CincyBattletech

Please login or register.

Login with username, password and session length
Advanced search  

News:

Reactor: Online.  Sensors: Online.  Weapons: Online.  All systems nominal.

Pages: [1] 2

Author Topic: Official Battletech Forums Down  (Read 3455 times)

Death or Glory

  • Showers
  • Command Master Sergeant
  • ****
  • Posts: 572
    • View Profile
Official Battletech Forums Down
« on: January 21, 2011, 02:21:46 AM »

I just tried to access the classicbattletech.com forums and received the following message:

"Due to a security breach the forums are being taken down indefinitely while the damage to the system is accessed. Because of the nature of this breach it is unlikely we will be restoring a backup of user accounts as it is impossible to know who's passwords and accounts have been compromised.

We are currently accessing our options and will get the forums back up in one form or another as soon as possible. Thank you for your patience.

Jason M. Knight classicbattletech.com System Administrator"

Does anyone know anything about this beyond what was stated in that message?
Logged

maddyfish

  • Corporal
  • ***
  • Posts: 189
  • The sword and hammer
    • View Profile
Re: Official Battletech Forums Down
« Reply #1 on: January 21, 2011, 09:26:13 AM »

Well, last night the forums were up, sort of, most of the posts were missing, and some users were missing, some accounts deleted, including Deathshadow.
Logged
Have Wasp, will travel.

ItsTehPope

  • Pontificus Rex
  • Administrator
  • Lieutenant
  • *****
  • Posts: 1823
    • View Profile
Re: Official Battletech Forums Down
« Reply #2 on: January 21, 2011, 12:32:52 PM »

I just tried to access the classicbattletech.com forums and received the following message:

"Due to a security breach the forums are being taken down indefinitely while the damage to the system is accessed. Because of the nature of this breach it is unlikely we will be restoring a backup of user accounts as it is impossible to know who's passwords and accounts have been compromised.

We are currently accessing our options and will get the forums back up in one form or another as soon as possible. Thank you for your patience.

Jason M. Knight classicbattletech.com System Administrator"

Does anyone know anything about this beyond what was stated in that message?


Whatever the issue is, its serious.  As we run the same package they do at CBT, I'm inclined to mandate password resets to be on the safe side
Logged

maddyfish

  • Corporal
  • ***
  • Posts: 189
  • The sword and hammer
    • View Profile
Re: Official Battletech Forums Down
« Reply #3 on: January 21, 2011, 01:53:29 PM »

ugh, I didn't even think about that, I have the same password here as at CBT.com.


Maddyfish exits to change password
Logged
Have Wasp, will travel.

Knightofargh

  • Semper Senex Morosus
  • Corporal
  • ***
  • Posts: 231
    • View Profile
Re: Official Battletech Forums Down
« Reply #4 on: January 21, 2011, 02:36:16 PM »

I just tried to access the classicbattletech.com forums and received the following message:

"Due to a security breach the forums are being taken down indefinitely while the damage to the system is accessed. Because of the nature of this breach it is unlikely we will be restoring a backup of user accounts as it is impossible to know who's passwords and accounts have been compromised.

We are currently accessing our options and will get the forums back up in one form or another as soon as possible. Thank you for your patience.

Jason M. Knight classicbattletech.com System Administrator"

Does anyone know anything about this beyond what was stated in that message?


Whatever the issue is, its serious.  As we run the same package they do at CBT, I'm inclined to mandate password resets to be on the safe side

I'm confused at this "serious" description as all things released by CSIRC are "serious" and what you are suggesting appears to be "proactive" which we frown upon.  Oh wait, that's my federal contractor habits coming out. 

This is a very good reason to keep your fora and online services userids/passwords separate.  Heck my real name can't be (easily) linked to my online handle (currently) and I like it that way.
Logged

serrate

  • Howe
  • Lieutenant
  • *****
  • Posts: 1851
    • View Profile
Re: Official Battletech Forums Down
« Reply #5 on: January 24, 2011, 11:16:01 AM »

I saw a copied post on LotB, from BattleCorps, that the forums were supposed to be back up today.  Anyone heard anything more recent/specific?
Logged

phlop

  • Painting God
  • Master Sergeant
  • ****
  • Posts: 719
    • View Profile
Re: Official Battletech Forums Down
« Reply #6 on: January 24, 2011, 11:47:27 AM »

They weren't as of 0800. Haven't checked since then.
Logged

Darrian Wolffe

  • Hazen
  • Administrator
  • Colonel
  • *****
  • Posts: 4868
    • View Profile
Re: Official Battletech Forums Down
« Reply #7 on: January 24, 2011, 03:18:03 PM »

From DeathShadow, on the HMPro forums:

Quote
Update from deathshadow at HMPro quote:

"Well, here's where we're at and the current battleplan.

It appears that we may have had TWO hacks occur near simultaneously or with overlap -- a nasty fast one atop a slow/insidious one.

