Concerning the security on the old site, is it known that any of our private information was compromised? Specially, email addresses? I shudder at the thought of them being harvested for spam mailing lists.
:deal:
SD
Concerning the security on the old site, is it known that any of our private information was compromised? Specially, email addresses? I shudder at the thought of them being harvested for spam mailing lists.
:deal:
SD
All we know right now is that the hacker attacked the YABB code of the message board and deleted all the user information and profiles...
I THINK we are ALL safe from that. I'll write more later on some specifics after the kids are down.
TDF
Here's what we DON'T know:Originally Posted by SpaceDawg
Confidently what information he got, if any.
How he got in
Where he was from
What we DO know:
- He did NOT come in through the FTP space which would have given him full access to all the files to download, including pw's and e-mail addresses
- It APPEARS that all the damage was done from inside the message board. It almost acted like a backdoor into the site which allowed him to access the admin section and change the templates, configurations, delete boards, purge/delete messages, delete members, change passwords (although not able to SEE the original ones) and pretty much anything that EJ, Dwayne, AustinDawg, Forum Admin, or myself could do.
They could have seen everyone e-mails that were public, but if they were hidden, I doubt he got them. I don't even know if they TRIED to get them. I don't think they hung around long enough.
I THINK your passwords are safe, but for your own security, I would change them.
Any other questions about what we don't know?
TDF
YaBB, the old board, does use a very strong password encryption, from what I remember reading, so you password is "probably" safe, never hurts to change it though, :-)