Author Topic: Ubuntuforums.org compromised  (Read 886 times)

0 Members and 1 Guest are viewing this topic.

Offline parad0x

  • VIP
  • Royal Highness
  • *
  • Posts: 638
  • Cookies: 118
    • View Profile
Ubuntuforums.org compromised
« on: August 03, 2013, 11:33:40 am »
I saw this email just now in spam. I had registered on ubuntuforums.org when I installed Ubuntu for free cloud storage on their server. Here is the email.


Quote
Hello,
You are receiving this message because you have an account registered with this address on ubuntuforums.org.

The Ubuntu forums software was compromised by an external attacker. As a result, the attacker has gained access to read your username, email address and an encrypted copy of your password from the forum database.

If you have used this password and email address to authenticate at any other website, you are urged to reset the password on those accounts immediately as the attacker may be able to use the compromised personal information to access these other accounts. It is important to have a distinct password for different accounts.

The ubuntuforums.org website is currently offline and we are working to restore this service. Please take the time to change your ubuntuforums.org account password when service is restored.

We apologize for any inconvenience to the Ubuntu community, thank you for your understanding.


The Canonical Sysadmins.
« Last Edit: August 03, 2013, 11:34:01 am by parad0x »

Offline vezzy

  • Royal Highness
  • ****
  • Posts: 771
  • Cookies: 172
    • View Profile
Re: Ubuntuforums.org compromised
« Reply #1 on: August 03, 2013, 06:39:30 pm »
You're a little too late to the party, I'm afraid.
Quote from: Dippy hippy
Just brushing though. I will be semi active mainly came to find a HQ botnet, like THOR or just any p2p botnet

Offline parad0x

  • VIP
  • Royal Highness
  • *
  • Posts: 638
  • Cookies: 118
    • View Profile
Re: Ubuntuforums.org compromised
« Reply #2 on: August 04, 2013, 06:21:45 am »
You're a little too late to the party, I'm afraid.
I got this email at the correct time but I haven't paid attention to what is in my spam folder, yesterday when I saw it, I shared it.

Offline Mordred

  • Knight
  • **
  • Posts: 360
  • Cookies: 135
  • Nvllivs in Verba
    • View Profile
Re: Ubuntuforums.org compromised
« Reply #3 on: August 04, 2013, 09:00:27 pm »
You're a little too late to the party, I'm afraid.

I got this email at the correct time but I haven't paid attention to what is in my spam folder, yesterday when I saw it, I shared it.

It's a bit awkward though. The hack happened on the 20th of July (on a Saturday) and was reported quite fast. Even ArsTehnica had gotten around to publishing an article already by Sunday night (source).
A bit of a slow reaction time with those e-mails from ubuntuforums.org it seems.
\x57\x68\x79\x20\x64\x69\x64\x20\x79\x6f\x75\x20\x65\x76\x65\x6e\x20\x66\x75\x63\x6b\x69\x6e\x67\x20\x73\x70\x65\x6e\x64\x20\x74\x68\x65\x20\x74\x69\x6d\x65\x20\x74\x6f\x20\x64\x65\x63\x6f\x64\x65\x20\x74\x68\x69\x73\x20\x6e\x69\x67\x67\x72\x3f\x20\x44\x61\x66\x75\x71\x20\x69\x73\x20\x77\x72\x6f\x6e\x67\x20\x77\x69\x74\x68\x20\x79\x6f\x75\x2e