DVD rental | Canon G11 | House Insurance | Find jobs | Submit articles
vbulletin insecurity [Archive] - Muslim Programmers & Designers Community - Islamic Webhosting and Nasheeds

PDA

View Full Version : vbulletin insecurity



abdullah
06-26-2003, 03:08 AM
for those of you who have 5 digit passwords and use vbulletin on a public computer, this might come as a shock.

vbulletin stores a hashed version of your password on your computer when you login. if you use a public computer, a hacker can decrypt your pasword and gain access to your account.

it takes abt 2-4 hours to crack md5 hash of 5 characters : )

ozzie123
11-19-2003, 03:52 PM
It is a shock to me... but well, It's a bulletin anyway...

And I doubt that there's someone that will try to hack my account since I'm a little but nobody :)

alik
11-19-2003, 05:43 PM
I agree i am in the same situation as ozzie123

wizard
11-20-2003, 07:56 AM
that is a very dangerous attitude.

ppl say .. "i have nothing top secret in my computer .. so what does it matter even if someone got in my computer" or something similar.

well.. guess what? very dangerous things can happen. a hacker could hack into your computer, ... get your credit card information, name, address and what not.. and steal your identity (identity theft)

a hacker can hack into your computer .. install a trojan horse, and then attack other computers using your computer .. can you guess who will be arrested? DDOS and DRDOS attacks happen like this... ( even though you dont get into much trouble .. it is a hassle when government officials come looking for you and your computer)

what can a vbulletin password do? consider this, a hacker hacks your password.. uses your account to hack into the site . vbulletin stores your ip address when you sign up and your "last login" ip .. a hacker will be using a proxy (obviously) .. guess who get arrested? answer: you


how do u keep something like this happening to u?

- try not to login to any accounts of yours from public computers

- if you have to login to an account from a public computer, make sure you log off.. and that you clear all cookies, history and teporary internet files

- install a firewall on your computer. zone alarm is the best free firewall i have come across. it is better than the full version of black ice.. which
checks only the incoming traffic.

-keep up 2 date with viruses, worms, update your system with patches, etc

for people wondrering about if they should install service pack 1 for xp... the service pack has problems of its own .. and someone had made a very good comments abt this : may be they will make a service pack for the service pack 1 (lol)

- have an anti-virus to check for trojan horses, worms, etc

- keep your password minimum of 8 characters.. make a password with numbers, alphabets (lower and upper case).. and if possible use shell characters (!@#$%^...)

alik
11-20-2003, 04:04 PM
I am convinced!!!

ozzie123
12-16-2003, 02:11 PM
Wizard... you convinced me....

Big Byte
01-01-2004, 12:48 AM
good advice bro wizard but do they not use a 1way has function?