Soul - thats something that is very hard to do, and i would doubt that the person who did it was actually "stealing" the cookies, rather than running some html code in the posts, or exploiting a hole in vB. but vB does use MD5 encoded passwords so its not a big deal to leak them out like that.
Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.
Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.