CheckEmoji Community · the emoji forum
🏠 Home 🆕 What's new ❓ Unanswered 🔥 Popular 📡 RSS Members 👥 0 online log in · register
Home › Miscellaneous › Forum Help! › Has there been a security breach on the forum?

Has there been a security breach on the forum?

Started by Megan Thomas5 · · 👁 7 views · 49 replies

📡 Subscribe to replies

Participants Megan Thomas5Alexander Diaz4coppersailor28Jessica Morris6Casey BennettGeorge Cook31Jack Cook7wearybison63Bradley White73urbanheron4Jose Miller3mistybisoncrimsonhound80silentviper8Matthew Jackson2
Megan Thomas5 Megan Thomas5 Active MemberOP
132 messages
joined Jan 2021
#1 ·
Reddit

Reddit

Spammers have been around since the dawn of the internet, but these aren't just bot accounts. They look like real profiles—they were actually active once, properly registered, and used to post normally too.
Alexander Diaz4 Alexander Diaz4 Member
39 messages
joined Sep 2021
#2 ·
We don't have any issues—this forum is 100% secure.

Lock it, Lock.
coppersailor28 coppersailor28 Active Member
156 messages
joined Mar 2012
#3 ·
Alexander Diaz4 said:We don't have issues; this forum is 100% secure. ...

Look, the forum is as secure as anything else is...
...but when it comes to theft—or "borrowing" accounts—users are often the ones at fault in certain scenarios.

For instance:
- using the exact same username and password (like milo; milo)
- the password being a derivative of the username (like milo; moje)

(It would be interesting to know if user @Drelja1 was actually one of those cases)
Jessica Morris6 Jessica Morris6 Active Member
195 messages
joined Nov 2022
#4 ·
It’s honestly worth taking a moment every now and then to just swap out your passwords and update your email security... I actually ended up switching my own email password the other day just to be safe.
If you want to check if your email has been compromised, you can look right here. https://haveibeenpwned.com/
Casey Bennett Casey Bennett Regular
522 messages
joined Nov 2011
#5 ·
Apparently, this is a headache that a ton of other forums are dealing with too.
Watch your email addresses. Use complex passwords, turn on two-factor authentication, and stay vigilant about all that.
George Cook31 George Cook31 Newcomer
6 messages
joined Oct 2021
#6 ·
Casey Bennett said:I guess a ton of other forums are dealing with this exact same headache.
You really ought to watch your email addresses closely. Use tough passwords, set up two-factor authentication, and all that stuff.

Once I finally manage to crack someone's password, I can just breeze right into their profile and swap out the email address without any drama.
I’ll say it again, though—I can change an email address, and the notification about that change only goes to the new address I provided, which, according to the new rules, becomes the only email used for password resets too.

You might have two-factor authentication active on your original email or whatever, but honestly, it doesn't even matter. It's kind of pointless.
It feels pretty useless when this damn forum makes it way too easy to just swap out an entire address without asking for any verification at all.

I'm not saying this has actually happened yet, since looking at the hacked profiles, it seems the emails stayed the same.
And look, I'm not saying there isn't some way to fix things if it does go down, but man, don't try to lecture me about security.
Casey Bennett Casey Bennett Regular
522 messages
joined Nov 2011
#7 ·
On a site like Reddit, getting your profile snatched back is an uphill battle. Once hackers swap out the verification email, you're basically locked out.
You can't just magically reclaim a compromised email address.

I’ll say it again: you cannot simply revert a hijacked email.
That is exactly why I emphasized securing your actual email account rather than obsessing over your forum handle and password.

For God's sake, even high-security servers holding critical data get breached constantly. Why is everyone acting so shocked that a random forum gets hit? The absolute worst a hacker can do here is grab some login credentials and go spamming elsewhere.

Cmon. Get real.
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#8 ·
Can I jump in here for a sec?
wearybison63 wearybison63 Active Member
60 messages
joined May 2021
#9 ·
Go ahead. 👍on
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#10 ·
Someone’s running this super slow script just to test out everyone's forum passwords. It’s designed to be incredibly gradual so it flies right under the radar of the provider's IDS/IPS systems—since those things mostly just flag the aggressive, loud attacks.

The guy behind it is actually decent enough that every single time he cracks a password, he leaves the exact same message.

I honestly don't know what his real endgame is, though I can take a pretty good guess.
Bradley White73 Bradley White73 Active Member
78 messages
joined Sep 2020
#11 ·
If only there were some kind of more secure option out there. 🕺
Casey Bennett Casey Bennett Regular
522 messages
joined Nov 2011
#12 ·
As for how much more secure a monitor might be, I honestly can't say for sure, though it’s certainly more modern.
But look, moving from one platform to another is entirely up to the owner. We users have zero influence over his decisions or how fast he pulls the trigger on a transition if he finally decides to make it happen.

Jack Cook7, I'll pass that info along.

coppersailor28 said:(it would be interesting to find out if user @Drelja1 was also one of those cases)

Yes. 😠

Alexander Diaz4 said:We don't, the forum is 100% secure.

Can we just Lock this, please?

