Attempted hack?

Get help with technical problems and keep up to date with any changes to the forum.
Post Reply
Travis
Preternatural Poster
Preternatural Poster
Posts: 1909
Joined: Tue Mar 14, 2006 3:00 am
antispam: no

Mon Feb 14, 2011 7:00 pm

You exceeded the maximum allowed number of login attempts. In addition to your username and password you now also have to solve the CAPTCHA below.

This is what I was greeted with when logging in today. I can only surmise that someone has repeatedly tried to access my account. How else would this built-in security function have been "tripped"?

I assume, Big Orange, that you have no way of discovering the villain's identity?

Unmasked or not however, I'd like to extend a very derisive FUCK YOU to the perpetrator.

Sincerely,

Me
There's only one rule in street and bar fights: maximum violence, instantly. (Martin Amis, "Money")
David
Moderator
Moderator
Posts: 13973
Joined: Sat Feb 18, 2006 4:40 pm
Location: Ellan Vannin

Mon Feb 14, 2011 7:49 pm

That's odd. I got the very same thing tonight. Strange, strange, passing strange.
Ros
Moderator
Moderator
Posts: 7963
Joined: Sun Dec 07, 2008 4:53 pm
antispam: no
Location: this hill-shadowed city/of razors and knives.
Contact:

Mon Feb 14, 2011 7:55 pm

I had this last night.
Rosencrantz: What are you playing at? Guildenstern: Words. Words. They're all we have to go on.
___________________________
Antiphon - www.antiphon.org.uk
Travis
Preternatural Poster
Preternatural Poster
Posts: 1909
Joined: Tue Mar 14, 2006 3:00 am
antispam: no

Mon Feb 14, 2011 8:04 pm

Has anyone else experienced this? I'd like to know if people outside of the admin/mod/former mod circle has been affected.

That suspicion aside, because it wasn't isolated (you two had it happen as well), the likelihood that it's related to some sort of update is more likely. But we'll see I guess.
There's only one rule in street and bar fights: maximum violence, instantly. (Martin Amis, "Money")
Travis
Preternatural Poster
Preternatural Poster
Posts: 1909
Joined: Tue Mar 14, 2006 3:00 am
antispam: no

Mon Feb 14, 2011 8:11 pm

Oh, and just to be safe, I'd advise changing your current passwords, even if you think they're sturdy enough. Strictly speaking, if attempts were made to hack your accounts, the person or persons responsible now have more information than they did prior to making the attempts; i.e., they know what your passwords AREN'T. It's a small mathematical edge you can give yourselves. Reset them back to zero. Assuming of course, that "they" exist. But better safe than sorry.
There's only one rule in street and bar fights: maximum violence, instantly. (Martin Amis, "Money")
David
Moderator
Moderator
Posts: 13973
Joined: Sat Feb 18, 2006 4:40 pm
Location: Ellan Vannin

Mon Feb 14, 2011 8:16 pm

I could change my password, but ... I can't see what advantage anyone would gain by hacking into my PG account. Perhaps that's just my ignorance showing. They could pretend to be me, but how long could they plausibly keep that up for? Even I find it hard work.

Of course I suppose they could change my password, which would be an enormous pain.
Travis
Preternatural Poster
Preternatural Poster
Posts: 1909
Joined: Tue Mar 14, 2006 3:00 am
antispam: no

Mon Feb 14, 2011 8:21 pm

They could change your password, locking you out. You would lose your privacy (hacker would have immediate access to private correspondences). Your post history would be in jeopardy (hacker could delete/edit posts). And because you're a mod, everyone else would be at risk of altered/deleted posts as well.
There's only one rule in street and bar fights: maximum violence, instantly. (Martin Amis, "Money")
David
Moderator
Moderator
Posts: 13973
Joined: Sat Feb 18, 2006 4:40 pm
Location: Ellan Vannin

Mon Feb 14, 2011 8:23 pm

Erk. Here's hoping I remember the damn new one.
User avatar
Nicola
Site Admin
Site Admin
Posts: 1081
Joined: Sun May 09, 2004 5:35 pm

Mon Feb 14, 2011 8:40 pm

That's weird. It did the same for Cam but not me. Strange. I will investigate.
User avatar
Nicola
Site Admin
Site Admin
Posts: 1081
Joined: Sun May 09, 2004 5:35 pm

Mon Feb 14, 2011 8:46 pm

I have investigated -

phpbb support forum says:

"This is not a new occurrence, it may just now happening to you.
It is happening world wide and not just to phpBB, and it's not version specific.
Hackers/spammers are trying to 'brute force' passwords"

They recommend people use strong passwords so perhaps it's time to change them!
Lake
Perspicacious Poster
Perspicacious Poster
Posts: 2294
Joined: Fri Jun 08, 2007 4:55 pm
Location: Sky Blue Waters

Tue Feb 15, 2011 2:30 pm

It happened to me, too.
Aim, then, to be aimless.
Seek neither publication, nor acclaim:
Submit without submitting.

