Today's downtime

Log in to stop seeing adverts

Status
Not open for further replies.

Jeff

Administrator
Staff member
The site is back up now after around an hour being unavailable.

This is due to an attack by hackers, who exploited a recently discovered vulnerability in the forum software.

There are a few things I still need to do to ensure it can't happen again, and I may need to take the site down as a result, but for the time being, everything is running as it should.
 
I wondered what had happened.
Bloody hackers I can never understand the mentality of these people.
Still it is Pirate day and I suppose in todays terms it was like Pirates attacking the ship. But good old Cap'n Jeff has repelled the boaders and sent them off to whence they came. Arrrrgggghhhh
 
I wondered what had happened.
Bloody hackers I can never understand the mentality of these people.
Still it is Pirate day and I suppose in todays terms it was like Pirates attacking the ship. But good old Cap'n Jeff has repelled the boaders and sent them off to whence they came. Arrrrgggghhhh

:icon_lol: FFS MoFo
 
But good old Cap'n Jeff has repelled the boaders and sent them off to whence they came. Arrrrgggghhhh

I'm still working on repairing the damage. They accessed a security problem in the forum software to create an admin user, and used this to upload a script that gave them access to files on the system, as well as full access to the site admin system.

I've done what I can to close off their original point of access, but they may have left other stuff behind that allows them to get in again, so I have a lot of checking of files etc before I can be confident everything is OK. I may resort to reinstalling the forum from scratch, but that will create a lot of work, and will involve some downtime.
 
Will any of this have caused passwords to be compromised or any other information?

No. Passwords are encrypted in the database and it's impossible to convert the encrypted version into the password. That's why people who forget their password have to request a new one, it's not possible to retrieve the old one.

The admin logs show that the attacker didn't access any user information.

They appear to have been just trying to deface the site to show a "hacked by" message, but at the same time they made the site inaccessible so they didn't do what they wanted.
 
No. Passwords are encrypted in the database and it's impossible to convert the encrypted version into the password. That's why people who forget their password have to request a new one, it's not possible to retrieve the old one.

The admin logs show that the attacker didn't access any user information.

They appear to have been just trying to deface the site to show a "hacked by" message, but at the same time they made the site inaccessible so they didn't do what they wanted.

I heard they tried to find the secret of Joe's betting plan success.
 
Status
Not open for further replies.
Log in to stop seeing adverts

Championship

P Pld Pts
1Ipswich4389
2Leicester4288
3Leeds Utd4387
4Southampton4284
5West Brom4372
6Norwich City4371
7Hull City4265
8Coventry City4263
9Middlesbro4363
10Preston 4363
11Cardiff City4359
12Bristol City4358
13Sunderland4356
14Swansea City4353
15Watford4352
16Millwall4350
17Blackburn 4349
18Plymouth 4348
19QPR4347
20Stoke City4347
21Birmingham4345
22Huddersfield4344
23Sheffield W4344
24Rotherham Utd4323

Latest posts

Top