View Full Version : vBulletin Vulnerability: Passwords Shuffled for Some Users
Jason Dunn
07-31-2008, 08:51 PM
<p>If you're trying to log into our forums and having trouble, here's why: there are some individuals going around and running scripts against vBulletin installs, specifically looking to hijack user accounts where the username and password are the same. These people then use these hijacked accounts to send our spam private messages and email messages (I've turned off the email function on our board). I was shocked to learn that we have 559 users who have done exactly that: chosen their password to match their user-name. Not only is this bad security, it leaves the door open for hacker-types to get into our board, pretending to be real users, and cause problems. To prevent this, what we've done is randomize the passwords for the 559 users who were impacted by this.</p><p>If you're one of these users, all you need to do is use the <a href="http://forums.thoughtsmedia.com/login.php?do=lostpw" target="_blank">Lost Password Recovery Form</a> to have the password sent to you - which you'll then want to reset the password to something else...something other than your user name of course. If you have any trouble with this process, <a href="http://forums.thoughtsmedia.com/sendmessage.php" target="_blank">please contact me</a> and I'll manually reset your password. I apologize for any hassle this may cause, but this step was necessary to protect the security of all our users.</p>
Rocco Augusto
08-01-2008, 01:14 AM
Are we going to prevent users from using their username as their password in the future?
Jason Dunn
08-01-2008, 04:06 AM
Are we going to prevent users from using their username as their password in the future?
At the moment vBulletin lacks any such feature...which completely blows my mind. I'm hoping they'll release a patch in the near future to address this problem.
Rocco Augusto
08-01-2008, 07:43 PM
At the moment vBulletin lacks any such feature...which completely blows my mind. I'm hoping they'll release a patch in the near future to address this problem.
I hope so. Because if there is one thing I learned from my years of using the Internet, at least one of those 500+ people will try to change their password back to their username ;)
what's the point in hijacking an account fr this purpose? is it that hard to generate an account? all that hassle because of the CAPTCHA?
Pony99CA
12-04-2008, 11:35 PM
what's the point in hijacking an account fr this purpose? is it that hard to generate an account? all that hassle because of the CAPTCHA?
Because your spam will appear to come from a legitimate user. If you're really lucky, it will be one with an extensive posting history. Admins probably won't be so quick to ban accounts for those people like they would with new users; instead, they'll do what Jason (and I, when this happened at pocketnow) did and change the passwords (I also E-mailed the few users I noticed to let them know what happened).
For example, one user at pocketnow who seemed to fall into this was the CEO of a well-known gadget clothing company. That one really surprised me. I wasn't about to ban or delete his account, though.
Given that this happened over four months ago, I hope there's now code in place to prevent passwords that are the same as user names. It seems like it should be a very simple change.
For what it's worth, I just tested this on my phpBB 2.x forum (http://forum.svpocketpc.com) and nothing prevents user IDs and passwords from being identical, either. (I haven't tested phpBB 3.x.)
Steve
vBulletin® v3.8.9, Copyright ©2000-2019, vBulletin Solutions, Inc.