Page 1 of 1

Hacked-For those of you with Lost City accts.

PostedThu Aug 04, 2005 1:29 pm
by Sti-Fi
Hello all,

One of our ex-guild members who was kicked out on the *day* the CU launched for immaturity and harrassment, recently went overboard.

He's been dropping by our forums, creating accounts and harrassing players. He claimed to be a CSR and then in another post, said he sold his acct. Of course, he was reported to SOE as they do not take either of those lightly.

He'll leave us alone for a week, then come back in. Now, I'm on my 3rd programmer helping me with the PHP site and we know it needs to be upgraded to a more secure version.

Well...I managed to go in and delete his GOD acct and reset my password. However, I have been informed that the people he got to hack our site, also hacked the websites of people who have their URL in their Lost profile.

This site is safe, obviously, and so is any site with plain old HTML. If you have an older version of PHPNuke, please check your site asap.

Heck, many of you probably received the email about our hacked site.
*SIGH*

I'm posting this here, since it *does* affect SWG and those who play it. If it needs to be moved to Jibber Jabber or whatnot, that's cool.

Anyway...that's what I'm dealing with this morning. *le sigh*

PostedThu Aug 04, 2005 4:12 pm
by Seret Sajet
Thank you for the heads up. We are currently working on ways to secure the site though we are not by any means totally secure. Its important for everyone to keep a look out for things like these when they slip by.

Thanks again.

PostedThu Aug 04, 2005 4:14 pm
by Jabe Adaks
Well... to let the cat out of the bag and since we're hours away from correcting it... This site was compromised two days ago by an attacker who gained moderator access on all forums.

We will be taking these forums offline starting tonight in order to upgrade our software. The amount of time it will take to do this is uncertain. I do plan on having everything back online by Friday night (hopefully).

I did not want to announce this before the fact because I didn't want to encourage the attacker to resume their attempts. At any rate we know what they did and how they did it. Its patched already but we are doing a major upgrade anyway.

Jabe

PostedThu Aug 04, 2005 4:38 pm
by Sti-Fi
Seret Sajet wrote:Thank you for the heads up. We are currently working on ways to secure the site though we are not by any means totally secure. Its important for everyone to keep a look out for things like these when they slip by.

Thanks again.
I just hate that I had to post it in the first place. I mean, if it was just us, I wouldn't have said anything. But since Tymez convinced the goonwhatevers to do this for him *and* anyone who links to Lost...well..I had no choice.