vBulletin security flaw

Quantum Windbag

Gold Member
May 9, 2010
58,308
5,099
245
I thought this was the quickest way to make sure the appropiate people saw this, especially since I really don't know who is in charge of this type of stuff.

Attackers appear to have compromised tens of thousands of Web sites using a security weakness in sites powered by the forum software vBulletin, security experts warn.
http://krebsonsecurity.com/wp-content/uploads/2013/10/vbattack1.png


In a blog post in late August, vBulletin maker Jelsoft Internet Brands Inc. warned users that failing to remove the “/install” and “/core/install” directories on sites running 4.x and 5.x versions of the forum software could render them easily hackable. But apparently many vBulletin-based sites didn’t get that memo: According to Web site security firm Imperva, more than 35,000 sites were recently hacked via this vulnerability.
The security weakness lets attackers quickly discover which forums are vulnerable, and then use automated, open-source exploit tools to add administrator accounts to vulnerable sites.

Thousands of Sites Hacked Via vBulletin Hole ? Krebs on Security
 

Forum List

Back
Top