Warning! Attention All Members!

Discuss anything not covered in another forum (life, the universe etc.)... Please keep it PG-13 and avoid spam.
User avatar
Ken
Posts: 12191
Joined: Wed Dec 31, 1969 7:00 pm
Location: Tampa

Warning! Attention All Members!

Post by Ken »

An apparent exploit of the forums is allowing a massive amount of spam PM's. Do not open any links on any PM's, or even PM's, if they are not from people that you know. (***EDIT-even if you know them as if their user & password is the same, their account has probably been hijacked...) Some are porn, some have virus and trojans!

We are working it on it and hope to have it in control soon.

Thanks!

If your User name and Password are the same, CHANGE IT NOW!!!! That is the exploit...
User avatar
Ken
Posts: 12191
Joined: Wed Dec 31, 1969 7:00 pm
Location: Tampa

Post by Ken »

Let's keep this thread on top guys. Many people don't always see the sticky's!
User avatar
Ken
Posts: 12191
Joined: Wed Dec 31, 1969 7:00 pm
Location: Tampa

Post by Ken »

If your user name is the same as your password, change it immediately!

This is the exploit!
User avatar
Ken
Posts: 12191
Joined: Wed Dec 31, 1969 7:00 pm
Location: Tampa

Post by Ken »

Check "Who's Online"...
User avatar
Dan
Posts: 18684
Joined: Sat Jul 29, 2000 12:00 pm
Location: Orangevale ,Ca

Post by Dan »

Ken wrote:Check "Who's Online"...
thats crazy :eek:
User avatar
PsykoPenguin
Posts: 1378
Joined: Mon Nov 12, 2007 1:31 am
Location: Somewhere in the Antarctic Circle

Post by PsykoPenguin »

Yep... Just sent something to Phillip about this... Also don't install those activex crap things for the porntube stuff. It's not real. Besides the video is actually just an image. :p
"I'm like a lion on the prowl after prey"
User avatar
MadDoctor
New Member
Posts: 5
Joined: Fri Apr 27, 2001 12:00 pm
Location: Looks dark

Post by MadDoctor »

I wanted to change my password anyway. thanks Ken.
People will forget what you said... and people will forget what you did... but people will never forget how you made them feel.
User avatar
JawZ
Posts: 21941
Joined: Fri Feb 23, 2001 12:00 am

Post by JawZ »

IT's the damn Chinese....we're under ATTTTAAAAAAAAAAAAACCCCCCCCKKKKK!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
User avatar
Dan
Posts: 18684
Joined: Sat Jul 29, 2000 12:00 pm
Location: Orangevale ,Ca

Post by Dan »

penguincomrade wrote:Yep... Just sent something to Phillip about this... Also don't install those activex crap things for the porntube stuff. It's not real. Besides the video is actually just an image. :p
yep ! I got the pm from a member thats been here since 01,so be careful everyone! :irate:
User avatar
Ken
Posts: 12191
Joined: Wed Dec 31, 1969 7:00 pm
Location: Tampa

Post by Ken »

UOD wrote:IT's the damn Chinese....we're under ATTTTAAAAAAAAAAAAACCCCCCCCKKKKK!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Actually, the IP is from Israel.....

To the bomb shelters! Everyone, arms over your head and get under your desk! :D (Only the old people will get that! :D )
User avatar
downhill
Posts: 34799
Joined: Sat Jan 15, 2000 12:00 pm
Location: My Own Private Idaho

Post by downhill »

I don't get it, Ken. Can you explain?
User avatar
Philip
SG VIP
Posts: 11732
Joined: Sat May 08, 1999 5:00 am
Location: Jacksonville, Florida

Post by Philip »

The exploit is a script that tries to login as existing users, trying a password that equals the username. If it successfuly logs in, it then proceeds to send spam PMs to other members.

Working on it at the moment. The majority of spam was coming from the same israeli IP address that's already banned.
User avatar
JawZ
Posts: 21941
Joined: Fri Feb 23, 2001 12:00 am

Post by JawZ »

Ken wrote:Actually, the IP is from Israel.....

To the bomb shelters! Everyone, arms over your head and get under your desk! :D (Only the old people will get that! :D )

Make sure you keep your moth open to avoid lung damage from the overblast pressure!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!


