Kodi disclosed forum breach affecting about 400,000 users
- Organization
- Kodi
- Exploit
- Credential Compromise
- Industry
- Software
The team behind Kodi, the open source media centre software, disclosed on April 8, 2023 that its MyBB user forum had been breached and that a copy of the database was being offered for sale on a cybercrime forum. Kodi said it became aware of the dump being advertised for sale in the 24 hours before it published, and posted a follow-up update on April 11, 2023.
According to Kodi's account, an attacker used the account of a trusted but inactive member of the forum administration team to log into the web based MyBB admin console on February 16 and again on February 21, 2023. Once inside, the attacker generated database backups, downloaded them and then deleted the files from the server. Existing nightly full backups were downloaded as well.
The stolen database covered roughly 400,635 accounts. It included forum usernames, notification email addresses, passwords hashed and salted by MyBB version 1.8.27, all public forum posts, posts from the team forum and private messages exchanged between users. Kodi did not explain how the administrator's credentials were obtained. It said the account owner confirmed they had not performed the actions.
Kodi took the forum offline rather than restore it in place, and said it would rebuild on a new server running the current MyBB release, a process complicated by custom modifications and security backports it had applied. It forced a global password reset, submitted the exposed email addresses to Have I Been Pwned, restricted access to the admin console, reviewed administrative privileges, improved audit logging and said it would commission penetration testing. It also asked for volunteer security professionals to assist with auditing.