anything can be brute forced, but doing it over the net is either going to draw some some serious attention (or should, since it would be way out of the normal access pattern to get a couple measly passwords, presumably they'd be looking for the admin's stuff instead of our dumb accounts) or the system should stop accepting requests at some point.
And yeah, the MD5 hashing protects the actual password, but if you have enough of the system (collected it all up while hacking the board, unlikely in this case IMO), you can get something just as good: a password that results in the same thing as yours after having come through the MD5 hashing. Except we're not on the same board anymore, so there really isn't any point. The different hashing will make whatever they produce pointless.
I've said it before, vBulletin has its vulnerabilities just like any other board. Thus far infopop impressed me most for security, but if we get a search function as bad as that on this forum someone's going to have a stroke. My best reccomendation: customize your administration tables.
All the same, you should (admins especially) be regularly changing your passwords. Now's a good excuse to do it.
PS: glad to see the fellow geeks coming out of the woodwork