The nasty fast one somehow got itself elevated to admin rights and started deleting users MANUALLY and running mySQL commands to delete post indexes from the database -- and we're not talking indexes that can be rebuilt either. Since they appear to have had access to admin rights I cannot/will not trust any of the existing user accounts that were on it. It's odd though as they used a certain admin password without it showing up as being logged in for that user -- so I think they found a security flaw or had a backdoor installed from that previous failed hacking attempt back in July. (that I thought I cleaned out)... either that or the TWO DAYS since SMF 1.1.13 was released documented a new doorway. (and I was going to upgrade tomorrow too...). Maybe a four day upgrade gap was too wide?

The slow/insidious one appears to have been modifying forum .php files in the background slowly and quietly that I THINK was a failed attack circa late October, and that up and decided to start running when the 'fast one' started playing around with it.

It is unclear whether these were two separate attacks, or a slowly and well planned escalation over several months... Going through the monthly backups I am unwilling to trust the Jan, Dec or Nov backups as they all seem to have a slow corruption and bits and pieces of various hacking attempts in them. SO...

I'm with Ripley...

To try and turn this into a positive I'm going to take this 'nuke it from orbit' moment to move us to SMF 2.0 even if it is only at release candidate status -- I was going to wait for final but if we're going to start over, I'd like to do so on the next-gen.

It is going to take me a few days to get it to where I'm happy with the new security settings I'll be putting in place (things actually COULD have been worse!!! Lord help us if the main site had been running turdpress or boomla) at which point I'm gonna have the admins and mods go in and dot every t and cross every i on getting the correct forums and settings into place. We're also going to take this opportunity to review the rules and who's responsible for what.

We probably will NOT have a new forums up and running for the public until sometime after monday. I apologize for the delay but the old forum was starting to rot and was hack upon hack upon upgrade upon upgrade -- and like anything else after three years of use it needed a spring cleaning anyways. (TRYING to look at the bright side here!)

I'll try to keep you posted here as to where I'm at with this.

Oh, and if you know who's at 192.251.226.205 (that's a german IP), do me a favor and shove your boot straight up their backside. I should have listened to George -- I put up one of the biggest static fortifications possible on a server; and it ended up a Maginot line. Leave it to some German to goose-step through Belgium on me.

Fixed fortifications are a monument to the stupidity of man."




Folks, while we may WANT to speculate on who or what might have done this, there's no way to know.  The IP addy in questions is part of a specifically anonymous network known as "Tor" that largely exists to allow people to do things like this and trade illegal images.  The IP address in question, while German, doesn't mean that the attack originated from Germany, only that that IP address is as far as it can be traced.  Speculating that the attacker was HeroChip, or FrankTrollman, or Games Workshop isn't going to help.  Even if it might have been all three of them, working together while renting out WOTC's secret volcano lair...
Logged

agustaaquila

  • Backstabbing Capellan
  • Lieutenant J.G.
  • *****
  • Posts: 1376
    • View Profile
Re: Official Battletech Forums Down
« Reply #8 on: January 24, 2011, 03:29:26 PM »

Dan, we all know the real perpetrators of this all live in Flint Michigan and are angry about  Blake's insane devotees getting what was due to them. 

In alternate news, I have started to pray before turning on my computer to apisethe machine spirits within.
Logged

serrate

  • Howe
  • Lieutenant
  • *****
  • Posts: 1851
    • View Profile
Re: Official Battletech Forums Down
« Reply #9 on: January 24, 2011, 04:03:55 PM »

I know who Frank Trollman is, but who is HeroChip?
Logged

ItsTehPope

  • Pontificus Rex
  • Administrator
  • Lieutenant
  • *****
  • Posts: 1823
    • View Profile
Re: Official Battletech Forums Down
« Reply #10 on: January 24, 2011, 06:46:58 PM »

I know who Frank Trollman is, but who is HeroChip?

Bees man, goddamned bees!
Logged

serrate

  • Howe
  • Lieutenant
  • *****
  • Posts: 1851
    • View Profile
Re: Official Battletech Forums Down
« Reply #11 on: January 25, 2011, 03:58:17 PM »

Late afternoon on Tuesday, and still nothing.  Travesty.
Logged

maddyfish

  • Corporal
  • ***
  • Posts: 189
  • The sword and hammer
    • View Profile
Re: Official Battletech Forums Down
« Reply #12 on: January 25, 2011, 05:33:39 PM »

New CBT forums,  Coming Soon!
Logged
Have Wasp, will travel.

Darrian Wolffe

  • Hazen
  • Administrator
  • Colonel
  • *****
  • Posts: 4868
    • View Profile
Re: Official Battletech Forums Down
« Reply #13 on: January 25, 2011, 06:14:05 PM »

Don't worry - they'll be back up the day after the 25th Anniversary Boxed Set is released.


(DS: If you end up reading this - for god's sake it was a joke.)
Logged

maddyfish

  • Corporal
  • ***
  • Posts: 189
  • The sword and hammer
    • View Profile
Re: Official Battletech Forums Down
« Reply #14 on: January 25, 2011, 09:13:50 PM »

back up as of 9:15 tonight well maybe, it says it sent me a notification email, but, not so much


I have received no email.


9:55 still no email, trying hitting the resend button. Oh well.
« Last Edit: January 25, 2011, 09:56:28 PM by maddyfish »
Logged
Have Wasp, will travel.
Pages: [1] 2