Go Back  PPRuNe Forums > Misc. Forums > Computer/Internet Issues & Troubleshooting
Reload this Page >

Will in never end? Vertical Scope hacking.

Wikiposts
Search
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Will in never end? Vertical Scope hacking.

Thread Tools
 
Search this Thread
 
Old 14th Jul 2016, 13:26
  #1 (permalink)  
Psychophysiological entity
Thread Starter
 
Join Date: Jun 2001
Location: Tweet Rob_Benham Famous author. Well, slightly famous.
Age: 84
Posts: 3,270
Received 37 Likes on 18 Posts
Will in never end? Vertical Scope hacking.

Drowning in BS from road tax issues - two cars needing ages of phone time to sort road tax, masses of other @$^@$ and then I see a warning from these folk who I've never heard of.
Notice of Data Breach

You may have heard reports recently about a security issue involving VerticalScope. We would like to make sure you have the facts about what happened, what information was involved, and the steps we are taking to help protect you. VerticalScope owns and operates a number of community websites. You are receiving this email because you are a registered user of the following community website(s) involved in the data breach:
Tech Support Forum | Experts Online now for FREE Support!
Cadillac Owners and Enthusiasts Forum Homepage - Over 130,000 Members
DIY Chatroom Home Improvement Forum
ViperAlley.Com - Dodge Viper Forum - SRT Viper
AVSForum.com - Home Theater Discussions And Reviews
Mercedes-Benz Forum

What Happened?

On June 13, 2016, we became aware that February 2016 data stolen from VerticalScope was being made available online.

What Information Was Involved?

Community member usernames, email addresses, hashed passwords, community userIDS, community website, and the IP address the username originally registered with.
What We Are Doing etc., etc. And what I should do. Oh, @#$%#$ Will I fit that in after car maintainence, plumbing, doing woman's work, spending time on JB (which I'm not willing to stop doing ) or just ignore it.
Loose rivets is offline  
Old 14th Jul 2016, 13:55
  #2 (permalink)  
 
Join Date: Dec 2013
Location: Norfolk
Age: 67
Posts: 1
Likes: 0
Received 0 Likes on 0 Posts
Almost certainly a phishing scam. Do not click on any links provided.

If you genuinely think you may have been affected by a data hack, log on to the service by manually entering the web address and check for advice or change your password from there.

Never, ever, click on links provided in these sorts of emails.
G0ULI is offline  
Old 14th Jul 2016, 14:39
  #3 (permalink)  
 
Join Date: Mar 2002
Location: Florida
Posts: 4,569
Likes: 0
Received 1 Like on 1 Post
Almost certainly a phishing scam. Do not click on any links provided.
Are you talking about the links provide in the Rivets post above
lomapaseo is offline  
Old 14th Jul 2016, 16:12
  #4 (permalink)  
 
Join Date: Jul 2013
Location: NV (LAS)
Age: 76
Posts: 214
Received 18 Likes on 9 Posts
I am a member of AVSForum and have received no notice.
IBMJunkman is offline  
Old 14th Jul 2016, 16:46
  #5 (permalink)  
 
Join Date: Jul 2008
Location: uk
Posts: 894
Likes: 0
Received 0 Likes on 0 Posts
Oddly, I have just received an email from an outfit simply called 'Patient' telling me they are changing their terms and conditons so I should be aware when using the service, whatever that is.

Never heard of them.
.
vulcanised is offline  
Old 14th Jul 2016, 16:52
  #6 (permalink)  
Spoon PPRuNerist & Mad Inistrator
 
Join Date: Sep 2003
Location: Twickenham, home of rugby
Posts: 7,390
Received 247 Likes on 165 Posts
It would appear to be a genuine alert:

Hacker steals 45 million accounts from hundreds of car, tech, sports forums | ZDNet

This is among dozens of similar reports all around 14-15 June this year.

SD
Saab Dastard is offline  
Old 14th Jul 2016, 20:44
  #7 (permalink)  
 
Join Date: Jun 2011
Location: New Zealand
Posts: 172
Likes: 0
Received 0 Likes on 0 Posts
I belong to an American car forum and I thought the e-mail was a scam. However it
was genuine and all I had to do was change my password.
Nervous SLF is offline  
Old 16th Jul 2016, 17:09
  #8 (permalink)  
 
Join Date: Jul 2013
Location: NV (LAS)
Age: 76
Posts: 214
Received 18 Likes on 9 Posts
Try https://www.leakedsource.com/main/

Put in your user id, change search type to username and a list at the bottom of the screen will show sites that may have been compromised.

