Help Forum How To | General Corvetteforum Questions | Feedback

parent site hacked.

Thread Tools
 
Search this Thread
 
Old 08-17-2016, 10:40 AM
  #1  
--Z06--
Pro
Thread Starter
 
--Z06--'s Avatar
 
Member Since: Oct 2008
Location: Central Va
Posts: 652
Received 122 Likes on 46 Posts

Default parent site hacked.

So I got an email stating that the parent site for Corvette forums and many other forums which I am a member of was hacked and that email addresses, user names and passwords were stolen.

I have requested that they shut down any account sI have associated with my email addresses, what steps you all take are up to yoursleves.

I'll be back with a new username ASAP.
--Z06-- is offline  
Old 08-17-2016, 10:56 AM
  #2  
Huskerman
Race Director
Support Corvetteforum!
 
Huskerman's Avatar
 
Member Since: Jan 2014
Location: Huskerland
Posts: 10,519
Received 2,798 Likes on 1,958 Posts
2021 C6 of the Year Finalist - Modified

Default

my notice did not include the CF.........
Huskerman is offline  
Old 08-17-2016, 10:58 AM
  #3  
EVRose
Race Director
 
EVRose's Avatar
 
Member Since: Oct 2010
Location: Las Vegas NV
Posts: 14,475
Received 772 Likes on 612 Posts

Default

I got nothing.
EVRose is offline  
Old 08-17-2016, 10:58 AM
  #4  
jrose7004
Team Owner
 
jrose7004's Avatar
 
Member Since: Mar 2004
Location: Oklahoma City OK
Posts: 58,255
Received 1,673 Likes on 1,296 Posts
C6 of Year Finalist (appearance mods) 2019

Default

I didn't receive a notice.
jrose7004 is offline  
Old 08-17-2016, 11:18 AM
  #5  
EVRose
Race Director
 
EVRose's Avatar
 
Member Since: Oct 2010
Location: Las Vegas NV
Posts: 14,475
Received 772 Likes on 612 Posts

Default

Why not just change your password?
EVRose is offline  
Old 08-17-2016, 11:25 AM
  #6  
Bruze
Team Owner
 
Bruze's Avatar
 
Member Since: Mar 2014
Location: Below the bottom of Berby Hollow, NYS
Posts: 21,631
Received 1,136 Likes on 882 Posts
Default

Originally Posted by --Z06--
So I got an email stating that the parent site for Corvette forums and many other forums which I am a member of was hacked and that email addresses, user names and passwords were stolen.

I have requested that they shut down any account sI have associated with my email addresses, what steps you all take are up to yoursleves.

I'll be back with a new username ASAP.
Who was the email from, and what makes you think it's legit?
Bruze is offline  
Old 08-17-2016, 12:37 PM
  #7  
Not So Fast
Le Mans Master
 
Not So Fast's Avatar
 
Member Since: Sep 2014
Location: lake havasu city arizona
Posts: 7,011
Received 982 Likes on 711 Posts
Default

I got the Email also but it was concerning Challengertalk forums (yes I lurk) it was from Vertical Scope
Here ya go
NSF

Notice of Data Breach

You may have heard reports recently about a security issue involving VerticalScope. We would like to make sure you have the facts about what happened, what information was involved, and the steps we are taking to help protect you. VerticalScope owns and operates a number of community websites. You are receiving this email because you are a registered user of the following community website(s) involved in the data breach:
www.challengertalk.com

What Happened?

On June 13, 2016, we became aware that February 2016 data stolen from VerticalScope was being made available online.

What Information Was Involved?

Community member usernames, email addresses, hashed passwords, community userIDS, community website, and the IP address the username originally registered with.

