Author Topic: Forum possibly breached  (Read 4928 times)

Uffe

  • EA Practitioner
  • ***
  • Posts: 1859
  • Karma: +133/-14
  • Flutes: 1; Clarinets: 1; Saxes: 5 and counting
    • View Profile
Forum possibly breached
« on: September 21, 2020, 09:34:52 pm »
Hey guys,

I just received a scam email quoting the address and password I'd used for this forum (though not the forum itself).
It might be a good idea to reset your passwords.

/Uffe
« Last Edit: September 21, 2020, 09:37:09 pm by Uffe »
My theories are always correct, just apply them to the right reality.

Eve

  • EA Administrator
  • EA Guru
  • *****
  • Posts: 8078
  • Karma: +118/-20
    • View Profile
Re: Forum possibly breached
« Reply #1 on: September 22, 2020, 08:17:22 am »
I assume you're using a unique password for this forum? No chance of any malware on your system?

From what I can read online passwords here are stored as a salted hash, that's something at least.

Paolo F Cantoni

  • EA Guru
  • *****
  • Posts: 8605
  • Karma: +256/-129
  • Inconsistently correct systems DON'T EXIST!
    • View Profile
Re: Forum possibly breached
« Reply #2 on: September 22, 2020, 09:11:30 am »
I assume you're using a unique password for this forum? No chance of any malware on your system?

From what I can read online passwords here are stored as a salted hash, that's something at least.
I think Uffe's point is that he was provided with the password in PLAIN TEXT - intimating the hack had worked!  I've received similar emails, though not I suspect from this forum.  Fortunately, the passwords were some 20 years old and no longer used.

Paolo
Inconsistently correct systems DON'T EXIST!
... Therefore, aim for consistency; in the expectation of achieving correctness....
-Semantica-
Helsinki Principle Rules!

Eve

  • EA Administrator
  • EA Guru
  • *****
  • Posts: 8078
  • Karma: +118/-20
    • View Profile
Re: Forum possibly breached
« Reply #3 on: September 22, 2020, 10:43:40 am »
Yes, that was my understanding of what I read. All that means is that someone has gained access to Uffe's password. It doesn't say why. If that password is only used here, that limits the possible locations of the breach to his computer and our server.

I don't have any visibility on the server, and wouldn't know what kind of things to check for even if I did.

Uffe

  • EA Practitioner
  • ***
  • Posts: 1859
  • Karma: +133/-14
  • Flutes: 1; Clarinets: 1; Saxes: 5 and counting
    • View Profile
Re: Forum possibly breached
« Reply #4 on: September 22, 2020, 03:58:59 pm »
Hi again,


As far as I can remember this was a unique password but it was very old so I can't say for absolute certain. I did have it stored in my browser's password manager, and I do log in "forever" which I assume means there's something stored in a cookie, but my malware scans haven't turned up anything.

Of course, if the data was stolen from the forum it could be that that happened years ago and it's only recently that someone's got around to brute-forcing the passwords.

But it's probably worth it to check the logs for any recent suspicious activity, and for users to change their passwords.


/Uffe
My theories are always correct, just apply them to the right reality.

AndyJ

  • EA User
  • **
  • Posts: 337
  • Karma: +5/-3
  • It's only a model
    • View Profile
Re: Forum possibly breached
« Reply #5 on: October 08, 2020, 12:23:03 pm »
Hmm...

Changed my password, can't hurt...
Sun Tzu: "If you sit by the river long enough, eventually the body of MS Visio floats past."