Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi all! We have been experiencing an issue on site where threads have been missing the latest postings. The platform host Vanilla are working on this issue. A workaround that has been used by some is to navigate back from 1 to 10+ pages to re-sync the thread and this will then show the latest posts. Thanks, Mike.
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Boards.ie Attack - What Happened? Please post all questions here.

  • 22-01-2010 8:05pm
    #1
    Business & Finance Moderators, Entertainment Moderators Posts: 32,387 Mod ✭✭✭✭DeVore


    As you are most likely aware, we had an unauthorised access of the site's database. As a result you will need to request your new password using our forgotten password system. You should obviously NOT change it back to your old password.

    We also suggest that if you used your old password on other sites with the same username/email then you should change it there too.

    This thread is to answer your questions; ideally people won’t use it to converse about side topics. If you keep it to direct questions I will try to answer them directly too.

    I'm on stage all this week in the Boards Drama Group (No Drama)'s play so I wont be on until after 11pm this evening.

    The order of events of the day are appended below.

    DeV.
    • 11:22 – Administrative account compromised

    • 11:22 -> 11:34 – Administrative account used to insert malicious code into our software

    • 11:34 – User table dumped to public directory and downloaded

    • 11:36 – Unauthorized access spotted by technical team

    • 11:37 – Unauthorized files quarantined

    • 11:38 -> 11:50 – Investigating nature of access

    • 11:50 – Web servers shut down, shifted to maintenance mode to prevent further access

    • 12 noon – Team met to discuss our responses; as part of that we contacted IT Security specialist Brian Honan and communications specialist Damien Mulley. We took the following actions as our process specified and taking expert advice on board also.

    • Extended investigation of breach, it's cause, and planning of solution.

    • Initiated communications with the Garda Computer Crime Unit

    • Contacted the Data Protection Commissioner to make them aware of events.

    • Composed a Press Release and released it to relevant media.

    • Contacted the Press Office of RTE.ie to organise/facilitate 6.1 News report to broaden the reach of our notice.

    • Composed email to members and message for homepage to ensure facts were communicated clearly and openly

    • 16:00 Published homepage message and started sending approximately 300,000 emails.

    • Communicated with members via twitter and emailed queries

    • Responded to media queries including RTE news, The Last Word on TodayFM, KCLR FM, Techcentral.ie, Sunday Business Post, Irish Daily Mail, Metro Herald.

    • Communicated to member queries via Twitter and Email throughout the evening and all of today.
    Post edited by Shield on


«13456713

Comments

  • Registered Users, Registered Users 2 Posts: 11,987 ✭✭✭✭zAbbo


    Well done lads, very well communicated & handled. Kudos to the whole team.


  • Registered Users, Registered Users 2 Posts: 14,292 ✭✭✭✭ctrl-alt-delete


    Are the rumours about it being Lucky Lloyd true?

    he was out of the country after all!


  • Registered Users, Registered Users 2 Posts: 85,039 ✭✭✭✭Overheal


    Thank God - my caffeine-free solidarity is over. I had already fallen off my chair in Work.

    funny-pictures-kitten-has-a-happy.jpg


  • Registered Users, Registered Users 2 Posts: 804 ✭✭✭TimTim


    Just two questions from me:

    I know vBulletin hashes passwords using MD5 but was there a salt used in hashing? (is it even possible with vbulletin?)

    If the above answer is no is it possible to get my original hashed password sent by pm? I actually can't remember what password I used for boards.ie and I need to figure out what logins i need to reset.


  • Registered Users, Registered Users 2 Posts: 30,123 ✭✭✭✭Star Lord


    Well done to all involved. We missed ya!

    *hugs site*


  • Advertisement
  • Banned (with Prison Access) Posts: 23,089 ✭✭✭✭rovert


    The new password procedure was a piece of piss thankfully.

    Cheers


  • Registered Users, Registered Users 2 Posts: 40,038 ✭✭✭✭Sparks


    No, no, it was bikers.ie.
    Because, as you know, we're amateur hour here and store the passwords on the website.



    Along with the secret recipe for coca-cola and KFC chicken.


  • Registered Users Posts: 430 ✭✭moralproduction


    fair play to all involved in getting things back to normal


  • Registered Users, Registered Users 2 Posts: 26,152 ✭✭✭✭Berty


    Welcome back.

    Life has been empty without you. :o


  • Registered Users, Registered Users 2 Posts: 1,862 ✭✭✭flamegrill


    Overall well handled. Darragh did a good job on the twitter account fair play to him.

    I'd be good to hear how they got in and what you're doing to prevent it.

    Paul


  • Advertisement
  • Closed Accounts Posts: 22,559 ✭✭✭✭AnonoBoy


    I'm not joking here but could it have been StormFront?

