Forum Security

The place to talk about ALPINAs.
e.g. News, Reviews, Insurance, Warranties, Running Costs, Sightings, general questions etc.

Moderators: Charles, neil, D4

User avatar
Stuart Truman
ALPI
ALPI
Posts: 315
Joined: Thu Jul 28, 2011 12:14 am

Forum Security

Post by Stuart Truman » Wed Feb 13, 2019 12:08 am

Folks, it gives me no pleasure to write this:

There is a particularly insidious piece of blackmail spam going about that claims to have infected your device with malware, gained access to your webcam and recorded you watching porn. There is a request to pay up via bitcoin to keep quiet or else they will forward it to your friends and family. So far, so much to ignore. But here's the clever/nasty bit; they have a password that you’ve used with a website or forum and they share it back with you as some kind of “proof” that you’ve been hacked. This is where people start to panic.

What’s actually happened is that they’ve breached the security of the site that the password came from. I’ve had two of these mails in the past couple of weeks. Both with the same password, and it’s the password I use here. I use a password manager and my passwords are random strings of characters. The likelihood of the password manager I use being breached is negligible. I do not ever use the same password on multiple sites.

I can only assume that someone has breached the security of this forum. I did search the forum before posting this but I could not find anything alerting users to the possibility.

You may wish to change your passwords

Bob
ALPINA
ALPINA
Posts: 5527
Joined: Tue Nov 20, 2012 10:37 pm

Post by Bob » Wed Feb 13, 2019 12:58 am

Thanks for the heads up, hopefully the admin/mods will be along to advise more soon, but in the meanwhile ... new password time
B3 3.2 TOURING #062

User avatar
brett
ALPIN
ALPIN
Posts: 532
Joined: Sat Jul 23, 2005 5:06 pm
Location: Cradley (Blackcountry)

Post by brett » Wed Feb 13, 2019 9:21 am

Hi Stuart

I have had this also and its only the password I use on this forum , also if my browser logs me out for some reason I always get a warning message that the site is unsafe
brett

E39 V8s (043)

User avatar
Charles
Moderator
Moderator
Posts: 8072
Joined: Mon Jun 23, 2003 2:44 am
Location: Oxford

Post by Charles » Wed Feb 13, 2019 9:37 am

CaesarBob wrote:... hopefully the admin/mods will be along to advise more soon
Raised with Admin - way above my pay grade!
Charles
Teacher of Chemistry and driver of ALPINAs - not necessarily in that order ;)
B3S Touring (49/116) - been to the moon and now on the way back!
Renault Grand Espace - not mine but the wife's!

User avatar
neil
Administrator
Administrator
Posts: 7019
Joined: Wed Oct 30, 2002 8:16 pm
Location: Nottingham, UK
Contact:

Post by neil » Wed Feb 13, 2019 10:28 am

Hi Guys

No clear picture yet but am in process of investigating - I've upgraded a few things and as you say changed passwords etc. I'm also looking at how quickly I can swap to completely use https.

If you have anything that can help me work out the source of this please forward to me - either by pm or email.

Thanks

Neil
Last edited by neil on Wed Feb 13, 2019 10:28 am, edited 1 time in total.

---pete---
ALP
ALP
Posts: 159
Joined: Thu Aug 28, 2008 7:48 pm
Location: Northamptonshire

Post by ---pete--- » Wed Feb 13, 2019 10:28 am

Unfortunately I can also confirm this has happened to me with a password specific only to this site.

Pete
_____________________________________
2008 BMW Alpina B3 Biturbo Coupe no.137
2003 BMW Alpina B3s Coupe no.16
2014 BMW 525d M-Sport
2010 BMW 320d M-Sport
2000 BMW Alpina B3 3.3 Saloon no. 213
1995 BMW 328i Coupe
1989 Ford Escort XR3i lux

User avatar
neil
Administrator
Administrator
Posts: 7019
Joined: Wed Oct 30, 2002 8:16 pm
Location: Nottingham, UK
Contact:

Post by neil » Wed Feb 13, 2019 10:46 am

Hi all

The advice given re. ignoring the email is right - it is just someone exploiting a single piece of information to imply a huge issue for the person (porn etc.)

I do however strongly advise people to not use the same password everywhere - especially to secure sites or sites that can be exploited financially. Password managers are the simplest way to achieve this and are typically easy to use once you set them up.

If people use the same password here as they do elsewhere then I do suggest that you need to look to change all your passwords.

Sorry for the inconvenience and we are doing everything we can to track down the issue / secure the site further to avoid any further risks.

