Go Back  PPRuNe Forums > Misc. Forums > Computer/Internet Issues & Troubleshooting
Reload this Page >

Will in never end? Vertical Scope hacking.

Wikiposts
Search

Notices
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Will in never end? Vertical Scope hacking.

Thread Tools
 
Search this Thread
 
Old 14th July 2016 | 13:26
  #1 (permalink)  
Thread Starter
Psychophysiological entity
20 Anniversary
 
Joined: Jun 2001
Aviation Qualifications: ATPL
Posts: 3,383
Likes: 169
From: Walton on the Naze Essex.
Will in never end? Vertical Scope hacking.

Drowning in BS from road tax issues - two cars needing ages of phone time to sort road tax, masses of other @$^@$ and then I see a warning from these folk who I've never heard of.
Notice of Data Breach

You may have heard reports recently about a security issue involving VerticalScope. We would like to make sure you have the facts about what happened, what information was involved, and the steps we are taking to help protect you. VerticalScope owns and operates a number of community websites. You are receiving this email because you are a registered user of the following community website(s) involved in the data breach:
Tech Support Forum | Experts Online now for FREE Support!
Cadillac Owners and Enthusiasts Forum Homepage - Over 130,000 Members
DIY Chatroom Home Improvement Forum
ViperAlley.Com - Dodge Viper Forum - SRT Viper
AVSForum.com - Home Theater Discussions And Reviews
Mercedes-Benz Forum

What Happened?

On June 13, 2016, we became aware that February 2016 data stolen from VerticalScope was being made available online.

What Information Was Involved?

Community member usernames, email addresses, hashed passwords, community userIDS, community website, and the IP address the username originally registered with.
What We Are Doing etc., etc. And what I should do. Oh, @#$%#$ Will I fit that in after car maintainence, plumbing, doing woman's work, spending time on JB (which I'm not willing to stop doing ) or just ignore it.
Loose rivets is offline  
Reply
Old 14th July 2016 | 13:55
  #2 (permalink)  
 
Joined: Dec 2013
Posts: 1
Likes: 0
From: Norfolk
Almost certainly a phishing scam. Do not click on any links provided.

If you genuinely think you may have been affected by a data hack, log on to the service by manually entering the web address and check for advice or change your password from there.

Never, ever, click on links provided in these sorts of emails.
G0ULI is offline  
Reply
Old 14th July 2016 | 14:39
  #3 (permalink)  
 
Joined: Mar 2002
Posts: 4,569
Likes: 1
From: Florida
Almost certainly a phishing scam. Do not click on any links provided.
Are you talking about the links provide in the Rivets post above
lomapaseo is offline  
Reply
Old 14th July 2016 | 16:12
  #4 (permalink)  
10 Countries Visited
10 Anniversary
 
Joined: Jul 2013
Posts: 273
Likes: 42
From: SLF from NV (LAS)
I am a member of AVSForum and have received no notice.
IBMJunkman is offline  
Reply
Old 14th July 2016 | 16:46
  #5 (permalink)  
 
Joined: Jul 2008
Posts: 894
Likes: 1
From: uk
Oddly, I have just received an email from an outfit simply called 'Patient' telling me they are changing their terms and conditons so I should be aware when using the service, whatever that is.

Never heard of them.
.
vulcanised is offline  
Reply
Old 14th July 2016 | 16:52
  #6 (permalink)  
Administrator
 
Joined: Mar 2001
Aviation Qualifications: PPL
Posts: 8,121
Likes: 686
From: Twickenham, home of rugby
It would appear to be a genuine alert:

Hacker steals 45 million accounts from hundreds of car, tech, sports forums | ZDNet

This is among dozens of similar reports all around 14-15 June this year.

SD
Saab Dastard is offline  
Reply
Old 14th July 2016 | 20:44
  #7 (permalink)  
 
Joined: Jun 2011
Posts: 172
Likes: 0
From: New Zealand
I belong to an American car forum and I thought the e-mail was a scam. However it
was genuine and all I had to do was change my password.
Nervous SLF is offline  
Reply
Old 16th July 2016 | 17:09
  #8 (permalink)  
10 Countries Visited
10 Anniversary
 
Joined: Jul 2013
Posts: 273
Likes: 42
From: SLF from NV (LAS)
Try https://www.leakedsource.com/main/

Put in your user id, change search type to username and a list at the bottom of the screen will show sites that may have been compromised.

