AfterDawn: Tech news

MacRumors forum hacked and nearly a million accounts compromised, but hacker won't share

Written by Andre Yoskowitz @ 14 Nov 2013 6:50 User comments (5)

MacRumors forum hacked and nearly a million accounts compromised, but hacker won't share The Mac and iOS-based news site MacRumors confirmed this week that their forums were attacked by hackers, with 860,000 usernames and passwords being stolen.
Fortunately, the hacker says he will not leak any of the passwords stolen, but MacRumors has still begged users to change their password on the site and on other sites where they might have used the same pass and username combo.

"We're not terrorists," says the attacker, who goes by "lol." "Stop worrying, and stop blaming it on Macrumors when it was your own fault for reusing passwords in the first place."

The hacker accessed a moderator account for the vBulletin software that runs the site, then escalated their access privileges, eventually dumping a database containing all the usernames, email addresses and passwords. The passwords were md5 hashed and salted, which means they will be cracked within days if not sooner. MacRumors was upfront with their users and confirmed that hash/salt is not secure and reported the breach within hours of it occurring, unlike major corporations, many of which have waited days following attacks to say anything.



"Consider the 'malicious' attack friendly," added "lol." "The situation could have been catastrophically worse if some fame-driven idiot was the culprit and the database were to be leaked to the public." When asked why he didn't just alert the administrators to the flaw, lol responded by saying that "outside of this hobby, *cough*, I do partake in whitehat activities and try to contribute to some open source projects etc."

Previous Next  

5 user comments

115.11.2013 00:29

"Stop worrying, and stop blaming it on Macrumors when it was your own fault for reusing passwords in the first place."

Funny how criminals are "Never" responsible for their malicious actions, its always someone else's fault.

215.11.2013 11:34

We here in Ireland have just had a major one as well...

More than 1.5 million people are now known to have had personal information compromised by a major security breach at a Co Clare-Ireland based company which manages customer loyalty schemes across Europe.

A Garda (Irish police) investigation has been launched into what is fast becoming one of the worst data breaches in the history of the State.

315.11.2013 13:58

I'd translate the hacker's comment more as, "Stop worrying, so we have more time to try to access other accounts you may have, that use the same login" ^^' .

415.11.2013 14:52

Some white hat hackers/crackers will do this to put the frighteners to businesses just to make them aware of their security flaws, but time will tell whether this one is such an example.

516.11.2013 02:03

When asked why he didn't just alert the administrators to the flaw, lol responded.... because if he had done so do you think they would have acted in such a quick manner to make it known, if at all.
We saw in UK with 'Pleb Gate & 'NOTW' phone hacking that even when faced with the evidence/truth Organisations, people will go to any lengths to cover it up.
We're all able to take action now on Forums run by the same SW who'd have been oblivious to the problem but for lol going public.

Comments have been disabled for this article.

Latest news

Sony suspends memory card sales because memory chips are simply not available Sony suspends memory card sales because memory chips are simply not available (28 Mar 2026 6:49)
Sony has announced that it is temporarily suspending the sale of memory cards used in mobile phones and digital cameras, among other things. The company states that the reason is problems with the availability of memory chips.
Austria plans to ban social media for under 14 year olds Austria plans to ban social media for under 14 year olds (28 Mar 2026 6:17)
Austria is planning to ban social media for children under 14. The reform aims to protect children from harmful effects and addictions, but at the same time, it is problematic from a privacy perspective.
TP-Link urges users to update their routers - several vulnerabilities patched TP-Link urges users to update their routers - several vulnerabilities patched (26 Mar 2026 1:56)
Serious security vulnerabilities have been discovered in several TP-Link router models, for which patches were released at the end of March 2026. The company urges users to update their router software immediately.
Google: The feared Q-Day is now expected to happen in 2029 Google: The feared Q-Day is now expected to happen in 2029 (25 Mar 2026 4:32)
Google has advanced its estimate of when current forms of encryption will become insecure. The moment is called Q-Day, or Quantum Day, when the computational power of quantum computers will be sufficient to break currently used encryptions.
OpenAI shuts down its AI video service Sora OpenAI shuts down its AI video service Sora (24 Mar 2026 6:28)
OpenAI has decided to shut down Sora, its AI video creator, just months after its release. The decision is due to issues such as copyright problems and the deepfake phenomenon.

News archive