If anyone has any specific concerns please PM or email me.

Thanks

Neil

nkotecha
ALPIN
ALPIN
Posts: 585
Joined: Mon Mar 17, 2014 10:42 am
Location: Leicester
Contact:

Post by nkotecha » Wed Feb 13, 2019 11:38 am

neil you running it on a iis server or is it hosted in the cloud
D5 Biturbo saloon 109 (sold)
B3 3.2 Convertible 82
d3 biturbo Saloon 234
118d msport (sold)
x3 2.0 se (sold)

Rav
ALPINA
ALPINA
Posts: 825
Joined: Tue May 05, 2015 12:43 pm
Location: Marlborough

Post by Rav » Wed Feb 13, 2019 11:45 am

I received this e-mail and was terrified. I raised it with my IT literate 16 year old who informed me that it was rubbish.

I will change my Password at once. Thanks for informing us.
1999 #032 Alpina B3 3.3 saloon (UK Press Car) - Buchloe Beast
2000 Porsche Boxster S - Viola
2015 Audi A4 Avant Ultra - Wife's car
2002 VW Lupo 1.4 16v - Daughter's car

User avatar
jolls
ALPIN
ALPIN
Posts: 748
Joined: Sun Sep 02, 2007 8:06 pm
Location: Borehamwood

Post by jolls » Wed Feb 13, 2019 12:07 pm

I've had the same spam. Just delete it and change your password.
B3 E46 no.265

User avatar
neil
Administrator
Administrator
Posts: 7019
Joined: Wed Oct 30, 2002 8:16 pm
Location: Nottingham, UK
Contact:

Post by neil » Wed Feb 13, 2019 1:17 pm

nkotecha wrote:neil you running it on a iis server or is it hosted in the cloud
Hosted

User avatar
Stuart Truman
ALPI
ALPI
Posts: 315
Joined: Thu Jul 28, 2011 12:14 am

Post by Stuart Truman » Wed Feb 13, 2019 10:03 pm

I’ve got a background in IT security.

https is only encrypting the traffic between your browser and the server although implementating this would be a good idea.

The biggest concern I have is that the passwords are stored in plain text unencrypted. If this is the case then this is a major flaw in the design of the software the site runs on. I’d assume there’s a support community for the software you’re using and I t might be worth checking out if other people have seen the same thing. If so then the authors really need to get a patch out. I’m assuming you’re up to date with available patches.

Not knowing the software the board runs on, I can’t really comment further.

User avatar
neil
Administrator
Administrator
Posts: 7019
Joined: Wed Oct 30, 2002 8:16 pm
Location: Nottingham, UK
Contact:

Post by neil » Wed Feb 13, 2019 10:15 pm

Stuart Truman wrote:I’ve got a background in IT security.

https is only encrypting the traffic between your browser and the server although implementating this would be a good idea.

The biggest concern I have is that the passwords are stored in plain text unencrypted. If this is the case then this is a major flaw in the design of the software the site runs on. I’d assume there’s a support community for the software you’re using and I t might be worth checking out if other people have seen the same thing. If so then the authors really need to get a patch out. I’m assuming you’re up to date with available patches.

Not knowing the software the board runs on, I can’t really comment further.
Hi Stuart

The passwords are definitely only stored encrypted.

Thanks

Neil

Broch
ALPINA
ALPINA
Posts: 780
Joined: Mon Aug 13, 2007 1:11 am
Location: Aberdeenshire

Post by Broch » Thu Feb 14, 2019 4:19 pm

I've heard of this scam a few months ago, and one work collegue told me his experience.
I believe that the password that the scammer has for anyone are old passwords, possible a password used years ago from an old email account etc.
As we normally are asked to change passwords or change accounts throughout the years I guess most don't apply any longer.
Thinking of this site, I have the same password for this site as I started with.
Is it worth changing your password for this site....... :?
I'm not fussed as I know the scammer won't have video footage of me whilst I'm on this site..... or at least I hope not :wink:

Onzie
B6 Convertible
B3s Bi-Turbo Tourer

User avatar
Hector's Dad
ALP
ALP
Posts: 276
Joined: Mon Jun 22, 2009 12:16 pm
Location: Hampshire
Contact:

Post by Hector's Dad » Thu Feb 14, 2019 7:52 pm

I'm not convinced the breach was this forum. I started receiving these emails (up to 15 per day at the height!) in (I think) November last year. If it was this site, we'd all have had them and this would have been raised by someone before now.
D4 BT Coupé No. 166
D3 BT Coupé No. 127 (Sold at 147,000 miles)

Post Reply