Unconfigured Ad Widget

Collapse

Ubuntu Forums hacked ?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • bg
    Calguns Addict
    • Aug 2002
    • 5207

    Ubuntu Forums hacked ?

    I haven't been on the Ubuntu Forums for years, but received this
    e-mail today. I don't know if it was hacked or if I was hacked,
    but just a heads up in case.

    Hello,

    You are receiving this message because you have an account registered with this address on ubuntuforums.org.

    The Ubuntu forums software was compromised by an external attacker. As a result, the attacker has gained access to read your username, email address and an encrypted copy of your password from the forum database.

    If you have used this password and email address to authenticate at any other website, you are urged to reset the password on those accounts immediately as the attacker may be able to use the compromised personal information to access these other accounts. It is important to have a distinct password for different accounts.

    The ubuntuforums.org website is currently offline and we are working to restore this service. Please take the time to change your ubuntuforums.org account password when service is restored.

    We apologize for any inconvenience to the Ubuntu community, thank you for your understanding.

    The Canonical Sysadmins
    I've changed my passwords in my important accounts and seldom
    use Yahoo for my mail anymore, so I guess we'll see.
  • #2
    bigmike82
    Bit Pusher
    CGN Contributor
    • Jan 2008
    • 3876

    Got it as well.
    -- 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0

    Comment

    • #3
      the86d
      Calguns Addict
      • Jul 2011
      • 9587

      Hopefully all the searches on the Distro I use are not sent back to Canonical, but luckily I never made an account on *buntu forums...

      I hope nobody uses their registered e-mail and password combo on any financial web sites, or use the same password on the *buntu 4ums and e-mail account login... even salted hash is not-so-tasty.

      Comment

      • #4
        the86d
        Calguns Addict
        • Jul 2011
        • 9587

        /* Begin pseudo-relevant randomness...


        "Tripple 7's all up on the chmod"...
        */

        Comment

        • #5
          Hoshnasi
          Veteran Member
          • Nov 2010
          • 2515

          Lol, I got that too! I don't remember my password, so I really hope I've changed my other accounts since then! lol.
          Come to Flavor Country...

          Originally posted by Kappy
          You don't like homosexuality, don't let some dude stick his tab A into your slot B.

          Comment

          • #6
            stonith3901
            Member
            • Jul 2012
            • 175

            Really shouldn't use the same password on different authentication systems. Especially if its the same password to your critical accounts such as banking system or main email account etc. if it's forums or message boards that you don't care being hacked, i suppose that is ok.

            I keep all my unique passwords in a spreadsheet using an encrypted filesystem.

            Minimum passwords of 15 alphanumeric characters in length, and symbols should be practiced.

            Two factor authentication should be used as needed on systems/vpn that are considered critical if compromised. Two factors such as rsa securid, phone factor, or google two-step authenticator are some examples that can be hooked in.

            I only remember my top level encrypted filesystem password, also authenticating based on md5 checksum of a keyfile as a second factor, the rest i cut/paste randomized 30 character for auth.

            If its *nix boxes you are maintaining, obviously a SSH keypair with a password bound to private key is best.

            And of course periodically changing these passwords should be practiced as well.
            Last edited by stonith3901; 07-25-2013, 3:26 AM.

            Comment

            Working...
            UA-8071174-1