Someone Has Some Explaining To Do

bankybruce

All In!
Supporting Member
Joined
Mar 28, 2003
Posts
25,970
Reaction score
17,300
Location
Nowhere
So it appears you restored from a backup and did not get the database back from the hackers. With that being, hackers now have a copy of the sites database and being I am a Database Engineer, I know what they can and can't do with all that info, so please tell me you were using some sort of encryption for our passwords for our accounts.
 
OP
OP
bankybruce

bankybruce

All In!
Supporting Member
Joined
Mar 28, 2003
Posts
25,970
Reaction score
17,300
Location
Nowhere
thankfully my password on here really isnt used anywhere else :)

But that means they have your password here!!! So you might want to change that. Also, depending about how they got access, they could do it again and get that info too.
 

BigRedRage

Reckless
Supporting Member
Joined
Mar 25, 2005
Posts
48,274
Reaction score
12,521
Location
SE valley
But that means they have your password here!!! So you might want to change that. Also, depending about how they got access, they could do it again and get that info too.

if they are bored enough to login and post as me I am curious what they will post so ima leave it alone :)
 
OP
OP
bankybruce

bankybruce

All In!
Supporting Member
Joined
Mar 28, 2003
Posts
25,970
Reaction score
17,300
Location
Nowhere
I don't think you realize how much some people have posted in reguards to real life info. Links to LinkedIn, Facebook, Xbox Live and personal email. Mix that with the fact that many people may use the same password for those and a lof of other account could now be hacked. So I think it is fair to demand and explanation of how secure it is and what has been done to prevent it again.

Thankfully I too do not use this password for anything else, but that is not the point. I don't feel safe here anymore.
 

BigRedRage

Reckless
Supporting Member
Joined
Mar 25, 2005
Posts
48,274
Reaction score
12,521
Location
SE valley
I don't think you realize how much some people have posted in reguards to real life info. Links to LinkedIn, Facebook, Xbox Live and personal email. Mix that with the fact that many people may use the same password for those and a lof of other account could now be hacked. So I think it is fair to demand and explanation of how secure it is and what has been done to prevent it again.

Thankfully I too do not use this password for anything else, but that is not the point. I don't feel safe here anymore.

Oh no, im not rebutting your comments and expect shaggy will answer and come up with more safety for the site.

Im just talking.
 

unseenaz

ASFN Addict
Joined
Mar 6, 2013
Posts
6,546
Reaction score
4,979
Location
Gilbert
I don't think you realize how much some people have posted in reguards to real life info. Links to LinkedIn, Facebook, Xbox Live and personal email. Mix that with the fact that many people may use the same password for those and a lof of other account could now be hacked. So I think it is fair to demand and explanation of how secure it is and what has been done to prevent it again.

Thankfully I too do not use this password for anything else, but that is not the point. I don't feel safe here anymore.

Yeah this is fairly alarming. Thanks for the heads up Bruce. Gonna spend the better part of my morning changing all my passwords.

Is this at all related to the new owners of the board? Never saw anything like this with the company that ran the boards previously. Can anyone vouch for the new owners? Not accusing anyone but if there's malicious intent I can find a new place to talk AZ sports
 
OP
OP
bankybruce

bankybruce

All In!
Supporting Member
Joined
Mar 28, 2003
Posts
25,970
Reaction score
17,300
Location
Nowhere
Yeah this is fairly alarming. Thanks for the heads up Bruce. Gonna spend the better part of my morning changing all my passwords.

Is this at all related to the new owners of the board? Never saw anything like this with the company that ran the boards previously. Can anyone vouch for the new owners? Not accusing anyone but if there's malicious intent I can find a new place to talk AZ sports

I don't think there was any malicious intent by the new owners. Shaggy had been a poster for sometime before. Also, there are a lot of ways to hack a site like this, so maybe it is just lack of experience, like shotgunning changes to the site during the day without testing them. It appears to me he may be a UI developer, which in my experience means not a great Database Developer or Server Admin.
 
Last edited:

Shaggy

Site Owner Administrator
Administrator
Moderator
Joined
Sep 29, 2008
Posts
9,022
Reaction score
2,953
Location
Arizona
The original owners had been hacked before. Not sure if it was like this. I am also not sure if the hackers took the database or were just messing around. I had nothing to do with this. I would recommend changing your password on here and if you do use the same password on other sites, change those too, just in case. Keebali had alot of outdated files on this site that I thought I had updated, but I guess I messed it. I removed all those files and the front page(which is how I think they got in with the outdated software there) and have put in alot more protection. Sorry that this had to happen as this is something I never wanted to happen.

