Sponsored

The VerticalScope Breach: How it affects M6G.com?

Dirtyblueshirt

Award Winning Taste™
Joined
Jun 18, 2015
Threads
33
Messages
1,371
Reaction score
579
Location
Anaheim, CA
First Name
Aaron
Vehicle(s)
2022 Ford Ranger Lariat Tremor
Hopefully [MENTION=1]Jarstang[/MENTION] can help look into this.

Today, it was reported that VerticalScope suffered a breach of 45 million usernames and MD5-hashed passwords. VerticalScope owns several hundred car, hobby, and varied web forums and websites.

NOTE: VerticalScope does NOT Own Mustang6G.com and user credentials are not directly impacted by this breach. There is NO indication that there is any problem with the integrity of the M6G Forums.

It's stated that attackers gained access via known vulnerabilities in outdated versions of vBulletin software. M6G uses vBulletin 3.8.8, and the most current version of vBulletin software is 5.2.0.

As I'm sure many other members here also have similar logins at many car forums, some that may be owned by VerticalScope; I've changed my password here as well as other sites. You all should too.

As a career Network Security Analyst, I would like to know the following questions as it relates to the security of M6G:

1. What is the plan to update to a more modern and better-supported version of vBulletin to eliminate potential vulnerabilities?

2. What steps will M6G be taking in the wake of these breaches to ensure they do not fall victim to a similar attack?

Thanks for your attention!
Sponsored

 

Coaster

RallyNorthAmerica.com
Joined
Jan 9, 2015
Threads
11
Messages
937
Reaction score
455
Location
Central Ohio
Website
www.imprtcl.com
First Name
Brian
Vehicle(s)
'15 Fastback GT Guard
Step 1: Don't use the same password on multiple sites if you care at all about the security of those sites.
 
OP
OP
Dirtyblueshirt

Dirtyblueshirt

Award Winning Taste™
Joined
Jun 18, 2015
Threads
33
Messages
1,371
Reaction score
579
Location
Anaheim, CA
First Name
Aaron
Vehicle(s)
2022 Ford Ranger Lariat Tremor
Step 1: Don't use the same password on multiple sites if you care at all about the security of those sites.
I generally don't. But with so many logins, I do base my credentials on data breach risk (i.e my forum passwords aren't the same as my email passwords, or my bank passwords, etc...)
 

cbass

Well-Known Member
Joined
Feb 26, 2016
Threads
3
Messages
233
Reaction score
99
Location
Rochester, NY
First Name
God
Vehicle(s)
2015 400a A6
You guys know about the forum software password security features? If the forum detects that you are posting your password it filters it for you.

********** <- that's what happens when I type my password.
 

Jarstang

Administrator
Staff member
Administrator
Joined
Jan 8, 2012
Threads
618
Messages
2,342
Reaction score
3,596
Location
M6G
Vehicle(s)
Ford
The reason for the scale of the breach of the VerticalScope sites was the sheer amount of data and number of sites hosted on the same or connected servers. As you correctly stated, Mustang6G is not affiliated with them in any way.

However, we will be increasing our security monitoring that we perform on a regular basis and explore changes related to password strength and expiration.

There are thousands of sites that run VB 3.8.x without any security breaches and VB4 and VB5 sites were not immune to the breach. The reason Mustang6G does not run those versions is because frankly, vBulletin went downhill starting with VB4 and the loss of its core developers. You will find that much of the developer community share that opinion.

The breach of the VerticalScope sites was limited to usernames, email addresses and encrypted passwords. As a general matter, all members should use common sense with respect to your forum accounts.

- Change your password on a regular basis and choose a unique alphanumeric password that is not easy to guess and not shared with any of your other accounts.

- Minimize use of your forum account on public computers. Clear passwords, cache and cookies if you do so.

- It goes without saying you should avoid entering any sensitive or private info in your user profiles and signatures. There should be no reason to enter info such as home/work addresses, social security info, sensitive work email addresses, credit card/payment info etc.
 

Sponsored

OP
OP
Dirtyblueshirt

Dirtyblueshirt

Award Winning Taste™
Joined
Jun 18, 2015
Threads
33
Messages
1,371
Reaction score
579
Location
Anaheim, CA
First Name
Aaron
Vehicle(s)
2022 Ford Ranger Lariat Tremor
The reason for the scale of the breach of the VerticalScope sites was the sheer amount of data and number of sites hosted on the same or connected servers. As you correctly stated, Mustang6G is not affiliated with them in any way.

However, we will be increasing our security monitoring that we perform on a regular basis and explore changes related to password strength and expiration.

There are thousands of sites that run VB 3.8.x without any security breaches and VB4 and VB5 sites were not immune to the breach. The reason Mustang6G does not run those versions is because frankly, vBulletin went downhill starting with VB4 and the loss of its core developers. You will find that much of the developer community share that opinion.

The breach of the VerticalScope sites was limited to usernames, email addresses and encrypted passwords. As a general matter, all members should use common sense with respect to your forum accounts.

- Change your password on a regular basis and choose a unique alphanumeric password that is not easy to guess and not shared with any of your other accounts.

- Minimize use of your forum account on public computers. Clear passwords, cache and cookies if you do so.

- It goes without saying you should avoid entering any sensitive or private info in your user profiles and signatures. There should be no reason to enter info such as home/work addresses, social security info, sensitive work email addresses, credit card/payment info etc.

Thank you for your honest response. Beleive me, it's a far more refreshing dose of transparency than a majority of online communities.
 

Cobra Jet

Well-Known Member
Joined
Feb 12, 2015
Threads
771
Messages
17,554
Reaction score
19,982
Location
NJ
Vehicle(s)
2018 EB Prem. w/PP and 94 Mustang Cobra
I HOPE this site NEVER becomes part of Vertical Scope... Every site they have bought out has turned to crap and the original users have abandoned them...
Sponsored

 
 








Top