<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: vBulletin 3.7.0 Release Candidate 4</title>
	<atom:link href="http://www.t3-design.com/vbulletin-370-release-candidate-4/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.t3-design.com/vbulletin-370-release-candidate-4/</link>
	<description>Tefra Was Here</description>
	<pubDate>Thu, 20 Nov 2008 20:16:45 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Chris T</title>
		<link>http://www.t3-design.com/vbulletin-370-release-candidate-4/#comment-81</link>
		<dc:creator>Chris T</dc:creator>
		<pubDate>Wed, 23 Apr 2008 20:00:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.t3-design.com/?p=270#comment-81</guid>
		<description>Except a few quick edits, that was a fast upgrade. The vb team is making the upgrade script better and better this time it can handle the auto update for the CSRF (cross-site request forgery) vulnerability for all custom templates.

It took me only a few minutes, to add the new security check to vbsed too. What does it actually do ? 

It checks if POST request is done, and it checks for a hidden input that they added in every form which has a unique value for each user, so if you are not yourself there is pretty much no way to bypass this check. Unless of course if you are a lazy admin who likes to forget his cookies in some net cafe. In that case do yourself a favor and close your site, today.

vBulletin had a security check for POST request from 3dparty domains, but it wasn't secure enough, god bless php Global variables.</description>
		<content:encoded><![CDATA[<p>Except a few quick edits, that was a fast upgrade. The vb team is making the upgrade script better and better this time it can handle the auto update for the CSRF (cross-site request forgery) vulnerability for all custom templates.</p>
<p>It took me only a few minutes, to add the new security check to vbsed too. What does it actually do ? </p>
<p>It checks if POST request is done, and it checks for a hidden input that they added in every form which has a unique value for each user, so if you are not yourself there is pretty much no way to bypass this check. Unless of course if you are a lazy admin who likes to forget his cookies in some net cafe. In that case do yourself a favor and close your site, today.</p>
<p>vBulletin had a security check for POST request from 3dparty domains, but it wasn&#8217;t secure enough, god bless php Global variables.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
