Results 1 to 10 of 10
  1. #1

    Default vBulletin 0-Day Exploit Exposes User Info

    This Arstechnica article indicates that there may be a newly-discovered zero-day vulnerability in vBulletin v4 and v5 which allows an attacker to fully expose account IDs, password hashes and possibly the entire database.

    Normally, this would not concern me beyond the low probability of being e-mail spammed. However, since game and forum accounts are linked, the possibility of certain types of user information being exposed is unsettling.

    Is Turbine aware of this and what steps, if any, have been taken to avoid user data being compromised?
    The newest computer can merely compound, at speed, the oldest problem in the relations between human beings, and in the end the communicator will be confronted with the old problem, of what to say and how to say it. - Edward R. Murrow (1964)

  2. #2
    Community Member Vellrad's Avatar
    Join Date
    Sep 2009
    Posts
    4,421

    Default

    Quote Originally Posted by sebastianosmith View Post
    Is Turbine aware of this and what steps, if any, have been taken to avoid user data being compromised?
    Thanks for good laughs.
    Quote Originally Posted by Originally Posted by Random Person #2 View Post
    People who exploit bugs in code are cheaters cheaters cheaters. And they are big fat ****yheads too.

  3. #3
    Community Member whereispowderedsilve's Avatar
    Join Date
    Jun 2010
    Posts
    1,167

    Default Bump for Tolero/Cordovan or management @ Turbine or WB to take notice of!

    Bump for Tolero/Cordovan or management @ Turbine or WB to take notice of!
    http://dillonpfaff5.wix.com/theob Sign this!!!: http://goo.gl/vS6htg

    DDO toll free support phone#: 855-WBGAMES (855-924-2637)

  4. #4
    Community Member enochiancub's Avatar
    Join Date
    Dec 2008
    Posts
    351

    Default

    Considering some of the scumbags who frequent these boards thats actually mildly worrisome.

    Main: 18 Artificer, Thelanis

  5. #5
    Community Member Antheal's Avatar
    Join Date
    Feb 2010
    Posts
    710

    Default

    Two words:

    Offer Wall.

    Remember that, and how that turned out? Turbine is probably fully aware of this issue and they just don't care. Again, just like with the Offer Wall.
    Those are not pebbles surrounding the urn filled with Human teeth. They are megaliths!

  6. #6
    Community Member Tscheuss's Avatar
    Join Date
    Jan 2012
    Posts
    0

    Default

    This is not a happy thing. Can we get a Read by XXXX or something?
    1776 Growing Liberty for Centuries 2022

  7. #7
    Producer Tolero's Avatar
    Join Date
    Sep 2007
    Posts
    0

    Default

    Turbine’s web devs track developments on this kind of news closely and they are always looking for ways to improve our sites on that front. Our implementation of vBulletin is highly customized and follows good security practices. A key part of this customization is that we do not store any personally identifiable information in the vBulletin database. Sensitive information, including account passwords, are handled by an entirely separate system. All authentication is handled by this separate system, and not via the forums software. While no software is 100% secure, we believe that we've taken the appropriate steps to protect your account information.

  8. #8

    Default

    Quote Originally Posted by Tolero View Post
    we believe that we've taken the appropriate steps to protect your account information.
    When have we heard that one before...

  9. #9

    Default

    Quote Originally Posted by Tolero View Post
    Turbine’s web devs track developments on this kind of news closely and they are always looking for ways to improve our sites on that front. Our implementation of vBulletin is highly customized and follows good security practices. A key part of this customization is that we do not store any personally identifiable information in the vBulletin database. Sensitive information, including account passwords, are handled by an entirely separate system. All authentication is handled by this separate system, and not via the forums software. While no software is 100% secure, we believe that we've taken the appropriate steps to protect your account information.
    Hopefully your Forum Log-In site is not linked to vBulletin either...
    Thelanis - Ethforged - Etherar - Fjirty --- Mitis Mors
    Ghallanda - Ethrayne - Ethryne --- Omnipresence
    Youtube channel: http://www.youtube.com/channel/UCKVn...wLuzB2Q/videos

  10. #10

    Default

    Quote Originally Posted by Tolero View Post
    Turbine’s web devs track developments on this kind of news closely and they are always looking for ways to improve our sites on that front. Our implementation of vBulletin is highly customized and follows good security practices. A key part of this customization is that we do not store any personally identifiable information in the vBulletin database. Sensitive information, including account passwords, are handled by an entirely separate system. All authentication is handled by this separate system, and not via the forums software. While no software is 100% secure, we believe that we've taken the appropriate steps to protect your account information.
    Hey Tolero,

    Thank you for the feedback. I realize the forum and game share a common authentication server which is not part of vBulletin. My main concern was a quote in the article from Inject0r Team, specifically "We got shell, database and root server". I don't know how gaining root access through vBulletin might play out in an Linux/Nginx/VM environment because frankly my knowledge of that area is limited. But, as you say, nothing is 100% secure.

    Thank you again for addressing these concerns.
    The newest computer can merely compound, at speed, the oldest problem in the relations between human beings, and in the end the communicator will be confronted with the old problem, of what to say and how to say it. - Edward R. Murrow (1964)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

This form's session has expired. You need to reload the page.

Reload