Community
Wiki Posts
Search

flyertalk site redirected?

Thread Tools
 
Search this Thread
 
Old Nov 23, 2009 | 7:36 pm
  #46  
 
Join Date: Feb 2009
Posts: 959
Originally Posted by colonius
3.) A system that has been compromised as far as having backdoors installed, should never be considered safe until reinstalled or restored from a known good backup. Evidence that "they never accessed the database" may be false, since the backdoor application could as well have scrubbed the log files to hide its tracks - very common, btw.

And yes, I do system security for a living.
We understand the flaws in md5 hashes, however everyone I've personally discussed this with has verified that the vBulletin hashing method is sufficiently secure.

While we haven't restored the files from backup, hourly snapshots were diff'ed and we have ensured that the system is secure. This was a script kiddie script that exploited a vulnerability right after it was announced and before we had an attempt to patch.
IB-Dick is offline  
Old Nov 23, 2009 | 8:51 pm
  #47  
All eyes on you!
20 Years on Site
 
Join Date: Jul 2002
Location: Victoria, BC
Programs: UA 1k, AA Exec Plt 2MM, HH Diamond, *wood Gold, disgruntled Amex Ex-Centurion
Posts: 594
Originally Posted by IB-Dick
We understand the flaws in md5 hashes, however everyone I've personally discussed this with has verified that the vBulletin hashing method is sufficiently secure.
If it uses MD5, it must be considered broken. This has nothing to do with vB, it is the algorithm that is at fault.

While we haven't restored the files from backup, hourly snapshots were diff'ed and we have ensured that the system is secure. This was a script kiddie script that exploited a vulnerability right after it was announced and before we had an attempt to patch.
Good to learn that you verified the system's integrity to be uncompromised (which the check against the backups did). ^

I assume that you did additional checks to verify the confidentiality of the password data?
colonius is offline  
Old Nov 23, 2009 | 8:56 pm
  #48  
FlyerTalk Evangelist
 
Join Date: Mar 2008
Location: ACT/GRK/DAL/ABI/MIA/FLL
Programs: OMNIArchist, OMNIArchy!, OMNIIDGAS
Posts: 23,478
MD5 is so secure
http://milw0rm.com/cracker/insert.php

http://www.hashchecker.com/

sure salt adds a minor bit of complexity, but a little computer 'pepper' and it fades away.

these sites are HARDLY an effective way, just an example.
This is especially true if someone had a level of server access at any point.

Last edited by Steph3n; Nov 23, 2009 at 9:08 pm
Steph3n is offline  
Old Nov 24, 2009 | 10:40 am
  #49  
 
Join Date: Feb 2009
Posts: 959
Originally Posted by colonius
If it uses MD5, it must be considered broken. This has nothing to do with vB, it is the algorithm that is at fault.



Good to learn that you verified the system's integrity to be uncompromised (which the check against the backups did). ^

I assume that you did additional checks to verify the confidentiality of the password data?
Of course. As I said before, there is no way that password data was compromised.
IB-Dick is offline  
Old Nov 25, 2009 | 6:10 am
  #50  
 
Join Date: Jul 2007
Location: Sydney, Australia
Programs: VA Gold, UA, SPG Gold, HH Diamond, Marriott Gold, IHG Ambassador
Posts: 3,644
Originally Posted by mshaikun
Let me join with others in saying thanks to our hard working IT gurus.

Bigger sites have been hacked including sensitive government sites. The test of IT is how fast they can get things back together. Where we addicts look for instant gratification, you did well guys.
While I would like to say thanks, right now I am at the point of throwing my hands in the air. For SOME unknown reason to me, I am at 50% functionality on FT and have been since the FIRST attack (on 13 Nov I believe). I cant search, I cant PM or reply to PMs, I struggle to quote anyone's threads and doing a simple post on this thread so far has taken me 3 tries and 10 minutes. I keep getting redirected to the Internet Explorer page.....IE cannot display this webpage! So I am feeling much less thankful .

My messages sent to FT HELP have gone unanswered . I wont even start about how the FT Chat room has been broken for me and others for nearly 2 weeks since the first attack .

I have a trade thread in CC which I cant access/search to bump. It sure is a BUZZ KILL

Luckily Twitter has been keeping me mildly amused, but how much longer until FT IT gets these issues under control?????

I am in the camp of feeling relieved that I DIDNT subscribe and PAY money for this. Sorry but for me, its just gone on way TOO long.
Downunder girl is offline  
Old Nov 25, 2009 | 5:48 pm
  #51  
 
Join Date: Feb 2009
Posts: 959
We have been working around the clock to combat this ongoing cyber attack. While service has not yet been restored to normal, progress is being made. The site is most dramatically effected by those overseas in Asia, Australia, and NZ.

We once again apologize for the inconvenience.
IB-Dick is offline  
Old Nov 26, 2009 | 12:10 am
  #52  
 
Join Date: Jul 2007
Location: Sydney, Australia
Programs: VA Gold, UA, SPG Gold, HH Diamond, Marriott Gold, IHG Ambassador
Posts: 3,644
Originally Posted by IB-Dick
We have been working around the clock to combat this ongoing cyber attack. While service has not yet been restored to normal, progress is being made. The site is most dramatically effected by those overseas in Asia, Australia, and NZ.

We once again apologize for the inconvenience.
Thank you for replying and letting us know of the situation ^.

What has made Asia, Australia and NZ be more dramatically effected?

P.S I only got redirected twice before being able to post this post .
Downunder girl is offline  
Old Nov 26, 2009 | 4:32 pm
  #53  
 
Join Date: Feb 2009
Posts: 959
Originally Posted by Downunder girl
Thank you for replying and letting us know of the situation ^.

What has made Asia, Australia and NZ be more dramatically effected?

P.S I only got redirected twice before being able to post this post .
One part of the cyber attack was mostly coming from that area, I believe. I'm not sure though.
IB-Dick is offline  
Old Dec 6, 2009 | 6:10 am
  #54  
 
Join Date: Jul 2007
Location: Sydney, Australia
Programs: VA Gold, UA, SPG Gold, HH Diamond, Marriott Gold, IHG Ambassador
Posts: 3,644
IB-Dick - thank you for responding.

Could you or your colleagues PLEASE help me ? I am STILL getting REDIRECT to Internet explorer issues each time I try to post and I am still LOCKED out of FT Chat and getting that java exception error .

This is really starting to drag on (since 13 November for me) and frankly I have just stopped hanging out here on FT daily. All my friends can now get back into CHAT, but I cant .

What is going on?

Downunder girl is offline  
Old Dec 6, 2009 | 10:16 am
  #55  
All eyes on you!
20 Years on Site
 
Join Date: Jul 2002
Location: Victoria, BC
Programs: UA 1k, AA Exec Plt 2MM, HH Diamond, *wood Gold, disgruntled Amex Ex-Centurion
Posts: 594
Originally Posted by Downunder girl
IB-Dick - thank you for responding.

Could you or your colleagues PLEASE help me ? I am STILL getting REDIRECT to Internet explorer issues each time I try to post and I am still LOCKED out of FT Chat and getting that java exception error .

This is really starting to drag on (since 13 November for me) and frankly I have just stopped hanging out here on FT daily. All my friends can now get back into CHAT, but I cant .

What is going on?

I guess it is impossible to tell what is happening on your machine, but have you considered a local problem, like a malware infection of your system? Things you might try if you have just a little computer knowledge - or some friend who has:

try to install an alternative browser and see if the problem persists:

www.opera.com
www.firefox.com

Both browsers are "one click" downloads and a second click to install. If these browsers run fine, make sure to do a full malware check of your computer with a good up to date Antivirus product. Kaspersky would be a good choice and runs for free for at least 30 days.

If the problem persists, go to www.sun.com and download the current Java package. Do a re-install.

If the problem still persists, try the following:

www.knoppix.org

At that site, you can download a "Live Linux" DVD image, which needs to be burned to a DVD, of course. Your computer must be able to boot from a DVD. Boot Knoppix, which will take you all the way to a running, graphical desktop with many applications, including Firefox. If this brings back your flyertalk completely, your Windows installation is infected by something. Knoppix includes tools to eradicate Windows malware, but you should only try this with at least mid-level computer knowledge.

The reason I recommend the Live Session DVD/CD approach is that this is the only way to make sure that you boot a clean, infection-free system.
colonius is offline  
Old Dec 7, 2009 | 11:44 am
  #56  
 
Join Date: Feb 2009
Posts: 959
For starters, eveything that colonius has said is right on. I'd first start off by trying a different browser. That can really help diagnose problems.

Originally Posted by Downunder girl
IB-Dick - thank you for responding.

Could you or your colleagues PLEASE help me ? I am STILL getting REDIRECT to Internet explorer issues each time I try to post and I am still LOCKED out of FT Chat and getting that java exception error .

This is really starting to drag on (since 13 November for me) and frankly I have just stopped hanging out here on FT daily. All my friends can now get back into CHAT, but I cant .

What is going on?

FT chat is broken for almost everybody, and we're working on getting that sorted out asap.

If you continue to have problems, can you possible paste a traceroute in here? To do this, please follow these instructions:
1.) Got to Start > Run...
2.) Type in "cmd" (no quotes) and hit OK.
3.) On the line, type in "tracert www.flyertalk.com" (no quotes) and hit enter.
4.) Copy the output and paste it in here.

There is a more detailed explaination on running a traceroute here: http://support.verio.com/documents/v...fm?doc_id=3743 but instead of pasting that into notepad, you can just paste it into a reply window.
IB-Dick is offline  
Old Dec 7, 2009 | 12:36 pm
  #57  
Moderator: Smoking Lounge; FlyerTalk Evangelist
10 Countries Visited
1M
20 Years on Site
 
Join Date: Feb 2004
Location: SFO
Programs: Lifetime (for now) Gold MM, HH Gold, Giving Tootsie Pops to UA employees, & a retired hockey goalie
Posts: 29,074
Originally Posted by IB-Dick
For starters, eveything that colonius has said is right on. I'd first start off by trying a different browser. That can really help diagnose problems.



FT chat is broken for almost everybody, and we're working on getting that sorted out asap.

If you continue to have problems, can you possible paste a traceroute in here? To do this, please follow these instructions:
1.) Got to Start > Run...
2.) Type in "cmd" (no quotes) and hit OK.
3.) On the line, type in "tracert www.flyertalk.com" (no quotes) and hit enter.
4.) Copy the output and paste it in here.

There is a more detailed explaination on running a traceroute here: http://support.verio.com/documents/v...fm?doc_id=3743 but instead of pasting that into notepad, you can just paste it into a reply window.
how would that equate to those of us using a mac?
goalie is offline  
Old Dec 7, 2009 | 1:07 pm
  #58  
All eyes on you!
20 Years on Site
 
Join Date: Jul 2002
Location: Victoria, BC
Programs: UA 1k, AA Exec Plt 2MM, HH Diamond, *wood Gold, disgruntled Amex Ex-Centurion
Posts: 594
Originally Posted by goalie
how would that equate to those of us using a mac?
Since Mac OS is based on BSD Unix, it will have a traceroute utility somewhere. (Windows is the only OS that names it differently). Since I am not intimate with Mac OS: Google is your friend.
colonius is offline  
Old Dec 7, 2009 | 5:02 pm
  #59  
FlyerTalk Evangelist
1M
60 Nights
50 Countries Visited
20 Years on Site
 
Join Date: Mar 2004
Location: SGF
Programs: AS, AA, UA, AGR S+, Choice Platinum
Posts: 23,317
Originally Posted by colonius
Since Mac OS is based on BSD Unix, it will have a traceroute utility somewhere. (Windows is the only OS that names it differently). Since I am not intimate with Mac OS: Google is your friend.
Applications>Utilities>Terminal

At the prompt ([yourname]$), type (without quotes) "traceroute www.flyertalk.com" and hit return. It'll look something like this:

Code:
Last login: Sun Dec  6 22:03:04 on ttys000
xx-xx-178-69:~ jackal$ traceroute www.flyertalk.com
traceroute to flyertalk.com (67.201.16.68), 64 hops max, 40 byte packets
 1  * * *
 2  81-188-165-209 (209.165.188.81)  7.023 ms  10.632 ms  5.774 ms
 3  32-128-165-209 (209.165.128.32)  8.107 ms  16.984 ms  25.133 ms
 4  52-129-165-209 (209.165.129.52)  46.111 ms  37.644 ms  43.164 ms
 5  217-129-165-209 (209.165.129.217)  47.766 ms  49.909 ms  38.661 ms
 6  ge1-0.cr01.sea01.mzima.net (206.81.80.44)  43.749 ms  43.741 ms  53.306 ms
 7  te2-0.cr02.sjc02.us.mzima.net (69.174.120.81)  60.199 ms  53.506 ms  53.296 ms
 8  te0-1.cr01.lax02.us.mzima.net (69.174.120.85)  73.087 ms  60.371 ms  68.887 ms
 9  xe1-0.cr01.lax01.mzima.net (64.235.224.181)  69.084 ms  67.269 ms  73.567 ms
10  xe0-0.cr01.lax06.us.mzima.net (216.193.255.98)  87.500 ms  73.503 ms  68.107 ms
11  67.201.17.150 (67.201.17.150)  68.489 ms  65.303 ms  60.852 ms
12  flyertalk.com (67.201.16.68)  70.547 ms  61.350 ms  61.976 ms
13  * * *
14  * * *
15  * flyertalk.com (67.201.16.68)  61.114 ms !H  60.864 ms !H
xx-xx-178-69:~ jackal$
jackal is offline  
Old Dec 7, 2009 | 5:22 pm
  #60  
Moderator: Smoking Lounge; FlyerTalk Evangelist
10 Countries Visited
1M
20 Years on Site
 
Join Date: Feb 2004
Location: SFO
Programs: Lifetime (for now) Gold MM, HH Gold, Giving Tootsie Pops to UA employees, & a retired hockey goalie
Posts: 29,074
Originally Posted by jackal
Applications>Utilities>Terminal

At the prompt ([yourname]$), type (without quotes) "traceroute www.flyertalk.com" and hit return. It'll look something like this:

Code:
Last login: Sun Dec  6 22:03:04 on ttys000
xx-xx-178-69:~ jackal$ traceroute www.flyertalk.com
traceroute to flyertalk.com (67.201.16.68), 64 hops max, 40 byte packets
 1  * * *
 2  81-188-165-209 (209.165.188.81)  7.023 ms  10.632 ms  5.774 ms
 3  32-128-165-209 (209.165.128.32)  8.107 ms  16.984 ms  25.133 ms
 4  52-129-165-209 (209.165.129.52)  46.111 ms  37.644 ms  43.164 ms
 5  217-129-165-209 (209.165.129.217)  47.766 ms  49.909 ms  38.661 ms
 6  ge1-0.cr01.sea01.mzima.net (206.81.80.44)  43.749 ms  43.741 ms  53.306 ms
 7  te2-0.cr02.sjc02.us.mzima.net (69.174.120.81)  60.199 ms  53.506 ms  53.296 ms
 8  te0-1.cr01.lax02.us.mzima.net (69.174.120.85)  73.087 ms  60.371 ms  68.887 ms
 9  xe1-0.cr01.lax01.mzima.net (64.235.224.181)  69.084 ms  67.269 ms  73.567 ms
10  xe0-0.cr01.lax06.us.mzima.net (216.193.255.98)  87.500 ms  73.503 ms  68.107 ms
11  67.201.17.150 (67.201.17.150)  68.489 ms  65.303 ms  60.852 ms
12  flyertalk.com (67.201.16.68)  70.547 ms  61.350 ms  61.976 ms
13  * * *
14  * * *
15  * flyertalk.com (67.201.16.68)  61.114 ms !H  60.864 ms !H
xx-xx-178-69:~ jackal$
thank you ^
goalie is offline  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.