• Welcome to Maher's Digital World.

Just got an email from Avast!, they got hacked.

Started by iih, May 28, 2014, 06:14 AM

Previous topic - Next topic

iih

My sister reported yesterday she got an email from Avast! telling her
that their forum was hacked, and that all the E-Mails and its passwords
where compromissed, they where one-way encrypted.

QuoteHere's the email
""Dear NVM,

The AVAST forum is currently offline and will remain so for a brief period. It was hacked over this past weekend and user nicknames, user names, email addresses and hashed (one-way encrypted) passwords were compromised. Even though the passwords were hashed, it could be possible for a sophisticated thief to derive many of the passwords. If you use the same password and user names to log into any other sites, please change those passwords immediately. Once our forum is back online, all users will be required to set new passwords as the compromised passwords will no longer work.

This issue only affects our community-support forum. No payment, license, or financial systems or other data were compromised.

We are now rebuilding the forum and moving it to a different software platform. When it returns, it will be faster and more secure. This forum for many years has been hosted on a third-party software platform and how the attacker breached the forum is not yet known. However, we do believe that the attack just occurred and we detected it essentially immediately.

We realize that it is serious to have these usernames stolen and regret the concern and inconvenience it causes you. However, this is an isolated third-party system and your sensitive data remains secure.

All the best,

Ondrej Vlcek
COO AVAST Software""

I ask some of my friend on other forums initially i do not believe, also PM usmangujjar because I see him as Avast! users
Thats funny, a security company got owned. Nvm its just the forums, but yea its quite ironic Las time, Panda also got hacked.

After we discuss about Avast we have conclusion, AVast Forums still using SMF 2.0 2012 check HERE On page scroll to the bottom center.

QuoteSMF 2.0 with copyright in the footer from 2012, let's say it would be the latest version released in 2012, which is 2.0.3 (November 16 2012), there have been various updates released since then.
In SMF 2.0.4 (February 1 2013) a "Quick fix for Admin Password Reset vulnerability reported by Raz0r" is also included in the changelog.

Here is the Screenshot:

AVAST! forum..vulnerability reported by Raz0r (usually managed by Lazy Admins)



Maher's Digital World Website See? (Good enough Managed Admins)



So far we are secure enough condition... Just sharing have a great day.
+1 for the hackers and -1 for Avast  :o
eqso.orari-digital.org:8888 YBØIX

iih

Quote from: usmangujjar on May 28, 2014, 08:42 AM
yes, Brother IIH you are right, something gone wrong with Avast. they also sent me mail 2 or 3 days ago.
it is bad, but many big companies accounts and sites hacked in some previous years, there are always some vulnerabilities, and ways to break servers securities.
it's ok just on their forums...however you should change your password..also for other site
If you're using the same password. inshort if feels doubt..just change password that's it..you will be fine
not only AVAST! Panda also got hacked... :)
eqso.orari-digital.org:8888 YBØIX