Tales of the Parodyverse >> View Thread

Author
Anime Jason 

Owner

Location: Here
Member Since: Sun Sep 12, 2004
Posts: 2,834


anime.mangacool.net (10.0.255.1)
using Apple Safari 3.2.1 on MacOS X (0.41 points)

Some of you may have noticed that the PVB was down this morning. If you noticed it and you're running Windows, please run a virus/spyware scan as soon as possible.

Starting last night there was a heavy denial-of-service attack against this server. It happens fairly often - but what I didn't realize is it was either this domain in particular, or this message board, which was targeted.

Sometime during last night, the hackers who attacked this site finally succeeded. They replaced the contents of the site with a "hacked" message and possible downloadable malware. While I believe their malware was broken and didn't work anyway, you should check and make sure.

This is the fourth time in a year this site has been compromised and vandalized, only this was the worst one yet. There have been attempts, mostly unsuccessful, at least once per month, including Denial of Service attacks that cripple the site, one of which forced it to switch domains.

I'm not sure if it's because someone wants the mangacool.com/mangacool.net domains more than I do, and wants to force me to give them up. Or if it's a particular grudge against the PVB. The only thing I'm sure of is this site has become a high-profile hacker target somehow, and they will never rest. Since I don't have a Pentagon-sized staff to look after it, that means the only solution is to try and hide it.

In short, that means before next month, I'm considering moving the PVB to the strike-two.com or strike-two.net domain, and hope it doesn't become a target. Another thing I'm considering is changing the name of it (the url, I mean - instead of "parodyverse", maybe "pvb") as well.

I'd appreciate any suggestions in the mean time, especially in how to quickly notify all our posters of the move.

EDIT: I've taken some additional security precautions to try to protect the site. Hopefully they'll work. I won't move the board until I verify whether the precautions worked or not. Meanwhile, though, I really do want need a way to quickly notify all posters to the board if it does move.






killer shrike



Posted with Microsoft Internet Explorer 7 on Windows Vista

> Some of you may have noticed that the PVB was down this morning. If you noticed it and you're running Windows, please run a virus/spyware scan as soon as possible.
>
> Starting last night there was a heavy denial-of-service attack against this server. It happens fairly often - but what I didn't realize is it was either this domain in particular, or this message board, which was targeted.
>
> Sometime during last night, the hackers who attacked this site finally succeeded. They replaced the contents of the site with a "hacked" message and possible downloadable malware. While I believe their malware was broken and didn't work anyway, you should check and make sure.
>
> This is the fourth time in a year this site has been compromised and vandalized, only this was the worst one yet. There have been attempts, mostly unsuccessful, at least once per month, including Denial of Service attacks that cripple the site, one of which forced it to switch domains.
>
> I'm not sure if it's because someone wants the mangacool.com/mangacool.net domains more than I do, and wants to force me to give them up. Or if it's a particular grudge against the PVB. The only thing I'm sure of is this site has become a high-profile hacker target somehow, and they will never rest. Since I don't have a Pentagon-sized staff to look after it, that means the only solution is to try and hide it.
>
> In short, that means before next month, I'm considering moving the PVB to the strike-two.com or strike-two.net domain, and hope it doesn't become a target. Another thing I'm considering is changing the name of it (the url, I mean - instead of "parodyverse", maybe "pvb") as well.
>
> I'd appreciate any suggestions in the mean time, especially in how to quickly notify all our posters of the move.
>
>





HH



Posted with Microsoft Internet Explorer 6 on Windows 2000

> In short, that means before next month, I'm considering moving the PVB to the strike-two.com or strike-two.net domain, and hope it doesn't become a target. Another thing I'm considering is changing the name of it (the url, I mean - instead of "parodyverse", maybe "pvb") as well.

If the board is being specifically targetted then moving domain is unlikely to be anything but a temporary solution. Indeed, it may even encourage the attacker since he has won some kind of "victory" in forcing you to retreat.

On the matter of communication with board regulars, I'd suggest that an appeal be put out for posters who wish to be informed of site problems and changes to lodge an up-to-date e-mail address with the board moderators. That way a simple update e-mail can be sent to a group and people can be reasonably assured that their data will bb treated confidentially. Those who don't want to reveal such informationor who aren't interested in such updates can make that choice, of course.

I'd also suggest that once that list is created that any future discussion on anti-hacker measures is confined to that list. Hackers can read.

HH





Anime Jason 

Owner

Location: Here
Member Since: Sun Sep 12, 2004
Posts: 2,834


anime.mangacool.net (10.0.255.1)
using Apple Safari 3.2.1 on MacOS X (0 points)





Anime Jason 

Owner

Location: Here
Member Since: Sun Sep 12, 2004
Posts: 2,834


anime.mangacool.net (10.0.255.1)
using Apple Safari 3.2.1 on MacOS X (0.24 points)


> If the board is being specifically targetted then moving domain is unlikely to be anything but a temporary solution. Indeed, it may even encourage the attacker since he has won some kind of "victory" in forcing you to retreat.

It depends what their goal is. If they want to "win" by forcing me to take down the PVB altogether, then there's not much I can do but resist until I'm unable to anymore. If it's the domain they want, then moving it would work. Or maybe they just want to keep the domain hijacked so they can use it for malware/phishing schemes. I can only guess at this point, because whoever it is isn't communicating.

The only thing I'm sure of is that if it does get to the point where the attacks are so severe it cripples the server, I'll have to attempt to "hide" the PVB. That means placing it at another domain and changing the URL so search engines can't find it (which is why I'd need to email the posters).


> On the matter of communication with board regulars, I'd suggest that an appeal be put out for posters who wish to be informed of site problems and changes to lodge an up-to-date e-mail address with the board moderators. That way a simple update e-mail can be sent to a group and people can be reasonably assured that their data will bb treated confidentially. Those who don't want to reveal such informationor who aren't interested in such updates can make that choice, of course.

I could add a feature to the software for moderators to email *everyone* with accounts at once, but over half the posters here don't have registered accounts. Hence the problem contacting people. I was hoping you or Visionary or someone already had a contact list maintained.


> I'd also suggest that once that list is created that any future discussion on anti-hacker measures is confined to that list. Hackers can read.

They can also sneak into mailing lists. \:\) I know they can read, which is why I didn't specify which measures I took to protect the site. They'll have to figure it out the hard way, and by then I may have added more.







On Topic™ © 2003-2024 Powermad Software