6 ms·
Password hack of vBulletin.com
- CalRobert 13y agoWhen I was working with the company that produces vBulletin, I wasn't exactly dazzled by their competence.
- csmuk 13y agoAs someone who had to look after a relatively large vBulletin install (13000 users) for a number of years, I wasn't exactly dazzled by their competence either! I'd go as far to say that vBulletin is a pile of crap.
- mithras 13y agoIf only I had known that before I recommended it to a client.
- cdr 13y agoSure vB is crap... and then you look at the other options out there and realize they're even worse. Especially 5-10 years ago when many of the sites using vB started using it. It's wildly successful - at least in the niche I'm familiar with - for a reason. It's reasonably cheap, reasonably easy to work with even for nontechnical people, works reasonably well, and looks decent.
- tluyben2 13y agoEvery time I open the admin interface shivers run down my spine. I don't understand how anyone can find that 'easy to work with'. I'm technical so maybe that's it. But you are right; the competition (at least it used to be; haven't needed any forums recently and the last one I made myself) was every far worse.
- csmuk 13y agoPlease don't make excuses for it. I've had to deal with the multi-day aftermath of an XSS worm twice. That's when you realise that it's as bad as it is. After that it was "get fucked" and move to phpbb which while is not a stellar product it seems to be put together with a modicum of common sense and has a responsive community and support.
- hfern 13y agoWhat were your thoughts on XenForo?
- csmuk 13y agoHell no. It's based on the Zend framework which is an even greater pile of rot!
- sampk 13y agoFor real? Oh a spaghetti fan I see.
- csmuk 13y agoNope. Just not a fan of adding piles of abstraction on top of something that just crawls already. To be honest I'd use a different language/platform if you need to use patterns like that where they perform (java/c#). Bit of a "no true scotsman" that one as well. Just because someone doesn't use Zend doesn't mean they write spaghetti.
- leapius 13y agoI'd like to know opinions on IPB actually.
- Pxtl 13y agoI'm actually stunned by the terrible quality of most bulletin-board software. It's telling that every forum I enjoy frequenting is one where the developers pulled a NIH and re-invented the wheel.
- CalRobert 13y agoSome interesting background reading: http://www.theregister.co.uk/2011/05/22/vbulletin_abandons_motion_for_injuction_against_former_devs/ http://www.theregister.co.uk/2011/05/22/vbulletin_abandons_m...
- buro9 13y agoThis explains the email received a few days ago: > We take your security and privacy very seriously. Very recently, our security team discovered sophisticated attacks on our network, involving the illegal access of forum user information, possibly including your password. Our investigation currently indicates that the attackers accessed customer IDs and encrypted passwords on our systems. We have taken the precaution of resetting your account password. We apologize for any inconvenience this has caused but felt that it was necessary to help protect you and your account. > To regain access to your account: > Visit the vBulletin forums at http://www.vbulletin.com/settings/account http://www.vbulletin.com/settings/account > Enter in your existing password followed by your new password, twice for confirmation. > Save this page at the bottom. > Please choose a new password and do not use the same password you used with us previously. We also highly recommend that you chose a password that you are not using on any other sites. > If you have any additional questions or concerns, please feel free to contact our support team at http://www.vbulletin.com/go/techsupport http://www.vbulletin.com/go/techsupport or support@vbulletin.com. > Sincerely, Of course I reset the password to another generated LastPass one, but I did wonder what the scope of the attack was.
- pgrote 13y agoAre you sure that email was from vbulletin? I received the same one and it didn't come from vbulletin's domain name. If you go to the root of the domain name it says "Test page." When you click the "read in browser" option you are taken to a page where all the links to access the forums do not work. I thought it was a phishing attempt.
- buro9 13y agoAh, you are right: > http:// http:// click.shopping.ibemail. com/ Not that it matters, I never follow links in emails and went direct to vbulletin.com I bet they emailed everyone on their stolen email list though.
- JohnTHaller 13y agoI wish they would refer to password hashes as password hashes and not call them 'encrypted passwords'. Encrypted passwords screams that you don't understand security and were storing real passwords instead of hashes. (Or, more properly, salted hashes.)
- leapius 13y agoYes a cryptographic hash (like MD5 or SHA etc) stores a non-reversible string. Encryption means that it reversible but lets be honest here, when writing an article most laymen understand the general idea of encryption as opposed to hashing. I'd really like to see how this hack works for general knowledge and if it's purely via the script itself and not a server attack.
- alexkus 13y agoDon't forget that most symmetric encryption algorithms can be used as a hash. Just encrypt a known plaintext (usually all NUL bytes) using the password as the key.
