What's to be learned from this?
Server setting needed hardening?
Software needed updating and was vulnerable?
vBulletin is a well used and documented lice of code. I'd love to know what the security experts here think.
Server setting needed hardening?
Software needed updating and was vulnerable?
vBulletin is a well used and documented lice of code. I'd love to know what the security experts here think.
Oh goody! Another million credentials to refine my password dictionary!
If it was a known vulnerability there is nothing to learn but "patch your shit". But if you want some advice, the only thing you can learn from somebody exploiting a web application (assuming the hole was in vBulletin, which we have no idea) is that you can't trust the security of web applications. Do all the general system-hardening stuff that nobody ever does, install a webapp firewall, and pray.