Olly
Junior Member
- Jun 28, 2007
- 146
- 293
vBulletin uses salt?
Yep it does.
vBulletin uses salt?
well they black hat is goin down soon apperently so ill wait till a later time
Not really. They have the salt. They just can't use regular rainbow tables. They still have the dictionary attack, mask attack, bruteforce, etc etc.vBulletin uses salt? I didn't know that. That changes things considerably.
new post from that topic i posted from thel3vel.
interesting hopefully this doesn't happen again.
um wow ok........sometimes the unexplained is just unexplainable.Talent is sometimes hidden.Look back and ask,did I make someone mad,or were they already mad.
Lots of us are in school.Don't underestimate the well schooled.The Internet is a vast Ocean.Beware,my friends,don't make US angry.Be cool.Or we Will Be Back.
The Dark Child![]()
sometimes the unexplained is just unexplainable.Talent is sometimes hidden.Look back and ask,did I make someone mad,or were they already mad.
Lots of us are in school.Don't underestimate the well schooled.The Internet is a vast Ocean.Beware,my friends,don't make US angry.Be cool.Or we Will Be Back.
The Dark Child![]()
Well since they had a shell on, they had access to the index file so that means they had access to the vbulletin server files....they could have easily put a "logger" on the login.php so that every time somone logs in it makes the username and pass e-mail them...it's very easy really. I propose backing up the database and attachments then installing smf and converting the database with attachments on a new server just in case if they had root on this one.
Bingo, but they HAVE to make sure to do a clean format and reinstall the os becuz if they don't and even tho they would have smf...if thel3vel had root there is not stopping them then. But I would suggest going to a new server and just iporting db + attachments
This is a quick post being made on behalf of the admin.
FirewallScript has been installed.
All users passwords are NOT loose in the wild and there is no particular reason to change passwords for other sites you use. Vbulletin utilizes a salt which is over 4 charachters, so unless your password was 3 charachters or less there is no chance it could be decrypted to plain text.
All future attacks should be stopped now.
Dan - Http://www.firewallscript.com
Yes BUT if they had or still have a logger on login.php then your screwed. In that case they wouldn't need the DB. Just make an announcement to the members (just to be safe)to change there passwords. Becuase it is most likely they put up a logger. I know how they think...