DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

vBulletin, Foxit Software forums hacked by Coldzer0; hundreds of thousands of users’ info stolen

Posted on November 2, 2015 by Dissent

This post was co-authored with @Cyber_War_News.

Some days we scratch our heads at the folks who proudly claim hacks and then give law enforcement enough evidence to go after them. And then this happened:

#vBulletin 5.x.x hacked by Coldzer0 today. Licences & database dumped, shell on server. vBulletin denied. #0day #security #zeroday

— Terry Tran (@terryjunx) November 1, 2015 #vBulletin 5.x.x hacked by Coldzer0 today. Licences & database dumped, shell on server. vBulletin denied. #0day #security #zeroday

Meet Coldzer0. He says his name is Mohamed Osama, and on his web site, coldroot.com, he describes himself as a

Malware Analyst , Security Researcher , Reverse Engineer . Delphi Team Leader at Orbit Shield instructor/Trainer at Orbit Shield / SQunity .

He even has a LinkedIn profile. And when he hacked vBulletin’s forum, he left a calling card:

screen2

He also uploaded a video to YouTube demonstrating that he had access, although that YouTube video was subsequently removed. And just to make sure he got “credit,” he also posted screenshots on his Facebook page and elsewhere. He deleted the Facebook ones soon after, but here’s a screenshot of his Facebook page, followed by an enlargement of the proof of the vBulletin hack:

mq9Xlyi-e1446439674327

12015044_953739704662787_8312665075066572905_o

Seriously? He also posted evidence of a shell:

vbulletin---hacked---02-1446377431

At this point, it is not known to us how much of the data has been leaked and/or put up for sale, but a screenshot provided to @Cyber_War_News  indicates that userids, full names and email addresses, security questions and answers (both in plain text) with password salts are among the data he acquired. Here’s a redacted snippet from that screenshot (the original has many more entries):

VB_screen4

Vbulletin.com remains offline with a statement that it is “down for maintenance.” They have yet to even officially confirm that they’ve had a database breach, as a cached copy of a forum thread on the breach indicates. As of October 29, Vbulletin Forum claimed to have 344,581 members.

If you’ve used the Vbulletin forums, change your password immediately and assume that others are now in possession of the answer to your security question and other details -including credit card numbers (but not cvv).

The Vbulletin forum was not the only one hacked, however. An article in Vietnamese (translation here) reported that Foxit Software’s forum was also hacked. Coldzer0 informed @Cyber_War_News that he had breached Foxit’s forum over a period of two days, using the same 0day exploit he used with Vbulletin. He claims to have  obtained information on over 260,000 accounts.  According to Foxit forum’s member list, it has almost 537,000 user accounts. Coldzer0 informed @Cyber_War_News (typos in original):

vBsecurity team from yesterday and they can’t catch it.

and here’s the most weird thing

they using F5 on there servers and didn’t detect my shell or even detecting my traffic

Foxit Software was sent an email asking them to confirm the claimed hack of their forum and databases. This post will be updated as more information becomes available.

Category: Business SectorHackOf Note

Post navigation

← PageFair breach disclosure
TalkTalk data being used to con seniors →

3 thoughts on “vBulletin, Foxit Software forums hacked by Coldzer0; hundreds of thousands of users’ info stolen”

  1. dred says:
    November 2, 2015 at 9:48 am

    OMG

  2. Artur Marek Maciag says:
    November 4, 2015 at 10:46 am

    Can we use this URL in the Knowledge Vault as
    (2015-11-02 vBulletin, Foxit Software forums hacked by Coldzer0; hundreds of thousands of users’ info stolen http://www.databreaches.net/vbulletin-foxit-software-forums-hacked-by-coldzer0-hundreds-of-thousands-of-users-info-stolen/ EN #threats #report #advanced #priv #standard #vbulletin #hack #databreach #pwned #coldzer0 #dataleak)?
    https://docs.google.com/spreadsheets/d/17IuPDavAW-ZjsvpLhFDHQ5e4IlzBG2jowDFb5ozg1CM/edit?usp=sharing
    This is part of Security Culture Initiative
    https://drive.google.com/open?id=0B0TkBywht9JSeFdOWVlXZTlLMzlPcUlEdnlGZFJSVEhQUy1r

    1. Dissent says:
      November 4, 2015 at 11:03 am

      Sure.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)
  • Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information
  • Georgia hospital defeats data-tracking lawsuit
  • No Postal Service Data Sharing to Deport Immigrants

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.