PDA

View Full Version : vBulletin forum password hack



Rumcajs
4th November 2015, 07:18 PM
Since this forum is/runs vBulletin software, are we affected?


Piecing everything together, it's hard to escape the inference that the vBulletin software contained a zero-day vulnerability that allowed hackers in the wild to gain almost complete control over websites that used the forum app. If so, administrators for any site that uses vBulletin should drop whatever they're doing and immediately install Monday's patch.

vBulletin password hack fuels fears of serious internet wide 0 day attacks (http://arstechnica.com/security/2015/11/vbulletin-password-hack-fuels-fears-of-serious-internet-wide-0-day-attacks/)

Regards

AB
4th November 2015, 07:43 PM
Thanks for letting us know.

We have added security here along with an up to date software but will monitor this for more information.

I highly doubt we will be targeted but will ensure the members here are protected to the best of my ability.

Stropp
4th November 2015, 10:57 PM
Thanks for letting us know.

We have added security here along with an up to date software but will monitor this for more information.

I highly doubt we will be targeted but will ensure the members here are protected to the best of my ability.

You will be busy mate what with building the new kitchen and all 😋

AB
5th November 2015, 06:32 AM
The patch that Vbulletin has released to fix this issue is quite crap to be honest and you are required to confirm your email address each time you sign in.

I have other systems in place if someone tries to Brute Force passwords on here so I might not bother with there fix up to be honest.