Jump to content

Recommended Posts

Posted
We all are aware that the server was breached due to a bug in the VB software, and that as a precaution everyone was urged to change their passwords. I am sure Shaun is analysing log files in order to fill us all in... But as DosBox has had he also has to deal with users whom are still locked out of there account etc.

 

I was not aware of it and as far as I know it has never been generally posted which is what people are a bit up in arms about. Its good that this much has come out as its a far better root cause than a root password set to 1234 or suchlike (did not think that this was the case, just an example).

 

The fact that ZH has gone to as much trouble as he has reimplementing the site bit by bit and making it very clear about the breach is a good thing and does show commitment to security but the complete information vacum was a bit unfomfortable. Hopefully in a while when the dust has settled and VB have patched up their software we will get a better idea of what happened if that information is avalible.

Posted
If there was such a bug in VB dont you think we would of heard about it!!

We did in a way. Valve's Steam Users' forums and Sony's MyResistance.net forums were hacked around the same time as EduGeek. Both use vBulletin and the latter is still offline! :eek:

 

Steam forums taken offline following possible security breach - 09/11/2011

The Steam forums, run by Valve, are down following an apparent security breach perpetrated by a group of hackers, Eurogamer reports. The outlet states that a message board in the forums was "defaced" Monday night; the forums were subsequently taken down and replaced with a message from Steam stating they are "offline for maintenance."

 

Eurogamer reports that one Steam user contacted them saying that the hackers changed some text on the message board and sent some spam to registered users. The message board was redesigned to show a message from a website called Fkn0wned.com that documents video game hacks.

 

Because some players have reported receiving spam with similar content to the material illicitly splashed across the forums, it's possible that whoever hacked the site may have obtained the e-mail addresses of users who have registered with the site. No other forum users have come forward saying they received spam since the initial outbreak, and Valve has neither made a public statement nor responded to Ars' requests for comment on the incident.

 

As of this writing, the forums remain down and display only the maintenance message, telling players their "patience is appreciated." We'll be keeping an eye out for Valve's statement on the matter as well as for the forums to come back up. (Source Via)

 

Resistance Site, Forums are Down; Hacking Alleged - 12/11/2011

Visitors to MyResistance.net, the official site for the Resistance franchise of PS3 games, say the site was serving up malware yesterday. One of them alerted Insomniac Games, and now the entire site has been taken offline for maintenance.

The hacking and malware allegations could not be immediately verified with Insomniac or Sony Computer Entertainment America. The site itself is owned by Sony, with Insomniac providing moderation and content support. The studio thus is referring inquiries directly to SCEA. This morning Kotaku reached out to representatives of both; any statement the studio or Sony makes will be updated here.

 

This site outage comes a week after an attack and defacement of the Steam Forums that brought them down for nearly five days. Worse, Valve later said that a database containing user information, including encrypted credit card numbers, had been exposed in the attack, and advised users to monitor their credit card activity and change passwords elsewhere if it was the same as their Steam Forum login. (Source)

Posted
If you look back he was talking to another user!

 

Yes, but from the fact that he said they were working hard, due to a lot of people having used the contact us link, it still applies I think! Shaun is only one man, he can't be sorting people out on here at the same time as writing info on what happened as well as maintaining the site to ensure this sort of thing doesn't happen again, whilst also looking after his family.

 

People suddenly seem to be behaving like this site is some giant commercial operation when it isn't. If everyone had had their credit card details disclosed or something I'd say sure, demand explanations, but as it stands they have done full-site password resets, they have advised people to use services such as LastPass, to ensure people don't use passwords for more than 1 site etc... What else do you want?

 

As others have said, saying 'they stole X,Y and Z' is going to be basically impossible, so you should simply assume that they got the lot and change your passwords everywhere that uses the same one just in case. The worst you'll get out of this would be more spam I'd guess.

Posted

Surely a paragraph of some kind of explanation isnt allot to ask for? Shaun isnt the only one working on the site, there are other admins as well.

 

I know my date of birth could have been taken, that is a security question banks use. Its only part of a puzzle but can result into something more serious. Personally i dont care about the password as it was unique.

 

Was a copy of the database taken?

Do we know what was actually seen by the hackers? At the moment its speculation.

Do we know what the hackers actually did?

Posted

Working in a bank myself with a team of security guys I have an idea what can happen. The data collected could be sold on. The person who receives it will take what he needs. He might already have a portfolio of someone's data and the date of birth could be the last piece of te puzzle.

 

It's happened many times before....

Posted
Working in a bank myself with a team of security guys I have an idea what can happen. The data collected could be sold on. The person who receives it will take what he needs. He might already have a portfolio of someone's data and the date of birth could be the last piece of te puzzle.

 

It's happened many times before....

 

In which case, you're basically screwed. Local governments lose data all the time. Your schools did. Your banks do. The NHS does. Australia has far weaker data protection laws than the UK and as such it is illegal to send personal data from the EU to Australia, but you don't seem concerned about it, having moved there.

 

So, my suggestion is the same as everyone else - assume that your data has been copied, and act accordingly.

Posted
I for one am just happy Edugeek is back, to some semblance of normality, I think people forget sometimes that it is a relatively small outfit that runs the site and they have a million and one things to do as well as keep us happy, I do agree an update to what went on would be nice but I also understand that @ZeroHour has spent many hours working to get services restored (and by now should have a very nice ass groove worked into his chair!).

