I stumbled upon a vulnerability in this site. The other day I accidentally accessed the root menu. If I was able to do it then a hacker would have no problem. They could easily imbed all kinds of nasty stuff and the good folks here would never know until it was too late.
If you have any personal info here, remove it. Same for email. Don't provide anything that could provide a back door directly to you.
I contacted Steve about it but he never replied. Idk why not. He didn't get it? He doesn't care? Can't say. Just watch your back.
In the absence of a thank you I will say you are welcome.
Potential Vulnerability
Collapse
-
Created by:
Scottie2Hottie
- Published: 02-25-2019, 08:05 AM
- 3 comments
-
Categories
Collapse
Latest Articles
Collapse
-
by solonlHello I did a check on my emailaddress (via https://www.avast.com/hackcheck) to see if my credentials where leaked somehow, and I found that this forum has been hacked in december 2020 and a list of members has been exposed on the darkweb and sold to criminals. Luckily the passwords are stored encrypted, but I think it is a good idea for people to change their passwords, since hashes can be matched by a brute force attack.
...-
Channel: Bug Reports
-
-
I stumbled upon a vulnerability in this site. The other day I accidentally accessed the root menu. If I was able to do it then a hacker would have no problem. They could easily imbed all kinds of nasty stuff and the good folks here would never know until it was too late.
If you have any personal info here, remove it. Same for email. Don't provide anything that could provide a back door directly to you.
I contacted Steve about it but he never replied. Idk why not. He didn't...-
Channel: Bug Reports
-
-
by IldergreierThere seem to be a problem in the shopping cart, I can't remove items when/if I changed my mind. I can add more of same item, and remove the add, but not remove the product entirely from my cart. This is a problem. Could you guys check if there is a little bug somewhere? BobiiJo925 XSteveO...
-
Channel: Bug Reports
-
-
by XSteveOWe had an issue where support tickets were being created but our support suite was not being populated with said tickets. Pretty sure we fixed it, but if you did submit a ticket and did not get a response (within 24 hours), please submit another. No tickets were lost, just stuck in the ether.
Our new shopping market integrates all tickets with user accounts so you'll be able to track your order and any tickets you might have in the same place.
In the meantime there will...-
Channel: Bug Reports
02-15-2018, 08:27 AM -
-
by Abel.MannI have ordered many times through your web store but this time Pay Pal is saying I have to type in the product description and price. See Below. Something seems a little off here. This is after I type in my Paypal username and password.
Please Advise.
Aser Gruppe International, Corp.
Choose a way to pay
Error Message
Please enter an amount greater than zero.
Your order summary
Descripti...-
Channel: Bug Reports
-
Scottie2HottiecommentedAs far as posting about the situation I only did what I would want someone to do for me. It's potentially an extremely serious issue and people have a rightt to know. You obviously don't agree.
I see that you have taken away mu permissipns for the mens journals and that one of my threads is gone. I'm sure i know what's coming next.
Hey Steve remember what it feels like to be loyal to someone only to be cast out and purged ? Apparently not.
This truly saddens me.
When you say you're only trying to help you sent a private message to me even after all the times I've said to just call me because I get hundreds of messages and its difficult to get through any. That I'm literally months behind reading messages. Remember that time when I personally called you to tell you how to get a hold of me? Again though, nothing free for you so it obviously wasn't that important.
As to the alleged serious vulnerability as soon as I read your post I immediately contacted my guys to check it all out. There actually the engineers that created VB5.
Oh and BTW scotty lets talk about loyalty! You've been sending unsolicited Private Messages to male members asking them to come over to your forum. You'll send them a link when its done. The truly loyal members of XS were kind enough to share them. Your sending other messages to some of the ladies here and when that didn't go your way you began using horrible names towards them on the forum. That's mature! You sent Hayley your phone number in a Private Message too. She didn't go for it either. Hey you gave it the old try, but it didn't go your way. Move on bro. Its not cool to belittle someone when they didn't go for your advances.
The truth is scotty you threw a tantrum, multiple times, and it didn't go your way. Just like the multiple times you said you were going to leave and yet somehow here we still are. Your true colors are on display for people to see and wow I'm just... SMH! It is definitely sad indeed. Anyway I made it much easier for you to leave now. Best of luck to you in all that you do. I wish you all the success you desire and seek in life.
I closed your forum account for you.
The forum is upgraded to new versions every time they come out within a reasonable time to allow bugs to be worked out. We have a hardened server with 24/7/365 monitoring by a very, very good server company. We take a lot of steps to ensure security is an absolute priority and so when someone makes this type of claim, with no evidence of course, its a little bit suspicious. Especially when that same person has been implicated in sending Private Messages to other members soliciting them to leave and join his own forum. Anyway because we do take security here very seriously Glenn from vbmods.rocks is looking into this for me.