Hey everyone, I wanted to share an updated introduction to something I’ve been building called PosterFlow. PosterFlow started as a personal home theater project. I wanted a cleaner way to manage digital poster screens without constantly juggling folders, images, slideshow tools, display windows, schedules, and manual updates. The goal was to make poster displays feel more like part of a real cinema/preshow setup instead of just a rotating image folder. PosterFlow is a Windows desktop app with an
In the last 24 hours we became aware of a dump of the Kodi user forum (MyBB) software being advertised for sale on internet forums. This post confirms that a breach has taken place.
MyBB admin logs show the account of a trusted but currently inactive member of the forum admin team was used to access the web-based MyBB admin console twice: on 16 February and again on 21 February. The account was used to create database backups which were then downloaded and deleted. It also downloaded existing nightly full-backups of the database. The account owner has confirmed they did not access the admin console to perform these actions.
The admin team have disabled the account used in the breach and have conducted an initial review of team infrastructure the team member had access to.
The nightly full backups that were downloaded expose all public forum posts, all team forum posts, all messages sent through the user-to-user messaging system, and user data including forum username, email address used for notifications, and an encrypted (hashed and salted) password generated by the MyBB (v1.8.27) software. At the current time, we have found no evidence of unauthorised access to the underlying server that hosts the MyBB software.
Although MyBB stores passwords in an encrypted format we must assume all passwords are compromised. This requires actions from the team, and forum users:
We will post more information as it becomes available.
View the full article