Hello, everyone!
The site is back up and running after we had a bit of an incident.
An attacker found and used a vBulletin exploit to inject an SEO beacon into the site's main page. They attempted this several times, and wound up rendering the site completely inoperable.
I have no way of telling whether or not user data was exfiltrated, because they deleted the logs to cover their tracks. Ironically, this is what actually sed to the site breaking.
I would recommend that everyone go ahead and change their password, just to be safe.
Sorry, everyone. But we should be good to go again. Let me know if anything breaks.
The site is back up and running after we had a bit of an incident.
An attacker found and used a vBulletin exploit to inject an SEO beacon into the site's main page. They attempted this several times, and wound up rendering the site completely inoperable.
I have no way of telling whether or not user data was exfiltrated, because they deleted the logs to cover their tracks. Ironically, this is what actually sed to the site breaking.
I would recommend that everyone go ahead and change their password, just to be safe.
Sorry, everyone. But we should be good to go again. Let me know if anything breaks.
Comment