IMPORTANT: Community security breach

Started by LiroyvH, July 23, 2013, 12:45:08 PM

Previous topic - Next topic

bristol

Quote from: CoreISP on July 24, 2013, 07:21:40 AM

Yes, associated email addresses were obtained as well. It's in the user table.

Bummer. Can you please delete my account. I don't use your SMF software.


Johanvd

Did the attacker have more access on the simplemachines site or was it limited to just the forum database?
Could he make changes to any packages at download.simplemachines.org?
Are the mods, themes and other downloads still safe?

NanoSector

Quote from: Johanvd on July 24, 2013, 09:31:02 AM
Did the attacker have more access on the simplemachines site or was it limited to just the forum database?
Could he make changes to any packages at download.simplemachines.org?
Are the mods, themes and other downloads still safe?

Only the database should be gathered, downloads shouldn't be damaged. If you are worried, do scan the files with your antivirus, if you have one.
My Mods / Mod Builder - A tool to easily create mods / Blog
"I've heard from a reliable source that the Answer is 42. But, still no word on what the question is."

LiroyvH

Downloads are isolated and just fine :)
((U + C + I)x(10 − S)) / 20xAx1 / (1 − sin(F / 10))
President/CEO of Simple Machines - Server Manager
Please do not PM for support - anything else is usually OK.

Ckemoi


Deaks

johanvd those are stored elsewhere, the logs show that downloads and customise were not effected.
~~~~
Former SMF Project Manager
Former SMF Customizer

"For as lang as hunner o us is in life, in nae wey
will we thole the Soothron tae owergang us. In truth it isna for glory, or wealth, or
honours that we fecht, but for freedom alane, that nae honest cheil gies up but wi life
itsel."

elliatt

Admins -

Thank you for the notification and for what you are doing behind the scenes. Someone made a mistake, it happens.  Heaven knows I have made more than my share  ;)

Take a break, have a cold one and grab a few moments to relax.

ApplianceJunk

Quote from: CoreISP on July 23, 2013, 01:35:49 PM
Quote from: The Burglar! on July 23, 2013, 01:35:04 PM
Thanks for the information, changed mine also thanks Antes for the message he just sended me ;)

That raises my curiosity, did you not get our email?
We did send out a notification, so please let me know if you received it. It's very important people receive it.

Thank you :)

I never received a email about this. Just happen to see the post on my own this morning.

ApplianceJunk

Quote from: IchBin™ on July 23, 2013, 11:09:56 PM
Ouch, this sucks. Glad you guys caught the issue quickly. Changing passwords even if I do use different ones. :)

I did the same, great minds think a like. ;)

Johanvd

Quote from: CoreISP on July 24, 2013, 10:23:20 AM
Downloads are isolated and just fine :)
Quote from: Runic on July 24, 2013, 10:30:03 AM
johanvd those are stored elsewhere, the logs show that downloads and customise were not effected.

Thanks!

Also thanks for your hard work to solve this.

cyberjack


nend

My password here is different than my others.

Makes you wonder how beneficial the db dump in the admin panel is. If you think about it, if it wasn't there then none of this would of happened... Makes me think about disabling mine since I back up my db differently.

But then again they could just upload a mod and get a dump, convenience looks to be a security issue. :-/

Kindred

nend... sorry, but you're wrong.
The hacker did not access the database from the admin panel backup option.
(that option would likely choke on the size of our database anyway)
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

nend

Quote from: Kindred on July 24, 2013, 12:05:16 PM
nend... sorry, but you're wrong.
The hacker did not access the database from the admin panel backup option.
(that option would likely choke on the size of our database anyway)

I guess I can be since I assumed how it happened.

FrizzleFried

FWIW - I... the "Drama Queen"... see no benefit what so ever of outting the admin who made this mistake.  We are all human and dumping on the guy (or gal) serves no good purpose.

The Craw

Quote from: exxocet on July 24, 2013, 03:46:37 AM
Sorry Micky, your GT5 cheats, Modern war, signature is telling your 15 years old kid story. Unfortunately this is a serious discussion, talking about serious facts. Allow yourself to grow up. See ya in 2015! Eat your corn flakes!

Just a quick side note to defend a friend of mine, you can own gaming forums without being a kid. Mike is married and has a son in the US Air Force, so that makes him older than 15.

TimL

How to I delete my account.  I prefer that option over having this happen again which I find inexcusable. 

IchBin™

Go into your profile and select the option from the profile menu to delete your account.
IchBin™        TinyPortal

Chalky

Though this forum is probably the most secure place to be now  ;)

Advertisement: