Hacked today

azhousepro

Administrator
Staff member
Admin
Moderator
Woke up to the phone ringing from the east coast at 5:30 this morning. Then saw text messages about us being hacked.

I think I have cleaned up everything that was hacked, but please let me know if anyone experiences anything strange today. I can be emailed at housepro@azbilliards.com

If you get a pop up asking for permission to run a java plugin, please do not allow it and email me to let me know about it.

Sorry about the problems today.
 
screw the hackers - did you get back to sleep?

gotta keep those priorities straight Mike lol
 
Mike, thanks for fixing. Is this why I had to re-login today? Any chance the hackers stole our logon information?
 
Just about no chance of that. Even if they had gotten access to the database (which I see reason to believe that they did), the passwords are encrypted in the database. (Unlike those on linkedin)

Mike
 
Mike, thanks for fixing. Is this why I had to re-login today? Any chance the hackers stole our logon information?

Just about no chance of that. Even if they had gotten access to the database (which I see reason to believe that they did), the passwords are encrypted in the database. (Unlike those on linkedin)

Mike

iusedtoberich:

Additionally, the reason why people have to "re-login" is because the previous cookie stored in your computer's browser was invalidated by Mike's necessary rebuild/repair of the site. All previous cookies prior to the rebuild/repair are invalidated, and you'll just have to login again, checking the box to "save" the login information, to get a new cookie installed in your browser.

Good question, though!

-Sean
 
yep, it was hacked

I had problems with it - all of the sections from the az home page worked fine except FORUMS.

When that was clicked I rec'd an error message stating "susbcribers digital signature is invalid" and that screen had an option to run something that would fix something to do with width.

I did not opt to run anything but when I "x" 'd out from there it automatically opened "grifters.org" whose home page states "gamers underworld".

All seems okay now.

best,
brian kc
 
iusedtoberich:

Additionally, the reason why people have to "re-login" is because the previous cookie stored in your computer's browser was invalidated by Mike's necessary rebuild/repair of the site. All previous cookies prior to the rebuild/repair are invalidated, and you'll just have to login again, checking the box to "save" the login information, to get a new cookie installed in your browser.

Good question, though!

-Sean

Thank you for the explanation.
 
Pure speculation: could this have been the cause of the slowdowns over the last couple of months? Maybe the hack was there for a long time, slowing things down, and only this morning did it fully manifest itself and was seen?
 
I doubt it. There is still the belief that the slowdown is on the ad server. I don't think the two are related though.

Mike
 
Pure speculation: could this have been the cause of the slowdowns over the last couple of months? Maybe the hack was there for a long time, slowing things down, and only this morning did it fully manifest itself and was seen?

iusedtoberich:

Possible? Yes. Likely? I'm not sure -- I don't have visibility into Mike's security policy for AZBilliards.

But I can tell you this -- many hacks are performed this way. It's called "low and slow" attacks. Meaning, the attacker is trying his/her (yes, there are female hackers!) damdest to make sure noone sees or "feels" the effects of penetrating the security of the website. Only after the attacker is sure all the ducks are in a row, and it's time to unleash the hounds, do the effects of the attack become clear.

Most often, "low and slow" attacks are used to go after government entities, or huge corporations with IP (intellectual property) that the attacker is after. One of the largest information security firms, RSA Security, was successfully penetrated in this way:

http://bits.blogs.nytimes.com/2011/04/02/the-rsa-hack-how-they-did-it/

In fact, RSA Security had to reissue -- for free -- all new tokens to their customer base because large portions of their source code was stolen.

"Low and slows" are the bane of any security officer's existence.

Getting back to AZB, do I think a "low and slow" was in process during the forum slowdowns these past couple of weeks / months? No. I personally think it was (and might still be, if Mike didn't fix it) issues with the adserver.

I can make the problem completely go away on my side by short-circuiting my browser from pulling ads from the adserver, as I explained in this post:

http://forums.azbilliards.com/showthread.php?p=3652405#post3652405

When I do this, the forums are lightning fast. However, this is obviously not a sanctioned "fix" -- the proper thing to do is to let Mike fix the adserver issues. AZB's existence is paid in large part by its sponsors, afterall.

Hope that helps,
-Sean
 
I just googled vbulletin hacks and there are TONS of sites designed to help people hack this forum software.

Although the PWs are encrypted here, I wonder if the encryption key is different from "vbulletin instance to vbulletin instance" or if the encryption key is default-standard among all instances.

There really isn't anything here to steal, per se, if they DID get the PWs; however, if you're one of those people who use the exact same username/pw for all of your sites (banking, etc), it's good policy to change them now. NOT saying you're in danger---- but I'm just giving you a public service announcement to keep all critical web logins (bank bill-pay, retirement account login, etc..) DIFFERENT.

Otherwise, one site can be hacked (say a billiard site) and then they go to Wells Fargo and try the same combo---- if it works--- they got your cash.
 
vbulletin encrypts and also salts passwords. I believe the salt is different for different installs of the forums.

Sean, are you still thinking the issue is the ad server? That troubles me as what I found dragging down the ad server has been disabled and I am not seeing a slow down at the adserver.

Mike
 
vbulletin encrypts and also salts passwords. I believe the salt is different for different installs of the forums.

Sean, are you still thinking the issue is the ad server? That troubles me as what I found dragging down the ad server has been disabled and I am not seeing a slow down at the adserver.

Mike

Mike:

I'm sending you a PM about this.

-Sean
 
AZB Skin

Before this morning, I used the skin of AZB that had the blue/white format. Since the hack and subsequent restoration of service, I have the gray skin, and I can't find the link that was available to switch back and forth between skins.

Is that capability available anymore?

Thanks,
Joe
 
Nice work Mike

Way to get right on it dude...
I don't wanna find out how long I can live without AZ. :smile:
 
I got the Java thing this AM and somehow was not quite stupid enough to click on it.

I heard someone was upset that the 'Code of Conduct' thread is still a sticky:)
 
Back
Top