![]() |
Originally Posted by colonius
(Post 12868263)
3.) A system that has been compromised as far as having backdoors installed, should never be considered safe until reinstalled or restored from a known good backup. Evidence that "they never accessed the database" may be false, since the backdoor application could as well have scrubbed the log files to hide its tracks - very common, btw.
And yes, I do system security for a living. While we haven't restored the files from backup, hourly snapshots were diff'ed and we have ensured that the system is secure. This was a script kiddie script that exploited a vulnerability right after it was announced and before we had an attempt to patch. |
Originally Posted by IB-Dick
(Post 12870176)
We understand the flaws in md5 hashes, however everyone I've personally discussed this with has verified that the vBulletin hashing method is sufficiently secure.
While we haven't restored the files from backup, hourly snapshots were diff'ed and we have ensured that the system is secure. This was a script kiddie script that exploited a vulnerability right after it was announced and before we had an attempt to patch. I assume that you did additional checks to verify the confidentiality of the password data? |
MD5 is so secure :rolleyes:
http://milw0rm.com/cracker/insert.php http://www.hashchecker.com/ sure salt adds a minor bit of complexity, but a little computer 'pepper' and it fades away. these sites are HARDLY an effective way, just an example. This is especially true if someone had a level of server access at any point. |
Originally Posted by colonius
(Post 12870550)
If it uses MD5, it must be considered broken. This has nothing to do with vB, it is the algorithm that is at fault.
Good to learn that you verified the system's integrity to be uncompromised (which the check against the backups did). ^ I assume that you did additional checks to verify the confidentiality of the password data? |
Originally Posted by mshaikun
(Post 12867652)
Let me join with others in saying thanks to our hard working IT gurus.
Bigger sites have been hacked including sensitive government sites. The test of IT is how fast they can get things back together. Where we addicts look for instant gratification, you did well guys. My messages sent to FT HELP have gone unanswered :(. I wont even start about how the FT Chat room has been broken for me and others for nearly 2 weeks since the first attack :td:. I have a trade thread in CC which I cant access/search to bump. It sure is a BUZZ KILL :( Luckily Twitter has been keeping me mildly amused, but how much longer until FT IT gets these issues under control????? I am in the camp of feeling relieved that I DIDNT subscribe and PAY money for this. Sorry but for me, its just gone on way TOO long. |
We have been working around the clock to combat this ongoing cyber attack. While service has not yet been restored to normal, progress is being made. The site is most dramatically effected by those overseas in Asia, Australia, and NZ.
We once again apologize for the inconvenience. |
Originally Posted by IB-Dick
(Post 12881162)
We have been working around the clock to combat this ongoing cyber attack. While service has not yet been restored to normal, progress is being made. The site is most dramatically effected by those overseas in Asia, Australia, and NZ.
We once again apologize for the inconvenience. What has made Asia, Australia and NZ be more dramatically effected? P.S I only got redirected twice before being able to post this post :D. |
Originally Posted by Downunder girl
(Post 12882455)
Thank you for replying and letting us know of the situation ^.
What has made Asia, Australia and NZ be more dramatically effected? P.S I only got redirected twice before being able to post this post :D. |
IB-Dick - thank you for responding.
Could you or your colleagues PLEASE help me ? I am STILL getting REDIRECT to Internet explorer issues each time I try to post and I am still LOCKED out of FT Chat and getting that java exception error :(. This is really starting to drag on (since 13 November for me) and frankly I have just stopped hanging out here on FT daily. All my friends can now get back into CHAT, but I cant :td:. What is going on? :( |
Originally Posted by Downunder girl
(Post 12934868)
IB-Dick - thank you for responding.
Could you or your colleagues PLEASE help me ? I am STILL getting REDIRECT to Internet explorer issues each time I try to post and I am still LOCKED out of FT Chat and getting that java exception error :(. This is really starting to drag on (since 13 November for me) and frankly I have just stopped hanging out here on FT daily. All my friends can now get back into CHAT, but I cant :td:. What is going on? :( try to install an alternative browser and see if the problem persists: www.opera.com www.firefox.com Both browsers are "one click" downloads and a second click to install. If these browsers run fine, make sure to do a full malware check of your computer with a good up to date Antivirus product. Kaspersky would be a good choice and runs for free for at least 30 days. If the problem persists, go to www.sun.com and download the current Java package. Do a re-install. If the problem still persists, try the following: www.knoppix.org At that site, you can download a "Live Linux" DVD image, which needs to be burned to a DVD, of course. Your computer must be able to boot from a DVD. Boot Knoppix, which will take you all the way to a running, graphical desktop with many applications, including Firefox. If this brings back your flyertalk completely, your Windows installation is infected by something. Knoppix includes tools to eradicate Windows malware, but you should only try this with at least mid-level computer knowledge. The reason I recommend the Live Session DVD/CD approach is that this is the only way to make sure that you boot a clean, infection-free system. |
For starters, eveything that colonius has said is right on. I'd first start off by trying a different browser. That can really help diagnose problems.
Originally Posted by Downunder girl
(Post 12934868)
IB-Dick - thank you for responding.
Could you or your colleagues PLEASE help me ? I am STILL getting REDIRECT to Internet explorer issues each time I try to post and I am still LOCKED out of FT Chat and getting that java exception error :(. This is really starting to drag on (since 13 November for me) and frankly I have just stopped hanging out here on FT daily. All my friends can now get back into CHAT, but I cant :td:. What is going on? :( If you continue to have problems, can you possible paste a traceroute in here? To do this, please follow these instructions: 1.) Got to Start > Run... 2.) Type in "cmd" (no quotes) and hit OK. 3.) On the line, type in "tracert www.flyertalk.com" (no quotes) and hit enter. 4.) Copy the output and paste it in here. There is a more detailed explaination on running a traceroute here: http://support.verio.com/documents/v...fm?doc_id=3743 but instead of pasting that into notepad, you can just paste it into a reply window. |
Originally Posted by IB-Dick
(Post 12941685)
For starters, eveything that colonius has said is right on. I'd first start off by trying a different browser. That can really help diagnose problems.
FT chat is broken for almost everybody, and we're working on getting that sorted out asap. If you continue to have problems, can you possible paste a traceroute in here? To do this, please follow these instructions: 1.) Got to Start > Run... 2.) Type in "cmd" (no quotes) and hit OK. 3.) On the line, type in "tracert www.flyertalk.com" (no quotes) and hit enter. 4.) Copy the output and paste it in here. There is a more detailed explaination on running a traceroute here: http://support.verio.com/documents/v...fm?doc_id=3743 but instead of pasting that into notepad, you can just paste it into a reply window. |
Originally Posted by goalie
(Post 12942043)
how would that equate to those of us using a mac? ;)
|
Originally Posted by colonius
(Post 12942281)
Since Mac OS is based on BSD Unix, it will have a traceroute utility somewhere. (Windows is the only OS that names it differently). Since I am not intimate with Mac OS: Google is your friend. ;)
At the prompt ([yourname]$), type (without quotes) "traceroute www.flyertalk.com" and hit return. It'll look something like this: Code:
Last login: Sun Dec 6 22:03:04 on ttys000 |
Originally Posted by jackal
(Post 12943828)
Applications>Utilities>Terminal
At the prompt ([yourname]$), type (without quotes) "traceroute www.flyertalk.com" and hit return. It'll look something like this: Code:
Last login: Sun Dec 6 22:03:04 on ttys000 |
| All times are GMT -6. The time now is 4:46 am. |
This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.