Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

[caption id="attachment_676" align="aligncenter" width="408"]SQL injection vulnerability SQL injection vulnerability[/caption] An administrator of a hacker community forum, Nytro found sql injection vulnerability in Vbulletin forum. Nytro has now confirmed on his Romanian Security team forum that patches are released for the flaw which was found on Monday.

Also SEE: Kronos malware designed for banking systems attack

Emergency patches released for SQL injection vulnerability

The technical support leader of Vbulletin Wayne Luke said that the flaw found could allow the attackers to make a sql injection attack. This would give an access to the malicious attacker to run and execute sql commands. To resolve this sql vulnerability, Vbulletin forum developers have released patches for 5.0.4, 5.0.5, 5.1.0, 5.1.1 and 5.1.2 versions of Vbulletin. The users would need to manually apply the code and fix the bug.

Also SEE: Hack facebook account with REST API

What is Vbulletin?

Vbulletin provides online cloud base service and allows you to build forums. Vbulletin 5 connects and cloud hosting services are the two popular products offered. It is written in PHP and my SQL databases. The company build's commercial online forum software. Companies such as Electronic Arts, Sony pictures, NASA Valve Corporation and Zynga run on Vbulletin.Vbulletin official website link[caption id="attachment_677" align="aligncenter" width="614"]SQL injection vulnerability found in Vbulletin hosted websites SQL injection vulnerability found in Vbulletin hosted websites[/caption]

Earlier attack on Vbulletin hosted websites

This is not the first time that attackers have attacked Vbulletin based websites. Last year also hackers stole around 1 million user email ids and passwords from UbuntuForums.org. openSUSE Linux forum was also hacked 2 years ago with the same SQL injection method. Among all, the official forum of Vbulletin was vulnerable last year.

You might also be interested to read

[caption id="attachment_490" align="alignleft" width="150"]Certified web application security expert Certified web application security expert[/caption] [caption id="attachment_435" align="alignleft" width="150"]DNS Sinkhole prevent against malware attack DNS Sinkhole prevent against malware attack[/caption]

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.