PDA

View Full Version : [Urgent] - Ubuntuforums.org vbulletin board hacked | change passwords



Amrut
23 July 2013, 12:37 AM
Namaste,

If you are using Ubuntu or have registered to Ubuntuforums.org, please change your password ASAP

Since this is a vbulletin forums, it would be better to post a message here.

Thing to note is that Ubuntu had recently upgraded to latest software

I got info from OMG! Ubuntu - Ubuntu Forums Hacked, 1.8 Million Passwords, E-Mails & Usernames Stolen (http://www.omgubuntu.co.uk/2013/07/ubuntu-forum-hacked-users-advised-to-change-passwords)

The Ubuntu Forums have been hacked, with attackers grabbing data from more than 1.8 million users accounts.

‘Every user’s local username, password, and email address [were stolen] from the Ubuntu Forums database’ Canonical say in a statement posted on the website, adding that while the ‘passwords (stolen) are not stored in plain text’ those who use the same password on other services should ‘change the password on the other service[s] ASAP.’

If you are using a common password for many forums or / and your email, please change it immediately.

Ubuntuforums.org (http://ubuntuforums.org/announce.html) is down


What we know


Unfortunately the attackers have gotten every user's local username, password, and email address from the Ubuntu Forums database.
The passwords are not stored in plain text, they are stored as salted hashes. However, if you were using the same password as your Ubuntu Forums one on another service (such as email), you are strongly encouraged to change the password on the other service ASAP.
Ubuntu One, Launchpad and other Ubuntu/Canonical services are NOT affected by the breach.



Hari Aum

satay
23 July 2013, 09:41 AM
namaste,
Just when was making serious effort to upgrade our forums. Do you know if they were using version 5 or 4? I suspect 5 as it just came out.

Amrut
23 July 2013, 10:43 AM
namaste,
Just when was making serious effort to upgrade our forums. Do you know if they were using version 5 or 4? I suspect 5 as it just came out.

Namaste,

Not Sure. As far as my memory recalls, upgradation talks were going since Jan - Feb 2013 to upgrade, the time when Vbulletin was released as stable version. All I remember is that they were working on a patch to fix login by openID.

Few months back, I got a message about forum upgradation process after logging in. After they are back to normal, I will try to find out which version they are using. I am not much active on any Linux Forums, last one was Linux Mint that I daily use at home.

Aum

Amrut

Amrut
23 July 2013, 12:09 PM
I tried to browse vbulletin forums (http://www.vbulletin.com/forum/forum/vbulletin-announcements/vbulletin-announcements_aa), but things are going above my head :(

Hari Aum

Amrut
31 July 2013, 06:33 AM
namaste,
Just when was making serious effort to upgrade our forums. Do you know if they were using version 5 or 4? I suspect 5 as it just came out.

Namaste,

Ubuntuforums is up. It is using v4.x. Earlier they were using v3.x

Also please check that bulletin board forum and the version of total package is same. It may be possible that they have upgraded other components like blog and may not have done major upgrade on forum software.

After I recover from my illness, I will try to search for more info and share it here if I find something worth sharing.

Aum

Amrut

satay
31 July 2013, 04:12 PM
Namaste and Thank you IS.

Namaste,

Ubuntuforums is up. It is using v4.x. Earlier they were using v3.x

Also please check that bulletin board forum and the version of total package is same. It may be possible that they have upgraded other components like blog and may not have done major upgrade on forum software.

After I recover from my illness, I will try to search for more info and share it here if I find something worth sharing.

Aum

Amrut