Archive for July, 2010

The Boat’s Sinking and They’re Taking it Easy?

July 27th, 2010

I’ve been reading the recent comments and posts on vBulletin.com and I’ve heard several accusations of vBulletin Solutions Leadership taking vacations.

Recently hired manager Fabian and Don both have been on a break in recent weeks, according to several posts by customers.

My question: WHY THE HECK ARE THEY TAKING VACATIONS AT A TIME LIKE THIS?!!?

This is absolutely insane. The boat is burning. It’s sinking and the people at the helm feel they can take their sweet time getting things corrected and righted? All the while, customers are piling into life jackets and life boats, but still waiting for the wonderful leadership at Internet Brands to lower the boats to save their lives.

As a customer, I’m furious. They should not be taking a vacation right now. They need to right the wrongs now. They need to get everyone on the same page YESTERDAY instead of now. Reading what people like PirateReports have been posting have suggested they have absolutely no idea what’s going on and that they can’t decide which direction to go.

Here’s an idea. How about bringing customers who actually know what’s going on instead of pulling people who know absolutely nothing about the software or community?

Time’s ticking, and I think it’s time Internet Brands senior management start paying attention to what’s happening here. It’s not just our butts on the line, but theirs.

Oh yes, there’s a conference call in two days. Anyone want to ask questions? In particular to their wonderful security flaw that made the headlines of TheRegister, ZDNet, BBC and others? And especially where the heck they are going?

Start ‘Splaining

July 23rd, 2010

I want answers and I want them now. This is completely and utterly ridiculous. Absurd. A complete farce.

Never have I ever been so concern than I was two days ago. After watching this ridiculous security flaw unfold, and talking it over with Chronos, he made a strong point. HOW THE !@#$%& DO YOU SCREW UP A STABLE PLATFORM LIKE VBULLETIN 3.8?!?!!

We’ve had our fair share of vulnerabilities when vBulletin was under Jelsoft. They varied from Cross Site Request Forgeries, Cross Site Scripting Vulnerabilities and SQL Injections. NEVER EVER had I ever seen a vulnerability as bad as the one introduced by Internet Brands. A vulnerability that could potentially expose your SQL Username, SQL Password, SQL Server and SQL Port information? My God!

Vulnerabilities were at least contained strictly to the application itself, but now it has completely spread beyond the application and allowing script kiddies direct access into people’s database server.

I find that extremely unsettling. To err is human, to screw up a stable version of vBulletin requires Internet Brands.

More vBulletin Security Flaws – Yes Please, May I Have Another?

July 23rd, 2010

As many are now aware, a recent security flaw was discovered in vBulletin 3.8.6 which could potentially allow a hacker to gain crucial information such as the MySQL username and password. Although Internet Brands was quick to release a patch and fix this issue, the question still stands – How did this happen?

No doubt the die-hard IB fans will say it’s perfectly normal and expected that software have some bugs, as it’s part of the process, and I agree with this to a point, but to have a flaw as big as this is completely unacceptable. We’re not talking about a minor bug, we are talking about extremely critical administrator information being potentially exposed to anyone in a few simple steps to take advantage of this flaw. How does this make it past QA, and if they are missing flaws this extreme, what else lies beneath that we have yet to discover? With vBulletin 3 being as mature as it is, should we not have higher expectations, or is that asking too much?

Bravo, you have really outdone yourself this time Internet Brands.

What do the rest of you think? Is this something that’s acceptable or are we blowing this out of proportion?