Showing posts with label vBulletin Forum. Show all posts
Showing posts with label vBulletin Forum. Show all posts

Friday, 6 November 2015

Exploit For vBulletin Serious Flaw Made Public


Internet is an exploit for a serious vulnerability in the popular forum software vBulletin appeared, allowing attackers simply unpatched websites can take over. Last week vBulletin's website was hacked. Then followed a password reset to 345 000 users.

Last Monday vBulletin published a security update. According to security firm Sucuri vulnerability has been attacked since the end of October and that are easy to abuse. Through the vulnerability allows an attacker to execute arbitrary commands on a vulnerable website. Sucuri also states that vBulletin.com last week using this vulnerability has been hacked and defaced.

Now the exploit was made public administrators advised to get their website as soon as possible to patch. Through the attack, an attacker can completely take over the website viz. At present there are only perceived attacks against several large websites, but Daniel Cid Sucuri warns that this is likely to change soon as the exploit is included in automated attack programs.

Wednesday, 4 November 2015

Forum Software vBulletin Close After Hacking Vulnerability


The makers of the popular forum software vBulletin released a security update for a vulnerability in the software and reset the passwords of almost 345 000 users forum yesterday after an attacker managed to hack the vBulletin.com website.

According to the developers has a "sophisticated attack" occurred on the network. In addition, the attacker may have access to customer IDs and received encrypted passwords. As a precaution, it is now decided by all users on the official support forum of vBulletin to reset the passwords. According to the company's statistics, the forum has nearly 345 000 users.

Further details of the attack are not shared. Ten minutes after the news about the attack and password reset vBulletin installed a new communication line, this time on a vulnerability in the software. The Communication put the developers that they have been notified of a vulnerability in vBulletin 5 Connect 5:14 version to 5.1.9 and therefore a security update has been rolled out. Administrators are advised to install the update. Whether the update fixes the leak which has attacked the vBulletin forum software developer does not know.