Kodi forum hacked

Kodi confirmed a data breach in the user forum. The development team was made aware of the hack after it was circulated for sale on the darknet.

The Kodi software, (latest version is the Kodi 20), was not affected by the breach.

kodi

Initial investigation into the matter revealed that the attacker compromised an account of an inactive forum administrator, and managed to gain access to the administrator console twice. This happened in mid-February 2023.

The administrator account was used to back up the databases, which the attacker then downloaded.

Kodi disabled the account to prevent future access to its systems once it discovered the breach. It also "carried out an initial review of the team's infrastructure accessed by the team member," reported the incident to UK police and notified the UK Information Commissioner's Office.

The of the database circulating on the darknet "contain all public forum posts, all group forum posts, all messages sent through theof user-to-user messages, user data, such as forum name, email address that for notifications and an encrypted (hashed and salted) password generated by the MyBB software (v1.8.27)”.

Forum users should assume that their "Kodi forum credentials and any private data shared with other users through the user-to-user messaging system has been compromised."

Although the are encrypted, Kodi considers them compromised and should be changed.

Kodi announced the following measures to address the breach:

  • All exposed email data will be shared with Have I Been Pwned, a website that shows whether an email address has been part of a breach.
  • Planning to perform a password reset. This will reset all passwords and prevent further breaches or access to personal data. Kodi forum users should also change their passwords on other services if they used the same one.
  • The forum has been upgraded to the latest version and will be offline for a few days. Access to the admin console will be further restricted and strengthened.

Passwords will likely be reset once the forum is back online. Users will be notified by email of the reset and will need to set a new password when they first visit the forum.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.
Kodi

Written by giorgos

George still wonders what he's doing here ...

2 Comments

Leave a Reply
  1. I had KODI on the COSMOTE VOC and all was well, it upgraded to the latest version
    NEXUS 20.5 and the problems started (black screen, wouldn't close) and the uninstall, I did a new installation but when I try to install addons it gives me a message that I don't have an internet connection. I tried to install old version via DOWNLOANDER but it always installed the new version. Thanks for any solution you can suggest.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).