What is the status of the investigation on how everyone's account info was stolen? Should we assume the site vulnerability is still there waiting to be exploited again?
What is the status of the investigation on how everyone's account info was stolen? Should we assume the site vulnerability is still there waiting to be exploited again?
They logged into a moderator account, and escalated by posting an HTML announcement (it was a non-obvious setting).
1. All admin/mod passwords have been changed and will be forced rotated. Password managers used
2. HTML Announcements turned off for everyone (even admins)
So, those steps alone should plug the actual exploit that was used. But we've also done a lot more than just that, and are still working on more to improve security.
arn
Hello Arn,
Does it appear that the Vbulletin people will be doing anything to update/modify the passwd encryption/hashing methodology within their product?
If the answer is no, are you/MacRumors considering looking into Joomla or Drupal or some other product similar to Vbulletin?
Thank you for keeping this great forum up and operational.
Probably a very clever ad for iCloud Keychain
They logged into a moderator account, and escalated by posting an HTML announcement (it was a non-obvious setting).
1. All admin/mod passwords have been changed and will be forced rotated. Password managers used
2. HTML Announcements turned off for everyone (even admins)
So, those steps alone should plug the actual exploit that was used. But we've also done a lot more than just that, and are still working on more to improve security.
arn
As I mentioned in an earlier post in this thread, a photography site in which I hang out has decided to make the leap from vB to something else.....and a few days ago they finally did just that. They also went to a new server for greater capacity and such, too. The changeover did not take nearly as long as had been anticipated. They'd been telling us it would be as long as five or six days, maybe even over a week, and yet everything was up and running in about three or four days if I recall correctly.
From what I have seen so far of the new software they are using, XenForo, it looks pretty good and seems to be very user-friendly. It's early days yet, of course, so if there are any major problems they have not yet cropped up. Users of the site seem pleased and so do the admins and mods as they have been working "under the hood" to make various adjustments if indicated. However, I do realize that while the other site is a busy and active one, it is nowhere near as large as MacRumors and of course this may be a consideration when it comes to choosing new forum software. I think there is a fair amount of flexibility built into the XenForo software but it may not be flexible in all the ways that are needed by MR.
Whatever, just my little update on how that change is working out for another forum that prior to this had been using vBulletin.
As I mentioned in an earlier post in this thread, a photography site in which I hang out has decided to make the leap from vB to something else.....and a few days ago they finally did just that. They also went to a new server for greater capacity and such, too. The changeover did not take nearly as long as had been anticipated. They'd been telling us it would be as long as five or six days, maybe even over a week, and yet everything was up and running in about three or four days if I recall correctly.
From what I have seen so far of the new software they are using, XenForo, it looks pretty good and seems to be very user-friendly. It's early days yet, of course, so if there are any major problems they have not yet cropped up. Users of the site seem pleased and so do the admins and mods as they have been working "under the hood" to make various adjustments if indicated. However, I do realize that while the other site is a busy and active one, it is nowhere near as large as MacRumors and of course this may be a consideration when it comes to choosing new forum software. I think there is a fair amount of flexibility built into the XenForo software but it may not be flexible in all the ways that are needed by MR.
Whatever, just my little update on how that change is working out for another forum that prior to this had been using vBulletin.
There are some security issues that they need to patch.
Furthermore, a large forum like Macrumors would not be easy to convert to XenForo. Not something you just do in a few days.
AV Forums have just moved over to Xenforo, so it's not impossible, albeit not trivial either.
On Nov. 24, Trustwave researchers tracked that server, located in the Netherlands. They discovered compromised credentials for more than 93,000 websites, including:
318,000 Facebook (FB, Fortune 500) accounts
70,000 Gmail, Google+ and YouTube accounts
60,000 Yahoo (YHOO, Fortune 500) accounts
22,000 Twitter (TWTR) accounts
9,000 Odnoklassniki accounts (a Russian social network)
8,000 ADP (ADP, Fortune 500) accounts (ADP says it counted 2,400)
8,000 LinkedIn (LNKD)accounts
AV Forums have just moved over to Xenforo, so it's not impossible, albeit not trivial either.
It is amazing this thread is still going.
It has already served is purpose long ago.
The bottom line is that anything can be hacked, it is just a matter of time; and we have to all be careful and ever vigilant.
Other security theories and matters would reasonably belong in their own appropriate threads.
----------
I use a free open source platform and it works great with appropriate security measures.
It is called MyBB http://www.infamousdevelopers.com
But, even with all I have done I know that I have to be active, otherwise it like any other platform can be over run.
There's a lot of forum software packages out there. MyBB, XenForo, vBulletin (vB3, which this forum is based on I believe is End Of Life), Invision Power etc.
Yeah, MR uses vB3, but while it's old (and pretty much unsupported), all bugs and security issues has been ironed out - I guess it's more secure than vB4 and vB5.
Remember, this hack wasn't because of an exploit, but a moderator's weak password - no system can be stronger than the weakest link (in this case, a moderator with a weak password).
+ MR probably uses tons of custom plugins which would not work in newer vB-versions, and would have to be re-coded (also the case if they changed to XenForo/whatever).
Actually the thread was dead for over half a month before you just revived it. Thanks brah.It is amazing this thread is still going.
It has already served is purpose long ago.
The bottom line is that anything can be hacked, it is just a matter of time; and we have to all be careful and ever vigilant.
Other security theories and matters would reasonably belong in their own appropriate threads.
----------
I use a free open source platform and it works great with appropriate security measures.
It is called MyBB http://www.infamousdevelopers.com
But, even with all I have done I know that I have to be active, otherwise it like any other platform can be over run.