One of my other userids showed a few sites I had never visited but one I did. Not surprising as the ID was not that unique. Changed the password on the site I did use.
IBMJunkman is offline  
Reply
Old 16th July 2016 | 22:48
  #9 (permalink)  
Thread Starter
Psychophysiological entity
20 Anniversary
 
Joined: Jun 2001
Aviation Qualifications: ATPL
Posts: 3,383
Likes: 169
From: Walton on the Naze Essex.
The Caddy forum in the US was a wondrous site, a bloke, sorry guy called Bobinski or somesuch told us things about the development of the N* or NorthStar V8 that left me sitting there with me mouth hanging open. The crush on bearings followed by hours at 6000 rpm before doing all again a tenth of a tho' up etc., etc. The Mercedes site had a load of people talking about how many times they'd polish their cars in a week. (Bloody things would probably be broke, so polishing them was one way of passing the time.)

My neighbour pal had a Viper, so it's possible I looked things up for him.

So, if one does not really care about the site - i.e., I don't care if someone knows I get turned on by the fact you mustn't used Helix but 'TimeCert' thingies to repair head-stud threads - I'll assume it doesn't matter much, relax and go back to my book on Head Up displays.
Loose rivets is offline  
Reply
Old 17th July 2016 | 17:32
  #10 (permalink)  
10 Countries Visited
10 Anniversary
 
Joined: Jul 2013
Posts: 273
Likes: 42
From: SLF from NV (LAS)
I paid for 1 day on https://www.leakedsource.com/main/ $4.

I then checked all my userids, email addresses and my friends email addresses.

Most seemed to be the LinkedIn hack of 2012 and something related to Adobe this year.

A couple showed emails used on the Ashley Madison site and something called Fling.com (NSFW).

I called those 2 friends and told them. I know neither of them would use those sites. But if those sites send an email for whatever reason, and the email address is shared with SHMBO, there may be some explaining to do.
IBMJunkman is offline  
Reply
Old 18th July 2016 | 16:08
  #11 (permalink)  
15 Anniversary
 
Joined: Jul 2009
Posts: 1,038
Likes: 0
From: NI
I paid for 1 day on https://www.leakedsource.com/main/ $4.

I then checked all my userids, email addresses and my friends email addresses.
I hope they have a watertight privacy policy because otherwise that sounds like a marvellous method for collecting valid userIDs and e-mail addresses for various websites... and have people pay to contribute them!

Did you ask your friends for consent before submitting their e-mail addresses to an online service?

Another good reason to use a unique e-mail address for each website to which you register.
El Bunto is offline  
Reply
Old 18th July 2016 | 22:13
  #12 (permalink)  
 
Joined: Aug 2007
Posts: 647
Likes: 0
El Bunto

I sincerely Hope So.

I was very nearly tempted to access the site(on a paid basis) too, after being hammered by Spam at my primary EM address.

It was only after a good nights sleep that it dawned on me that perhaps this was not a good idea.

I’m afraid that the OP heeds to approach his ISP and obtain a new a new default EM address.

Or alternatively: set up a set of G Mail addresses.

CAT III
Guest 112233 is offline  
Reply
Old 23rd July 2016 | 16:28
  #13 (permalink)  
20 Anniversary
 
Joined: Jul 2002
Posts: 1,442
Likes: 55
From: Under a recently defunct flight path.
haveibeenpwned.com enables a check of any email address or username for data breach. Had to change my Adobe & Tumblr passwords.
Lyneham Lad is offline  
Reply
Old 24th July 2016 | 11:11
  #14 (permalink)  
 
Joined: Apr 2016
Posts: 221
Likes: 0
From: localhost
On another note, (in response to the OP's "will it never end" question), no.

As a penetration tester (someone who is paid to break websites to find the flaws before a malicious hacker is) I can tell you there are many companies that don't bother getting a security report and many more that once they've got one, don't act on the information within because it's going to cost too much etc. This is basically handing their website to hackers on a plate.

There is always going to be hacking/phishing/malware but steps can be taking to protect against it and minimise the impact. Unfortunately not everyone takes those steps which is why we end up with a lot of these breaches.
crablab is offline  
Reply

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.