Announcement

Collapse
No announcement yet.

vBulletin 5.5.6 PL1 - Post hack

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    vBulletin 5.5.6 PL1 - Post hack

    Just a quick update - a security flaw was discovered in vBulletin and I didn't manage to get it all patched in time before a bunch of Indonesian hackers exploited it to take over the site and backend database. They weren't very good hackers, because we managed to get the whole thing restored from last nights backup.

    As mentioned on Twitter, the hack happened at 4am and the last backup was taken at midnight, so anything posted between then is lost, like tears in the rain.

    Most of the work was done by Tim and Nathan at the ISP, I just patched us up. Speaking of which, there is an additional upgrade that will be done shortly to get us onto a later version. I'm also going to be much more proactive in updating OTF, which will unfortunately see us go offline for an hour or so every six weeks or so depending on releases.

    Bear with me as I tidy away bits and pieces. The indexes are about to be rebuilt, but I think we're good enough to go for now.
    Last edited by Snake Plissken; 20-05-2020, 19:39.

    #2
    Thanks for all your efforts Ken.

    Comment


      #3
      One Kenny Snakepiss

      There's only one Kenny Snakepiss

      Comment


        #4
        Heĺlo

        Comment


          #5
          and thanks.

          Comment


            #6
            Thanks Ken.

            Comment


              #7
              Thanks Kenny.

              Comment


                #8
                Thanks.

                Comment


                  #9
                  Cheers, Ken. That was all very exciting, wasn't it?

                  If nothing else it forced me to use a decent (Last Pass generated) password for once.

                  Comment


                    #10
                    I produced so much brilliant OTF content in the hours between the last back-up and the hack, though. It was hilarious, insightful and deeply compassionate. Now it is lost forever. Now none of you will ever be able to read it and will just have to take me at my word about how utterly world-class all those posts were.

                    Comment


                      #11
                      Many thanks for the testing, Ken SP.

                      Comment


                        #12
                        That Ken Snakepiss is one helluva guy. They say he never sleeps and is invisible to bat radar.

                        Comment


                          #13
                          Many thanks Snakey. I blame Covid 19.

                          Comment


                            #14
                            Many thanks Snake/Ken

                            Every time I click on the home icon I get taken back to the hacked page, is there anything I can do except not press home?

                            Comment


                              #15
                              Well done Snake, I thought I was locked out for good, I was surprised how upset I was, I'd miss the lot of youse.

                              Comment


                                #16
                                I wondered what had happened. Many thanks for the prompt fix Snakeman.

                                Comment


                                  #17
                                  Don't put me back in the box. I don't want to be put back in the box.

                                  Comment


                                    #18
                                    What's the frequency Kenneth? An hour or so every six weeks is a small price to pay to keep this site online and, more importantly, safe. Smart work whateveryournameis.

                                    Comment


                                      #19
                                      Nice work Snakey, much appreciated.

                                      Comment


                                        #20
                                        Originally posted by Antepli Ejderha View Post
                                        Many thanks Snake/Ken

                                        Every time I click on the home icon I get taken back to the hacked page, is there anything I can do except not press home?
                                        Yes, me too. Or if I try to get to the site via onetouchfootball.com

                                        Comment


                                          #21
                                          Hmm, what browser are you using? I keep getting redirected to www.onetouchfootball.com which is the correct home page.

                                          Comment


                                            #22
                                            "Indonesian hackers", you say, well they were obviously only coming in to subvert the holiday destinations vote. I've been to Indonesia, yeah, it's fucking gorgeous, but so is the rest of South East Asia and frankly your cuisine is like fourth out of six there, and your only sport is badminton which no-one cares about so just do one!
                                            Last edited by Rogin the Armchair fan; 20-05-2020, 22:05.

                                            Comment


                                              #23
                                              They left a message in the source code for the hacked main page saying “indonesian hackers rule”.

                                              To be fair, I would have done the same if I was a teenager hacking stuff. Hypothetically speaking, of course.

                                              Comment


                                                #24
                                                You're a legend, Snakey

                                                Comment


                                                  #25
                                                  Originally posted by Snake Plissken View Post
                                                  Hmm, what browser are you using? I keep getting redirected to www.onetouchfootball.com which is the correct home page.
                                                  Chrome, that link sends me to the hackers page.

                                                  Comment

                                                  Working...
                                                  X