Zune Thoughts: vBulletin Vulnerability: Passwords Shuffled for Some Users

Be sure to register in our forums! Share your opinions, help others, and enter our contests.


Laptop Thoughts

Loading feed...

Windows Phone Thoughts

Loading feed...

Digital Home Thoughts

Loading feed...



Thursday, July 31, 2008

vBulletin Vulnerability: Passwords Shuffled for Some Users

Posted by Jason Dunn in "Thoughts Media Status Updates" @ 12:51 PM

If you're trying to log into our forums and having trouble, here's why: there are some individuals going around and running scripts against vBulletin installs, specifically looking to hijack user accounts where the username and password are the same. These people then use these hijacked accounts to send our spam private messages and email messages (I've turned off the email function on our board). I was shocked to learn that we have 559 users who have done exactly that: chosen their password to match their user-name. Not only is this bad security, it leaves the door open for hacker-types to get into our board, pretending to be real users, and cause problems. To prevent this, what we've done is randomize the passwords for the 559 users who were impacted by this.

If you're one of these users, all you need to do is use the Lost Password Recovery Form to have the password sent to you - which you'll then want to reset the password to something else...something other than your user name of course. If you have any trouble with this process, please contact me and I'll manually reset your password. I apologize for any hassle this may cause, but this step was necessary to protect the security of all our users.


Reviews & Articles

Loading feed...

News

Loading feed...

Reviews & Articles

Loading feed...

News

Loading feed...

Reviews & Articles

Loading feed...

News

Loading feed...

Reviews & Articles

Loading feed...

News

Loading feed...

Reviews & Articles

Loading feed...

News

Loading feed...

Sponsored links