Major vBulletin flaw found

LSA KingLSA King Regular
edited July 2010 in Tech & Games
A serious flaw in software widely used to power online discussion sites could allow hackers to harvest reams of personal data, the BBC has learned.

The flaw in a specific version of the vBulletin software allows anyone to easily access the main administrator username and password for a site.

This would also allow hackers to access data, such as e-mail addresses, and edit the site at will.


http://www.bbc.co.uk/news/technology-10714192

Comments

  • Big baby jesusBig baby jesus Regular
    edited July 2010
    So basically..anybody can get our IP's or the emails we signed up with. Ooooh those clever bastards really got us now.
  • DaSkipperDaSkipper Regular
    edited July 2010
    Which versions?
  • D7D7 Regular
    edited July 2010
    DaSkipper wrote: »
    Which versions?

    vBulletin 3.8.6
    Which is what we are using currently
    Anybody interest on trying it here?
  • LSA KingLSA King Regular
    edited July 2010
    So basically..anybody can get our IP's or the emails we signed up with. Ooooh those clever bastards really got us now.



    and you forgot they can basically takeover the entire board doing whatever they want to it and the database. That's a pretty big "opps" considering VBulletin 3.8.6 isn't necessarily new by all means to suffer from such a major, yet simple attack.
  • KatzenklavierKatzenklavier Regular
    edited July 2010
    That's a fucking huge oops on jelsoft's part.
  • 1357913579 Death Cog Machine
    edited July 2010
    Wow, I didn't think mistakes of this magnitude were still made by whoever writes BBS software.

    Tempting to try it. Not on here though. What version is Zoklet running again?
  • DfgDfg Admin
    edited July 2010
    Zoklet is safe, it's running 3.8.1.

    We were at risk 3.8.6 but I pm'ed the Admin with the fix and it was patched. So, we're safe.
  • edited July 2010
    I think it's time to go shopping for account details ;)
  • 1357913579 Death Cog Machine
    edited July 2010
    But I want websites to screw with....*Googles*
  • edited July 2010
    13579 wrote: »
    But I want websites to screw with....*Googles*

    Google for something like "Powered by Vbulletin 3.6.8 or whatever it is" and click on the 5th page :D

    For bonus points, mess with schools, because they are lulz.
  • 1357913579 Death Cog Machine
    edited July 2010
    Found one. I don't understand though...

    I got the database name, username, password, host and port number. How do I /use it/?

    I tried logging into the forum with the username and password, didn't work. I have no idea how to attempt to log into the database...it's been forever since I've done anything with mysql databases.
Sign In or Register to comment.