Start ‘Splaining

I want answers and I want them now. This is completely and utterly ridiculous. Absurd. A complete farce.

Never have I ever been so concern than I was two days ago. After watching this ridiculous security flaw unfold, and talking it over with Chronos, he made a strong point. HOW THE !@#$%& DO YOU SCREW UP A STABLE PLATFORM LIKE VBULLETIN 3.8?!?!!

We’ve had our fair share of vulnerabilities when vBulletin was under Jelsoft. They varied from Cross Site Request Forgeries, Cross Site Scripting Vulnerabilities and SQL Injections. NEVER EVER had I ever seen a vulnerability as bad as the one introduced by Internet Brands. A vulnerability that could potentially expose your SQL Username, SQL Password, SQL Server and SQL Port information? My God!

Vulnerabilities were at least contained strictly to the application itself, but now it has completely spread beyond the application and allowing script kiddies direct access into people’s database server.

I find that extremely unsettling. To err is human, to screw up a stable version of vBulletin requires Internet Brands.

More vBulletin Security Flaws – Yes Please, May I Have Another?

As many are now aware, a recent security flaw was discovered in vBulletin 3.8.6 which could potentially allow a hacker to gain crucial information such as the MySQL username and password. Although Internet Brands was quick to release a patch and fix this issue, the question still stands – How did this happen?

No doubt the die-hard IB fans will say it’s perfectly normal and expected that software have some bugs, as it’s part of the process, and I agree with this to a point, but to have a flaw as big as this is completely unacceptable. We’re not talking about a minor bug, we are talking about extremely critical administrator information being potentially exposed to anyone in a few simple steps to take advantage of this flaw. How does this make it past QA, and if they are missing flaws this extreme, what else lies beneath that we have yet to discover? With vBulletin 3 being as mature as it is, should we not have higher expectations, or is that asking too much?

Bravo, you have really outdone yourself this time Internet Brands.

What do the rest of you think? Is this something that’s acceptable or are we blowing this out of proportion?

Internet Brands’s and vBulletin 4’s State of Affairs? – by DJ RRebel

Just wondering what the opinion is of some of you long time members on what you feel about vB4?

Personally I was really frustrated with the way everything wasn’t fully thought through when they added the social networking a couple of years ago. I stood up screaming at some of the obvious problems and sure enough most of the things I mentioned would be problems turned out to be problems (but at least 90% addressed from what I can tell).

To say this left me rather frustrated was an understatement. I’m looking at starting a new site, but am seeing the same frustrating pattern as in the past. What really boggled my mind is that vB put a gold label on a product that clearly wasn’t gold! From what I can tell from some of the discussions going on in various threads is that vB4 still isn’t really a “gold” product.

I haven’t installed or played/tested it yet .. So my question simply falls to some of you regular participants here who can give me an honest opinion .. Is vB 4.0.2 what you would consider Gold?

Meaning are there so many bugs, issues and things “they are working to improve” that each update is more of a major upgrade needing to revert 30+ templates among other things?

I see complaints of search not being very user friendly, as well as the asset manager being frustrating to new end users .. are these claims legit .. or are they just the usual complainers from those who complain about anything?

I did look around and ticker around here a couple of months ago when it went gold and was frustrated that as much as I like vB .. vB4 clearly did not merit the gold status it was given and was still Beta in my mind. I could spend a couple of days tinkering again .. but at this point I can’t be bothered wasting the time and would like a simple paragraph or two from some of you summarizing your experience with vB4.0.2 and whether you feel it’s a product worthy of Gold status and thus worthy of my time in developing a new site around it .. or do you feel it’s not really “gold” and that I might be better off waiting a little longer for the product to stabilize a bit more?

