Login Register






MyBB DataBreach?? filter_list
Author
Message
MyBB DataBreach?? #1
[redacted] just came out saying they just got breached because of a mybb vulnerability.

is siniter.ly in the clear?

Reply

RE: MyBB DataBreach?? #2
If there is a problem, I'm glad I didn't use my password for anything else here. Hopefully we're all good and everyone else.

Reply

RE: MyBB DataBreach?? #3
We have extra precautions in place for things like this. That said, I'm looking into it, and making extra sure we were not impacted.
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)

Reply

RE: MyBB DataBreach?? #4
I do have qualms with how the MyBB devs chose to deal with the recent situation and I'll make an effort to speak with them. That said, our security measures were sufficient, and nothing of harm was done. The board is up to date and we only suffered a couple hours of downtime.

My statement to the developers:
Quote:I spoke with Nervo about the transparency of vulnerabilities several years ago. I've ran a forum for almost a decade and I've never seen a situation so dire. Board owners need to be updated with security flaws and there's no reason it should have taken until the 10th to do so. I expect more from the MyBB team and I'm sure the other board owners do as well. It is not realistic to expect users to keep up to date with the Github. These vulnerabilities were in the wild long before other owners heard.
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)

[+] 1 user Likes Oni's post
Reply

RE: MyBB DataBreach?? #5
(06-23-2019, 12:00 AM)Oni Wrote: I do have qualms with how the MyBB devs chose to deal with the recent situation and I'll make an effort to speak with them. That said, our security measures were sufficient, and nothing of harm was done. The board is up to date and we only suffered a couple hours of downtime.

My statement to the developers:
Quote:I spoke with Nervo about the transparency of vulnerabilities several years ago. I've ran a forum for almost a decade and I've never seen a situation so dire. Board owners need to be updated with security flaws and there's no reason it should have taken until the 10th to do so. I expect more from the MyBB team and I'm sure the other board owners do as well. It is not realistic to expect users to keep up to date with the Github. These vulnerabilities were in the wild long before other owners heard.

That's the risk you have to take running a site. You always have to be active with security patches and such. Hopefully MyBB can deal with stuff like this better later on.

Reply

RE: MyBB DataBreach?? #6
(06-23-2019, 12:00 AM)Oni Wrote: My statement to the developers:
Quote:I spoke with Nervo about the transparency of vulnerabilities several years ago. I've ran a forum for almost a decade and I've never seen a situation so dire. Board owners need to be updated with security flaws and there's no reason it should have taken until the 10th to do so. I expect more from the MyBB team and I'm sure the other board owners do as well. It is not realistic to expect users to keep up to date with the Github. These vulnerabilities were in the wild long before other owners heard.

They only pushed the commit fixing the issue on Jun 10th, the same day they released a new version.
So even if you were to track the changes on git it wouldn't have made much of a difference from waiting for a new release and patching it then.
Personaly I can't think of a solution for reporting about these things to the board owners, maybe send an email to everyone after every single release, but that wouldn't be any different from just following mybb's twitter feed and keeping an eye out for updates.

Reply

RE: MyBB DataBreach?? #7
(06-23-2019, 02:18 AM)Drako Wrote:
(06-23-2019, 12:00 AM)Oni Wrote: I do have qualms with how the MyBB devs chose to deal with the recent situation and I'll make an effort to speak with them. That said, our security measures were sufficient, and nothing of harm was done. The board is up to date and we only suffered a couple hours of downtime.

My statement to the developers:
Quote:I spoke with Nervo about the transparency of vulnerabilities several years ago. I've ran a forum for almost a decade and I've never seen a situation so dire. Board owners need to be updated with security flaws and there's no reason it should have taken until the 10th to do so. I expect more from the MyBB team and I'm sure the other board owners do as well. It is not realistic to expect users to keep up to date with the Github. These vulnerabilities were in the wild long before other owners heard.

That's the risk you have to take running a site. You always have to be active with security patches and such. Hopefully MyBB can deal with stuff like this better later on.

That's assumed, but in this case the developers knew for a week, and didn't disclose.
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)

Reply

RE: MyBB DataBreach?? #8
(06-23-2019, 11:47 AM)Oni Wrote: but in this case the developers knew for a week, and didn't disclose.

Sadly, It's the case with most data breaches.

Companies/devs do not enjoy a negative Impact on their reputation, by revealing breaches there and then.
[Image: AD83g1A.png]

Reply

RE: MyBB DataBreach?? #9
Are you talking about the RCE and XSS exploit?
Die  But Don't Lie
“Oh Abu Dharr! Don’t look at the smallness of the sin but look at the one you disobeyed.” Prophet Muhammad (pbuh)
[Image: p_237m2jx1.png]
Click for Free VPN

Reply

RE: MyBB DataBreach?? #10
(06-26-2019, 01:40 PM)Mr.Kurd Wrote: Are you talking about the RCE and XSS exploit?

Yes. We weren't affected.
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)

[+] 1 user Likes Oni's post
Reply