Jump to content


Toggle shoutbox Shoutbox Open the Shoutbox in a popup

@  furrykef : (24 July 2015 - 11:25 AM)

Also I still have to figure out how to set up our e-mail accounts on the new host.

@  furrykef : (24 July 2015 - 08:19 AM)

As soon as I figure out how to restore it. Sorry, I know I said it'd be done by now, but I didn't expect to have to put up with this DNS crap and other issues that popped up.

@  Uncle Ben : (24 July 2015 - 07:56 AM)

So when's the black theme coming back??

@  Uncle Ben : (24 July 2015 - 07:56 AM)

"Should"

@  furrykef : (24 July 2015 - 07:27 AM)

That DNS took longer to propagate properly than I thought it would. *Now* we should be back for good, though.

@  furrykef : (23 July 2015 - 08:48 PM)

Or it might be because Bluehost *finally* got around to that server wipe (one week after we'd asked for it) and that wiped out our DNS settings. I'm not sure which and I don't really care. In any case, we've severed our last ties with Bluehost, so this will not happen again.

@  furrykef : (23 July 2015 - 08:08 PM)

Looks like Bluehost yanked our DNS since our hosting account expired. That's why the site went down a while ago. But as you can see, it's fixed now.

@  Misk : (23 July 2015 - 04:55 PM)

No, they do not.

@  furrykef : (23 July 2015 - 04:27 AM)

The goggles do nothing?

@  Misk : (22 July 2015 - 05:50 PM)

My eyes.

@  furrykef : (22 July 2015 - 12:24 PM)

Looks like forum uploads might have been broken since last night. That should be fixed now too.

@  furrykef : (22 July 2015 - 01:33 AM)

Heh, whoops! Server went down for a few mins when I borked the config. Looks like it's back up now.

@  Uncle Ben : (21 July 2015 - 09:09 PM)

It looked like a napkin

@  ILOVEVHS : (21 July 2015 - 09:04 PM)

Fan-fuckin-tastic.

@  furrykef : (21 July 2015 - 08:25 PM)

As for the beaver picture while the forum was down, I think Tim drew it. On a napkin.

@  furrykef : (21 July 2015 - 08:24 PM)

No kiddin' about that "Finally!", Shadow. I am *so mad* at Bluehost for never responding to our support ticket. I submitted it early Friday morning and they *still* haven't answered it!

@  Uncle Ben : (21 July 2015 - 06:37 PM)

Maybe he did that himself

@  Shadow : (21 July 2015 - 05:25 PM)

Say, who made the cute picture of Beaver Chief?

@  Shadow : (21 July 2015 - 05:24 PM)

Finally!

@  RedMenace : (21 July 2015 - 05:02 PM)

Woooo! The site's back up! Three cheers for Kef!


Photo

Fus Has Been Hacked


  • Please log in to reply
4 replies to this topic

#1 FUS News Robot

FUS News Robot

    Extra! Extra!

  • Newsbot
  • 144 posts
  • Gender:Not Telling

Posted 07 June 2015 - 09:00 PM

I have some grave news, amigos.

On May 30th, FUS was hacked by a spammer. We still don't know for 100% certain how they got in, but I'm 99% certain they got in through a Wordpress exploit, since our Wordpress was rather out of date. The main thing they did, possibly the only thing, was put up a bunch of spam pages and maybe send out spam e-mails.

But there is also a chance they got ahold of the forum database, including the password table. The passwords are encrypted (or more accurately "hashed"), which means they cannot just read your password, but they might be able to decode some of them. If you reused your FUS password anywhere else, such as for an e-mail account, we highly recommend changing those passwords just to be safe. Also, though we think the chance is tiny, FUS may still be compromised for the moment. Now, the chance they got or will get your password is very small, but it's not impossible.

We think we have patched up the security holes, but the nature of security is one can never be too sure. So what we're going to do is torch the site and run. *ahem* I mean, we're going to make a big backup of everything, wipe the server, and then put everything back in as secure a manner as possible. That means that, within a day or two, FUS is going to be down for probably a few hours. We won't lose anything; when we're back up, everything will still be there and, we hope, it will look as though nothing had ever happened.

We deeply apologize for the inconvenience. Heck, it's a hassle for us too! But bear with us and everything should be fine within a couple of days, OK?

Read the full story here



#2 furrykef

furrykef

    Fellow FUSer

  • Tech Guy
  • 3,983 posts
  • Gender:Male

Posted 09 June 2015 - 12:07 AM

I have not done the full reinstall just yet. I may start the process within the next couple of hours or I might wait until tonight; it depends on when I finish preparations and how confident I am in them.

Anyway, it seems clear now that FUS is currently compromised. A malicious "indes.php" (note the "s") file was uploaded or generated a few hours ago which allows anyone who uses it to execute arbitrary PHP code. Hopefully, this was just generated by something left over from the previous hacking and isn't a sign of new hacking, in which case things should still be back to normal after I do the full reinstall.

#3 HeavensChampion

HeavensChampion

    Fellow FUSer

  • Fellow FUSer
  • 137 posts

Posted 09 June 2015 - 12:25 AM

I've changed my password, and I'll say just that.



#4 Arekkisu

Arekkisu

    The Pymann

  • Game Staff
  • 1,245 posts
  • Gender:Male
  • Location:Earth

Posted 10 June 2015 - 10:22 AM

Should I do a double check through all my files because my site is hosted through FUS or should I be safe?


p4YlRRx.png


#5 furrykef

furrykef

    Fellow FUSer

  • Tech Guy
  • 3,983 posts
  • Gender:Male

Posted 10 June 2015 - 10:33 AM

I upgraded your Wordpress to 4.2.2 last night, and I haven't found anything compromised in it. Your site should be safe. You may still want to change the password of your Wordpress account, because they may still have read your database, but you might as well wait until the reinstall first 'cause FUS may still be compromised (and so you'd just have to change it again).




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users