Page 1 of 2

[Very Important] The site was hacked

PostPosted: 25 Jan 2013, 09:45
by Goblin Hero
Unfortunately the site was hacked. Some visitors were redirected to the fishing sites instead.
The vulnerability is now closed. But the intruder has had the ability to access/modify all files and databases.
So I'm highly recommend you to change your passwords.
I'm restoring the site from scratch to be sure all files are intact. For a little while only basic forum features will be available. Please, report any problems here or via PM.

Re: [Very Important] The site was hacked

PostPosted: 25 Jan 2013, 17:32
by Huggybaby
Thanks GH, changing password now. Pls consider sending a mass email notification.

Re: [Very Important] The site was hacked

PostPosted: 25 Jan 2013, 17:41
by Goblin Hero
Forum, bug tracker and wiki functionality is completely restored (I hope). Time to rest. Bugs are possible so do not forget to report it to me.
Main site page is redirecting to the forum now. I'm not sure what to do with the old vulnerable joomla CMS. Upgrading to the latest version will be very difficult and I'm not sure we need a big complex CMS on the site.
My current idea is to recreate old pages (about MA, MWS and other stuff) on wiki. Any suggestions?

Re: [Very Important] The site was hacked

PostPosted: 25 Jan 2013, 17:57
by Huggybaby
Hmmm...I'm not sure how that would work, the wiki already has tumbleweeds blowing through it.

Re: [Very Important] The site was hacked

PostPosted: 25 Jan 2013, 18:42
by MaraxusOfFishes
i can't find where to change the password. pls tell me.

Re: [Very Important] The site was hacked

PostPosted: 25 Jan 2013, 18:53
by Goblin Hero
MaraxusOfFishes wrote:i can't find where to change the password. pls tell me.
User Control Panel->Profile->Edit account Settings

Re: [Very Important] The site was hacked

PostPosted: 25 Jan 2013, 19:14
by Hellfish
That was quick work, I barely noticed the outage. oO
Thank you, Goblin Hero!

Re: [Very Important] The site was hacked

PostPosted: 25 Jan 2013, 20:51
by Max mtg
Looking much better now with svn up again.

Please restore favicon for the site. It helps a lot to distinguish tabs in browser.

Does the forum have any kind of its own portal? Might come handy to replace the broken frontpage.

Re: [Very Important] The site was hacked

PostPosted: 25 Jan 2013, 21:29
by pcastellazzi
Thank you very much for your time and effort.

Re: [Very Important] The site was hacked

PostPosted: 26 Jan 2013, 13:49
by Goblin Hero
Max mtg wrote:Please restore favicon for the site.
Restored.
Max mtg wrote:Does the forum have any kind of its own portal? Might come handy to replace the broken frontpage.
I'll check it.

Re: [Very Important] The site was hacked

PostPosted: 27 Jan 2013, 17:23
by Max mtg
Может такое подойдёт?* - https://www.phpbb.com/customise/db/mod/board3_portal/

* Please consider this link as an option to set up a portal on frontpage.

Re: [Very Important] The site was hacked

PostPosted: 28 Jan 2013, 12:18
by Goblin Hero
I've made my mind. There will be no CMS on my site. It's overkill. I'll recreate old pages in the wiki.
Pros:
1. Less software to update.
2. Less chances to be hacked again.
3. Everyone can contribute and edit the wiki (important pages will be locked).
Cons: can't find.
P.S. Here's a first example: http://www.slightlymagic.net/wiki/Magic_Album

Re: [Very Important] The site was hacked

PostPosted: 29 Jan 2013, 15:14
by Max mtg
I wish there were some kind of a portal to announce new software releases, new scans avaliable for download and very important messages like this thread.

Re: [Very Important] The site was hacked

PostPosted: 29 Jan 2013, 17:04
by Goblin Hero
Max mtg wrote:I wish there were some kind of a portal to announce new software releases, new scans avaliable for download and very important messages like this thread.
Special forum thread?

Re: [Very Important] The site was hacked

PostPosted: 31 Jan 2013, 08:02
by silly freak
Goblin Hero wrote:I've made my mind. There will be no CMS on my site. It's overkill. I'll recreate old pages in the wiki.
Pros:
1. Less software to update.
2. Less chances to be hacked again.
3. Everyone can contribute and edit the wiki (important pages will be locked).
Cons: can't find.
P.S. Here's a first example: http://www.slightlymagic.net/wiki/Magic_Album
Good! Will probably somewhat revive the Wiki from its minority status.

I usually stay logged in. You say it was a phishing attack. Does that mean that if I didn't provide my password during the last few weeks, it's not too probably that my password was affected?