I still say it's the damn Chinese using Israeli networks!!!!!!!!!!!!!!!!!!
User avatar
JawZ
Posts: 21941
Joined: Fri Feb 23, 2001 12:00 am

Post by JawZ »

Philip wrote:The exploit is a script that tries to login as existing users, trying a password that equals the username. If it successfuly logs in, it then proceeds to send spam PMs to other members.

Working on it at the moment. The majority of spam was coming from the same israeli IP address that's already banned.
Is there a vB hack that can be installed that will disallow the username and password to be of the same value?
User avatar
PsykoPenguin
Posts: 1378
Joined: Mon Nov 12, 2007 1:31 am
Location: Somewhere in the Antarctic Circle

Post by PsykoPenguin »

Ken wrote:An apparent exploit of the forums is allowing a massive amount of spam PM's. Do not open any links on any PM's, or even PM's, if they are not from people that you know, even if you know them as if their user & password is the same, their account has probably been hijacked.... Some are porn, some have virus and trojans!

We are working it on it and hope to have it in control soon.

Thanks!

Edit!!!! If your User name and Password are the same, CHANGE IT NOW!!!! That is the exploit...
That's just it. My password and username are NOT the same.
"I'm like a lion on the prowl after prey"
User avatar
downhill
Posts: 34799
Joined: Sat Jan 15, 2000 12:00 pm
Location: My Own Private Idaho

Post by downhill »

penguincomrade wrote:That's just it. My password and username are NOT the same.
Nope and your account wasn't taken over either.
User avatar
brembo
Posts: 18725
Joined: Tue Mar 20, 2001 12:00 am
Location: crawlspaces

Post by brembo »

I push butan.
Tao_Jones Cult Member since 2004
I gave Miss Manners a Dirty Sanchez, and she LIKED it.
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

Ken wrote:Do not open any links on any PM's, or even PM's, if they are not from people that you know, even if you know them as if their user & password is the same...

Huh? :p
User avatar
JawZ
Posts: 21941
Joined: Fri Feb 23, 2001 12:00 am

Post by JawZ »

penguincomrade wrote:That's just it. My password and username are NOT the same.

right, you just received PM's from folks who did have accounts where the username and password were the same. Their accts were hacked, not yours.
User avatar
Philip
SG VIP
Posts: 11732
Joined: Sat May 08, 1999 5:00 am
Location: Jacksonville, Florida

Post by Philip »

YoS, Ken was simply trying to say that the spam PM could be coming from existing users, simply because they were using a weak password - the exploit targets users whose username and password are the same.
User avatar
brembo
Posts: 18725
Joined: Tue Mar 20, 2001 12:00 am
Location: crawlspaces

Post by brembo »

Philip wrote:YoS, Ken was simply trying to say that the spam PM could be coming from existing users, simply because they were using a weak password - the exploit targets users whose username and password are the same.


Yard is being a tool and criticizing Ken's grammar.
Tao_Jones Cult Member since 2004
I gave Miss Manners a Dirty Sanchez, and she LIKED it.
User avatar
Ken
Posts: 12191
Joined: Wed Dec 31, 1969 7:00 pm
Location: Tampa

Post by Ken »

brembo wrote:Yard is being a tool and criticizing Ken's grammar.
It was a quick post made to hopefully keep as many members as possible, from becoming a victim. It's not like I had a lot of time to think about the post as we were trying to stop the SOB's and figure out what was going on. When the specific exploit was discovered, it wasn't just PM's from people that you didn't know, they could be from any account, so that part was an after the fact edit... Not to mention that my PM's were coming in like flies to stink... Multi tasking at it's finest... :D
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

brembo wrote:Yard is being a tool and criticizing Ken's grammar.
Ken wanted it kept at the top, I was just helping :)
User avatar
Comtrad
Senior Member
Posts: 4059
Joined: Fri Sep 22, 2006 10:25 am
Location: IL

Post by Comtrad »

Who is stupid enough to have their name/pw the same?

so it's not really anyting on SG side, just some users being stupid and someone using a script to take advantage of it.
User avatar
9mmprincess
Posts: 1756
Joined: Sun Nov 23, 2003 7:30 am
Location: out where the lions roar

Post by 9mmprincess »

yeah I got a pm with porn spam from "raromoney"....
There is security in fearlessness.
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

Comtrad wrote:Who is stupid enough to have their name/pw the same?

so it's not really anyting on SG side, just some users being stupid and someone using a script to take advantage of it.
Could also be old spam accounts.
User avatar
Sava700
Posts: 24051
Joined: Wed Feb 27, 2002 7:51 am
Location: Somewhere

