Do you consider Brivium addons a security risk?

Alpha1

Administrator
Joined
May 28, 2007
Messages
4,268
As you probably know, Brivium was banned from XenForo after being exposed as running a hackers collective / site and using stolen code. There also was the ethically questionable issue of their addons secretly using callbacks to send data over to their server.

Brivium had the most addons of any developer on xenforo.com so a lot of websites were running their software.
The new information forced webmaster to make a choice about whether or not to trust Brivium software. Software already paid for.

It is almost unthinkable that any addon developer could add exploits in their software. Such could be abused against millions of members of online communities. We can only hope that this will not happen in the XenForo addon community.
No exploit has ever been reported in Brivium software. But still, the questionable ethics shown are worrisome enough to ask yourself the question: would you use a Brivium addon that you already paid good money for?

When Brivium was exposed, several webmaster and I had a group fund running with Brivium to expand an addon. We decided that we would continue the project and simply inspect the code once delivered. Each software release Brivium provided was bug ridden. Eventually Brivium simply sent me fake files and claimed the project was completed. I was able to get a refund through a Paypal claim, so I could refund the group. I did remove all Brivium addons from my sites. That was the last I heard of Brivium in some months.

Last night my account here on TAZ was hacked to delete Brivium related threads. My account has moderating rights on XenForo forums here. I was foolish enough to use a password similar to the one that I used for the Brivium website. I am not sure if that is the cause. To avoid any more incidents, security has been beefed up since. The hacker used an email with the same domain as Briviums hackers collective ******. While this is no definite proof that this was Brivium it seems likely.

Brivium runs an affiliate program. I wonder if some of the addons in the xenforo.com resource manager are created by Brivium and resold on XF.com by other people.

So what do you think about Brivium addons? Do you have them installed? Do you feel secure with it?
Will you keep using them?
What do you think the risks are?
 

Steve

Fanatic
Joined
Apr 17, 2009
Messages
3,710
I would start second guessing downloading anything from them to your PC, not just installing addons on your server.
 

JordanH

Imperial Majesty
Joined
Feb 3, 2014
Messages
324
I have several addons with him:
ai.imgur.com_tOpSVJz.png

However, as you can see with the number of domains, I actually have bought several of each addon / licenses for different websites. A total of 15 bought licensed addons I have from them.

Sadly, I been looking for a replacement ever since he has been exposed.

Looks like audentios new AD Credits and Shop addons might work, but to replace them on just a couple of my forums would cost well over $400 if not more. It is getting to be expensive.

I think he is a huge hazard and risk. I would no longer use any of his services.
 

AdamD

Devotee
Joined
Oct 21, 2007
Messages
2,897
I'd consider anything Brivium to be a security risk at this point.
People would have to be pretty stupid at this point, to keep using his addons.
Especially with the staff members account here being hacked by a possible Brivium staffer.
 

Robust

Developer
Joined
Dec 7, 2014
Messages
1,344
He's a huge, huge risk. I've had a PayPal dispute with him and won this morning. His add-ons are utter crap. Look through the code in one. His practices are very unethical. He creates code listeners after, and assigns them to XenForo. His add-ons can only be removed if you have a valid license at Brivium. He has classes made COMPLETELY to confuse someone looking to edit the code. Completely redundant classes making callbacks to each other. 1 hour later you realise he's ****ing around with you. I wouldn't touch anything by him with a ten foot bargepole anymore.
 

zappaDPJ

Moderator
Joined
Aug 26, 2010
Messages
8,450
He's a huge, huge risk.

I agree. I installed a couple of their add-ons on a test site and didn't like what I saw. I had a more competent coder than me take a look and the end result was I wiped the entire installation.
 
Joined
Jan 6, 2004
Messages
5,948
When I first found out about the callbacks in those add-ons I warned anyone that would listen that using them was a bad idea. Very few listened and installed them anyway.

Using them months ago was foolish, using them now is stupidity.
 
Joined
Sep 3, 2012
Messages
504
I had a website that had a Brivium add-on installed on a corporate server for an almost million user community and we uninstalled, switched servers, and forced password changes for every user when we realized what they had been doing. We then even hired outside analysts to search through our system and ensure it was clean of Brivium garbage. We write our own add-ons now thankfully. :)
 

49er

Enthusiast
Joined
Oct 26, 2011
Messages
242
I find it hard to believe that an hacker would hack just one account to delete posts about himself ..


Not saying it didn't happen ..
 

Liam W

in memoriam 1998-2020
Joined
Oct 3, 2013
Messages
157
I only had one or two add-ons from Brivium on my sites... (the widget framework), and I uninstalled it. Their code always used a callback, and they sent the entire $_SERVER array to their site - this includes the your IP, as well as any basic authentication (htaccess) details used to access the AdminCP area (which I'm not sure many people are aware of).

I believe this was removed after it was brought public, but it shouldn't have been there in the first place.

I wouldn't go near Brivium anymore.

Liam
 

LeadCrow

Apocalypse Admin
Joined
Jun 29, 2008
Messages
6,818
Do you consider Brivium addons a security risk?
Abstumolutely... Software with apparent backdoors doesn't get designed by mistake by people that experienced.

But even if that's corrected, that leaves a durable issue with trust (to be deserved, not just earned the way con-men earn victims' trust). IMO the bigger concern to have. You may be (or erroneously feel) safe now, but what's to say this won't or hasn't discretely changed without your awareness?
 

Isil`Zha

Aspirant
Joined
Jan 18, 2015
Messages
33
I was already solidly in "nope" land even after that "apology." This really looks like it was a very empty apology and he was only sorry he got caught. I'd consider anything from Brivium outright malicious.
 
  • Like
Reactions: Xon

Danielx64

Developer
Joined
Nov 8, 2009
Messages
3,300
Q: Do you consider Brivium addons a security risk?

A: I consider the developer a national security threat.
 

Dan18

Fan
Joined
Jun 9, 2014
Messages
772
So I just uninstalled one Premium Addon from Brivium due to possible security issue.
After 1 hour, he released an update: https://***********/resources/like-reply-to-view-attachment.22/update?update=1046
Not really sure what's being changed on that update.
I tried to Diff Compare the two version files and a lot has been changed.
I'm not a coder so can't tell if it's really addon fixes and improvement.
 

LeadCrow

Apocalypse Admin
Joined
Jun 29, 2008
Messages
6,818
After 1 hour, he released an update
I say keep that old version handy, in case they purge their download system of old files or some code review of the differences is necessary. What's the addon version you were using btw?
 
Top