vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Community Lounge (https://vborg.vbsupport.ru/forumdisplay.php?f=13)
-   -   Vbulletin.com hacked (https://vborg.vbsupport.ru/showthread.php?t=320673)

shimei 10-31-2015 07:05 PM

Quote:

Originally Posted by Max Taxable (Post 2558050)
I laugh at XRumer. defeated long ago.

I have no idea what it is. Could you please elaborate, any suggestions?

ForceHSS 10-31-2015 07:35 PM

I hope or accounts are all safe do we need to change or passwords on all sites of vb

final kaoss 10-31-2015 07:38 PM

Quote:

Originally Posted by ForceHSS (Post 2558055)
I hope or accounts are all safe do we need to change or passwords on all sites of vb

They should be safe if all they got were 1 minute of access. Not nearly enough time to do a mysql dump. If you're super paranoid about it, it can't hurt to be safe & change the login details.

Dave 10-31-2015 07:41 PM

Well dumping just the username, password, salt and email column of the user table shouldn't take too long. You can gather a lot of information in just 1 minute.

Let's hope vBulletin makes an announcement regarding this because I'm really curious what happened and what damage the "hackers" managed to do.

ForceHSS 10-31-2015 07:43 PM

Quote:

Originally Posted by final kaoss (Post 2558056)
They should be safe if all they got were 1 minute of access. Not nearly enough time to do a mysql dump. If you're super paranoid about it, it can't hurt to be safe & change the login details.

A lot can be done in one min

TheLastSuperman 10-31-2015 08:09 PM

Quote:

Originally Posted by ForceHSS (Post 2558055)
I hope or accounts are all safe do we need to change or passwords on all sites of vb

I would wait to change, if it's still showing as hacked we don't know what level of extent the hack was i.e. shell script uploaded? Logging user logins? No clue other than the defaced forum currently but point being no need to change if being logged or if still hacked.

Quote:

Originally Posted by final kaoss (Post 2558056)
They should be safe if all they got were 1 minute of access. Not nearly enough time to do a mysql dump. If you're super paranoid about it, it can't hurt to be safe & change the login details.

Who says they wanted anything from the database? The whole point could have been to gain access and deface or some other motive. It's not always about getting info, sometimes it's about injection and other methods.

Quote:

Originally Posted by Dave (Post 2558058)
Well dumping just the username, password, salt and email column of the user table shouldn't take too long. You can gather a lot of information in just 1 minute.

Let's hope vBulletin makes an announcement regarding this because I'm really curious what happened and what damage the "hackers" managed to do.

Paul is on vacation so someone else we be fixing this, with it being Halloween if they have kids... well not sure if they'll be in sooner or later on a Saturday. I would guess that others are lined up to take care of issues like this, they have someone looking at it already if I had to guess ;).

Quote:

Originally Posted by ForceHSS (Post 2558061)
A lot can be done in one min

Yes it can, then again depends on who is in there during that one minute.

TheLastSuperman 10-31-2015 08:46 PM

It's back up everyone :D.

So someone took the time to fix this on a Saturday, for that I'm thankful ;).

Edit: I spoke too soon! I was on this page when refreshing:
http://www.vbulletin.com/forum/forum...google-adsense

^Which does come up now, so it seems only the forumhome page remains defaced. Soon as someone is working on it else the thread would not be coming up now :cool:.

shimei 10-31-2015 08:48 PM

Quote:

Originally Posted by TheLastSuperman (Post 2558069)
It's back up everyone :D.

So someone took the time to fix this on a Saturday, for that I'm thankful ;).

Edit: I spoke too soon! I was on this page when refreshing:
http://www.vbulletin.com/forum/forum...google-adsense

^Which does come up now, so it seems only the forumhome page remains defaced. Soon as someone is working on it else the thread would not be coming up now :cool:.

Betcha you were sweating when you noticed the VB5 owners beginning to form a mob and grabbing pitch forks. :eek: Just curious will you be our VB spokesperson for damage control?

TheLastSuperman 10-31-2015 08:57 PM

Quote:

Originally Posted by shimei (Post 2558070)
Betcha you were sweating when you noticed the VB5 owners beginning to form a mob and grabbing pitch forks. :eek: Just curious will be VB spokesman for damage control?

Nah not really, tons of sites are hacked daily... granted someone with big basketballs tries to hack an official site either that or a very intelligent idiot which contrary to popular belief and contrary to being a contradiction in themselves do exist!

I will not be the spokesperson for damage control, I just moderate here on the org and do not work for vBulletin any longer (have not for a while now but great people there I will say that!). I just wanted to make sure everyone was ok here with what was going on there and as you can see they're making progress already else that thread I linked to would still have the same message up instead of actual content.

We all need to wait for an official announcement before speculating too much. It's always over speculation and assumptions that lead to the naysayers and now-fanboys of other software to start bombing this thread with banter and one-sided comments about the software's flaws and other tidbits of utterly useless information when they don't know anything until vB discloses it.

So please don't assume or speculate in a negative way - opinions are just that but overextending your imagination only works well with toys ;).

shimei 10-31-2015 09:01 PM

Well, I think you're doing a wonderful job and have been extremely helpful.

Thanks,
William


All times are GMT. The time now is 07:52 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01461 seconds
  • Memory Usage 1,749KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (9)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (3)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete