AfterDawn: Tech news

MacRumors forum hacked and nearly a million accounts compromised, but hacker won't share

Written by Andre Yoskowitz @ 14 Nov 2013 6:50 User comments (5)

MacRumors forum hacked and nearly a million accounts compromised, but hacker won't share The Mac and iOS-based news site MacRumors confirmed this week that their forums were attacked by hackers, with 860,000 usernames and passwords being stolen.
Fortunately, the hacker says he will not leak any of the passwords stolen, but MacRumors has still begged users to change their password on the site and on other sites where they might have used the same pass and username combo.

"We're not terrorists," says the attacker, who goes by "lol." "Stop worrying, and stop blaming it on Macrumors when it was your own fault for reusing passwords in the first place."

The hacker accessed a moderator account for the vBulletin software that runs the site, then escalated their access privileges, eventually dumping a database containing all the usernames, email addresses and passwords. The passwords were md5 hashed and salted, which means they will be cracked within days if not sooner. MacRumors was upfront with their users and confirmed that hash/salt is not secure and reported the breach within hours of it occurring, unlike major corporations, many of which have waited days following attacks to say anything.



"Consider the 'malicious' attack friendly," added "lol." "The situation could have been catastrophically worse if some fame-driven idiot was the culprit and the database were to be leaked to the public." When asked why he didn't just alert the administrators to the flaw, lol responded by saying that "outside of this hobby, *cough*, I do partake in whitehat activities and try to contribute to some open source projects etc."

Previous Next  

5 user comments

115.11.2013 00:29

"Stop worrying, and stop blaming it on Macrumors when it was your own fault for reusing passwords in the first place."

Funny how criminals are "Never" responsible for their malicious actions, its always someone else's fault.

215.11.2013 11:34

We here in Ireland have just had a major one as well...

More than 1.5 million people are now known to have had personal information compromised by a major security breach at a Co Clare-Ireland based company which manages customer loyalty schemes across Europe.

A Garda (Irish police) investigation has been launched into what is fast becoming one of the worst data breaches in the history of the State.

315.11.2013 13:58

I'd translate the hacker's comment more as, "Stop worrying, so we have more time to try to access other accounts you may have, that use the same login" ^^' .

415.11.2013 14:52

Some white hat hackers/crackers will do this to put the frighteners to businesses just to make them aware of their security flaws, but time will tell whether this one is such an example.

516.11.2013 02:03

When asked why he didn't just alert the administrators to the flaw, lol responded.... because if he had done so do you think they would have acted in such a quick manner to make it known, if at all.
We saw in UK with 'Pleb Gate & 'NOTW' phone hacking that even when faced with the evidence/truth Organisations, people will go to any lengths to cover it up.
We're all able to take action now on Forums run by the same SW who'd have been oblivious to the problem but for lol going public.

Comments have been disabled for this article.

Latest news

VLC hits milestone: over 5 billion downloads VLC hits milestone: over 5 billion downloads (16 Mar 2024 4:31)
VLC Media Player, the versatile video-software powerhouse, has achieved a remarkable feat: it has been downloaded over 5 billion times.
1 user comment
Sideloading apps to Android gets easier, as Google settles its lawsuit Sideloading apps to Android gets easier, as Google settles its lawsuit (19 Dec 2023 11:09)
Google settled its lawsuit in September 2023, and one of the settlement terms was that the way applications are installed on Android from outside the Google Play Store must become simpler. In the future, installing APK files will be easier.
8 user comments
Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets (06 Jun 2023 9:19)
Roomba Combo j7+ is the very first Roomba model to combine robot vacuum with mopping features. And Roomba Combo j7+ does all that with a very clever trick, which tackles the problem with mopping and carpets. But is it any good? We found out.
Neato, the robot vacuum company, ends its operations Neato, the robot vacuum company, ends its operations (02 May 2023 3:38)
Neato Robotics has ceased its operations. American robot vacuum pioneer founded in 2005 has finally called it quits and company will cease its operations and sales. Only a skeleton crew will remain who will keep the servers running until 2028.
5 user comments
How to Send Messages to Yourself on WhatsApp How to Send Messages to Yourself on WhatsApp (20 Mar 2023 1:25)
The world's most popular messaging platform, Meta-owned WhatsApp has enabled sending messages to yourself. While at first, this might seem like an odd feature, it can be very useful in a lot of situations. ....
18 user comments

News archive