Android Forums hacked: 1 million user credentials stolen
zdnet.com
zdnet.com
Server setting needed hardening?
Software needed updating and was vulnerable?
vBulletin is a well used and documented lice of code. I'd love to know what the security experts here think.
Oh goody! Another million credentials to refine my password dictionary!
If it was a known vulnerability there is nothing to learn but "patch your shit". But if you want some advice, the only thing you can learn from somebody exploiting a web application (assuming the hole was in vBulletin, which we have no idea) is that you can't trust the security of web applications. Do all the general system-hardening stuff that nobody ever does, install a webapp firewall, and pray.
So for a 2-iteration password cracker, that's enough to search almost a 48 bit space of passwords in a day. That's enough to check every possible ASCII password of 7 characters or less, and a good heuristic search will probably get you much more than that.
> If you still want to do it by steam, for a new user you just need to generate a 3 character salt randomly ...
I can't see the code example, but assuming char is 8 bits (which isn't unreasonable for ascii), that's at best, 16M unique salts.
(sorry, that was terrible).