Attackers appear to have compromised tens of thousands of Web sites using a security weakness in sites powered by the forum software
vBulletin, security experts warn.
In
a blog post in late August, vBulletin maker Jelsoft
Internet Brands Inc. warned users that failing to remove the “/install” and “/core/install” directories on sites running 4.x and 5.x versions of the forum software could render them easily hackable. But apparently many vBulletin-based sites didn’t get that memo: According to Web site security firm
Imperva, more than 35,000 sites were recently hacked via this vulnerability.