Results 1 to 14 of 14
  1. #1
    Thailand Expat harrybarracuda's Avatar
    Join Date
    Sep 2009
    Last Online
    @
    Posts
    103,054

    Ubuntu Forums Hacked, 1.8 Million Passwords, E-Mails & Usernames Stolen

    Ubuntu Forums Hacked, 1.8 Million Passwords, E-Mails & Usernames Stolen
    BY JOEY-ELIJAH SNEDDON UNDER NEWS 7 HOURS AGO

    The Ubuntu Forums have been hacked, with attackers grabbing data from more than 1.8 million users accounts.

    ‘Ubuntu One and Launchpad are not affected by the breach’
    ‘Every user’s local username, password, and email address [were stolen] from the Ubuntu Forums database’ Canonical say in a statement posted on the website, adding that while the ‘passwords (stolen) are not stored in plain text’ those who use the same password on other services should ‘change the password on the other service[s] ASAP.’

    While data from the Forums has been compromised they stress that other services, such as Ubuntu One and Launchpad, ‘are not affected by the breach’.

    Timeline

    Reports of the forums being ‘defaced’ surfaced on late Saturday (July 20th). The main page was redirected to that of an image touting a twitter account – @Spuntn1k_ – and text that read: “You dun goofed, it’s as simple as that”.

    Early Twitter accounts of the hack say that an unspecified music track was also played when accessing the homepage.

    ubuntu forums hack

    The Ubuntu Forum homepage was replaced with this image



    So how did this happen? That’s the question Canonical will be trying to find out as soon as possible.

    ‘The forum was running an outdated version of vBulletin [without] admin panel protection’

    Security blog Sucuri suggest that the hack may have been achieved due to lax protection on the backend. According to an un-named source they’ve been told that the forum was running an outdated version of vBulletin that ‘didn’t have the admin panel protected’.

    Canonical has since redressed the breach, replacing the image with an announcement on what happened so far.

  2. #2
    The Pikey Hunter
    Gerbil's Avatar
    Join Date
    Jan 2006
    Last Online
    @
    Location
    Roasting a Hedgehog
    Posts
    12,355
    How awful. Must have affected all dozen or so of their users.

  3. #3
    Thailand Expat harrybarracuda's Avatar
    Join Date
    Sep 2009
    Last Online
    @
    Posts
    103,054
    1.8 Million Passwords, E-Mails & Usernames Stolen
    Arithmetic not one of your strong points then.


  4. #4
    The Pikey Hunter
    Gerbil's Avatar
    Join Date
    Jan 2006
    Last Online
    @
    Location
    Roasting a Hedgehog
    Posts
    12,355
    ^ They were probably all multinics and Nigerian spammers

  5. #5
    Thailand Expat harrybarracuda's Avatar
    Join Date
    Sep 2009
    Last Online
    @
    Posts
    103,054
    Quote Originally Posted by Gerbil View Post
    ^ They were probably all multinics and Nigerian spammers
    Nah, they're probably all nerds who spend all their time saying how insecure Windows is, etc.


  6. #6
    Pronce. PH said so AGAIN!
    slackula's Avatar
    Join Date
    Jul 2009
    Last Online
    @
    Location
    Behind a slipping mask of sanity in Phuket.
    Posts
    9,088
    Quote Originally Posted by harrybarracuda
    Nah, they're probably all nerds who spend all their time saying how insecure Windows is, etc.
    Reading is not one of your strong points then.

    ‘The forum was running an outdated version of vBulletin [without] admin panel protection’

  7. #7
    Thailand Expat Boon Mee's Avatar
    Join Date
    May 2006
    Last Online
    13-09-2019 @ 04:18 PM
    Location
    Samui
    Posts
    44,704
    Never heard of 'em...

  8. #8
    Thailand Expat harrybarracuda's Avatar
    Join Date
    Sep 2009
    Last Online
    @
    Posts
    103,054
    Quote Originally Posted by quimbian corholla View Post
    Quote Originally Posted by harrybarracuda
    Nah, they're probably all nerds who spend all their time saying how insecure Windows is, etc.
    Reading is not one of your strong points then.

    ‘The forum was running an outdated version of vBulletin [without] admin panel protection’
    Really, and when was that part of Windows then?

    Written in PHP
    Operating system Cross-platform
    Platform PHP / MySQL

  9. #9
    Pronce. PH said so AGAIN!
    slackula's Avatar
    Join Date
    Jul 2009
    Last Online
    @
    Location
    Behind a slipping mask of sanity in Phuket.
    Posts
    9,088
    Quote Originally Posted by harrybarracuda
    Really, and when was that part of Windows then?
    Sigh.



    <thatsthejoke.jpg>

  10. #10
    Thailand Expat harrybarracuda's Avatar
    Join Date
    Sep 2009
    Last Online
    @
    Posts
    103,054
    Perhaps you can explain it.

  11. #11
    Pronce. PH said so AGAIN!
    slackula's Avatar
    Join Date
    Jul 2009
    Last Online
    @
    Location
    Behind a slipping mask of sanity in Phuket.
    Posts
    9,088
    Quote Originally Posted by harrybarracuda
    Perhaps you can explain it.
    Really? OK then.

    Your posts, especially the first and third, seemed to infer that the attack was possible because of a vulnerability in the OS when your article states that the attack was via a badly configured vBull installation.

    You ribbed Gerbil for his arithmetic after he made a light-hearted comment and then I ribbed you after you made one. That is all, nothing was really meant by it. Sorry if it came across badly.

  12. #12
    Thailand Expat harrybarracuda's Avatar
    Join Date
    Sep 2009
    Last Online
    @
    Posts
    103,054
    Quote Originally Posted by quimbian corholla View Post
    Your posts, especially the first and third, seemed to infer that the attack was possible because of a vulnerability in the OS
    Really? Where was that then?

    And my posts wouldn't "infer" anything, they'd "imply". I suggest you "inferred" a little too much.


  13. #13
    Pronce. PH said so AGAIN!
    slackula's Avatar
    Join Date
    Jul 2009
    Last Online
    @
    Location
    Behind a slipping mask of sanity in Phuket.
    Posts
    9,088
    Quote Originally Posted by harrybarracuda
    And my posts wouldn't "infer" anything, they'd "imply"
    Heh, I wrote 'imply' and then changed it to 'infer'. I always screw those two up.

  14. #14
    Thailand Expat
    poorfalang's Avatar
    Join Date
    Nov 2012
    Last Online
    27-02-2020 @ 08:01 PM
    Location
    in the sticks
    Posts
    1,427
    Quote Originally Posted by harrybarracuda
    ‘The forum was running an outdated version of vBulletin [without] admin panel protection’
    Isn't that the same as teakdoors?

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •