vBulletin Hack Exposes 820,000 Accounts from 126 Forums

Joeychgo

TAZ Administrator
Joined
Feb 28, 2004
Messages
7,028
A hacker going on Twitter by CrimeAgency claims to have hacked 126 forums running on vBulletin, stealing personal data belonging to forum admins and registered users, before leaking everything to an underground hacking forum.

The information was verified by breach notification platform Hacked-DB after they managed to scan the data.

Hack Read reports the attack was conducted between January and February 2017. The hacker managed to get his hands on 819,977 user accounts, including email addresses, hashed passwords, as well as 1681 unique IP addresses. Most of the accounts were linked to Gmail - over 219,000, followed by 121,000 Hotmail accounts and 108,000 Yahoo accounts.

More...

http://news.softpedia.com/news/vbulletin-hack-exposes-820-000-accounts-from-126-forums-513416.shtml
 

Sal Collaziano

Womanizer
Joined
Jan 1, 2004
Messages
881
Crazy. I learned very early on about keeping scripts up to date. Somebody managed to break into one of my vBulletin sites through an old script that I had running but didn't think much of. Not many people used it so I forgot about it and somebody snuck in. The guy downloaded and dropped my POST table in vBulletin but luckily I'm a very diplomatic person and got him to replace it and show me where my issue was...
 

Gus

Enthusiast
Joined
Jan 15, 2017
Messages
156
Hopefully all the owners of all those affected accounts use different passwords for their email, etc. Events like this remind us to use unique & different passwords for every thing you sign up for.
 
Joined
Apr 29, 2011
Messages
566
Sorry to hear that. Hope ozzy47 and others affected have a quick and as painless as possible recovery from this!

I've been there, and it sucks :(
 

ozzy47

Tazmanian Master
Joined
Oct 18, 2013
Messages
8,960
Sorry to hear that. Hope ozzy47 and others affected have a quick and as painless as possible recovery from this!

I've been there, and it sucks :(

It happens. I am probably just going to shut the site down anyway, no need to keep it open anymore.
 

ozzy47

Tazmanian Master
Joined
Oct 18, 2013
Messages
8,960
Why is that, because you have the content available here?

Sorta. Partly because I just don't want to deal with running it anymore, and partly because I have no access to a PC, only my phone, so no way to sort things on a timely manner.
 

Starskull

Enthusiast
Joined
Apr 25, 2011
Messages
235
That sucks ozzy47 . May I ask why not access to a pc? I thought that was common in today's world. Anyway we could help?
 

we_are_borg

Tazmanian
Joined
Jan 25, 2011
Messages
5,964
Sorta. Partly because I just don't want to deal with running it anymore, and partly because I have no access to a PC, only my phone, so no way to sort things on a timely manner.

Why not go for a raspberry pi3 install Linux on it monitor, keyboard and mouse and you are ready to go.
 

HallofFamer

Habitué
Joined
Sep 6, 2010
Messages
1,355
The issues have been fixed on the latest versions of the software, but the exploit still works on forums that haven't bothered to update.

So what is the latest versions with this issue fixed? Is VB 3.8.9 or the latest VB 4 good enough? Or its only fixed on VB5?
 

chown

Aspirant
Joined
Feb 14, 2017
Messages
25
All targeted forums are vB4?
Most of the sites seem to be using vBulletin 4.2.2 or older.

vBulletin 4.2.3 has been around since 2015 and has received 2 security related patches since then, so I guess these 126 sites put off updating for too long.

The final version of vBulletin 4.2.4 was released today.
 
Last edited:

ozzy47

Tazmanian Master
Joined
Oct 18, 2013
Messages
8,960
That sucks ozzy47 . May I ask why not access to a pc? I thought that was common in today's world. Anyway we could help?

My PC and laptop are dead, and I don't have the $ or time to deal with it. So I am stuck using my phone for awhile.

Why not go for a raspberry pi3 install Linux on it monitor, keyboard and mouse and you are ready to go.

Not really interested in doing much sitewise TBH.
 

Starskull

Enthusiast
Joined
Apr 25, 2011
Messages
235
My PC and laptop are dead, and I don't have the $ or time to deal with it. So I am stuck using my phone for awhile.



Not really interested in doing much sitewise TBH.

Sounds to me like you are hanging up your coat...
 

GTB

Tazmanian
Joined
Nov 24, 2005
Messages
4,011
Sorta. Partly because I just don't want to deal with running it anymore, and partly because I have no access to a PC, only my phone, so no way to sort things on a timely manner.
Don't know how u can use web all the time without a proper PC. My PSU died in PC a few days back and been using a tablet for now until I replace PSU this weekend. Terrible trying to use web on a tablet, never mind a phone
 
Last edited:

ozzy47

Tazmanian Master
Joined
Oct 18, 2013
Messages
8,960
Don't know how u can use web all the time without a proper PC. My PSU died in PC a few days back and been using a tablet for now until I replace PSU this weekend. Terrible trying to use web on a tablet, never mind a phone

Yeah it's not that easy posting on a phone constantly, I don't know how people do it all day long on social media.
 
Top