    They are after all massively daft racists.


  • Closed Accounts Posts: 88,972 ✭✭✭✭mike65


    It was politics.ie - they hate us


  • Registered Users Posts: 532 ✭✭✭Fergus


    Welcome back guys. Amazingly fast reactions by the team.


  • Registered Users, Registered Users 2 Posts: 44,028 ✭✭✭✭Basq


    Like I said on Twatter, I have to applaud the staff over at Boards HQ who handled the situation like absolute pros!

    So many sites would have simply said downtime with no real explanation, but to get full disclosure on the whole thing (was it a necessity by law, or anything?) was a welcome change.

    Great to have ye back...!


  • Moderators, Category Moderators, Music Moderators, Regional East Moderators, Regional Midlands Moderators, Regional Midwest Moderators, Regional Abroad Moderators, Regional North Mods, Regional West Moderators, Regional South East Moderators, Regional North East Moderators, Regional North West Moderators, Regional South Moderators Posts: 8,037 CMod ✭✭✭✭Gaspode


    Great to have Boards back!


  • Moderators, Science, Health & Environment Moderators Posts: 23,231 Mod ✭✭✭✭godtabh


    So whats been done to prevent this from happening again>?

    I'm not worried of it happening again but others might and I think whats happened over the last 36 hours or so may have done alot of damage to boards rep.

    I've been getting emails as far a field as Iceland about this.

    Maybe an announcement on that would be helpful?


  • Closed Accounts Posts: 6 Kopdave


    Thank God Boards is back, now hurry with adds! best of luck guys..........;)


  • Closed Accounts Posts: 6,164 ✭✭✭Konata


    Good work to all involved and thank you!


  • Closed Accounts Posts: 22,905 ✭✭✭✭Handsome Bob


    I didn't miss any of you mugs at all. :pac:


  • Registered Users, Registered Users 2 Posts: 1,102 ✭✭✭am i bovvered


    Its great to be back !!!!! Really missed all ye :P


  • Advertisement
  • Closed Accounts Posts: 10,817 ✭✭✭✭Dord


    Excellent work guys! very well handled. :)

    It was odd seeing boards.ie being mentioned everywhere. Hopefully it does you good in terms of vistors.


  • Registered Users Posts: 263 ✭✭Magaa


    happy that you are back!


  • Registered Users, Registered Users 2 Posts: 44,028 ✭✭✭✭Basq


    I'd be interested to know (in not too much specifics) how the site was compromised.

    Would I be correct in saying you're using an out-dated version of vBulletin? If so, was a security hole in this (that has since been patched)? If you are using an older version of vBulletin, it's probably due to all the custom code associated with modutils and such.

    But I could be way off here.. so feel free to correct me and set me straight (as an actress said to a bishop).


  • Moderators, Category Moderators, Arts Moderators, Entertainment Moderators, Technology & Internet Moderators Posts: 22,680 CMod ✭✭✭✭Sad Professor


    Great work, guys. Thanks! :D


  • Registered Users, Registered Users 2 Posts: 1,170 ✭✭✭Sagat06


    Two days of uninterrupted work, that simply wont do people :D

    Great job on the communication and getting the site back up!


  • Moderators, Social & Fun Moderators, Regional Abroad Moderators Posts: 6,485 Mod ✭✭✭✭silvervixen84


    Very well handled lads, the twitter feed was so helpful, and the change password procedure is dead easy. Scary stuff!!


  • Registered Users, Registered Users 2 Posts: 763 ✭✭✭F-Stop


    Fair play to you. Spotted quickly, handled well, and you were open and honest with the site users. Cheers.


  • Registered Users, Registered Users 2 Posts: 26,061 ✭✭✭✭Terry


    Gaspode wrote: »
    Great to have Boards back!

    I'm of to the CT thread to float that one! :)


    Thanks to all involved in getting the site back up and running.

    For those complaining about having to change their password, you really should be changing all passwords every so often anyway.


  • Registered Users, Registered Users 2 Posts: 40,038 ✭✭✭✭Sparks


    mike65 wrote: »
    It was politics.ie - they hate us
    No, it was the PROC forum. 'Cos they has mad skillz.

    Or it was us, 'cos boards files a tax return soon and the Revenue wouldn't ask for it if the site wasn't up.

    Or 'cos someone shot the hamster.


  • Advertisement
  • Closed Accounts Posts: 17,485 ✭✭✭✭Ickle Magoo


    I have never been so productive, please don't do that again!

    Q, Once all investigations have been concluded will the details of the perpetrators and any motive be released?


  • Registered Users, Registered Users 2 Posts: 51,342 ✭✭✭✭That_Guy


    Well done lads for keeping everybody informed. Fair play.


