Originally posted by Niterocker
View Post
Announcement
Collapse
No announcement yet.
So, What Happened?
Collapse
X
-
Pretty much what was said already.
Site went down on July 4th. I logged in and saw nothing. Literally nothing.
Contacted the server company. Waited two days for a response and they said it all looked good. Huh? Good? There is no website. No reply from them.
Got Lrrpie involved. He knows this stuff. We both started digging through the server and found a ransom file that stated they wanted money via bitcoin or else they would release the files to the public. Checked and double checked the logs. They didn't get into the server via hacked passwords or traditional methods. Definitely a hole in the software.
So in lies the problem. Have backups, but can't just slap back up the software that they hacked.
Put on the latest and greatest software with no issues onto a new server that we also know has not been compromised. We are good now. Now comes the task of trying to import some of the old stuff, but safely and carefully. Have to go through it to make sure nothing in it is wrong also. Can't poison the new server nor do we know when it all truly happened.
Basically we had to make the decision to either stay down and work on this for who knows how long (in our spare time, we do have full time jobs) or we get the site back up and running and it gives us an excuse to just make it even more awesome.
Went that route.I am the admin...
Comment
-
Originally posted by Painthappy View Postor else they would release the files to the public.
Comment
-
Originally posted by Painthappy View PostPretty much what was said already.
Site went down on July 4th. I logged in and saw nothing. Literally nothing.
Contacted the server company. Waited two days for a response and they said it all looked good. Huh? Good? There is no website. No reply from them.
Got Lrrpie involved. He knows this stuff. We both started digging through the server and found a ransom file that stated they wanted money via bitcoin or else they would release the files to the public. Checked and double checked the logs. They didn't get into the server via hacked passwords or traditional methods. Definitely a hole in the software.
So in lies the problem. Have backups, but can't just slap back up the software that they hacked.
Put on the latest and greatest software with no issues onto a new server that we also know has not been compromised. We are good now. Now comes the task of trying to import some of the old stuff, but safely and carefully. Have to go through it to make sure nothing in it is wrong also. Can't poison the new server nor do we know when it all truly happened.
Basically we had to make the decision to either stay down and work on this for who knows how long (in our spare time, we do have full time jobs) or we get the site back up and running and it gives us an excuse to just make it even more awesome.
Went that route.
Long story short, I applaud you for not giving in. F those guys!My Old Feedback (300+) https://web.archive.org/web/20180112...-feedback.html
Comment
-
Wait, they threatened to release the files of an open, public forum... to the public?
Or did they mean they'd release the names and passwords? Names being irrelevant in this age of Facebook, and 95% of the passwords would be useless the day they were released (having been used only for that site) and the other 5% would be changed and thus invalidated in short order.
Good to know you have backups, though.
Doc.Doc's Machine & Airsmith Services: Creating the Strange and Wonderful since 1998!
The Whiteboard: Daily, occasionally paintball-related webcomic mayhem!
Paintball in the Movies!
Comment
-
Originally posted by Painthappy View Postor else they would release the files to the public. Checked and double checked the logs. They didn't get into the server via hacked passwords or traditional methods. Definitely a hole in the software.
During a routine security check, we found that your login info might have been compromised through a site unconnected to Booking.com. Since lots of people use the same email and password combinations across multiple sites, we've temporarily locked your account as a precaution. Your Booking.com account is safe and hasn't been compromised
Comment
-
Originally posted by DocsMachine View PostWait, they threatened to release the files of an open, public forum... to the public?
I did have a lot of private files on the server - but nothing raunchy nor anything that would come back and bite me if made public, so I'm not really concerned there either - plus I have back ups of it all and that folder is now on my desktop.
As for the memberships, we will get all that up and running back next week. Working through one step at a time. When you had many many years of simple modifications you get used to having access to, it take a while to add them all back in.
I am the admin...
Comment
-
I suppose the moderator forums, the member section, and PMs could be made public. But what clown is going to wade through that ocean looking for mildly embarrassing quips
Originally posted by Painthappy View Post
Right? So the passwords were all protected - so much so that even I could not see them. That's why when people asked, all I could do is reset it, not tell them their password.
Last edited by Axel; 07-12-2020, 11:11 AM.Dulce et decorum est pro comoedia mori
Comment
Comment