Close

Results 1 to 4 of 4
  1. #1
    DF VIP Member biffo1's Avatar
    Join Date
    Sep 2007
    Location
    Manchester
    Posts
    1,303
    Thanks
    1
    Thanked:        2
    Karma Level
    383

    Info vBulletin easily hacked

    A serious flaw in software widely used to power online discussion sites could allow hackers to harvest reams of personal data, the BBC has learned.

    The flaw in a specific version of the vBulletin software allows anyone to easily access the main administrator username and password for a site.

    This would also allow hackers to access data, such as e-mail addresses, and edit the site at will.

    The owner of the program - Internet Brands - released a fix on 21 July.

    However, at time of writing, many sites remain vulnerable.

    The BBC was alerted to the problem by Stuart Wright of audio visual reviews site AV forums, which uses the software for its discussion boards, before the patch was released.

    "It is very worrying that they are releasing a product which has such a horrendous flaw," Mr Wright told BBC News.

    "I'm really not happy - we rely on this software for our business."

    AV Forums has around 300,000 members. It was not using the version with the flaw.

    Internet Brands has not responded to requests for comment on the problem.

    vBulletin is software that is used to power the vast majority of internet forums and discussion boards on the web.

    It was originally developed by Jelsoft and vBulletin Solutions, but was sold to Internet Brands in 2007.

    The flaw affects version 3.8.6 of the software, which was released on 13 July.

    "If the provider of the software says there is a issue with it, they have flagged it up to the entire internet” Graham Cluley

    The simple hack, which the BBC has confirmed, allows even unskilled people to access many websites.

    With a few key strokes the person can obtain the administrator's username and password for the website.

    This can be used to log in to the site and modify and delete elements at will.

    David Ross, founder of Hexus.net, a technology news and reviews website, said the flaw was a "potential nightmare".

    "It could allow someone to access all of the user accounts for the site," he said.

    This would be useful to a hacker, he said, because it was "good quality information" that had already been verified.

    Hexus.net, which has 75,000 registered users, updated their site as soon as they were made aware of the flaw.

    Internet Brands announced a patch for the problem at 1900 BST on 21 July on its website.

    It also sent e-mails to its customers and sent out a message that appeared on the main control panels of individual customers' software.

    However, hours before the official announcement, third party firms that provide services to vBulletin were already warning of a problem.

    "It has come to our attention that a vulnerability on vBulletin 3.8.6 has been discovered," read one from vBSEO.

    "The exploit allows a malicious user to retrieve a forum's database credentials."

    It then offered advice on how to fix the problem.

    Kier Darby, the former lead developer of vBulletin also issued an alert via Twitter.

    However, nearly 24 hours later, many websites are still vulnerable.

    Graham Cluley of security firm Sophos said that this could be because firms were testing the new patch.

    "If this is a piece of software running on your company website then it is good practice to test it before it goes live to make sure you're not introducing more problems," he told BBC News.

    However, he said, firms should plug the flaw as soon as possible.

    "If the provider of the software says there is a issue with it, they have flagged it up to the entire internet," he said.

    "That means that criminal will be looking at it to see if there is there anything they can exploit."

    http://www.bbc.co.uk/news/technology-10714192

  2. #2
    DF VIP Member Bald Bouncer's Avatar
    Join Date
    Jun 2001
    Location
    UK
    Posts
    9,771
    Thanks
    4,161
    Thanked:        5,596
    Karma Level
    1132

    Default Re: vBulletin easily hacked

    vBulletin™ Version 3.8.6 only, from what I can gather "someone" left the debug code in the released version and leaves it vulnerable via the help and FAQ search

  3. #3
    DF VIP Member Geezah's Avatar
    Join Date
    Jun 2004
    Location
    cyberspace
    Posts
    939
    Thanks
    52
    Thanked:        177
    Karma Level
    325

    Default Re: vBulletin easily hacked

    Quote Originally Posted by biffo1 View Post
    "It is very worrying that they are releasing a product which has such a horrendous flaw," Mr Wright told BBC News.
    What would Bill gates say about the flaws in his products used by 85% of pc users?

    You dont see public complaints about Windows on the local news, which is far more serious than a bit of data harvesting from a web forum database.

  4. #4
    DF VIP Member purpleanimal23's Avatar
    Join Date
    Nov 2004
    Location
    UK
    Posts
    895
    Thanks
    43
    Thanked:        86
    Karma Level
    308

    Default Re: vBulletin easily hacked


Similar Threads

  1. Some Tw*t has hacked my icq number
    By FireBlade in forum System Security
    Replies: 5
    Last Post: 25th November 2002, 01:49 PM
  2. Need a good cheap Host that works easily with forms!
    By Piratevirus in forum Web Hosting & Domain Names
    Replies: 11
    Last Post: 12th November 2002, 11:55 AM
  3. "hacked" google perhaps??
    By chippy in forum The Dog and Duck
    Replies: 2
    Last Post: 5th November 2002, 07:53 PM
  4. vBulletin
    By FLuxo in forum Website Coding & Graphics
    Replies: 3
    Last Post: 16th September 2002, 04:32 PM

Social Networking Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •