Membership is FREE, giving all registered users unlimited access to every DNForum feature, resource, and tool! Optional membership upgrades unlock exclusive benefits like profile signatures with links, banner placements, appearances in the weekly newsletter, and much more - customized to your membership level!

Major Forum Community almost Destroyed

Status
Not open for further replies.

Gregcyber

Exclusive Lifetime Member
Legacy Exclusive Member
Joined
Sep 28, 2007
Messages
453
Reaction score
5
What do we know about the damage done?
This attack was very deliberate, sophisticated and calculated. The attacker was able to circumvent our security measures and access via an arcane backdoor protected by additional firewall. We are still investigating the situation, but we know the attacker infiltrated and deleted the backups first and then deleted three databases: user/post/thread. We have no record or evidence that private message data was accessed. Absolutely no credit card or PayPal data was exposed.

Do we know the motivation behind the attack?
We don’t know enough at this time, so any insight would be purely speculative in nature. (edited) is a platform where positive and negative information is shared and exposed about business and individuals. Under TOS policy, we cannot edit or remove user-generated content at the request of an unsatisfied third party. Therefore, (edited) tends to become the target for disgruntled individuals and businesses.

Have we been able to restore more recent back-ups?
The offsite backup, the onsite backup and the operational data were destroyed by the attacker, so we’ve resorted to a physical back-up of last resort. Unfortunately, we are experiencing difficulty restoring from our most recent physical backup. At this point, October is the most recent backup that we were able to restore. We continue to work to extract data from a more recent set of DVDs. What is (edited) focused on doing now?
The first priority, which kicked in immediately upon discovering the hack while in process, was locking down the infrastructure to avoid further damage and restoring the site. We also had to block the potential for a repeat attack. Now we are working on investigating how much prior data is restorable, reinstating premium memberships, contacting business partners, and communicating with the community members. We are also doing everything possible to identify the attacker and bring them to justice. Disappointments happen – we are working hard to restore trust among community members and to bring things back to normal.

We had three, protected data back-up units with one offsite behind a firewall and a fourth physical data back-up layer. We evaluated our disaster recovery plan as recent as late-2008, and carefully reviewed how to recover from a disaster situation. The attacker appeared to have deliberately targeted our data back-up systems, a scenario that our disaster recovery plan did not fully anticipate. We have implemented changes to our data backup and disaster recovery plans to address this weakness. And we advise others to consider a scenario of deliberate, malicious data destruction in their backup and recovery plans.

What a shame.
Hope DNForum management gets to read this if the other Forum did not send a waning.
 
Last edited:

Sonny Banks

<span style="font-weight: bold;"><span style="font
Legacy Exclusive Member
Joined
Jul 18, 2008
Messages
3,940
Reaction score
0
What a bad story :(

I hope you can restore all data.

Good luck.
 

Tia Wood

Web Developer
Legacy Exclusive Member
Joined
Jan 11, 2006
Messages
3,372
Reaction score
349
The offsite backup? How the heck did they get to the offsite backup?
 

Focus

Making Everything Click
Legacy Exclusive Member
Joined
May 15, 2005
Messages
8,934
Reaction score
245
:smokin: Here is to their speedy recovery :smokin:
 

stock_post

JewelryRelated.com
Legacy Exclusive Member
Joined
Sep 3, 2006
Messages
2,418
Reaction score
8
I am not a happy user there.
I am a member, bought one re-seller hosting there.
(Remember the one that sent more than one subscriptions and I signed up not suspecting)

I can not even post a followup or talk to the seller on that form.

They say I do not have permission for that.

If I had access I would have talk to that guy and cleared the things there.

It is bad site for some one looking for a web host.
 
Status
Not open for further replies.

Who has viewed this thread (Total: 1) View details

Who has watched this thread (Total: 2) View details

The Rule #1

Do not insult any other member. Be polite and do business. Thank you!

Members Online

Premium Members

Our Mods' Businesses

*the exceptional businesses of our esteemed moderators

Top Bottom