TheLastSuperman |
10-31-2015 08:09 PM |
Quote:
Originally Posted by ForceHSS
(Post 2558055)
I hope or accounts are all safe do we need to change or passwords on all sites of vb
|
I would wait to change, if it's still showing as hacked we don't know what level of extent the hack was i.e. shell script uploaded? Logging user logins? No clue other than the defaced forum currently but point being no need to change if being logged or if still hacked.
Quote:
Originally Posted by final kaoss
(Post 2558056)
They should be safe if all they got were 1 minute of access. Not nearly enough time to do a mysql dump. If you're super paranoid about it, it can't hurt to be safe & change the login details.
|
Who says they wanted anything from the database? The whole point could have been to gain access and deface or some other motive. It's not always about getting info, sometimes it's about injection and other methods.
Quote:
Originally Posted by Dave
(Post 2558058)
Well dumping just the username, password, salt and email column of the user table shouldn't take too long. You can gather a lot of information in just 1 minute.
Let's hope vBulletin makes an announcement regarding this because I'm really curious what happened and what damage the "hackers" managed to do.
|
Paul is on vacation so someone else we be fixing this, with it being Halloween if they have kids... well not sure if they'll be in sooner or later on a Saturday. I would guess that others are lined up to take care of issues like this, they have someone looking at it already if I had to guess ;).
Quote:
Originally Posted by ForceHSS
(Post 2558061)
A lot can be done in one min
|
Yes it can, then again depends on who is in there during that one minute.
|