Password hack of vBulletin.com
arstechnica.com
arstechnica.com
It doesn't end there. The folks who own vBulletin run a whole series of communities themselves:
http://www.internetbrands.com/
At one point into configuring vBulletin I realized they had code in there that would allow them to monitor your site's traffic and performance. Which is genius if you run hundreds of sites yourself and want "probes" out there to discover areas that you could launch sites into. And, it is even more brilliant if you can have these "probes" be people who pay you to use software you produce. Imagine thousands of business experiments actually paying you and feeding you audience data. That really didn't sit well with me and a number of people who were awake while installing and configuring their vB software. The vast majority of folks running vB communities either don't care or don't have a clue.
There are other issues. Maybe someone else has the time to chime in.
I guess my point is that password security might not be at the top of their priority list.
I found the code for the "anonymous survey", but you have to submit it manually.
Edit: I think you might mean the news loaded remotely in the Admin CP upon every login. It's injected in the page as is.
Like I said, I stopped using vB a long time ago. For all I know they've fixed this issue. Please don't take my word for it as current versions might behave differently. If you are a vB user I suggest you ask in their various official and unofficial support forums.
I worked for a SaaS ecommerce outfit a few years ago and they sold their stuff to all the competitors in the same market space. After a bit, they yanked it with 28 days' notice and went into direct competition with them. Assholes. Strikes me as the same sort of company.
There are 2 types of websites. Those which are important enough for you to remember a password for and those which aren't. Well the 50 or so which aren't important enough have one password and this password has been compromised at least 5 times this year. As far as I know people haven't been logging into my accounts but I guess there is nothing stopping them.
I find it really difficult to understand how this happens so often. In many cases it seems like security is an after-thought and procedures are poorly implemented.
If it is true that the vulnerability exploited has been in vB since version 4.. that means it has been there for 3 years! I wonder how sophisticated it really was? I wonder when the vBulletin last got an external security audit done..
I'd go as far to say that vBulletin is a pile of crap.
But you are right; the competition (at least it used to be; haven't needed any forums recently and the last one I made myself) was every far worse.
I've had to deal with the multi-day aftermath of an XSS worm twice. That's when you realise that it's as bad as it is. After that it was "get fucked" and move to phpbb which while is not a stellar product it seems to be put together with a modicum of common sense and has a responsive community and support.
Bit of a "no true scotsman" that one as well. Just because someone doesn't use Zend doesn't mean they write spaghetti.
I'd really like to see how this hack works for general knowledge and if it's purely via the script itself and not a server attack.
By the way, if anyone is wondering how VBulletin forums store passwords... It's md5(md5(password)+salt).
if (md5(password + salt) == stored value) ..
If they'd just used a vague handwavy word like "encoded" we'd be left wondering what they did to the passwords and it would still be just as legible to the laymen, instead of being given an actually incorrect piece of information.
And a "cracker" is a subset of hackers. So as much as it makes self-identified hackers cringe, it is correct to say that a hacker broke into a system.
"encoded passwords".
So hashing is a subset of encrypting, just like crackers are a subset of hackers.
From a theoretical point of view, hash functions are not only a subset of block ciphers: hash functions and block ciphers are equivalent. You can take a hash function and build a block cipher from it (use a Feistel network). You can also take a block cipher and build a hash function from it (use the Merkle–Damgård construction).
But even if you can build one from the other, saying something is 'encrypted' implies, in even the meanest definition, that it can be decrypted. If the layperson definition does not include this aspect, then it is, well, wrong. Even if you disagree on this point, I would expect a tech journalist to endeavor to use the correct, field-standard terminology, regardless, because as Pxtl says, anyone who is familiar with even the basics of cryptography will interpret "encrypted password" in an incorrect way (i.e., they'll see it as what Adobe did).
> We take your security and privacy very seriously. Very recently, our security team discovered sophisticated attacks on our network, involving the illegal access of forum user information, possibly including your password. Our investigation currently indicates that the attackers accessed customer IDs and encrypted passwords on our systems. We have taken the precaution of resetting your account password. We apologize for any inconvenience this has caused but felt that it was necessary to help protect you and your account.
> To regain access to your account:
> Visit the vBulletin forums at http://www.vbulletin.com/settings/account
> Enter in your existing password followed by your new password, twice for confirmation.
> Save this page at the bottom.
> Please choose a new password and do not use the same password you used with us previously. We also highly recommend that you chose a password that you are not using on any other sites.
> If you have any additional questions or concerns, please feel free to contact our support team at http://www.vbulletin.com/go/techsupport or support@vbulletin.com.
> Sincerely,
Of course I reset the password to another generated LastPass one, but I did wonder what the scope of the attack was.
I received the same one and it didn't come from vbulletin's domain name. If you go to the root of the domain name it says "Test page."
When you click the "read in browser" option you are taken to a page where all the links to access the forums do not work.
I thought it was a phishing attempt.
> http:// click.shopping.ibemail. com/
Not that it matters, I never follow links in emails and went direct to vbulletin.com
I bet they emailed everyone on their stolen email list though.
I think that the browser developers should push for a keychain of random, generated passwords and use as many UI pointers as possible to push people to use these. Apple's implementation in Safari is what we should be aiming for, but pretty useless to me as I have Linux/Windows/Android devices that don't support Safari.
Unfortunately, all three major browser vendors seem too busy pushing their own single sign-on schemes (Chrome: Google account, IE: Microsoft account, Mozilla: Persona). So they're unlikely to pay any attention to plain old password generation and storage for the foreseeable future. Which is a real pity because passwords aren't going to disappear overnight.
I've been using LastPass for a long time and even purchased their their Enterprise version for $work. I also use KeePass and recommend both.
Also, "We wanted to prove that nothing in this world is not safe" has a double negation, so they wanted to prove that there is something out there that could be safe?