Please I recommend changing you password here for sure, just to be safe!
 

Brian in Mesa

Advocatus Diaboli
Super Moderator
Moderator
Supporting Member
Joined
May 13, 2002
Posts
70,690
Reaction score
21,238
Location
The Dark Side
Are posts (and possibly threads) missing because it was backed up to a certain time/date?

I know I responded to a few threads yet they now say I have never commented in them.

Oh well, your loss. :raccoon: :D
 

Shaggy

Site Owner Administrator
Administrator
Moderator
Joined
Sep 29, 2008
Posts
9,022
Reaction score
2,953
Location
Arizona
Yep had to use a backup from the night before and lost all posts from yesterday. Wish I didn't have to do it as I don't want to lose any of your posts but needed to happen. Brian make sure you change your password as all staff need to.
 

Brian in Mesa

Advocatus Diaboli
Super Moderator
Moderator
Supporting Member
Joined
May 13, 2002
Posts
70,690
Reaction score
21,238
Location
The Dark Side
Yep had to use a backup from the night before and lost all posts from yesterday. Wish I didn't have to do it as I don't want to lose any of your posts but needed to happen. Brian make sure you change your password as all staff need to.

Will do that right now. :thumbup:
 

Mulli

...
Supporting Member
Joined
Jul 16, 2004
Posts
52,371
Reaction score
4,310
Location
Generational
Are posts (and possibly threads) missing because it was backed up to a certain time/date?

I know I responded to a few threads yet they now say I have never commented in them.

Oh well, your loss. :raccoon: :D

You must hate the lost threads/posts. :)
 

Russ Smith

The Original Whizzinator
Supporting Member
Joined
May 14, 2002
Posts
84,450
Reaction score
33,165
I just changed my password after getting an email telling me to do so but I have to admit that doesn't change my feeling of security. If Someone hacked in, they would already have the passwords wouldn't they? So they could presumably also have something that allows them to see everyones new password after they changed it.

I don't use the same password elsewhere but I wonder how many people are now going to change their password to one they use elsewhere thus exposing that one?
 

jf-08

Guy Smiley
Administrator
Super Moderator
Supporting Member
Joined
May 15, 2002
Posts
26,081
Reaction score
20,298
Location
Eye in the Sky
FWIW - the stored passwords are encrypted. I don't know if anyone can "un-encrypt" them, but it's better to be safe than sorry.
 

Russ Smith

The Original Whizzinator
Supporting Member
Joined
May 14, 2002
Posts
84,450
Reaction score
33,165
FWIW - the stored passwords are encrypted. I don't know if anyone can "un-encrypt" them, but it's better to be safe than sorry.

OK that's good to know. A friend of mine is a professor that specializes in computer security. He said one of the oldest tricks they use is to access a site and plant software that allows them to track changes to passwords, then let everyone know so they all change the password, and then they have the passwords that they didn't actually have before.

So encrypted sounds good.
 
OP
OP
bankybruce

bankybruce

All In!
Supporting Member
Joined
Mar 28, 2003
Posts
25,970
Reaction score
17,300
Location
Nowhere
FWIW - the stored passwords are encrypted. I don't know if anyone can "un-encrypt" them, but it's better to be safe than sorry.

It depends on the type of encryption. Some are very simple to break and as old as this site is it is most likely a basic hash which is extremely simple to decrypt. In fact, there are sites out there that will decrypt a hash encrypted password.
 
Last edited:

Twist18

Registered
Joined
Jan 22, 2003
Posts
882
Reaction score
17
Location
Pocahontas , IL
I just worry about being a contributor in the past to the site if they can get any of my paypal or financial records? I also changed my password and the email I had on here was at my last address.
 
OP
OP
bankybruce

bankybruce

All In!
Supporting Member
Joined
Mar 28, 2003
Posts
25,970
Reaction score
17,300
Location
Nowhere
I just worry about being a contributor in the past to the site if they can get any of my paypal or financial records? I also changed my password and the email I had on here was at my last address.

I wouldn't worry about that, PayPal uses a token that is not useful by itself. They are pretty rock-solid with their security.
 

Phoenix219

Rookie
Joined
Jul 24, 2014
Posts
58
Reaction score
0
I hope I didn't lose any posts... I didn't have enough to begin with :p

Crappy... I made some decent points yesteday, and I *did* lose all my posts :(
 

LoyaltyisaCurse

IF AND WHEN HEALTHY...
Joined
Aug 10, 2004
Posts
53,873
Reaction score
19,664
Location
CA
I Blame Shane! Haven't had an opportunity to use that in a while! :D
 
Top