21:40:54 GMT</pubDate>
			<description>Following on from an exploit created by an Iranian Security group, it would appear that *any* vBulletin version below 3.8.6 PL1 is vulnerable, not...</description>
			<content:encoded><![CDATA[<div>Following on from an exploit created by an Iranian Security group, it would appear that <b>any</b> vBulletin version below 3.8.6 PL1 is vulnerable, not just the ones listed in the exploit documentation.<br />
<br />
Basically, if I'm an administrator (Floren <i>uid 1</i>), the hacker can generate a registered user (Floren <i>uid 3856</i>).<br />
<br />
If you allow the <i>Registered Users</i> group to change their user title, the hacker can impersonate any admin and start posting fake announcements, or simply emulate your posting behavior like replying to public threads, etc. The group permissions still apply, so no direct abuse can be inflicted to forum. However, since the impersonator's username is identical to yours, he/she will start receiving your PM's also, gaining privacy control over all data sent to you.<br />
<br />
The only fix available is to filter your usernames and allow only alphanumeric characters, when a guest tries to register.<br />
Go to vBulletin Options and select the <i>User Registration Options</i> menu.<br />
Into <i>Username Regular Expression</i> field, enter:<br />
<font face="Courier New">^[a-zA-Z0-9@\._ ]+$</font><br />
<br />
This regular expression will allow new usernames to contain only alphanumeric characters, as well the @, dot, underscore and space symbols. You can add other symbols, if you like. <font color="Blue">The regex is used to stop a guest registering an username containing the &amp; and # characters. </font>The exploit use those characters to generate a fake username identical to an existing forum member. Unfortunately, the regex fix will affect all forums who allow unicode characters into usernames.<br />
<br />
I recommend you to apply the modification, as soon as possible.</div>

]]></content:encoded>
			<category domain="http://www.axivo.com/forum/forumdisplay.php?f=15">Tutorials and Reviews</category>
			<dc:creator>Floren</dc:creator>
			<guid isPermaLink="true">http://www.axivo.com/forum/showthread.php?t=138</guid>
		</item>
		<item>
			<title>Question about getdaily and getnew</title>
			<link>http://www.axivo.com/forum/showthread.php?t=133&amp;goto=newpost</link>
			<pubDate>Tue, 31 Aug 2010 18:42:04 GMT</pubDate>
			<description>Floren, 
 
Finally installed at automotiveforums.com - the search is awesome. 
 
However, while any keyword search is blazing fast (~0.2 seconds)....</description>
			<content:encoded><![CDATA[<div>Floren,<br />
<br />
Finally installed at automotiveforums.com - the search is awesome.<br />
<br />
However, while any keyword search is blazing fast (~0.2 seconds).<br />
search.php?do=getdaily and getnew for some reason take well over 3 seconds every time.<br />
<br />
Are the settings incorrect somewhere? Is there an explanation for this? I am wondering if Searchlight is being used for these queries.<br />
<br />
Thanks!<br />
<br />
Igor</div>

]]></content:encoded>
			<category domain="http://www.axivo.com/forum/forumdisplay.php?f=20">General Discussions</category>
			<dc:creator>igor@af</dc:creator>
			<guid isPermaLink="true">http://www.axivo.com/forum/showthread.php?t=133</guid>
		</item>
	</channel>
</rss>