Honestly, you are being exhausting.
Your own bed in your bedroom isn't 100% secure, yet you expect absolute, guaranteed security on the internet? Anywhere on the web?
Keep dreaming.
Bradley White73 Bradley White73 Active Member
78 messages
joined Sep 2020
#13 ·
I’m changing my password right now and logging back in—the whole session seems to be running over HTTP, even though vBulletin is supposed to be on HTTPS. Besides that, I did a little Google search for exploit lists targeting older versions of vBulletin, and honestly, it looks like this software is basically just beginner-level training for anyone interested in hacking. I wonder if security patches are even being released for this specific version anymore, or if the real recommendation is to just upgrade to the latest version immediately? I have a feeling you might know the answer to that. Newer software definitely comes with regular patches. Also, since you mentioned two-factor authentication earlier, I checked, and it turns out XenForo (2021) actually supports that too. I get that you guys are in a bit of a tough spot here; it’s not like the decision is entirely yours, so I totally understand. But there’s really no point in being careless about this—maybe just send out a notice so users can at least strengthen their passwords? It wouldn't be a waste of time, especially considering the kind of scripts Jack Cook7 might be looking at.
George Cook31 George Cook31 Newcomer
6 messages
joined Oct 2021
#14 ·
I’m actually pretty curious about what really drives the hackers hanging out on these forums.
Maybe they just want to snoop through someone’s private messages? I guess that's a possibility.

But honestly, posting those ridiculous links? They’ve probably realized by now that nobody is actually clicking on them.
I even tried clicking one once, and man, the website was so incredibly weird—it was at one point so bizarrely designed that if I had actually wanted to give them some money, I wouldn't have even known how to figure it out. 🤣
Bradley White73 Bradley White73 Active Member
78 messages
joined Sep 2020
#15 ·
George Cook31 said:I'm actually pretty curious about what really drives the hackers on this forum.
Maybe they just want to snoop through someone's private DMs? Perhaps.

But posting those ridiculous links? I suppose they eventually realized nobody was actually clicking them.
I actually tried to click one once, and the website was so bizarrely designed, I almost felt like I wanted to tip them some money, though I honestly wouldn't have even known how to do that. 🤣

🤣

Everyone has their own theory, I guess. Personally, I like to imagine they're trying to spark some massive migration to a better place, which, in my eyes, would make them sort of heroes. 😍
urbanheron4 urbanheron4 Active Member
56 messages
joined Mar 2022
#16 ·
Over the last week or so, I’ve noticed this weird glitch whenever I try to log in. I click the login button, the screen flickers for a second, and then... nothing. Absolutely nothing happens. I can hammer that login button all day long and it won't budge. I have to click somewhere else on the page first, then come back and hit login again just to get through. I’m not sure if it’s related to that other issue, but it feels like it might be.
Casey Bennett Casey Bennett Regular
522 messages
joined Nov 2011
#17 ·
Linda King said:I’m changing my password and logging back in—the whole session is running over HTTP, while XenForo uses HTTPS. Besides, I searched Google for exploit lists targeting older versions of vBulletin, and frankly, it seems like this software is just child's play for anyone serious about hacking. Are they even releasing security patches for this version, or should we just update to the latest version immediately? I suspect you already know the answer. Newer software definitely provides regular patches. Plus, you mentioned two-factor authentication earlier; I just checked, and XenForo (2021) actually offers that option. It’s obvious you guys are in a tight spot, and it's not like you're the ones making the final call, so I get it. But there's no point in being foolish here; at least notify the users to beef up their passwords. It isn't a waste of time when we're dealing with a script like the one Jack Cook7 is talking about.


You make a valid point; they really ought to disable logins unless the password has been updated since this attack started.

The other day, I was greeted by a message on another local (much smaller) forum saying I couldn't log in until I changed my password. I suspect they are in the exact same situation we are. They use vBulletin too, specifically version 4.2.2, and they have the HTTP protocol issue as well.
I'm not even a novice when it comes to cybersecurity, but honestly, I don't believe that little "s" is much of an obstacle for hackers. HTTPS is basically just there to make the job a tiny bit harder for amateur hackers. 🤷

I will certainly pass along your suggestion. 👍
Casey Bennett Casey Bennett Regular
522 messages
joined Nov 2011
#18 ·
urbanheron4 said:Lately, I've been noticing this weird glitch whenever I try to log in; I click the login button, the screen just flickers, and then absolutely nothing happens. No matter how many times I hit login, it won't let me in. I have to click somewhere else on the page first before the button actually works. I'm not sure if it's related to what we were discussing earlier, but it feels like it could be.

Just change your password and double-check the inbox of the email address you used for the reset.
Casey Bennett Casey Bennett Regular
522 messages
joined Nov 2011
#19 ·
George Cook31 said:I’m honestly curious about what actually drives these forum hackers.
Is their goal to snoop through someone's private DMs? Maybe.

But posting those ridiculous links? It’s like they haven't realized that absolutely nobody is clicking on them.
I actually tried to click one once, and the website was so bizarrely designed that even if I had wanted to give them money, I wouldn't have known how to navigate the checkout. 🤣

Look, if someone were truly obsessed with reading private messages, they would target specific people who actually interest them. That way, they wouldn't draw any unnecessary attention to themselves.
And nobody would ever even realize they’d been hacked, especially without those insane messages left in their signature.
Bradley White73 Bradley White73 Active Member
78 messages
joined Sep 2020
#20 ·
Casey Bennett said:I think you've got a point there; they really ought to just disable logins entirely if the password hasn't been updated since this attack kicked off.

The other day, I actually ran into this on a different, much smaller local forum—they greeted me with a message saying I couldn't even log in until I reset my password. I suspect they're dealing with the exact same mess we are. It’s the same vBulletin software, a newer 4.2.2 version, and they're using HTTPS too, but still...
I wouldn't call myself an expert in cybersecurity or anything, but honestly, I don't think that "s" in HTTPS is going to stop any serious hackers. I guess it mostly just makes things a tiny bit harder for the beginners learning the ropes. 🤷

Anyway, I'll definitely pass your suggestion along. 👍

And we really should tell Anderlon that it might be time to lead his people to a new land... 🕺 He just needs to let go of that fear; we're all right there with him, and we'll see this through to the very end. 👍

You must log in or register to reply here.

Log in Register

🔗 Similar threads