
03-23-2009, 01:55 PM
|
|
View Beta Profile
iNET Community Coordinator
|
|
Join Date: Jun 2001
Location: WebHostingTalk
Posts: 28,700
|
|
|
Recent WHT down time
I reported yesterday that our recent downtime was due to issues with our backup servers followed by the corruption of some db tables from a hack attempt.
We've since learned that this very deliberate, sophisticated and calculated hack against Web Hosting Talk was carried out by gaining access to our offsite backup servers. From our backup servers, the hacker gained access to the WHT db server. The malicious attacker deleted all backups from the backup servers within the infrastructure before deleting tables from our db server. We were alerted of the db exploitation and quickly shut down the site to prevent further damage.
This individual is still in possession of our user table that includes all user names, email addresses and hashed passwords. Absolutely no credit card or PayPal data was compromised.
Passwords are hashed with salt. It would be an unprecedented event to reverse engineer our passwords. I change my password periodically though, so maybe today is a good day for that. Go here to change your password.
My concern is the distribution of your email addresses and the potential spam you may receive. We know the hacker has posted the user table containing email addresses to various places (file sharing sites) and we're working diligently to remove the tables as we find them. If you see the user table posted anywhere, please let us know so we can get it taken off line.
We are working on recovering the deleted data. In the meantime, we've restored to an old db. We cannot yet determine if we can restore to a more recent db backup.
If you have any clues as to the individual who caused this malicious attack on the Web Hosting Talk community, please let me know.
__________________
Together, we can make a difference. Hosting For Haiti - 100% of donations go to the American Red Cross Haiti Relief and Development Fund.
|

03-23-2009, 01:59 PM
|
|
|
At least it's back, I guess. I've only lost 800 posts and countless topics of interest to me... 
|

03-23-2009, 02:01 PM
|
|
View Beta Profile
Premium Member
|
|
Join Date: Feb 2006
Location: Rochester NY
Posts: 659
|
|
Good luck  !
|

03-23-2009, 02:01 PM
|
|
View Beta Profile
Just Married :)
|
|
Join Date: Dec 2007
Location: Indianapolis, Indiana USA
Posts: 6,994
|
|
I saw the uploads that you are referring to, I wanted to see how much of my information was there and it's 5400+ pages of account information but only usernames/e-mails/hashed passwords + salt.
Luckily I use a secondary address for forum notifications so I can set it to :blackhole: and just create a new forwarder.
My personal advise is that *EVERYBODY* change their passwords.
__________________
█ Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all services! Proudly hosting over 3,200 domains!
█ http://www.mddhosting.com/ - Read our reviews at RatePoint! - Call us at 866-758-HOST (4678)!
|

03-23-2009, 02:05 PM
|
|
View Beta Profile
Premium Member
|
|
Join Date: Apr 2007
Location: United Kingdom
Posts: 1,130
|
|
Quote:
Originally Posted by MikeDVB
My personal advise is that *EVERYBODY* change their passwords.
|
My personal advice is that WHT should secure their stuff properly and not just backup to one location.
It's ridiculous!
__________________
▪ EZPZ Hosting - Dependable and Affordable UK and US Web Hosting
▪ LiteSpeed Powered cPanel Shared with R1Soft and Installatron | Managed VPS and Dedicated | Shoutcast
▪ Reseller Hosting Specialists | WHMCS-Based End User Support | Geotrust SSL | Hosting Templates
▪ 24/7 Support | 99.9% Uptime Guarantee | 30 Day Money Back Guarantee
|

03-23-2009, 02:06 PM
|
|
View Beta Profile
Just Married :)
|
|
Join Date: Dec 2007
Location: Indianapolis, Indiana USA
Posts: 6,994
|
|
Quote:
Originally Posted by Dan_EZPZ
My personal advice is that WHT should secure their stuff properly and not just backup to one location.
It's ridiculous!
|
What has been done, is done - and hopefully it will be a learning experience.
__________________
█ Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
█ LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
█ Incremental R1Soft CDP Backups on all services! Proudly hosting over 3,200 domains!
█ http://www.mddhosting.com/ - Read our reviews at RatePoint! - Call us at 866-758-HOST (4678)!
|

