PDA

View Full Version : ALERT!! Please read.


Bryant
03-06-2004, 12:06 AM
*****DO NOT REPLY TO THIS POST TELLING ANYONE WHAT ACCOUNTS YOU HAVE THAT MAY BE AFFECTED FROM THIS POTENTIAL IDENTITY THEFT!!!*********

First of all, I'd like to thank Sean and a few others for keeping an eye out for us regarding suspicious "lurkers" on our forums. As many of us online junkies already know, internet identity theft is a serious problem in this world. We've recently had an unidentified person going by the name of "SamAdams" who appeared to have been running scripts on our forums to steal member usernames and passwords. I am not entirely sure if he was successful in any way, but since nothing on the internet is entirely secure, Hypercycles recommends for your safety that if you use the same username and password on Hypercycles as you do for an online account that deal with money (ie. banking accounts, credit card accounts, wireless cell phone accounts, personal accounts, etc.) you may want to change your password or user information. This is just a precautionary measure.

We always try our hardest to keep our members' privacy as secure as possible. To that end, the memberlist viewing option has been indefinately disabled on our forums. We apologize for any inconvenience this may cause but this is for the best for all of our sakes.

Because of these issues at hand, we would like to have more of our membership keeping a look out for "suspicous" online activity on our forums. One way is to check the "who is online" feature on our forms and taking a look at their activity. If you find that there is a FLOOD of "guests" "lurking" on the board and the IP of the guests are all the same, that is a good indication that something fishy is going on.

The specific vulnerability involves the memberlist.php file.... if anyone has more information on this, please feel free to share here.

REMINDER: DO NOT REPLY TO THIS POST TELLING ANYONE WHAT ACCOUNTS YOU HAVE THAT MAY BE AFFECTED FROM THIS POTENTIAL IDENTITY THEFT!!!

TreAdidas
03-07-2004, 07:55 PM
dammit... I saw that guy on here and I was like... hrm that just doesn't feel right to me... :red: :red:

Philo
03-08-2004, 12:22 AM
Originally posted by Bodmaster
Because of these issues at hand, we would like to have more of our membership keeping a look out for "suspicous" online activity on our forums. One way is to check the "who is online" feature on our forms and taking a look at their activity. If you find that there is a FLOOD of "guests" "lurking" on the board and the IP of the guests are all the same, that is a good indication that something fishy is going on.

Does this only apply to moderators??? I can't find a "who is online" link anywhere. Then again, I once spent 5 minutes looking for my keys and they were in my hand the whole time.:blink:

Philo
03-08-2004, 12:32 AM
True to form, I found it 30 seconds after posting. Spent 5 minutes looking for it before. :errf:

While inside a forum or thread, go to the "Forum Jump" scrolldown box at the bottom of the screen. It's near the top of the list. I assume Bodmaster would like us to immediately PM a moderator (Jae, Bodmaster, GPtechman, others???) if something seems fishy.

*edit*

Humble suggestion.....a who is online link in the "Active Users" section on homepage. Sounds redundant, but it would take you to the page showing activity of online guests/members. <grovels> <exits>