# Still safe, I think?

**URL:** <https://boards.straightdope.com/t/still-safe-i-think/762531>\
**Category:** About This Message Board\
**Created:** [August 12, 2016, 5:46am UTC](https://boards.straightdope.com/t/still-safe-i-think/762531 "2016-08-12T05:46:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Melbourne](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@Melbourne](https://boards.straightdope.com/u/Melbourne)\
**Post date:** [August 12, 2016, 5:46am UTC](https://boards.straightdope.com/t/still-safe-i-think/762531/1 "2016-08-12T05:46:48Z")

</div>

If I understand this correctly, [http://legalhackers.com/advisories/vBulletin-SSRF-Vulnerability-Exploit.txt](http://legalhackers.com/advisories/vBulletin-SSRF-Vulnerability-Exploit.txt)  
… it means that we aren’t affected because posting of pictures is disabled on this board:

“vBulletin allows forum users to share media files by uploading them to the  
remote server. Some pages allow users to specify a URL to a media file  
that a user wants to share which will then be retrieved by vBulletin.  
The user-provided links are validated to make sure that users can only access  
resources from HTTP/HTTPS protocols and that connections are not allowed in to  
the localhost.”

---

<div class="post-metadata">

**Author:** ![gnoitall](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@gnoitall](https://boards.straightdope.com/u/gnoitall)\
**Post date:** [August 12, 2016, 1:42pm UTC](https://boards.straightdope.com/t/still-safe-i-think/762531/2 "2016-08-12T13:42:57Z")

</div>

> [@Melbourne](#):
>
> If I understand this correctly, [http://legalhackers.com/advisories/vBulletin-SSRF-Vulnerability-Exploit.txt](http://legalhackers.com/advisories/vBulletin-SSRF-Vulnerability-Exploit.txt)  
> … it means that we aren’t affected because posting of pictures is disabled on this board:

Well, except for in the Marketplace forum. So the danger space is limited, and Marketplace posters have to be paying subscribers.

> [@Gary Robson sticky](#):
>
> ## \*\*Putting images in your posts \*\*
> 
> Unlike the rest of the SDMB, the Marketplace forum allows images in your posts (but only in your own threads–please do not add images to someone else’s threads).  
> Including pictures is straightforward. Just copy the web address (URL) of the picture, and paste it between IMG tags.

From [Marketplace run rules sticky](http://boards.straightdope.com/sdmb/showpost.php?p=13224583&postcount=1)

Practically speaking, that means that a bad actor has to go to the trouble of registering and paying for a subscription, and the malware being served up would be explicitly tied to their on-board identity. It’s probably easier and more effective to just put malspam on an advertising provider. [Not like that ever happens or anything](http://boards.straightdope.com/sdmb/showthread.php?t=800991). :rolleyes:

---

<div class="post-metadata">

**Author:** ![voltaire](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/voltaire/32/313_2.png) [@voltaire](https://boards.straightdope.com/u/voltaire)\
**Post date:** [August 12, 2016, 1:48pm UTC](https://boards.straightdope.com/t/still-safe-i-think/762531/3 "2016-08-12T13:48:27Z")

</div>

Sounds like it would NOT affect posts in the Marketplace forum, or any other; it’s limited to specially crafted links placed in the the attacker’s profile.

> [@](#):
>
> HTTP redirects are also prohibited however there is one place in the vBulletin codebase that accepts redirects from the target server specified in a user-provided link. The code is used to upload media files within a logged-in user’s profile and can normally be accessed under a path similar to: [http://forum/vBulletin522/member/1-mike/media](http://forum/vBulletin522/member/1-mike/media) By specifying a link to a malicious server that returns a 301 HTTP redirect to the URL of [http://localhost:3306](http://localhost:3306) for example, an attacker could easily bypass the restrictions presented above and make a connection to mysql/3306 service listening on the localhost. This introduces a Server Side Request Forgery (SSRF) vulnerability.

I haven’t read all the details, but it might be a good idea to disable the posting of links in profiles. (Sorry, avatar script users!)

---

<div class="post-metadata">

**Author:** ![voltaire](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/voltaire/32/313_2.png) [@voltaire](https://boards.straightdope.com/u/voltaire)\
**Post date:** [August 12, 2016, 1:54pm UTC](https://boards.straightdope.com/t/still-safe-i-think/762531/4 "2016-08-12T13:54:11Z")

</div>

> [@gnoitall](#):
>
> Well, except for in the Marketplace forum. So the danger space is limited, and Marketplace posters have to be paying subscribers.  
> From [Marketplace run rules sticky](http://boards.straightdope.com/sdmb/showpost.php?p=13224583&postcount=1)
> 
> Practically speaking, that means that a bad actor has to go to the trouble of registering and paying for a subscription, and the malware being served up would be explicitly tied to their on-board identity. It’s probably easier and more effective to just put malspam on an advertising provider. [Not like that ever happens or anything](http://boards.straightdope.com/sdmb/showthread.php?t=800991). :rolleyes:

“Malspam on an advertising provider” would generally be targeting us users. This thing would be targeting the board itself.