Cross Site Scripting Vulnerability for Internet Brands vBulletin 4.0.2 Patch Level 1

Vendor: Internet Brands (Nasdaq: INET)
Software: vBulletin
Version: 4.0.2 Patch Level 1
Type: Cross Site Scripting

[+] Discovered By: 5ubzer0
[+] My id : http://inj3ct0r.com/author/2307
[+] Original : http://inj3ct0r.com/exploits/9697
# Version: Vbulletin 4.0.2

www.site.com/path/search.php?search_type=1&contenttype=vBBlog_BlogEntry&query=">
<script>alert('xss');</script>
www.site.com/path/search.php?search_type=1&contenttype=vBBlog_BlogEntry&query=">
<script>alert(document.cookie);</script>

Marmite. – by Carnage-

You either love it or hate it, right?

It seems that the same can be said for vbulletin 4 and its starting to bug me. On one side you’ve got dozens of threads proclaiming “upgrading to vb4 was the worst mistake i’ve ever made” and “why i ditched vb4” etc. On the other side, you’ve got a handful of people who are defending Ib/vbulletin to greater or lesser extents; some to almost religious proportions. I want to have my say, a more realistic view on vb4 without it getting burried in another ‘omg vb4 sucks’ type thread.

1. vBulletin 4 has bugs; probably more than any released vbulletin version in the past however this is probably due in part to far greater scruitiny of the code, the bug tracker is more active so more stuff is being reported. The other major cause is the fact that vbulletin 4 was rushed out, this was almost certainally done for ‘shareholder’ reasons and I feel it was a shame that this happened. If I were a shareholder, I’d be far more interested in keeping the reputation of the brand up instead of making a quick buck in the short term.

2. Stylevars. Probably one of the biggest causes of complaints. I agree that the system is totally useless, however one of my admins described it thus: ‘Its not ****, its just extreamly verbose.’ I agree with this fully; As a coder, I’ve dug into the style vars system the concept is great, the implemntation is well… lacking. I could go into how and why but thats a tl;dr in and of itself.

3. vB4 itself. A lot of people are ‘holding off on upgrades till its better’ I’ve seen complaints that traffic has dropped on sites that have upgraded already. I upgraded my boards a couple of weeks ago and have seen no sigificant changes in traffic, positive or negative. The only complaints i’ve had from my members is the fact that most of the skins have not yet been converted to vb4. As far as the forum goes, there were a couple of minor issues, nothing site killing mostly style related.

Myself, I’m pleased with vbulletin 4 the upgrade has given a breath of life into a few areas of the forums and I’m hoping that activity will pick up more significantly in the coming weeks after I’ve launched the CMS. The new framework looks promising from a development point of view; I’ve already put together the begginings of my own webcomic content type and written some widgets. For the longer term i’ve sketched out plans for a store mod. The framework needs work, but its almost certainally going to be good to work with once the kinks are worked out.

I think what i’m trying to say here is that there are too many people saying vb4 is a disaster and not enough people giving a realistic view – it works for me, its not spectacular but it does its job.

My last day as an Internet Brands’s “licensed customer”. by texterted

I’m sad to go, in a way, as I loved the old regime and was happy with the 3x series and really looking forward to the 4x series.

I moved my site across to IPS last July after the “leak” fiasco. They gave me a free conversion to their platform and my user base and myself as admin, quickly adapted without much trouble and sulking.

Since then I have started another two forums both running on IPS software. So things are looking positive, which is nice.

I could only voice my discontent, at the direction that IB was taking us, with my feet and my wallet. I did this and went elsewhere for my forum solutions. I still don’t understand the business mind that IB has and why it should seem to actively want to reduce its existing customer base. I don’t really care now as I feel they are as worthless as my “owned” vB license is.

I’d like to thank some of you fellows and some of the staff for helping me with issues when I needed you.

You – the users are what really helped to make vB what it is, it’s a shame that those in charge just can’t see that.

Good luck to everyone and thanks again.

Cheers
Ted (texterted)

Internet Brands’ Customer Service Failings by nathant

So annoyed right now. I seldom rant like this but I have NEVER had as bad customer service as I have from vbulletin.

We ponied up the $285 to get the support as well as the CMS. Vbulletin came highly recommended and although I prefer open source software, we spent the money on vbulletin.

After 2 separate installs, I can’t get the visual editor to work. All I get is a bunch of placeholder text.

