Categories: SecurityWorkspace

vBulletin Forum Passwords Taken, Thousands Of Sites May be Affected

The vBulletin forums software has been breached, with hackers stealing customers’ password data. The breach – the latest in a series relating to vBulletin – could affect thousands of sites which use the popular bulletin board platform.

vBulletin staff have reset all passwords on its own user forum following evidence of the breach, but the software was in use at many other Internet sites, including MacRumors, where an attacker stole around 860,000 passwords last week, and Ubuntu Forums where an attack in July exposed 1.8 million user accounts. There are now fears that other vBulletin-based forums may also be exposed to danger.

vBulletin logo

Did you get the vBulletin memo?

One hacker group, Inj3ct0r, claimed on its Facebook page to have been behind both the MacRumours and vBulletin hack. The  group’s statement claims: “We found a critical vulnerability in vBulletin all versions 4.x.x and 5.х.x.

The group then offers a link to its site, where users are invited to pay for a patch, and justifies its actions, saying somewhat nonsensically: “We wanted to prove that nothing in this world is not safe”.

vBulletin, which is owned by Internet Brands, has not spoken about the wider danger, but has moved to secure its own bulletin board.

“Very recently, our security team discovered sophisticated attacks on our network, involving the illegal access of forum user information, possibly including your password,” it told users in a post on the vBulletin forum. “Our investigation currently indicates that the attackers accessed customer IDs and encrypted passwords on our systems. We have taken the precaution of resetting your account password. We apologise for any inconvenience this has caused but felt that it was necessary to help protect you and your account.”

Security experts have been critical of vBulletin for some time. Brian Krebs in August warned that thousands of vBulletin sites had been hacked because their owners missed a crucial memo from the software maker, detailing a vulnerability that users could leave open if they did not delete the “install” directory.

In 2011, game compny Valve Software’s  forums were breached because the company had not upgraded to the latest version of vBulletin.

Are you a security expert? Try our quiz!

Peter Judge

Peter Judge has been involved with tech B2B publishing in the UK for many years, working at Ziff-Davis, ZDNet, IDG and Reed. His main interests are networking security, mobility and cloud

Recent Posts

OpenAI’s Lightcap To Take On Expanded Role

OpenAI chief operating officer Brad Lightcap to oversee international expansion as company consolidates lead in…

12 hours ago

China Unveils Deep-Sea Cable-Cutting Device

Chinese researchers publish details on device that could wreak havoc on undersea communications cables in…

12 hours ago

Pat Gelsinger Joins Faith-Based Tech Company Gloo

Former Intel chief Gelsinger expands role at Gloo, becoming executive chairman and head of technology…

13 hours ago

MEPs Ramp Pressure For Second EU Chips Act

MEPs add to Commission pressure for second EU Chips Act amidst industry calls for renewed…

13 hours ago

Xiaomi Raises $5.5bn In Expanded Share Sale

Smartphone maker Xiaomi reportedly raises about $5.5bn in Hong Kong share sale as it invests…

14 hours ago

BYD Launches Rival To Tesla’s Model 3 At Half Price

BYD's Qin L EV sedan starts at about half the price of Tesla's Model 3,…

14 hours ago