MyBB Hacked!

Discussion in 'MyBB Discussions' started by MordyT, May 31, 2012.

  1. MordyT

    MordyT Grand Master

    Joined:
    Dec 6, 2009
    Messages:
    529
    Likes Received:
    50
    First Name:
    Mordy
    Ok, not so much hacked as social engineered...

    UGNazi has claimed credit, same clowns as WHMCS last week (of which I use). They did leak the entire site last time...

    Oh, who is next....
     
  2. AWS

    AWS Administrator

    Joined:
    Feb 1, 2010
    Messages:
    1,616
    Likes Received:
    692
    Location:
    Joliet, IL U.S.A.
    First Name:
    Bob
    I never understand how anyone can give out any credentials to anyone.

    Too bad for them that they have stupid people in charge of the servers.
     
  3. Justin S.

    Justin S. Regular Member

    Joined:
    Feb 2, 2008
    Messages:
    206
    Likes Received:
    30
    Location:
    Central Ohio
    To our knowledge, they never actually managed to get access to the servers, just the domains. It was the result of a compromise of Chris' Apple ID (and we're not entirely sure how they managed to get access it), but they were able to reset passwords for the hosting and domain that way. Fortunately SoftLayer called Chris directly when the hosting password was reset and were able to completely shut off public access to the server shortly afterward.

    A full explanation of what happened can be found here: http://blog.mybb.com/2012/06/02/well-be-back-soon/
     
  4. AWS

    AWS Administrator

    Joined:
    Feb 1, 2010
    Messages:
    1,616
    Likes Received:
    692
    Location:
    Joliet, IL U.S.A.
    First Name:
    Bob
    Thanks for the info. How is the apple id tied into softlayer hosting?
     
  5. David

    David Regular Member

    Joined:
    May 30, 2003
    Messages:
    1,088
    Likes Received:
    133
    Location:
    Australia
    Probably used his apple id and email address to send all hosting stuff too.
     
  6. AWS

    AWS Administrator

    Joined:
    Feb 1, 2010
    Messages:
    1,616
    Likes Received:
    692
    Location:
    Joliet, IL U.S.A.
    First Name:
    Bob
    That makes sense. I use mine only for app updates.
     
  7. Mikey

    Mikey Mikeylicio.us

    Joined:
    Sep 12, 2009
    Messages:
    484
    Likes Received:
    92
    Location:
    United Kingdom
    It's a very odd attack vector. So unfortunate that MyBB was targeted as a result of one of their users forums.
     
  8. TronXD

    TronXD Regular Member

    Joined:
    Jun 8, 2012
    Messages:
    2
    Likes Received:
    0
    Location:
    England, UK
    First Name:
    Martin
    Yeah nothing to do with the myBB software and everything is sorted now so there is no issue in using the myBB software.
     

Share This Page