- ReidZB 13y agoIf you do that and only that, you open yourself up to related-key attacks. A better approach would be to use a well-known scheme like the Merkle–Damgård construction.
- code_duck 13y agoIf tech journalists would use the right terms that would at least help lead the public towards a better understandings of this issue. I presume they say 'encrypted' as their generally means 'not plain text' to the lay person. To be fair, we do call these cryptographic hashes. By the way, if anyone is wondering how VBulletin forums store passwords... It's md5(md5(password)+salt).
- leapius 13y agough, cos md5 squared is twice as secure as just once - why not md5 x 10 to be uber secure?
- martinald 13y agoThis is getting ridiculous now. I've had my password stolen probably at least four times this year. I think that the browser developers should push for a keychain of random, generated passwords and use as many UI pointers as possible to push people to use these. Apple's implementation in Safari is what we should be aiming for, but pretty useless to me as I have Linux/Windows/Android devices that don't support Safari.
- dublinben 13y agoHave you tried KeePass or LastPass? They work pretty well on just about every platform.
- kijin 13y agoThe problem with KeePass, LastPass, etc. is that you need to hear about them, look them up, and install them. Things would be much simpler if the browser included a similar functionality by default. Unfortunately, all three major browser vendors seem too busy pushing their own single sign-on schemes (Chrome: Google account, IE: Microsoft account, Mozilla: Persona). So they're unlikely to pay any attention to plain old password generation and storage for the foreseeable future. Which is a real pity because passwords aren't going to disappear overnight.
- projct 13y agohttp://www.gottabemobile.com/2013/10/22/setup-icloud-keychain-ios-7-os-x-mavericks/ http://www.gottabemobile.com/2013/10/22/setup-icloud-keychai... http://www.chromium.org/developers/design-documents/password-generation http://www.chromium.org/developers/design-documents/password... Looks like this is being done.
- dublinben 13y agoInstead of using a cross-browser solution that works today, you're complaining that the browser makers haven't created their own schemes.
- 13y ago
- robomartin 13y agoI own a license of vBulletin. After approximately a year of experience with their codebase I decided that burning off my eyeballs with a hot spoon would be more fun. I wouldn't know where to start to describe just how bad their software is. It doesn't end there. The folks who own vBulletin run a whole series of communities themselves: http://www.internetbrands.com/ http://www.internetbrands.com/ At one point into configuring vBulletin I realized they had code in there that would allow them to monitor your site's traffic and performance. Which is genius if you run hundreds of sites yourself and want "probes" out there to discover areas that you could launch sites into. And, it is even more brilliant if you can have these "probes" be people who pay you to use software you produce. Imagine thousands of business experiments actually paying you and feeding you audience data. That really didn't sit well with me and a number of people who were awake while installing and configuring their vB software. The vast majority of folks running vB communities either don't care or don't have a clue. There are other issues. Maybe someone else has the time to chime in. I guess my point is that password security might not be at the top of their priority list.
- Revisor 13y agoCould you please post some details about what you mean with them monitoring your site's traffic and performance? I found the code for the "anonymous survey", but you have to submit it manually. Edit: I think you might mean the news loaded remotely in the Admin CP upon every login. It's injected in the page as is.
- robomartin 13y agoI haven't touched the codebase in quite some time. My recollection might be a little off. If I remember correctly, when you integrate Google Analytics through the admin panel you are integrating a flavor of Google Analytics that actually passes the data through the vBulletin mothership. Like I said, I stopped using vB a long time ago. For all I know they've fixed this issue. Please don't take my word for it as current versions might behave differently. If you are a vB user I suggest you ask in their various official and unofficial support forums.
- 13y ago
- SilkRoadie 13y agoIt is a joke isn't it. "Security" lol There are 2 types of websites. Those which are important enough for you to remember a password for and those which aren't. Well the 50 or so which aren't important enough have one password and this password has been compromised at least 5 times this year. As far as I know people haven't been logging into my accounts but I guess there is nothing stopping them. I find it really difficult to understand how this happens so often. In many cases it seems like security is an after-thought and procedures are poorly implemented. If it is true that the vulnerability exploited has been in vB since version 4.. that means it has been there for 3 years! I wonder how sophisticated it really was? I wonder when the vBulletin last got an external security audit done..
- BitMastro 13y agoSlightly off-topic, but is it common for an hacking team nowadays to have a facebook page? I could understand twitter for announcements, but the facebook interaction feels out of place, or is it just me? Also, "We wanted to prove that nothing in this world is not safe" has a double negation, so they wanted to prove that there is something out there that could be safe?
- atpfluk 13y agoHelped perform hack http://facebook.com/HolidayPalaceService http://facebook.com/HolidayPalaceService And then send it to. atpfluk@gmail.com