  • Moderators, Entertainment Moderators Posts: 17,994 Mod ✭✭✭✭ixoy


    I atually got the Metro Herald today 'coz I saw the boards story on the front cover - welcome back!

    Question though: Are you worried this will affect the site's perceived worth? Or that it might make advertisers wary?


  • Registered Users, Registered Users 2 Posts: 26,061 ✭✭✭✭Terry


    Wait. I know what happened.
    This was all planned in the name of free publicity.

    Ooh, you're a crafty one, Darragh.


  • Closed Accounts Posts: 10,910 ✭✭✭✭RoundyMooney


    Fair play for the transparency, guys. Pats on the back all round for the hard work I'm sure was involved.


  • Registered Users, Registered Users 2 Posts: 46 thejetset


    Thank you and a job well done here! Just one comment, The Last Word is on TodayFM and not Newstalk ;)! But besides that, openness was brilliant a sincere thanks!


  • Advertisement
  • Moderators, Regional East Moderators Posts: 23,228 Mod ✭✭✭✭GLaDOS


    Thanks to all the staff and good work with getting the passwords sorted so easily

    Cake, and grief counseling, will be available at the conclusion of the test



  • Posts: 5,589 ✭✭✭ [Deleted User]


    godtabh wrote: »
    So whats been done to prevent this from happening again>?

    I'm not worried of it happening again but others might and I think whats happened over the last 36 hours or so may have done alot of damage to boards rep.

    I've been getting emails as far a field as Iceland about this.

    Maybe an announcement on that would be helpful?

    Root password is now

    passwerd2 instead of password1. It will take another ten years of attempts for people to get at this...


  • Registered Users, Registered Users 2 Posts: 11,363 ✭✭✭✭rossie1977


    Terry wrote: »
    Heh. I thought the same after seeing the 6.1 news. It was read as if they were begrudging the site and were happy that it was down. :)

    sharon was probably unhappy after reading some of the comments about her by some board members


  • Closed Accounts Posts: 3,305 ✭✭✭yoshytoshy


    When I seen it on BBC's website ,I thought it's great how far the site has come so far.

    Fair play to all !


  • Registered Users, Registered Users 2 Posts: 17,727 ✭✭✭✭Sherifu


    Welcome back to the web. :)


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 3,135 ✭✭✭fifth


    Just another few days and Ireland would have worked it's way out of the recession!

    Haha, fair play lads. We're all behind you, you handled it well! Good to be back.


  • Closed Accounts Posts: 88,972 ✭✭✭✭mike65


    yoshytoshy wrote: »
    When I seen it on BBC's website ,I thought it's great how far the site has come so far.

    Fair play to all !

    Really, got a linky poo?


  • Registered Users, Registered Users 2 Posts: 1,651 ✭✭✭thebiglad


    Its like an old friend coming home - seems like so much longer than 36 hours.

    Thanks for all your efforts to get back and safe so quick and for keeping us informed.


  • Registered Users, Registered Users 2 Posts: 10,992 ✭✭✭✭partyatmygaff


    Well I know I shouldn't have re-regged but i'm too impatient! :p

    As you can guess, I'm partyatmygaff and to prove it I can get Terry to vouch for me (Well he better vouch for me anyways :D), I sold him an old computer back in june so maybe I could PM him some details that only I would know like the area we met up and some other details only I would know.

    Would that be alright to verify I am the real partyatmygaff? I can't even remember what email address I used for my account :eek:


  • Registered Users, Registered Users 2 Posts: 21,264 ✭✭✭✭Hobbes


    Root password is now

    passwerd2 instead of password1.

    Thought it would be hunter2.

    Nice breakdown Dev and well thought out. Very CSI. :)

    Glad your all back.


  • Moderators, Technology & Internet Moderators, Regional South East Moderators Posts: 28,510 Mod ✭✭✭✭Cabaal


    Well done lads, you handled it as best as you could.

    Not ideal but this type of ****e happens....hell even to Microsoft :p


  • Closed Accounts Posts: 3,305 ✭✭✭yoshytoshy




  • Registered Users, Registered Users 2 Posts: 18,503 ✭✭✭✭Also Starring LeVar Burton


    Well done to all the staff who got the site back up on running... It's obvious by the sheer amount of people who are back posting within a half hour of the site being back up, how many people were dying for a boards fix...


  • Registered Users, Registered Users 2 Posts: 40,038 ✭✭✭✭Sparks


    funkyflea wrote: »
    Just another few days and Ireland would have worked it's way out of the recession!
    Damn, I hadn't heard the "Brian Cowen made them take boards.ie down" theory yet :D


  • Registered Users, Registered Users 2 Posts: 661 ✭✭✭fend


    Well done! All those fire drills paid off I bet :P
    Good to see you guys back in action!


  • Advertisement
Advertisement