Post by Sava700 »

Good warning.. bumped.
User avatar
blebs
Posts: 12819
Joined: Sat Dec 02, 2000 12:00 am
Location: North Canton, Ohio

Post by blebs »

Philip or Ken can one of you send the IP address or addresses for this exploit by PM so I can ban it at the heart forum before it starts on us too please?
Success is a lousy teacher. It seduces people into thinking they can't lose. -Bill Gates
User avatar
Philip
SG VIP
Posts: 11732
Joined: Sat May 08, 1999 5:00 am
Location: Jacksonville, Florida

Post by Philip »

Comtrad wrote:Who is stupid enough to have their name/pw the same?

so it's not really anyting on SG side, just some users being stupid and someone using a script to take advantage of it.

To answer that question...
I've identified 895 :eek: accounts (711 of which with 0 posts) in the SG user database that have their names set for their password.

It is still our problem, since those can be used to spam the forums/PMs to no end unless addressed.
User avatar
MadDoctor
New Member
Posts: 5
Joined: Fri Apr 27, 2001 12:00 pm
Location: Looks dark

Post by MadDoctor »

Philip wrote:To answer that question...
I've identified 895 in the SG user database that have their names set for their password.
894 now. I fixed mine.






:D
People will forget what you said... and people will forget what you did... but people will never forget how you made them feel.
User avatar
Philip
SG VIP
Posts: 11732
Joined: Sat May 08, 1999 5:00 am
Location: Jacksonville, Florida

Post by Philip »

In addition to those 895, there were another 600 with very weak passwords, i.e. 123, 1234, password, qwerty, etc.

All those 1500+ users are in the process of having their passwords reset, and the server is emailing them with a link to reactivate their account and choose a stronger password.

The moral of all this being, please, use common sense and strong passwords!
User avatar
Noevo
Posts: 14191
Joined: Mon Feb 28, 2000 12:00 am
Location: Floating in FL Red Tide

Post by Noevo »

I got no PM's...sad

:D
User avatar
Ken
Posts: 12191
Joined: Wed Dec 31, 1969 7:00 pm
Location: Tampa

Post by Ken »

Noevo wrote:I got no PM's...sad

:D

Are you ready?









Wait for it...




















L

Note the capital "L"... No respect, even from spambots! LMAO!!! :D
User avatar
OSULLY
Senior Member
Posts: 1347
Joined: Thu Nov 08, 2007 11:21 pm
Location: Catskills NY

Post by OSULLY »

Too late, I opened mine before I read this.
___________________________________________
User avatar
Red Rose
Member
Posts: 51
Joined: Wed Mar 06, 2002 8:07 pm
Location: MI

Post by Red Rose »

Yes I got one of those porntube things in a PM and didn't know what to make of it?
I live in my own little world, but it's OK, they know me here.
User avatar
Randy
Posts: 12030
Joined: Mon Jan 17, 2000 12:00 am
Location: British Columbia Canada

Post by Randy »

9mmprincess wrote:yeah I got a pm with porn spam from "raromoney"....

as did I :thumb: however I was unable to thank him as my keyboard keys got stuckified.

I was going to post a link to that thread, but the SG search results for "bullsh|t" were too numerous

sometimes you have to think outside the box to get inside the box ;).
User avatar
Noevo
Posts: 14191
Joined: Mon Feb 28, 2000 12:00 am
Location: Floating in FL Red Tide

Post by Noevo »

Ken wrote:
L

Note the capital "L"... No respect, even from spambots! LMAO!!! :D
It's like they can't even see me, or i'm invisible or something right? :(


:D
User avatar
Philip
SG VIP
Posts: 11732
Joined: Sat May 08, 1999 5:00 am
Location: Jacksonville, Florida

Post by Philip »

I've just deleted ~1000 spam PMs from the database that were sent this morning using those accounts.
Ronny
Advanced Member
Posts: 691
Joined: Wed Nov 29, 2000 12:00 am
Location: Kannapolis,NC

Post by Ronny »

yeah i got a pm for the porntube site too but i just deleted it.
ken & phillip, good job on catching this and getting it fixed.

also greetings from sweetwater,tx today
CableDude
SG VIP
Posts: 26801
Joined: Sat Jun 02, 2001 12:00 pm

Post by CableDude »

I'll take a pm. :D
Post Reply