Go Back   vb.org Archive > News and Announcements > vBulletin Pre-Sales Questions
FAQ Community Calendar Today's Posts Search

Closed Thread
 
Thread Tools Display Modes
  #11  
Old 04-11-2014, 07:10 AM
recon2010 recon2010 is offline
 
Join Date: Aug 2010
Posts: 11
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Who said they dont have passwords yet ?

Passwords and logins in diferent database place, so they trying to pick right. They dont know what password for what account lol. How otherise they know my login while i almoust not posted anything few years
  #12  
Old 04-11-2014, 07:18 AM
ukcobra ukcobra is offline
 
Join Date: Dec 2002
Posts: 23
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I have been getting the same since 10am UK time on Wednesday, and the IP addresses trying to gain access have been in Thailand and Ukraine amongst others.

It would be nice to hear from the Moderators what suggested actions we should take.
I have already changed my password to one that is very unlikely to be cracked by brute force.

I don't believe in co-incidences, and the timing along with Heartbleed is intriguing.
  #13  
Old 04-11-2014, 08:26 AM
AdrianH AdrianH is offline
 
Join Date: Sep 2007
Posts: 222
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by ukcobra View Post
I have been getting the same since 10am UK time on Wednesday, and the IP addresses trying to gain access have been in Thailand and Ukraine amongst others.

It would be nice to hear from the Moderators what suggested actions we should take.
I have already changed my password to one that is very unlikely to be cracked by brute force.

I don't believe in co-incidences, and the timing along with Heartbleed is intriguing.

Heartbleed?.......... no way.


Ignore them is what you do. This has happened on all forum software since the 'net began.

I have had this at both VB sites several times a year for the last 7 years, and on every forum I have membership of.

It is called a BOT. Never heard of XRumer?

Just make sure you have a decent password that the Bot can't break.

Surely as forum admins you should know what is happening?
  #14  
Old 04-11-2014, 09:25 AM
kollam003 kollam003 is offline
 
Join Date: May 2007
Posts: 154
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thank god I'm not alone in this
  #15  
Old 04-11-2014, 09:28 AM
flapjack flapjack is offline
 
Join Date: Jan 2006
Location: Tampa Bay, Florida
Posts: 38
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Seems pretty clear someone is launching a pretty big brute force attack against the site., probably using known passwords from sources like the Adobe cache (although that's pure speculation..).

I've been getting these emails for days, and my poor account has been inactive for ages. Most of the IPs hitting me are located throughout EU and Asia, leading me to believe it's the work if a botnet.

Whatever the case, it has nothing to do with Heartbleed. If you know anything about the exploit, you'd know if they'd used it (which is NOT by any means easy), they would not be getting passwords wrong and would not be hitting accounts like mine that haven't been used in years.
  #16  
Old 04-11-2014, 09:29 AM
BirdOPrey5's Avatar
BirdOPrey5 BirdOPrey5 is offline
Senior Member
 
Join Date: Jun 2008
Location: New York
Posts: 10,610
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

We apologize to all those being inconvenienced by these emails. We will work on preventing such mass emails in the future- but for this "attack" the damage is already done.

First, the vast vast majority of you should just delete/ignore the emails- we do not need to know the IP addresses in them.

If you are not using a secure (complex / uncommon) password OR not using a password unique to vBulletin.org then you should change your password as soon as possible to be as safe as can be.

Anyone with a complex and unique password should feel absolutely safe.

Even if you got 50 such emails that translates to only a max of 250 passwords being tried against your account- likely the 250 most common passwords wich are simple words and numbers like 123456. There is no chance they will randomly get a password like monKEY$803, not with vBulletin's built in lock out system, which is the reason for the emails you are getting.

This is absolutely unrelated to the well publicized OpenSSL (Heartbleed) bug. vBulletin.org does not use SSL and that vulnerability doesn't present itself as a brute force attack.

It is also unlikely they are using passwords from Adobe or any other site- This is a brute force attack where they are using password lists of the most common passwords including those people who have the same username and password. Unfortunately this can be very effective on a site like this with many user accounts near a decade old, some of which haven't been touched in years and created at a time when password security was much less a concern.

In the mean time if you want to read more there is an open thread if the Site Feedback forum: https://vborg.vbsupport.ru/showthread.php?t=280796

If you no longer wish to have a vBulletin.org account I am sorry but we do not delete accounts. What you can do to stop getting emails is to go to Edit your Email Address: https://vborg.vbsupport.ru/profile.php?do=editpassword

Provide some new/random and undeliverable email address like 9djsbsjh@djdhdhd7shs.com and save changes. Your account will never get reconfirmed and you will no longer get any further emails, you can consider the account dead at that point.

Once again, we apologize for the inconvenience.
2 благодарности(ей) от:
Kat-2, RichieBoy67
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 11:33 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.05330 seconds
  • Memory Usage 2,224KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (6)post_thanks_box
  • (2)post_thanks_box_bit
  • (6)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit
  • (6)post_thanks_postbit_info
  • (6)postbit
  • (6)postbit_onlinestatus
  • (6)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete