vBulletin Forum hacked with Zero Day vulnerability, caused Macrumors Forum Data breach
Nov 17, 2013
   Last Tuesday, Popular Mac news website MacRumors's user forums was hacked  and forum database  has been compromised including the username, email and passwords belonging to all 860,000 registered users.     Yesterday,  Inj3ct0r Team  of Exploit Database website  1337Day  claimed the responsibility for the hack and also claimed that they have also hacked the official website of vBulletin  Forum  using a   Zero Day exploit .   " Macrumors.com was based on vBulletin  CMS. We use our 0day exploit vBulletin , got password moderator. 860000 user data hacked too. The network security is a myth " he told me.     During the conversation, team leader told me that he has discovered a Zero Day Remote Code Execution vulnerability in vBulletin  v4.x.x and 5.х.x, that allows an attacker to execute arbitrary code on the server end remotely.     On their exploit marketplace  they are also selling this zero day exploit with Shell Upload payload at $7000 USD. " We found a critical v...