One of my other userids showed a few sites I had never visited but one I did. Not surprising as the ID was not that unique. Changed the password on the site I did use.
IBMJunkman is offline  
Old 16th Jul 2016, 22:48
  #9 (permalink)  
Psychophysiological entity
Thread Starter
 
Join Date: Jun 2001
Location: Tweet Rob_Benham Famous author. Well, slightly famous.
Age: 84
Posts: 3,270
Received 37 Likes on 18 Posts
The Caddy forum in the US was a wondrous site, a bloke, sorry guy called Bobinski or somesuch told us things about the development of the N* or NorthStar V8 that left me sitting there with me mouth hanging open. The crush on bearings followed by hours at 6000 rpm before doing all again a tenth of a tho' up etc., etc. The Mercedes site had a load of people talking about how many times they'd polish their cars in a week. (Bloody things would probably be broke, so polishing them was one way of passing the time.)

My neighbour pal had a Viper, so it's possible I looked things up for him.

So, if one does not really care about the site - i.e., I don't care if someone knows I get turned on by the fact you mustn't used Helix but 'TimeCert' thingies to repair head-stud threads - I'll assume it doesn't matter much, relax and go back to my book on Head Up displays.
Loose rivets is offline  
Old 17th Jul 2016, 17:32
  #10 (permalink)  
 
Join Date: Jul 2013
Location: NV (LAS)
Age: 76
Posts: 214
Received 18 Likes on 9 Posts
I paid for 1 day on https://www.leakedsource.com/main/ $4.

I then checked all my userids, email addresses and my friends email addresses.

Most seemed to be the LinkedIn hack of 2012 and something related to Adobe this year.

A couple showed emails used on the Ashley Madison site and something called Fling.com (NSFW).

I called those 2 friends and told them. I know neither of them would use those sites. But if those sites send an email for whatever reason, and the email address is shared with SHMBO, there may be some explaining to do.
IBMJunkman is offline  
Old 18th Jul 2016, 16:08
  #11 (permalink)  
 
Join Date: Jul 2009
Location: NI
Posts: 1,033
Likes: 0
Received 0 Likes on 0 Posts
I paid for 1 day on https://www.leakedsource.com/main/ $4.

I then checked all my userids, email addresses and my friends email addresses.
I hope they have a watertight privacy policy because otherwise that sounds like a marvellous method for collecting valid userIDs and e-mail addresses for various websites... and have people pay to contribute them!

Did you ask your friends for consent before submitting their e-mail addresses to an online service?

Another good reason to use a unique e-mail address for each website to which you register.
El Bunto is offline  
Old 18th Jul 2016, 22:13
  #12 (permalink)  
 
Join Date: Aug 2007
Posts: 647
Likes: 0
Received 0 Likes on 0 Posts
El Bunto

I sincerely Hope So.

I was very nearly tempted to access the site(on a paid basis) too, after being hammered by Spam at my primary EM address.

It was only after a good nights sleep that it dawned on me that perhaps this was not a good idea.

I’m afraid that the OP heeds to approach his ISP and obtain a new a new default EM address.

Or alternatively: set up a set of G Mail addresses.

CAT III
Guest 112233 is offline  
Old 23rd Jul 2016, 16:28
  #13 (permalink)  
 
Join Date: Jul 2002
Location: Under a recently defunct flight path.
Age: 77
Posts: 1,375
Received 21 Likes on 13 Posts
haveibeenpwned.com enables a check of any email address or username for data breach. Had to change my Adobe & Tumblr passwords.
Lyneham Lad is offline  
Old 24th Jul 2016, 11:11
  #14 (permalink)  
 
Join Date: Apr 2016
Location: localhost
Age: 25
Posts: 220
Likes: 0
Received 0 Likes on 0 Posts
On another note, (in response to the OP's "will it never end" question), no.

As a penetration tester (someone who is paid to break websites to find the flaws before a malicious hacker is) I can tell you there are many companies that don't bother getting a security report and many more that once they've got one, don't act on the information within because it's going to cost too much etc. This is basically handing their website to hackers on a plate.

There is always going to be hacking/phishing/malware but steps can be taking to protect against it and minimise the impact. Unfortunately not everyone takes those steps which is why we end up with a lot of these breaches.
crablab is offline  

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.