03-23-2009, 02:07 PM
|
|
View Beta Profile
EvenDivide
|
|
Join Date: Aug 2001
Location: Toronto, Ontario
Posts: 3,603
|
|
|

03-23-2009, 02:07 PM
|
|
|
Quote:
Originally Posted by MikeDVB
What has been done, is done - and hopefully it will be a learning experience.
|
oh come on, you're not serious, right? You're comfortable knowing that there's hundreds/thousands of people sitting in front of their computers with a copy of your password, and every other members? I know I'm not.
|

03-23-2009, 02:08 PM
|
|
View Beta Profile
Premium Member
|
|
Join Date: May 2003
Location: California, USA, Earth
Posts: 586
|
|
Wow, this is disappointing. I hope the lost data can be recovered some how and that you have some luck limiting the distribution of all our email addresses. Major blow to WHT.
Good luck.
__________________
▌ Blesta - Professional Billing Software
▌ We are about creating good experiences
▌ Trial - Demo | 866.478.7567 | Twitter @blesta
|

03-23-2009, 02:08 PM
|
|
View Beta Profile
Web Hosting Master
|
|
Join Date: Jan 2005
Location: Dublin and Belfast
Posts: 1,061
|
|
Quote:
Originally Posted by Dan_EZPZ
My personal advice is that WHT should secure their stuff properly and not just backup to one location.
It's ridiculous!
|
and how many different backup locations do you use?
__________________
█ Mark Railton
█ OutHOST Solutions - Providing Quality Internet Solutions for all
█ NEW SITE LIVE
|

03-23-2009, 02:08 PM
|
|
|
Saying "this is unforgivable" may sound too hard. But it really is. WebHostingTalk, a place where we often read "make backup of backup" got hacked and lost their only backup. Great.
|

03-23-2009, 02:08 PM
|
|
|
Quote:
Originally Posted by Dan_EZPZ
My personal advice is that WHT should secure their stuff properly and not just backup to one location.
It's ridiculous!
|
I hate be like this but I agree.
WHT has has issues like this before if I member correctly.
So now I could be spammed great.
Password changed.
I'm curious as to how they got into the backup server? software, password, or other exploit?
Quote:
Originally Posted by MikeDVB
What has been done, is done - and hopefully it will be a learning experience.
|
Mike is right but I'm still furious that this happened.
I understand people can get hacked, problems happen. But i would figure there would be at least two back up servers for the forum. Seeing as the forum has been DDoSS or attacked before if I remember correctly.
I know this is no ones fault. But steps need to be taken so this doesn't happen again.
I hate to sound like a whinner but this could happen again.
This is serious breach of security.
Last edited by ShaunH; 03-23-2009 at 02:15 PM.
|

03-23-2009, 02:10 PM
|
|
View Beta Profile
Premium Member
|
|
Join Date: May 2007
Location: United Kingdom
Posts: 251
|
|
I've received about 5 spam e-mails today, I hope it isn't due to this.
|

03-23-2009, 02:11 PM
|
|
|
THE BEST THING YOU CAN DO DENNIS IS CHECK THE IP LOGS AND FIND OUT WHO DID THIS AND GO FROM THERE!!
Go back thru EVERY IP UNTIL YOU GET TO THE SCUMBAG WHO DID THIS!! (Its not impossible my friend)
Good luck!
__________________
Tinyurl is the answer for posting long urls!!!
|

03-23-2009, 02:11 PM
|
|
|
Quote:
Originally Posted by citricsquid
oh come on, you're not serious, right? You're comfortable knowing that there's hundreds/thousands of people sitting in front of their computers with a copy of your password, and every other members? I know I'm not.
|
Welcome to the Internet.
There's really no reason to make a huge issue out of this. Simply change your password(s) and move on.
|
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Linear Mode
|
| Postbit Selector |
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
|