Thoughts Media.com

 





Go Back   Thoughts Media Forums > Thoughts Media Status Updates

Reply
 
LinkBack (6) Thread Tools Display Modes
  6 links from elsewhere to this Post. Click to view. #1 (permalink)  
Old 07-31-2008, 08:51 PM
Executive Editor
Jason Dunn's Avatar
Join Date: Aug 2006
Posts: 23,069
Default vBulletin Vulnerability: Passwords Shuffled for Some Users

If you're trying to log into our forums and having trouble, here's why: there are some individuals going around and running scripts against vBulletin installs, specifically looking to hijack user accounts where the username and password are the same. These people then use these hijacked accounts to send our spam private messages and email messages (I've turned off the email function on our board). I was shocked to learn that we have 559 users who have done exactly that: chosen their password to match their user-name. Not only is this bad security, it leaves the door open for hacker-types to get into our board, pretending to be real users, and cause problems. To prevent this, what we've done is randomize the passwords for the 559 users who were impacted by this.

If you're one of these users, all you need to do is use the Lost Password Recovery Form to have the password sent to you - which you'll then want to reset the password to something else...something other than your user name of course. If you have any trouble with this process, please contact me and I'll manually reset your password. I apologize for any hassle this may cause, but this step was necessary to protect the security of all our users.

__________________
Thanks for visiting our forums!
 
Reply With Quote
  #2 (permalink)  
Old 08-01-2008, 01:14 AM
Managing Editor
Rocco Augusto's Avatar
Join Date: Aug 2006
Posts: 2,010

Are we going to prevent users from using their username as their password in the future?
__________________
RoccStar Accessories
http://www.roccstar.com
 
Reply With Quote
  #3 (permalink)  
Old 08-01-2008, 04:06 AM
Executive Editor
Jason Dunn's Avatar
Join Date: Aug 2006
Posts: 23,069

Quote:
Originally Posted by Rocco Augusto View Post
Are we going to prevent users from using their username as their password in the future?
At the moment vBulletin lacks any such feature...which completely blows my mind. I'm hoping they'll release a patch in the near future to address this problem.
__________________
Thanks for visiting our forums!
 
Reply With Quote
  #4 (permalink)  
Old 08-01-2008, 07:43 PM
Managing Editor
Rocco Augusto's Avatar
Join Date: Aug 2006
Posts: 2,010

Quote:
Originally Posted by Jason Dunn View Post
At the moment vBulletin lacks any such feature...which completely blows my mind. I'm hoping they'll release a patch in the near future to address this problem.
I hope so. Because if there is one thing I learned from my years of using the Internet, at least one of those 500+ people will try to change their password back to their username
__________________
RoccStar Accessories
http://www.roccstar.com
 
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On

LinkBacks (?)
LinkBack to this Thread: http://forums.thoughtsmedia.com/f21/vbulletin-vulnerability-passwords-shuffled-some-users-90129.html
Posted By For Type Date
forum exploit? - Page 2 - vBulletin Community Forum This thread Refback 08-15-2008 07:43 AM
forum exploit? - Page 2 - vBulletin Community Forum This thread Refback 08-14-2008 11:28 AM
forum exploit? - Page 2 - vBulletin Community Forum This thread Refback 08-13-2008 09:11 PM
forum exploit? - Page 2 - vBulletin Community Forum This thread Refback 08-12-2008 06:01 PM
forum exploit? - Page 2 - vBulletin Community Forum This thread Refback 08-12-2008 09:59 AM
forum exploit? - Page 2 - vBulletin Community Forum This thread Refback 08-12-2008 09:56 AM


All times are GMT +1. The time now is 06:07 AM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC7
Copyright Thoughts Media Inc. 2007