Originally posted by PaulW2U
View Post
Announcement
Collapse
No announcement yet.
Ubuntu Forums hacked
Collapse
This topic is closed.
X
X
-
- Top
- Bottom
-
Originally posted by Detonate View PostOne of the favorite tricks of spammers is to send out an email appearing to be from a financial institution saying you need to update your profile and change your password. The email will contain a link to the spammers web site that will look like the financial institute's web site. If the site spoofed is your financial institution, you could be sucked in. Well, not anyone on this forum would be tricked, but a lot of folks would.Kubuntu 22.04 (desktop & laptop), Windows 7 &2K (via VirtualBox on desktop PC)
================================
- Top
- Bottom
Comment
-
Originally posted by Detonate View PostOne of the favorite tricks of spammers is to send out an email appearing to be from a financial institution saying you need to update your profile and change your password. The email will contain a link to the spammers web site that will look like the financial institute's web site. If the site spoofed is your financial institution, you could be sucked in. Well, not anyone on this forum would be tricked, but a lot of folks would.
My bank now addresses me by name and includes either the last four digits of my account number or part of my address. I hope all banks now follow a similar practise.
if the email isn't addressed to you personally then it's not for you.
- Top
- Bottom
Comment
-
Originally posted by PaulW2U View PostYes, I've had hundreds, no thousands of those over the years and some are very believable. But then they go and ask you for your complete password rather than just two or three characters as per the bank's standard practise.
My bank now addresses me by name and includes either the last four digits of my account number or part of my address. I hope all banks now follow a similar practise.
if the email isn't addressed to you personally then it's not for you.
It would be interesting to know how Ubuntuforums got hacked, but I'd doubt we ever will.Kubuntu 22.04 (desktop & laptop), Windows 7 &2K (via VirtualBox on desktop PC)
================================
- Top
- Bottom
Comment
-
Originally posted by Tom_ZeCat View PostEven if it were addressed to me personally, I would not trust it. I would call the bank.
Originally posted by Tom_ZeCat View PostIt would be interesting to know how Ubuntuforums got hacked, but I'd doubt we ever will.
See http://ubuntu-discourse.org/t/looks-...3/65?u=paulw2u. cariboo907 is an admin on the Ubuntuforums site.Last edited by Guest; Jul 22, 2013, 09:56 PM.
- Top
- Bottom
Comment
-
Originally posted by PaulW2U View PostSee http://ubuntu-discourse.org/t/looks-...3/65?u=paulw2u. cariboo907 is an admin on the Ubuntuforums site.
We now know what happened, it wasn't anything to do with a security hole in VB, all this came about via social engineering and legacy problems left over from when the previous owner was still running the forum.
For some reason, some of the loco mods had admin privileges, and it was one of those accounts that was compromised, along with quite a few hooks in pnp that allowed the attacker tp deface the site.
Canonical IS is in the process of rectifying the problems.Windows no longer obstructs my view.
Using Kubuntu Linux since March 23, 2007.
"It is a capital mistake to theorize before one has data." - Sherlock Holmes
- Top
- Bottom
Comment
-
While nosing around fedora forums I found this thread.
In light of the Ubuntu Hack and recent suggestions, the use of Avatars has been removed for now.
Ken.Opinions are like rear-ends, everybody has one. Here's mine. (|)
- Top
- Bottom
Comment
-
Pan-Galactic QuordlepleenSo Long, and Thanks for All the Fish
- Jul 2011
- 9524
- Seattle, WA, USA
- Send PM
Originally posted by Frank616 View PostI too was surprised that the member information could have been taken from a Linux site.Originally posted by Tom_ZeCat View PostThey were using a Microsoft OS for their server, ew, ew, ew, and their security practices were poor. I did not expect a Linux forum to get hacked.
Originally posted by Snowhog View PostHis comment: "We now know what happened, it wasn't anything to do with a security hole in VB, all this came about via social engineering and legacy problems left over from when the previous owner was still running the forum. For some reason, some of the loco mods had admin privileges, and it was one of those accounts that was compromised, along with quite a few hooks in pnp that allowed the attacker tp deface the site."
Originally posted by lcorken View PostWhile nosing around fedora forums I found... "In light of the Ubuntu Hack and recent suggestions, the use of Avatars has been removed for now." Don't know how they got that idea or if it's valid. Hopefully it's nothing. I kind of like the avatars.
- Top
- Bottom
Comment
-
Originally posted by SteveRiley View PostThe fact that a site is based on Linux is not a guarantee that it can't be attacked. The fact that a site is based on Windows is not a guarantee that it will always be attacked. Poor administrative practices almost always trump operating system exploits, and this is true for every platform.Kubuntu 22.04 (desktop & laptop), Windows 7 &2K (via VirtualBox on desktop PC)
================================
- Top
- Bottom
Comment
-
Originally posted by SteveRiley View PostWhat a curious reaction...I am flummoxed as to how disallowing avatars might reduce any risk -- unless Fedora Forum permits executable code, like Javascript, in their avatars? That's unwise.sigpic "Let us think the unthinkable, let us do the undoable, let us prepare to grapple with the ineffable itself, and see if we may not eff it after all." -- Douglas Adams
- Top
- Bottom
Comment
-
Pan-Galactic QuordlepleenSo Long, and Thanks for All the Fish
- Jul 2011
- 9524
- Seattle, WA, USA
- Send PM
-
Pan-Galactic QuordlepleenSo Long, and Thanks for All the Fish
- Jul 2011
- 9524
- Seattle, WA, USA
- Send PM
-
man people are getting pissy over on UF trying to log in, etc. Seems they direct people to "ubuntu one" - which is using their Single Sign-On system (SSO) which is used for Launchpad, the wikis, etc, including U1. SO some are thinking they are being forced to sign up for U!, and by gum they'll switch to Arch over this!!!! lololololololol
This is a classic tl;dr as this was clearly explained on the main page. Having said that, going to login.ubuntu.com makes it look like you are signing up for U1 (and in a sense you are)
I am not one to dis a distro's user base, but if all these angry sticks do go to that distro, I sure won't venture there...and probably all the hardcore Archers will go somewhere else because of all the griping gumps lol!
And gee, that theme is still garish.
- Top
- Bottom
Comment
Comment