What We Are Doing

We have invalidated passwords of all VerticalScope user accounts. We have posted a site security notification on each site updating users on the potential risk to certain accounts, the password reset and steps we are implementing to improve security. We have implemented stronger password rules (passwords now require a minimum of 10+ characters and a mixture of upper- and lower-case letters, numbers and symbols) along with automated account password expiries to encourage more frequent password changes. We will remind our users to use good password practices (not using the same password for multiple online accounts and using unique strong passwords). We are in the process of implementing additional safeguards to detect, alert and mitigate any future brute force attempts, and have notified our third party vendors that interact with our various forum API's of the February breach to allow their own security teams to investigate. We are continuing our investigation and will be collecting information to provide to the appropriate law enforcement authorities.

VerticalScope is taking steps to strengthen account security. We were already using encrypted passwords and salted hashes to store passwords, and our new password controls are intended to further strengthen user security. We are taking steps to investigate and test new encryption and security technologies to further protect our users.

What You Can Do

To keep your account as safe as possible, we recommend that you regularly change your VerticalScope community password, and that you use a unique password for each of your online accounts. Using the same password for multiple online accounts significantly increases your chances of being compromised. Even though the passwords stolen in February were hashed, we recommend that if you were using (or are currently using) your VerticalScope community password across multiple online accounts, that you change your password for such other online accounts. We encourage you to regularly review your accounts and report any suspicious or unrecognized activity immediately.

For More Information

If you have any questions, please feel free to contact our Community Management team by email at cmsupport@verticalscope.com or on the website that you frequent. A support thread has been created on each website, and our support teams are on there to help you through the process and answer any questions you may have. A Notice of Data Breach is also available on community websites involved in the data breach.



This email was sent by VerticalScope Inc., 111 Peter Street, Suite 700, Toronto, ON, M5V2H1. If you have any questions regarding the communications you receive from us, please contact us.

Last edited by Not So Fast; 08-17-2016 at 12:37 PM.
Not So Fast is offline  
Old 08-17-2016, 12:42 PM
  #8  
EVRose
Race Director
 
EVRose's Avatar
 
Member Since: Oct 2010
Location: Las Vegas NV
Posts: 14,475
Received 772 Likes on 612 Posts

Default

Isnt CF run by InternetBrands?
EVRose is offline  
Old 08-17-2016, 12:45 PM
  #9  
cclive
Team Owner
 
cclive's Avatar
 
Member Since: Mar 2008
Location: Southern Utah
Posts: 21,506
Received 434 Likes on 371 Posts
Default

Originally Posted by Bruze
Who was the email from, and what makes you think it's legit?
Bingo...
cclive is offline  
Old 08-17-2016, 12:46 PM
  #10  
Not So Fast
Le Mans Master
 
Not So Fast's Avatar
 
Member Since: Sep 2014
Location: lake havasu city arizona
Posts: 7,011
Received 982 Likes on 711 Posts
Default

Where's a moderator when you need one How do we contact one
NSF
Not So Fast is offline  
Old 08-17-2016, 01:01 PM
  #11  
Sox-Fan
Melting Slicks
 
Sox-Fan's Avatar
 
Member Since: Jul 2005
Location: Mt. Pleasant S.C.
Posts: 2,989
Received 345 Likes on 266 Posts

Default

Same forum software, two different parent companies.
Sox-Fan is offline  
Old 08-17-2016, 01:03 PM
  #12  
Sox-Fan
Melting Slicks
 
Sox-Fan's Avatar
 
Member Since: Jul 2005
Location: Mt. Pleasant S.C.
Posts: 2,989
Received 345 Likes on 266 Posts

Default

http://www.internetbrandsauto.com/sites
Sox-Fan is offline  
Old 08-17-2016, 01:05 PM
  #13  
Vette_DD
Team Owner
Support Corvetteforum!
 
Vette_DD's Avatar
 
Member Since: May 2004
Location: Southern Middle TN
Posts: 82,197
Received 1,276 Likes on 935 Posts
St. Jude Donor '21-'22-'23-'24

Default

The HELP forum is where it's been for the last 17 years.

Discuss it with JT. See if he can shed any light on the subject.

