navitron
 
Renewable Energy and Sustainability Forum
UK's most popular Renewable Energy Forum May 22, 2012, 11:52:27 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Anyone wishing to register as a new member on the forum is strongly recommended to use a "proper" email address - following recent spam/hack attempts on the forum, all security is set to "high", and "disposable" email addresses like Gmail, Yahoo and Hotmail tend to be viewed with suspicion, and the application rejected if there is any doubt whatsoever
 
Recent Articles: UPDATE ON DECC APPLICATION FOR LEAVE TO APPEAL TO THE SUPREME COURT | Yingli Green Energy's PV Module Ranks No.2 in TUV Rheinland Energy Yield Test | Navitron Solar Showers at Glastonbury for Year 5!
   Home   Help Search Login Register  
Pages: [1] 2 3 4 5   Go Down
  Print  
Author Topic: We have been hacked!  (Read 5114 times)
Samantha (Navitron)
Global Moderator
Newbie
*****
Offline Offline

Posts: 12


« on: May 26, 2010, 11:55:39 PM »

not a lot we can do until the sever people are contacted - presumably in the morning............
Logged
Other-Power
Sr. Member
****
Offline Offline

Posts: 366


« Reply #1 on: May 27, 2010, 12:12:21 AM »

how about pulling the plug till then..... is that even an option, DOS attach anyone please?
Logged
martin
Administrator
Hero Member
*****
Offline Offline

Posts: 11415



WWW
« Reply #2 on: May 27, 2010, 12:14:50 AM »

lawks! I was off on another forum, and came back to find a bit of a mess............ sadly I have no access to the server, database or major config files, but have just done a bit of "reverse hacking" of my own........ let's hope it holds until the morning  signofcross
« Last Edit: May 27, 2010, 12:35:37 AM by martin » Logged

Unpaid volunteer administrator and moderator (not employed by Navitron) - Views expressed are my own - curmudgeonly babyboomer! - http://www.farmco.co.uk
fje-iptelenet
Full Member
***
Offline Offline

Posts: 115



« Reply #3 on: May 27, 2010, 12:22:45 AM »

Hi Martin,
Just responded to your "personal message" - didn't realise you are involved in Balkan politics! Grin
Logged

Rayburn DHW + CH - Wood only
30 ET Solar DHW
3.42 kWp PV
5000 Liter Graf underground Rainwater Tank
PRIUS 2004, SMART Turbo Diesel 86 mpg
insolare
Sr. Member
****
Offline Offline

Posts: 449


« Reply #4 on: May 27, 2010, 12:45:40 AM »

Kosovans? There's plenty of them here in Chatham without being hassled by them on the Navitron forum as well.  Roll Eyes

Talking of Kosovo... brings back memories.... if you ever visit Pristina you must go to Tiffany's restaurant. Fantastic food and a great atmosphere.
Logged
StBarnabas
Hero Member
*****
Offline Offline

Posts: 2111


St Barnabas Chapel (2009)


« Reply #5 on: May 27, 2010, 08:12:00 AM »

Ah
checked last thing yesterday and got this from Kosovo on my laptop which I immediately switched off. Bu**er will have to look  at my anti-virus software and try to disinfect! Bit of a relief that it is Navitron and not my machine.... 
Logged


Gestis Censere. 40x47mm DHW with TDC3. 3kW ASHP, 9kW GSHP, 3kW Navitron PV with Platinum 3100S GTI, 6.5kW WBS, 5 chickens. FMY 2009.
insolare
Sr. Member
****
Offline Offline

Posts: 449


« Reply #6 on: May 27, 2010, 08:22:52 AM »

Did the hackers do much damage? It all went to text mode briefly last night but it all seems ok now. Have our email addresses or passwords been compromised?
Logged
martin
Administrator
Hero Member
*****
Offline Offline

Posts: 11415



WWW
« Reply #7 on: May 27, 2010, 08:48:22 AM »

To be frank, at this point I just don't know what damage has been done - sadly I don't have access to the server files, database or the config files - if Ivan's been spotted then I would expect he's now getting in touch with the server people. I'm hoping and suspect that it was a fairly amateurish hack - some years ago I had several sites on a chunk of webspace that was comprehensively hacked by the same lot of fundamentalist moslems that went for the "cartoon" sites (I'd upset a local crook who's daughter was married to one........) and spent a very long time trying to keep them up and running, and learnt a few tricks on how to "unhack" by trial and error............ Roll Eyes
I had to change my own password to get back in, I'm hoping it was just the "admins" who were affected, from the responses I've been getting, they got in and fired off a "mass mailing" to members, did a bit of peurile grafitti and then scarpered (thankfully leaving lots of doors open, through which I was able to creep back in...........) - as I said, amateurs! Wink
Logged

Unpaid volunteer administrator and moderator (not employed by Navitron) - Views expressed are my own - curmudgeonly babyboomer! - http://www.farmco.co.uk
breezy
Full Member
***
Offline Offline

Posts: 171


Omnibus bendibus


« Reply #8 on: May 27, 2010, 09:00:36 AM »

The PM that I received didn't have a payload, and wasn't picked up by my spam filtering.

Stating the obvious - don't click on the link in that PM!

Might be a good idea to change your passwords.
Logged

This message handcrafted from 100% recycled electrons. Caution: May contain nuts
MR GUS
Hero Member
*****
Offline Offline

Posts: 2285


Officially "Awesome" because Frotter said so!


« Reply #9 on: May 27, 2010, 09:01:20 AM »

Martin, get interpol involved on the basis that bad hackers practise.
it's potentially disruptive to a business, so surely they should respond in terms of tracking the tiny penised donkey shaggers?

(edit, sweary mary filter totally let that one go unedited)
Logged

Austroflamm stove & lot's of Lowe alpine fleeces, & a tiny pen15 ..if we're comparing solar set ups!

Noli Timere Messorem
jmp101
Newbie
*
Offline Offline

Posts: 7


« Reply #10 on: May 27, 2010, 09:19:40 AM »

It would be useful to know how well the password file is protected. Is  the data encrypted for instance?

Many people use common passwords across sites, and as emails are also stored it provide a good starting point for hackers to test email provider passwords.

I work in IT security. In my experience most forum software is very easily hacked.

John
Logged
Ally
Newbie
*
Offline Offline

Posts: 2


« Reply #11 on: May 27, 2010, 09:20:54 AM »

I've had it too!!!!!!!!!!!! help
Logged
martin
Administrator
Hero Member
*****
Offline Offline

Posts: 11415



WWW
« Reply #12 on: May 27, 2010, 09:25:45 AM »

I originally chose SMF because of it's superior features (including security) - here's a piece about password security "SMF encrypts what you enter into the password field before it gets sent to the server, and there is an encrypted version in the database" Wink
Logged

Unpaid volunteer administrator and moderator (not employed by Navitron) - Views expressed are my own - curmudgeonly babyboomer! - http://www.farmco.co.uk
MR GUS
Hero Member
*****
Offline Offline

Posts: 2285


Officially "Awesome" because Frotter said so!


« Reply #13 on: May 27, 2010, 09:26:14 AM »

So what's the general concensus? are we required to change password info on this forum?
Martin , Mods & navi-bods please update as soon as you know the full extent.

cheers.

NB. Yes, I had the illicit pm too.
Don't clicky the link!
« Last Edit: May 27, 2010, 09:28:19 AM by MR GUS » Logged

Austroflamm stove & lot's of Lowe alpine fleeces, & a tiny pen15 ..if we're comparing solar set ups!

Noli Timere Messorem
martin
Administrator
Hero Member
*****
Offline Offline

Posts: 11415



WWW
« Reply #14 on: May 27, 2010, 09:31:09 AM »

Never a bad idea to change/update your passwords, everyone who needs to know has now been fully informed, as we speak there should be teams getting covered in database grease from Bangalore to Minneapolis and back again! ralph
Nothing is suggesting that it was anything more than a "random hack", probably by some bored 11 year olds in Wigan who've got hold of a hacking book - it was crude and amateurish, and apart from a few "you've been hacked" messages, some grafitti, and locking the admins out, it appears not to be "serious"........... signofcross
Logged

Unpaid volunteer administrator and moderator (not employed by Navitron) - Views expressed are my own - curmudgeonly babyboomer! - http://www.farmco.co.uk
Pages: [1] 2 3 4 5   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!