一 Cameron
ray miller
Perspicacious Poster
Perspicacious Poster
Posts: 7435
Joined: Wed Apr 23, 2008 10:23 am

Thu Feb 17, 2011 2:30 pm

This happened to me just now.It asked me for my favourite animal then told me that the answer was chicken. I suspect fowl play.
I'm out of faith and in my cups
I contemplate such bitter stuff.
BenJohnson
Preternatural Poster
Preternatural Poster
Posts: 1701
Joined: Wed Nov 12, 2008 10:32 am
antispam: no
Location: New Forest, UK
Contact:

Fri Feb 18, 2011 10:11 am

Same here, damn spammers. Mind you I think they got in it explains that last poem from Ray :)
User avatar
twoleftfeet
Perspicacious Poster
Perspicacious Poster
Posts: 6761
Joined: Wed Dec 07, 2005 4:02 pm
Location: Standing by a short pier, looking for a long run-up

Fri Feb 18, 2011 5:48 pm

David wrote:I could change my password, but ... I can't see what advantage anyone would gain by hacking into my PG account. Perhaps that's just my ignorance showing. They could pretend to be me, but how long could they plausibly keep that up for? Even I find it hard work.

Of course I suppose they could change my password, which would be an enormous pain.
David,
Have a read of this:
http://lifehacker.com/#!5505400/how-id- ... -passwords

Many people use the same password for more than one site, and don't have a strong password for their Email a/c either.
If they get into your Email you could be in deep merde if there are personal and financial details to be had.
Instead of just sitting on the fence - why not stand in the middle of the road?
Travis
Preternatural Poster
Preternatural Poster
Posts: 1909
Joined: Tue Mar 14, 2006 3:00 am
antispam: no

Fri Feb 18, 2011 8:04 pm

Yeah, it's happened to me again today. Annoying.
There's only one rule in street and bar fights: maximum violence, instantly. (Martin Amis, "Money")
User avatar
Nicola
Site Admin
Site Admin
Posts: 1081
Joined: Sun May 09, 2004 5:35 pm

Fri Feb 18, 2011 9:05 pm

Just for reassurance - I have read this and made sure all the preventative measures have been taken.

http://www.phpbb.com/community/viewtopic.php?t=1947925

I'm not sure what else to do. I may go through the new members and delete those who haven't posted anything.

I think it would be a good idea for people to change their passwords even though I know it is a pain.
BenJohnson
Preternatural Poster
Preternatural Poster
Posts: 1701
Joined: Wed Nov 12, 2008 10:32 am
antispam: no
Location: New Forest, UK
Contact:

Fri Feb 18, 2011 11:45 pm

Have you banned the IP address range that attacks are coming from?
User avatar
Nicola
Site Admin
Site Admin
Posts: 1081
Joined: Sun May 09, 2004 5:35 pm

Sat Feb 19, 2011 9:00 am

BenJohnson wrote:Have you banned the IP address range that attacks are coming from?
I have looked at it but it's prving pretty difficult to establish where it's coming from.

See

http://www.phpbb.com/community/viewtopi ... &t=2116469

I think the key is your passwords - make sure they are complex. I do change the CAPTCHA regularly but if it gets too difficult real people can't read it which is frustrating.

The whole thing is very annoying but no forum security seems to have been breached so far.
David
Moderator
Moderator
Posts: 13973
Joined: Sat Feb 18, 2006 4:40 pm
Location: Ellan Vannin

Sat Feb 19, 2011 9:44 am

Yes, I just got it again too. My PG password is (a) pretty obscure and (b) not used for anything else, so I (hopefully) shouldn't be too much at risk.
Nash

Sat Feb 19, 2011 9:55 am

This has happened to me too.

Did the bit where you change your password always say:

Password must be between 6 and 30 characters long, must contain letters in mixed case and must contain numbers.

because my old one didn't. I've just changed it to include this and it all seems to be fine now.
User avatar
twoleftfeet
Perspicacious Poster
Perspicacious Poster
Posts: 6761
Joined: Wed Dec 07, 2005 4:02 pm
Location: Standing by a short pier, looking for a long run-up

Sat Feb 19, 2011 12:11 pm

David wrote:Yes, I just got it again too. My PG password is (a) pretty obscure and (b) not used for anything else, so I (hopefully) shouldn't be too much at risk.
Sounds good to me, especially the "not used for anything else" part.

I really don't think there's anything to worry about when the hacker only gets 3 attempts before being blocked!

Mind you, having read that article about passwords I won't be using a 6 character password anytime soon - more like 16!

EDIT: The articles gone! Maybe the site was hacked? :)
Instead of just sitting on the fence - why not stand in the middle of the road?
JohnLott
Preponderant Poster
Preponderant Poster
Posts: 1326
Joined: Tue Feb 22, 2011 9:35 pm
Location: Devon

Wed Mar 30, 2011 9:55 am

Same login problem for me: 30/03/11 10:54

J.
Before you shave with Occam’s razor - Try epilation or microlaser
Post Reply