Don't create new UserIDs without talking to someone here about it.

Last edited by Vette_DD; 08-17-2016 at 01:08 PM.
Vette_DD is offline  
Old 08-17-2016, 01:28 PM
  #14  
J T
IB Staff
 
J T's Avatar
 
Member Since: Feb 2009
Posts: 9,429
Likes: 0
Received 4 Likes on 4 Posts
Default

CorvetteForum is owned and operated by Internet Brands, not Vertical Scope. The two are completely different companies.

While both companies use the vBulletin software, there are some significant differences and a lot of variables. The core software, for example, is continuously updated and patched. Internet Brands' team followed the hack on Vertical Scope to find that Internet Brands' sites was approximately 9 updates ahead of Vertical Scope's sites and used better encryption of data than the MD5 that was noted in the hack on Vertical Scope. Internet Brands also imnplemented Multi-Factor Authentication, a long time ago, for advanced Administrator features to help prevent unauthorized access.
J T is offline  
Old 08-17-2016, 01:47 PM
  #15  
Not So Fast
Le Mans Master
 
Not So Fast's Avatar
 
Member Since: Sep 2014
Location: lake havasu city arizona
Posts: 7,011
Received 982 Likes on 711 Posts
Default

Thanks Jim and JT, puts my mind at ease a little
NSF
Not So Fast is offline  
Old 08-17-2016, 04:38 PM
  #16  
Bruze
Team Owner
 
Bruze's Avatar
 
Member Since: Mar 2014
Location: Below the bottom of Berby Hollow, NYS
Posts: 21,631
Received 1,136 Likes on 882 Posts
Default

Originally Posted by Not So Fast
Thanks Jim and JT, puts my mind at ease a little
NSF
Bruze is offline  
Old 08-17-2016, 06:56 PM
  #17  
RocketDawg
Le Mans Master
 
RocketDawg's Avatar
 
Member Since: Sep 2004
Location: Madison (Huntsville) Alabama
Posts: 5,118
Received 120 Likes on 108 Posts
CI 6-7-8 Veteran
St. Jude Donor '09

Default

I haven't received any information about the Corvette Forum, but about a month ago I got a notification from the Subaru Forester forum. What's funny about it is that the notification had 2 or 3 typos in it, and sounded like it was written in Nigeria, so I just ignored it. Turns out it was real. The Caddy ATS forum looks identical to the Subaru one, so I assume they are the same owner. I had to reset everything on both of them.

The only thing odd about this forum is that I've had to sign in a couple of times recently, and I normally just stay signed in all the time since I'm on my own computer. That issue seems to have cleared up though.
RocketDawg is offline  
Old 08-17-2016, 08:17 PM
  #18  
J T
IB Staff
 
J T's Avatar
 
Member Since: Feb 2009
Posts: 9,429
Likes: 0
Received 4 Likes on 4 Posts
Default

There was no notification sent about CorvetteForum because CorvetteForum is not owned by Vertical Scope and thus CorvetteForum was not involved in the data breach.

As far as the log in issue where you had to log in 2 or 3 times in the past few weeks, that was normal and also stated in the Help forum. They were due to updates and a few changes to the software. Some updates and changes are more seamless than others.

Originally Posted by RocketDawg
I haven't received any information about the Corvette Forum, but about a month ago I got a notification from the Subaru Forester forum. What's funny about it is that the notification had 2 or 3 typos in it, and sounded like it was written in Nigeria, so I just ignored it. Turns out it was real. The Caddy ATS forum looks identical to the Subaru one, so I assume they are the same owner. I had to reset everything on both of them.

The only thing odd about this forum is that I've had to sign in a couple of times recently, and I normally just stay signed in all the time since I'm on my own computer. That issue seems to have cleared up though.
J T is offline  

Get notified of new replies

To parent site hacked.




Quick Reply: parent site hacked.



All times are GMT -4. The time now is 11:28 PM.