English Amiga Board


Go Back   English Amiga Board > News

 
 
Thread Tools
Old 21 August 2020, 12:39   #21
mcgeezer
Registered User
 
Join Date: Oct 2017
Location: Sunderland, England
Posts: 2,702
Quote:
Originally Posted by DamienD View Post
What would you know Graeme; do you work in IT Security or something as a profession?

<joning of course, I know you do>
Lol... no mate, the last 20 years i’ve been making Amiga games as a profession.
It’s why i can only afford to have smoked salmon once a week instead of three.
mcgeezer is offline  
Old 21 August 2020, 17:40   #22
LongLifeA1200
Registered User
 
LongLifeA1200's Avatar
 
Join Date: Nov 2017
Location: Amiga Kingdom
Posts: 368
There has been an update of good news.
LongLifeA1200 is offline  
Old 21 August 2020, 18:08   #23
SquawkBox
Speedbump gimme goosebump
 
SquawkBox's Avatar
 
Join Date: Feb 2016
Location: France
Age: 50
Posts: 791
Send a message via ICQ to SquawkBox
Password changed. Thanks for the heads up.
SquawkBox is offline  
Old 21 August 2020, 19:45   #24
rare_j
Zone Friend
 
rare_j's Avatar
 
Join Date: Apr 2005
Location: London
Posts: 1,179
It's such a shame that running a forum as a hobbyist is basically lo longer viable.
Whether its from gdpr or constant hack attempts you more or less need a managed service now unless your hobby is also IT security and web privacy law.
rare_j is offline  
Old 22 August 2020, 09:00   #25
ztronzo
Registered User
 
ztronzo's Avatar
 
Join Date: Sep 2015
Location: Montreal
Posts: 301
I make it a habbit to always use a different password for different hosts.. this covers the case of your password being leaked from any...
otherwise in a while you will receive a blackmail e-mail by a scammer telling you "we got your password" etc etc... "send money so we dont leak your webcam vids" etc etc... (even if you dont have a webcam) :-P
ztronzo is offline  
Old 22 August 2020, 10:38   #26
S0ulA55a551n
Registered User
 
S0ulA55a551n's Avatar
 
Join Date: Nov 2010
Location: South Wales
Age: 47
Posts: 947
Did you say the used all of the hacked accounts to upvote Doom to the top of the table. ?????

Anyone smell Doomy ? ??

Quote:
Originally Posted by DamienD View Post
What would you know Graeme; do you work in IT Security or something as a profession?

<joking of course, I know you do>
Not info-sec, the bane of my life

Last edited by lilalurl; 22 August 2020 at 12:36.
S0ulA55a551n is offline  
Old 12 July 2024, 22:35   #27
lifeschool
Local Moderator
 
lifeschool's Avatar
 
Join Date: Oct 2009
Location: Lancashire, UK
Age: 48
Posts: 1,661
SQL injection, LA and L64 sites compromised. The hackers want money to reveal how they did it.

It may take some time to secure the site, but Kim says it can be done given some time.

This is an increasing problem, so I hope eab is secure?
lifeschool is offline  
Old 13 July 2024, 07:27   #28
TCD
HOL/FTP busy bee
 
TCD's Avatar
 
Join Date: Sep 2006
Location: Germany
Age: 46
Posts: 32,176
Ouch Fingers crossed it can be sorted quickly. I'll ask RCK about it once he is available again.
TCD is offline  
Old 13 July 2024, 09:15   #29
jurassicman
Registered User
 
jurassicman's Avatar
 
Join Date: Dec 2017
Location: Sassari/Italy
Posts: 908
Damn! I did notice that the site was down and I suspected something bad... hopefully the site will be fixed and up soon and there won't be data loss...
jurassicman is offline  
Old 13 July 2024, 09:31   #30
dreadnought
Registered User
 
Join Date: Dec 2019
Location: Ur, Atlantis
Posts: 2,130
Going after some niche hobby sites, that's really f-ed up.
dreadnought is offline  
Old 13 July 2024, 10:04   #31
Ian
Global Moderator
 
Ian's Avatar
 
Join Date: May 2001
Location: Derby, UK
Age: 46
Posts: 2,300
A niche forum will be an easy target, sadly

I don't know what forum software they use over there but anything bought probably has a huge list of known vulnerabilities a hacker or even just a script kiddie could use.

That's why you've got to keep up with the updates and even then there's no guarantee they fix everything.
Ian is offline  
Old 13 July 2024, 12:49   #32
AestheticDebris
Registered User
 
Join Date: May 2023
Location: Norwich
Posts: 466
It's gutting that people out there are so petty, but unfortunately they are. And that, more than anything is why Forums should run on modern, updated software even if it means they aren't as easily browsable on a real Amiga.
AestheticDebris is offline  
Old 13 July 2024, 13:07   #33
dreadnought
Registered User
 
Join Date: Dec 2019
Location: Ur, Atlantis
Posts: 2,130
...but hasn't Lemon been overhauled recently? I'm pretty sure there was a big update to the software somewhere last year. Also all the passwords were force-changed.
dreadnought is offline  
Old 13 July 2024, 13:15   #34
Retroplay
Lemon Curry ?
 