 

Patience is a virtue, I am sure the details will appear in time :)

 

That's a nice post . . . . but a troubling image.

Posted (edited)
Working in a bank myself with a team of security guys I have an idea what can happen. The data collected could be sold on. The person who receives it will take what he needs. He might already have a portfolio of someone's data and the date of birth could be the last piece of te puzzle.

 

It's happened many times before....

 

While I wait for my main account to get sorted (forgot about this one)

 

Are those in the bank winding the noobie up?

LMAO if the DOB was truly the magic bullet everyone on facebook would be done for. The amount of people who advertise there DOB to the public on that is insane and thats before we get to those that put their address.... and you have never told posted your age (as your month/day is public on edugeek according to your settings) which would allow the complete DOB.

Also if you bank with a bank that will let you into someones account with their DOB I would change banks ;)

The next office birthday will be interesting at least....

Edited by daustin
Posted
And before anyone says "ahar, I never put my YEAR of birth on fb/linkedin/whatever!" remember you have a nice sharp peak among your friends of people born in the same year as you... :D
  • Thanks 1
Posted

Zak has some point about data mining of personal details is rarely about a single breach (unless they are lucky and get a full DB of personal and card details) but a breach of any site could release information which can then be used to target other areas. However, it is often combined (when details are sold on) with attempted access to email account ... and the advice about changing passwords is good advice. The concern about DoB is only a very small one ... and if they have access to your email account as well, and that has your personal details in too then whether they gain your DoB from here or anywhere else is of no matter. I would not place my DoB as a security detail where possible anyway ... and have turned it off as a verification item where I can. My DoB is pretty public anyway ... people wishing me happy birthday and me mentioning my age ... it doesn't take a rocket scientist to work out.

 

Because of the uncertainty of what may have been targeted and for what reason, and the details about attack vector needing to be covered, etc there is little more that can be added other than that which was in the original article or from DB's subsequent posts. The ICO advise that sites should not be put straight back up to get to 'business as usual' but should take appropriate security action to deal with the issue. As a member, I am happy and confident that this has been done. I would not expect for DB and ZH to give me a complete public run-down of what they have done on the security side of things to improve things even further, in the same way I wouldn't expect any of the other members to give me a complete breakdown of your security arrangements on a public site. Although it may be considered security by obscurity, it is also a bit of common sense.

  • Thanks 1
Posted
We did in a way. Valve's Steam Users' forums and Sony's MyResistance.net forums were hacked around the same time as EduGeek. Both use vBulletin and the latter is still offline! :eek:

 

Sony's MyResistance.net forums ran on either MyBB or SMF not vBulletin (Can't remember which).

Posted
but you don't seem concerned about it, having moved there.

 

And you know me that well do you?

 

So, my suggestion is the same as everyone else - assume that your data has been copied, and act accordingly.

 

I wasnt asking for your advice.

Posted
People suddenly seem to be behaving like this site is some giant commercial operation when it isn't.

 

But the thing is we are always being told that edugeek is a global support site with huge member numbers from around the world and how it is recognized by important companies within the IT world. They even come to Philly to promote the site. Now when something like this happens we are told that it is a relatively small outfit and to stop fretting. So which is it?

Posted

I believe what Localzuk means is like an outfit like Amazon or MS Technet or something to that effect.

 

I can see where you are coming from @RoF however from Edugeeks' POV they are big fish in a small pond (infact the biggest fish in a small pond as Experts Exchange take most answers from here and charge for the privilege).

 

In terms of global multifunction tech support sites - Edugeek is the biggest

In terms of global tech support sites - Edugeek is small fry (Technet - largest, Apples equivalent - next, Redhat (which now covers all linux distro's) - 3rd, and so on and so forth).

 

Edugeek markets itself globally to get more hits, more users and more views (and in terms of ad revenue it is a huge boost...the site experiences a massive surge in users and such like during and after BETT for example). So it makes fiscal sense for them to market themselves globally (however I call dibs on the trips to AUS and NZ :D lol).

 

Personally I do not care if someone got my DOB as they could have gotten that from facebook/linkedin if they have me as a contact and the password for here, it is unique to this site only (usually my passwords are around 26 digits letters, numbers, symbols, upper case and lower case which is enjoyable remembering them! lol).

 

As for the statement, I wait with interest.

Posted
As for the statement, I wait with interest.

 

I don't. Any statement will be kinda superfluous to me, IMO. The fact that the site had an intrusion, and that passwords should be reset is enough. I don't see what a statement would do really.

Posted
I don't. Any statement will be kinda superfluous to me, IMO. The fact that the site had an intrusion, and that passwords should be reset is enough. I don't see what a statement would do really.

 

Personally, I'm interested to see a statement. But that's more from a professional point of view than a personal one.

Posted
I don't. Any statement will be kinda superfluous to me, IMO. The fact that the site had an intrusion, and that passwords should be reset is enough. I don't see what a statement would do really.

 

If @nephilim is anything like me it is more of a technical curiosity thing than a 'Oh Crap wheres my data gone!' type of thing. We are all technical people here, I like many others use a different password here than anywhere else and other information about me is available on the likes of Facebook and Twitter.

Guest
This topic is now closed to further replies.



×
×
  • Create New...