2011-09-08, 09:19 PM
Raul Wrote:I doubt that he hacked the SW/SP databases.
My old account has the email address that my Nexon account uses, and it also has the same password.
If this was how he got it, I would be fucked.
The basil databases sounds more likely. More info, more people, more idiots (not to be stereotypical, but really).
eos Wrote:Auditing last night's logs I discovered an attempt to download every user's email and hashed password, one by one. I can't tell for certain whether they were able to succeed, I'm hoping that due to the nature of the error it was triggering they didn't/couldn't, but can not rely on vBulletin's security to have actually prevented it since it was a (another) hole in their search code that allowed the attack in the first place.

