DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

vBulletin, Foxit Software forums hacked by Coldzer0; hundreds of thousands of users’ info stolen

Posted on November 2, 2015 by Dissent

This post was co-authored with @Cyber_War_News.

Some days we scratch our heads at the folks who proudly claim hacks and then give law enforcement enough evidence to go after them. And then this happened:

#vBulletin 5.x.x hacked by Coldzer0 today. Licences & database dumped, shell on server. vBulletin denied. #0day #security #zeroday

— Terry Tran (@terryjunx) November 1, 2015 #vBulletin 5.x.x hacked by Coldzer0 today. Licences & database dumped, shell on server. vBulletin denied. #0day #security #zeroday

Meet Coldzer0. He says his name is Mohamed Osama, and on his web site, coldroot.com, he describes himself as a

Malware Analyst , Security Researcher , Reverse Engineer . Delphi Team Leader at Orbit Shield instructor/Trainer at Orbit Shield / SQunity .

He even has a LinkedIn profile. And when he hacked vBulletin’s forum, he left a calling card:

screen2

He also uploaded a video to YouTube demonstrating that he had access, although that YouTube video was subsequently removed. And just to make sure he got “credit,” he also posted screenshots on his Facebook page and elsewhere. He deleted the Facebook ones soon after, but here’s a screenshot of his Facebook page, followed by an enlargement of the proof of the vBulletin hack:

mq9Xlyi-e1446439674327

12015044_953739704662787_8312665075066572905_o

Seriously? He also posted evidence of a shell:

vbulletin---hacked---02-1446377431

At this point, it is not known to us how much of the data has been leaked and/or put up for sale, but a screenshot provided to @Cyber_War_News  indicates that userids, full names and email addresses, security questions and answers (both in plain text) with password salts are among the data he acquired. Here’s a redacted snippet from that screenshot (the original has many more entries):

VB_screen4

Vbulletin.com remains offline with a statement that it is “down for maintenance.” They have yet to even officially confirm that they’ve had a database breach, as a cached copy of a forum thread on the breach indicates. As of October 29, Vbulletin Forum claimed to have 344,581 members.

If you’ve used the Vbulletin forums, change your password immediately and assume that others are now in possession of the answer to your security question and other details -including credit card numbers (but not cvv).

The Vbulletin forum was not the only one hacked, however. An article in Vietnamese (translation here) reported that Foxit Software’s forum was also hacked. Coldzer0 informed @Cyber_War_News that he had breached Foxit’s forum over a period of two days, using the same 0day exploit he used with Vbulletin. He claims to have  obtained information on over 260,000 accounts.  According to Foxit forum’s member list, it has almost 537,000 user accounts. Coldzer0 informed @Cyber_War_News (typos in original):

vBsecurity team from yesterday and they can’t catch it.

and here’s the most weird thing

they using F5 on there servers and didn’t detect my shell or even detecting my traffic

Foxit Software was sent an email asking them to confirm the claimed hack of their forum and databases. This post will be updated as more information becomes available.


Related:

  • Attorney General James Announces Settlement with Wojeski & Company Accounting Firm
  • Hackers Say They Have Personal Data of Thousands of NSA and Other Government Officials
  • John Bolton Indictment Provides Interesting Details About Hack of His AOL Account and Extortion Attempt
  • UK: 'Catastrophic' attack as Russians hack files on EIGHT MoD bases and post them on the dark web
  • Data BreachesProsper Data Breach Impacts 17.6 Million Accounts
  • The Alliance That Wasn’t: A Critical Analysis of ReliaQuest’s Q3 2025 Ransomware Report
Category: Business SectorHackOf Note

Post navigation

← PageFair breach disclosure
TalkTalk data being used to con seniors →

3 thoughts on “vBulletin, Foxit Software forums hacked by Coldzer0; hundreds of thousands of users’ info stolen”

  1. dred says:
    November 2, 2015 at 9:48 am

    OMG

  2. Artur Marek Maciag says:
    November 4, 2015 at 10:46 am

    Can we use this URL in the Knowledge Vault as
    (2015-11-02 vBulletin, Foxit Software forums hacked by Coldzer0; hundreds of thousands of users’ info stolen http://www.databreaches.net/vbulletin-foxit-software-forums-hacked-by-coldzer0-hundreds-of-thousands-of-users-info-stolen/ EN #threats #report #advanced #priv #standard #vbulletin #hack #databreach #pwned #coldzer0 #dataleak)?
    https://docs.google.com/spreadsheets/d/17IuPDavAW-ZjsvpLhFDHQ5e4IlzBG2jowDFb5ozg1CM/edit?usp=sharing
    This is part of Security Culture Initiative
    https://drive.google.com/open?id=0B0TkBywht9JSeFdOWVlXZTlLMzlPcUlEdnlGZFJSVEhQUy1r

    1. Dissent says:
      November 4, 2015 at 11:03 am

      Sure.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.