Attackers are mass-exploiting a vBulletin 5 vulnerability, now patched, allowing remote code execution, after an exploit was anonymously published Monday
Dan Goodin / Ars Technica :
Ars Technica Dan Goodin
Related Coverage
- Botnet Uses Recent vBulletin Exploit to Block Other Hackers BleepingComputer
- Anonymous researcher drops vBulletin zero-day impacting tens of thousands of sites ZDNet
- vBulletin Patches Vulnerability Exploited in the Wild SecurityWeek
- Critical Zero-Day Pre-authentication Remote Code Execution Exploit Published for 5.x Versions of vBulletin Tenable
- Zero-Day RCE in vBulletin v5.0.0-v5.5.4 Sucuri Blog
- This vBulletin vBug is vBad: Zero-day exploit lets miscreants hijack vulnerable web forums The Register
Discussion
-
@notdan
@notdan
on x
If you're not testing every single company on @Hacker0x01 and @Bugcrowd for this vBulletin 0day RCE, you're missing out on free money. *make sure its in scope tho
-
@x0rz
@x0rz
on x
Someone making sure he's the only one capable to exploit the vBulletin vulnerability by patching the code and adding a password to the condition, smart move https://www.bleepingcomputer.com/ ... (misleading title if you ask me)
-
@ilyasu
Ilya Sukhar
on x
If you seek intriguing startup opportunities, I think the continued prevalence of vBulletin and phpBB is a good path to explore. https://arstechnica.com/...
-
@campuscodi
Catalin Cimpanu
on x
@dangoodin001 More info on what that botnet is doing. Took a while to decipher their code, but there's good coverage on Bleeping. Basically, attackers are hacking vBulletin sites, semi-patching the vulnerable code, and adding a password to run malicious commands https://www.bleep…
-
@campuscodi
Catalin Cimpanu
on x
I've also confirmed active exploitation coming from a pretty large botnet with Bad Packets, BinaryEdge, and GreyNoise. Was supposed to write a follow-up piece on all of this, but I see @dangoodin001 covered the attacks and patch already: https://arstechnica.com/...
-
@campuscodi
Catalin Cimpanu
on x
Anonymous researcher publishes proof-of-concept code for vBulletin zero-day -zero-day is a pre-auth RCE -impacts vBulletin 5.x only -estimated impact is in the tens of thousands -PoC verified by multiple sources https://www.zdnet.com/... pic.twitter.com/ecsbv2QIyN
-
@campuscodi
Catalin Cimpanu
on x
If this guy was smart, he would have sold the zero-day to Zerodium and got $10k for it... Instead, he dumped it on SecLists, out of all places: https://seclists.org/... https://twitter.com/...