I emailed vbulletin support from the member’s area – after confirming my license, and all I got back was a message saying I had to get an authentication code.

I replied with the code I thought they wanted, didn’t hear anything.

Wrote back a week later. No response.

Waited another week, wrote again. Nothing.

I’ve contacted vbulletin SEVEN times to get the answer to a SIMPLE QUESTION that most likely could be answered in a few minutes, but they’re more concerned with making customers who have PAID for their software jump through their hoops to make sure that it’s not pirated.

Would I contact the company directly and draw attention to myself if I hadn’t paid?

I’ve spent a MONTH with content management system that looks awful, and makes our 9-warehouse operation look like a joke.

I’ve put in a call to the head of support at vbulletin, and no doubt I’m not going to hear back.

I don’t care if it’s your email filtering system. I don’t care if it’s your ticket support system. I don’t care if it’s the authentication code. I sent SEVEN EMAILS. Over a MONTH. On the only other reply I got, the answer was that I needed to go to your page to get an authentication code. Your page was down. And I emailed and mentioned that, so I couldn’t get that code. And I still didn’t get a reply.

You’re running a business. I PAID for a service, namely support. PROVIDE IT. I don’t care how big your company is or how you do things. Taking money for a service and not providing it is still called fraud.

I don’t care how popular your software is or how many people download it. When you offer a product – and ESPECIALLY when somebody pays more for support – you’re obligated to provide it.

Do I really have to do a credit card chargeback to get your attention? Because it’s pretty obvious that you’re not providing the service you promised.

A Customer’s Perspective of Internet Brands by Abomination

I see many many vb users in the licensed areas of Invision Power, myself included.

It appears we will make the switch to IP.Board 3.1 when it comes out also. Our forum is incompatible with the business model Internet Brands is using.

Internet Brands has a fasinating history starting out as CarsDirect.com, and I invite anyone with interest to take 10 minutes to google ‘cars direct.com wiki’ and read what comes up. I found Roger Penske’s involvement, especially when he left the board of directors particularly fascinating.

From what I can tell they are not interested in what the vb customer wants/needs at all – “they” being top management, not the support staff. Clearly there are people in the company that are passionate about vb and the customers well being.

From my perspective, IB revenue from vb is dwarfed from other income they receive, although I’ve not seen any hard numbers of Autodata vs vb for the licensing revenue. I do wonder however if the companies that pay to advertise on IB forums know where their ads are showing up, at least at one point they were being shown on a motorcycle forum which was 98% spam from Nike shoes, womans purses, and viagra ads.

The only remaining question which I continue to ask myself: Is IB purposly driving customers away so their network of sites are some of the few remaining using vb (and by that time it will be a superior product)? Or do they simply not care.

And my only remaining concern is: what will happen to the vb support staff after progressively fewer sites are using vb, and with the reduced revenue vb brings in. IB is a business. Hopefully they will be offered new positions in other parts of the company.

What Internet Brands needs to do to fix vBulletin – by Off-Topic

If IB were able to get Kier back to developing vBulletin in his original role and a couple of the others, let’s say… out with the new, in with the old it would restore a lot of peoples faith. I am not saying current developers suck (I feel quite sorry for them), though the management decisions do. I’d love to see the old vBulletin team back together, they might not fix this mess over night but I dare say a lot of customers would stick around for their fix up rather than IBs. (Hence some going to IPB). I am on a fine line myself, the whole customization of themes is getting on my nerves more and more, slowly.

I am not a “theme” developer, yes I build websites but I don’t sell themes. vB 3 was easily customizable, vB4 is not. And I am having more and more doubts that StyleVars (even as a complete system) would make things any better. I personally think StyleVars was a very sensitive thing to put in or not. Converting the template to all CSS is one thing, but I think they should have only done that and kept the old system. Not a complete overhaul at once given IB have said VB4 comes in installments anyway. StyleVars being incomplete/buggy/etc = kills all development. Having to redevelop it, while it might prove successful runs the chance of throwing everyone off, again.