Daniel B Posted July 11, 2016 Report Posted July 11, 2016 http://www.webhostingtalk.com/showthread.php?t=1584028 I know quite a few people over here have accounts on WHT, just wanted to make sure everyone saw this so they can change their passwords if they haven't. PauloV 1 Quote
Michael Posted July 11, 2016 Report Posted July 11, 2016 I wouldn't change their password if I was anyone there, I can't log into mine so my passwords aren't effected but they haven't announced it themselves and I bet the hackers still have access as it's a outdated forum with a SQLi exploit fixed in June (if they updated). Quote
Nelsa Posted July 11, 2016 Report Posted July 11, 2016 Last time I cheked it is not just WHT but complete databases from 4 of 5 Penton's websites....all user data from these 4 websites are available....e-mails,usernames, ..and other profile fields stored in DB .. till now about 60% of passwords are decrypted..the rest is not decrypted yet..probably passwords from users who used harder passwords I read somewhere that all user will have to use reset pass link but I didn't see it on published on WHT but I couldn't log in with mine so I suppose it is true.. To be hones when you lok all penton's sites...one wordpress 3.9 second W.P 4.x.x version , vBulletin 4...must feel like in museum,maybe this is not reason but just fact that they use outdated version will make them targeted much more . I understand that such big user base is not easy to upgrade but they should have resouce for this..or they just worry for income.. PauloV 1 Quote
Michael Posted July 11, 2016 Report Posted July 11, 2016 Last time I cheked it is not just WHT but complete databases from 4 of 5 Penton's websites....all user data from these 4 websites are available....e-mails,usernames, ..and other profile fields stored in DB .. till now about 60% of passwords are decrypted..the rest is not decrypted yet..probably passwords from users who used harder passwords I read somewhere that all user will have to use reset pass link but I didn't see it on published on WHT but I couldn't log in with mine so I suppose it is true.. To be hones when you lok all penton's sites...one wordpress 3.9 second W.P 4.x.x version , vBulletin 4...must feel like in museum,maybe this is not reason but just fact that they use outdated version will make them targeted much more . I understand that such big user base is not easy to upgrade but they should have resouce for this..or they just worry for income.. As far as I know it's just for the WHT Staff, and yeah the people with a symbol in the password like !*():;<> as I don't think rainbow tables will have them. Quote
Paul Posted July 11, 2016 Report Posted July 11, 2016 I saw this briefly on another website on Friday, that they were selling the leaks. Hotscripts was also affected among others. Double checked that the password I was using there was unique, and it was. With so many properties being hit, I can't help but think Penton was negligent in some way. Quote
Paul Posted July 11, 2016 Report Posted July 11, 2016 Just read through some of the posts in that WHT thread... they were using MD5 passwords?!! Seriously. They might as well be plain text. We switched to bcrypt, HMAC-SHA-256 hashes in Blesta 3.0 years ago and wrote about it a year before v3 was released here - http://www.blesta.com/2012/08/17/blesta-3-0-more-on-security-video-2/ Nobody learns, and big companies like Penton have no excuses. They have the means. Michael and PauloV 2 Quote
Nelsa Posted July 11, 2016 Report Posted July 11, 2016 As far as I know it's just for the WHT Staff, and yeah the people with a symbol in the password like !*():;<> as I don't think rainbow tables will have them. You can read here about penton's sites hacked (it is link I find on WHT ) http://www.csoonline.com/article/3093018/security/mac-forums-hot-scripts-and-web-hosting-talk-databases-for-sale.html In short they say these sites owned by Penton are compromited(1,7 million users); Mac-Forums, Hot Scripts, and Web Hosting Talk Data is selling through "The Real Deal Dark Web" marketplace but I didn't chek ...what to say luckly they only had forum account and profil data...But I suppose there is some users or even host masters who use same passwords everywhere..like root passwords..etc..this should be big warning to everyone... Quote
Joseph H Posted July 12, 2016 Report Posted July 12, 2016 Scary stuff, As soon as I saw this I had to go change all my important passwords. And migrated to Dashlane password manager Quote
jobplease Posted July 12, 2016 Report Posted July 12, 2016 Using Dashlane and passwords updated. Quote
PauloV Posted July 15, 2016 Report Posted July 15, 2016 Hello, Thanks for the warning, I was distracted this days and didnt notice the Hack, time to update passwords once again Luckly all are diferent WebHostingTalk is/was to quiet lol only yesterday they started anounce on a Post with a strange title lol "Security Update for Registered Users" insted "Security Breach at WebHostingTalk" Like this one in 2009 http://www.webhostingtalk.com/showthread.php?t=729362 Michael 1 Quote
Paul Posted July 15, 2016 Report Posted July 15, 2016 Hello, Thanks for the warning, I was distracted this days and didnt notice the Hack, time to update passwords once again Luckly all are diferent WebHostingTalk is/was to quiet lol only yesterday they started anounce on a Post with a strange title lol "Security Update for Registered Users" insted "Security Breach at WebHostingTalk" Like this one in 2009 http://www.webhostingtalk.com/showthread.php?t=729362 Yep, it's called damage control, and it's shady. People miss it, and don't change their password at other sites if they used the same one. It made me reset my password today but I couldn't log in on the page it directs you to, totally broken. Probably why not many people logged in right now. Michael 1 Quote
ExpertIntegrations Posted August 14, 2016 Report Posted August 14, 2016 Yeah I noticed that a lot of these community forums are being exploited, I know there is a few car forums that I belong to seem to got done the same way WHT got done. So apparently this is a wide spread issue & hopefully something can be done to help minimize any future exploits to help safe-guard users & there private sensitive details. Michael 1 Quote
Michael Posted August 14, 2016 Report Posted August 14, 2016 4 hours ago, ExpertIntegrations said: Yeah I noticed that a lot of these community forums are being exploited, I know there is a few car forums that I belong to seem to got done the same way WHT got done. So apparently this is a wide spread issue & hopefully something can be done to help minimize any future exploits to help safe-guard users & there private sensitive details. What irritates me is WHT (vb 4.2.2 Patch Level 4) and Ubuntu forums (vb 4.2.2 Patch Level 1) haven't upgraded they are going along as if it's nothing. VB released a new patch called vb4.2.2 Patch Level 6, so they should be on that version, but they aren't so glad I don't use WHT anymore or Ubuntu because they don't care about their users. That or security is so low they are just waiting to get a nice hack page before they act. Paul and ExpertIntegrations 2 Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.