You can help CodeWalrus stay online by donating here. | New CodeWalrus | Old (dark mode) | Old (light) | Discord server

Important security notice about your CodeWalrus account

b/Website News Started by Dream of Omnimaga, December 06, 2015, 04:31:35 AM

Previous topic - Next topic

0 Members and 2 Guests are viewing this topic.

u/bb010g December 07, 2015, 04:07:01 AM
Quote from: Cumred_Snektron on December 06, 2015, 10:20:46 AM
We used KeePassX on my dad's linux computer. The problem was he deleted the database one time and said it was my own fault <_<
baaaackuuuuups
u/Adriweb December 07, 2015, 04:22:28 AM
Yeah, I have access logs for that IP, same User agent etc.
Still doesn't tell who it actually is, though.
u/Dream of Omnimaga December 07, 2015, 04:35:03 AM
Indeed. I hope we will know one day. If the hacker has a CodeWalrus account or is on our IRC channel, so far the agreement with Street is that the user will get banned (I haven't managed to get an hold of Ivoah, Juju and Cumred about it yet). It's also possible that we start cracking down on Tor users and multi-user accounts on IRC and forums (eg banning them if they refuse to reveal who they are or to use a real IP address).
u/Adriweb December 07, 2015, 04:47:52 AM
The obvious action would be to ban the user/ip (if he's ever found with sufficient proof), but... the problem is that if it's a proxy, more than one person could be using this IP, including legit users. And it's not like the user in question wouldn't just use yet another IP and/or account to do whatever he's doing.

In the meantime, not much is known unless some IPs in France and a user-agent.
Last Edit: December 07, 2015, 04:52:23 AM by Adriweb
u/Dream of Omnimaga December 07, 2015, 04:50:16 AM
YEah, if it's a proxy then that could be a problem. I remember Omni had issues with false positive bans after many spambots were IP-banned. This is why we no longer ban spambots by their IP.
u/novenary December 07, 2015, 01:25:43 PM
Quote from: bb010g on December 07, 2015, 04:07:01 AM
Quote from: Cumred_Snektron on December 06, 2015, 10:20:46 AM
We used KeePassX on my dad's linux computer. The problem was he deleted the database one time and said it was my own fault <_<
baaaackuuuuups
Yup, I love that pass encrypts with PGP, I use git integration and have the store on a remote private repo and my phone as well, the only problem would be if I lost my private key.
u/Dream of Omnimaga December 07, 2015, 02:31:13 PM
Nanowar confirmed on Revsoft via news and a PM sent to me that Revsoft was attacked as well. Database was compromised.

@Juju please redo scans of the two suspicious IPs
u/novenary December 07, 2015, 02:36:56 PM
I see both IPs in today's Nginx logs. We should disable password authentication on ssh and use only private keys.
u/critor December 07, 2015, 03:32:27 PM
Quote from: Juju on December 07, 2015, 12:53:57 AM
Well, the most recent ones, as in, the last 3 incidents or so. He knows about other sites because we told him so.

And apparently he should stop assuming and implying strange things.

We've got hacking attempts almost everyday in the logs.
It's not because he doesn't know about it that it doesn't happen.
Last Edit: December 07, 2015, 03:35:26 PM by critor
u/alexgt December 07, 2015, 04:45:24 PM
This is strange how multiple websites are getting hacked at the same time O.O.
It is ISIS nooooo : P
u/Dream of Omnimaga December 07, 2015, 04:53:39 PM
Could this be why ticalc.org have troubles with their login and voting system since POTY started? @Travis should run some scans
u/Travis December 07, 2015, 06:55:44 PM
I did discover suspicious activity from 90.11.159.131 on ticalc.org yesterday. We're investigating.

Edit: We may have something official to say later, but at this point, I do strongly recommend that people consider change their ticalc.org passwords now, especially if you're using the same passwords for anything else.
Last Edit: December 07, 2015, 07:39:29 PM by Travis
u/KermMart̕ian December 07, 2015, 07:21:36 PM
Sorry to hear that you guys were also hit a day later by this attacker. I hope as a community we can all get to the bottom of who feels so destructively towards us.
Last Edit: December 09, 2015, 02:12:24 AM by KermMartian
u/alexgt December 07, 2015, 07:43:39 PM
Well, if they blame us it doesn't mean that CW is bad it means there is a member that should be banned.
u/Lionel Debroux December 07, 2015, 07:48:53 PM
Quote from: KermMartian on December 07, 2015, 07:21:36 PM
Of course, this all happened after the rest of the community noted how interesting it was that CodeWalrus was spared. That's a very unfortunate coincidence.
Strongly disappointed by your first comment ever on CW, Kerm, though not surprised nowadays. You know you can be a much more useful community member than you show here.
Last Edit: December 10, 2015, 09:48:48 PM by Lionel Debroux
Website statistics


MyCalcs | Ticalc.org | Cemetech | Omnimaga | TI-Basic Developer | MaxCoderz | TI-Story | Casiocalc.org | Casiopeia | The Museum of HP Calculators | HPCalc.org | CnCalc.org | Music 2000 Community | TI Education | Casio Education | HP Calcs | NumWorks | SwissMicros | Sharp Calculators
Powered by EzPortal