Avast Forums hacked

Soldato
Joined
4 Feb 2004
Posts
13,430
Location
Écosse
http://blog.avast.com/2014/05/26/avast-forum-offline-due-to-attack/

Don't think this is the first time the Avast forums have been targeted. Has a certain touch of irony. Anyway, they are advising users change their passwords and have stated that no customer details, licenses etc have been compromised, only forum accounts.

The AVAST forum is currently offline and will remain so for a brief period. It was hacked over this past weekend and user nicknames, user names, email addresses and hashed (one-way encrypted) passwords were compromised. Even though the passwords were hashed, it could be possible for a sophisticated thief to derive many of the passwords. If you use the same password and user names to log into any other sites, please change those passwords immediately. Once our forum is back online, all users will be required to set new passwords as the compromised passwords will no longer work.

This issue only affects our community-support forum. Less than 0.2% of our 200 million users were affected. No payment, license, or financial systems or other data was compromised.

We are now rebuilding the forum and moving it to a different software platform. When it returns, it will be faster and more secure. This forum for many years has been hosted on a third-party software platform and how the attacker breached the forum is not yet known. However, we do believe that the attack just occurred and we detected it essentially immediately.

We realize that it is serious to have these usernames stolen and regret the concern and inconvenience it causes you. However, this is an isolated third-party system and your sensitive data remains secure.

Sincerely,

Vince Steckler

CEO AVAST Software
 
motivator6d560db7c7787768b430366da4.jpg
 
http://blog.avast.com/2014/05/26/avast-forum-offline-due-to-attack/

Don't think this is the first time the Avast forums have been targeted. Has a certain touch of irony. Anyway, they are advising users change their passwords and have stated that no customer details, licenses etc have been compromised, only forum accounts.


Most have been hacked at some point,here is Kaspersky's one ,http://www.infopackets.com/news/4309/antivirus-company-admits-site-hacked-exposed-11-days ,Panda's one http://www.esecurityplanet.com/hackers/panda-security-hacked-lulzsec-is-your-website-safe.html .

Plenty more if you use Google search engine,are you really surprised?....

Hackers have been a pain for decades for many companies ie game companies,software,sites etc...
 
Last edited:
Don't think this is the first time the Avast forums have been targeted. Has a certain touch of irony. Anyway, they are advising users change their passwords and have stated that no customer details, licenses etc have been compromised, only forum accounts.

I wonder if they were using an out of date version of SMF.

Password hashing is only SHA1+salt, sadly.
 
I wonder if they were using an out of date version of SMF.

Password hashing is only SHA1+salt, sadly.

I'm not even sure if they updated the forum software (I think they did do it once) so that might be the reason (or it might be that there was a vulnerability in SMF that hadn't been fixed and they decided to move to another so they didn't have to wait for it to be fixed).

And that password hashing isn't going to take that long to crack since another forum I frequent was compromised through a dormant admin account that created a thread which included a piece of javascript that allowed the hacker to download the entire user database and the password were encrypted the same way and one person there has already reported an account using the same e-mail address and password had been accessed.

well just recently moved to avast on my laptop. Will be removed shortly

facepalm.jpg
 
Back
Top Bottom