Retroplay's Avatar
 
Join Date: Sep 2004
Location: Denmark
Age: 49
Posts: 4,153
Yes, it was.
I lost my old Lemon64 account because of it.
The email I used to register way back when in early 2000s went down the tubes just before that happened and it's needed to update password on my old forum account.
Retroplay is offline  
Old 13 July 2024, 13:40   #35
lifeschool
Local Moderator
 
lifeschool's Avatar
 
Join Date: Oct 2009
Location: Lancashire, UK
Age: 48
Posts: 1,661
The forum uses PHPBB. I presume the database uses SQL. Hackers can get around any updates and just walk straight in to your computer unless you get domain protection, and even then, using SQL is very old.

It's going to take maybe a few weeks to sort this out, maybe months, so all we can do is wait and see. No data has been deleted. From the look of things, its the domain which seems hacked.
lifeschool is offline  
Old 13 July 2024, 14:33   #36
AestheticDebris
Registered User
 
Join Date: May 2023
Location: Norwich
Posts: 466
Quote:
Originally Posted by lifeschool View Post
The forum uses PHPBB. I presume the database uses SQL. Hackers can get around any updates and just walk straight in to your computer unless you get domain protection, and even then, using SQL is very old.
SQL injection is a flaw in non SQL code, not in SQL itself. And it's very easy to avoid so there's really no excuse for a modern system to be vulnerable to it.
AestheticDebris is offline  
Old 13 July 2024, 14:50   #37
Megalomaniac
Registered User
 
Join Date: Sep 2022
Location: Eastbourne
Posts: 1,125
It's a nightmare for us to be without this invaluable resource for Amiga and C64 retrogaming. I'd noticed an increase in the amount of spam messages recently, which may be related to what's happened. I really hope it can be back up and running shortly. Do we know what the impact on the competition will be?

Not sure of the exact situation with the sites, but I know Kim Lemon himself has had health challenges in recent years, so that may have limited the time that could be put into securing the site.
Megalomaniac is offline  
Old 13 July 2024, 18:24   #38
kremiso
Registered User
 
Join Date: Dec 2020
Location: Italy
Posts: 1,974
what a sad news
wondering whats the point in attacking a retrogaming forum
kremiso is offline  
Old 13 July 2024, 18:24   #39
lifeschool
Local Moderator
 
lifeschool's Avatar
 
Join Date: Oct 2009
Location: Lancashire, UK
Age: 48
Posts: 1,661
Quote:
Originally Posted by AestheticDebris View Post
SQL injection is a flaw in non SQL code, not in SQL itself. And it's very easy to avoid so there's really no excuse for a modern system to be vulnerable to it.
Can you explain how it is possible to avoid it? For example, is it the uploading of files to the server which is the leak? Or perhaps somehow the custom back end is the issue? I dont know what an SQL injection is, so any help might help Kim put things back together. He describes it as looking for "needles in a haystack". But maybe if he can understand the vulnerabilities, it can help to pin down the issues?

Quote:
Originally Posted by Megalomaniac View Post
It's a nightmare for us to be without this invaluable resource for Amiga and C64 retrogaming. I'd noticed an increase in the amount of spam messages recently, which may be related to what's happened. I really hope it can be back up and running shortly. Do we know what the impact on the competition will be?

Not sure of the exact situation with the sites, but I know Kim Lemon himself has had health challenges in recent years, so that may have limited the time that could be put into securing the site.
Kim is currently feeling better, or at least able to look at this for us. He has contacted the Law today, but I can't imagine how this can help us. Spam is just spam, and any bot can sent it, but this was a hijack.

I dont know what you mean by competition. If you mean rival sites like MobyGames, maybe they will be ok? I dont think this is targetting Commodore users specifically, (or we should start asking around Atari Age), and these guys seem like chancers to me. If you mean the games competition on L64, the scores are kept on a different server, so it should be possible to make a post in the Competition section of EAB and carry on posting scores as normal. We dont know if this will be fixed any time soon, so at this stage I am willing to risk saying maybe a few months?

Last edited by lifeschool; 13 July 2024 at 18:31.
lifeschool is offline  
Old 13 July 2024, 18:50   #40
Seiya
Registered User
 
Seiya's Avatar
 
Join Date: Nov 2014
Location: Italy
Posts: 2,485
If they have a backup of forum and site, could be move to another server.
Seiya is offline  
 


Currently Active Users Viewing This Thread: 2 (0 members and 2 guests)
 
Thread Tools

Similar Threads
Thread Thread Starter Forum Replies Last Post
amiga magix website is hacked Retro-Nerd Amiga scene 19 14 July 2006 03:31
The Lemon Amiga forum is Launched Lemon News 13 15 July 2004 23:03
Amiga.com hacked ! RCK Amiga scene 34 29 December 2002 01:01
Another Amiga WebPage Hacked Carlos Ace Amiga scene 13 11 May 2002 01:21
Amiga.org Hacked/Down Galahad/FLT Amiga scene 3 24 December 2001 16:35

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 07:28.

Top

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
Page generated in 0.14350 seconds with 14 queries