Announcement

Collapse
No announcement yet.

So... what happened then?

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    So... what happened then?

    Just a brief update on what happened.

    Yesterday, it was publicly announced that vBulletin 5 had a serious security flaw. (For more detail on the flaw see https://arstechnica.com/information-...vbulletin-bug/)

    Of course, what happens as soon as such a vulnerability is made public is that every hacker and script kiddie on the block starts scanning for vulnerable sites to copy and paste the attack to prove how L33t they are. I got a couple of PMs late last night and missed an email due to being in that London for a networking event. Not that, to be honest, it would have helped. For Reasons, we were running a slightly oldish, unsupported version of vBulletin5 and although the devs issued a patch, it didn't apply to our version. In short, if we hadn't been hacked, I'd probably have had to take the entire board offline anyway as a precaution. It was that severe a hole in the system.

    The most excellent Tim @ Latitude has done all the work is getting us back and much, much faster than I thought possible. We are on a new server, with upgraded back-end and an upgraded and patched vBulletin 5. (You'll notice some icons have changed.) We had a choice of taking the current database as of this morning, or the last backup which was midnight 24/9/2019. Although I don't think the hackers left anything behind in the DB, I decided that it was better safe than sorry and went for the pre-hack database backup. This means that any postings or changes made yesterday will have disappeared. Good job nothing news or discussion worthy happened yesterday.

    As I say, I don't think that the database was affected and all passwords are salted and hashed properly. However, as a precaution, it would be very prudent for you to change your account password. I've created a topic with instructions to do so here - https://www.onetouchfootball.com/for...word?p=2203032

    There will probably be little bits and pieces that aren't quite as they were, probably due to me putting a customisation in or something - I'll try and sort them as they are discovered.

    We now return you to your regularly scheduled nonsense.

    Last edited by Snake Plissken; 26-09-2019, 14:37.

    #2
    Well done to you and Mr Snakepiss. Much obliged.

    Comment


      #3

      Comment


        #4
        So yesterday was wiped out and it was sunny all day in Taunton?

        Comment


          #5
          Yes.

          Comment


            #6
            Nicely done SP.

            Comment


              #7
              Wow. Amazing work. Can I come work for you?

              Comment


                #8
                What am I risking if I don't change my password?

                Comment


                  #9
                  Not a lot.

                  Basically they might have downloaded the database and might be able to brute force the password or might be able to cross-reference your email against another site where they have cracked the password and if you've reused it then can log in as you (or more likely try your details on other sites).

                  It's a request. Depends on how much risk you want to take over something that should take a minute.

                  Comment


                    #10
                    I kept getting an email address disnae match message when I tried to change mine. Even though they were the same.

                    Comment


                      #11
                      As on the other thread, check the change email box hasn't be automatically filled in by your browser.

                      Comment


                        #12
                        Yeah, mine always likes to put my handle in the first email box. You have to delete it before you can save changes.

                        Comment


                          #13
                          A minute is a long time in politics. Or something. Yeah. Ok ta. I'll sort it. It's just that I won't remember it.

                          Comment


                            #14
                            So yeah, so now I've no idea whatsoever what my password is, to use on my phone. Maybe that's a good thing.

                            Comment


                              #15
                              The OP is all gobbledegook to me SP, but I'm very glad you're here. Thanks.

                              Comment


                                #16
                                Really he just switched the whole thing off for a day to make us all appreciate him.

                                Comment


                                  #17
                                  You are a ninja, SP. Thanks for having our backs.

                                  Comment


                                    #18
                                    Originally posted by Sits View Post
                                    Really he just switched the whole thing off for a day to make us all appreciate him.

                                    Comment


                                      #19
                                      I think that all the fun and games of the last couple of days might have resulted in a problem with the e-mailing function, which people alluded to in relation to password resets.

                                      I haven't received any e-mail notifications of PMs, replies and so on since the small hours of Thursday morning, though notifications are still being highlighted on the website.

                                      Comment


                                        #20
                                        AE is still locked out of his account, Snake Plissken and asks if you can reset his password please?
                                        Last edited by Toby Gymshorts; 27-09-2019, 17:07.

                                        Comment


                                          #21
                                          AE should have an email with his password in. Thanks for letting me know.

                                          Comment


                                            #22
                                            I've notified the hosting company about the email situation. Probably the new server hasn't got permissions to send.

                                            Comment


                                              #23
                                              Originally posted by Toby Gymshorts View Post
                                              AE is still locked out of his account, Snake Plissken and asks if you can reset his password please?
                                              Cheers TG for rescuing me.

                                              Comment


                                                #24
                                                De rien.

                                                Comment


                                                  #25
                                                  Originally posted by Snake Plissken View Post
                                                  I've notified the hosting company about the email situation. Probably the new server hasn't got permissions to send.

                                                  Nice one.

                                                  Comment

                                                  Working...
                                                  X