Welcome to the EGGhead Forum - a great place to visit and packed with tips and EGGspert advice! You can also join the conversation and get more information and amazing kamado recipes by following Big Green Egg to Experience our World of Flavor™ at:
Facebook  |  Twitter  |  Instagram  |  Pinterest  |  Youtube  |  Vimeo
Share your photos by tagging us and using the hashtag #BigGreenEgg.

Want to see how the EGG is made? Click to Watch

Hacker Alert!

Options
Hillbilly-Hightech
Hillbilly-Hightech Posts: 966
edited September 2012 in EggHead Forum
Howdy,

So some Einstein hacker wannabe has decided he'd try to access my forum account.  

Just wanted to let ya'll know that you should reset your passwords - and please, do NOT use a password like "password" or your username, or anything like that.  

You should use a password which means something ONLY to you, should be a combination of lowercase & uppercase letters, as well as numbers, and it should be a pass "phrase" (meaning, instead of a word, like "hello", it should be something like "HAhybhIDfowua43" which means "Hello A$$hole hacker you better hope I Don't find out who u are").  

Anyway, this has been a friendly service announcement... 

BTW Tweeve, think you could access my acct that easily, eh???


Don't get set into one form, adapt it and build your own, and let it grow, be like water. Empty your mind, be formless, shapeless — like water. Now you put water in a cup, it becomes the cup... Now water can flow or it can crash. Be water, my friend. - Bruce Lee

Comments

  • gerhardk
    Options
    How did you know that somebody tried hacking your user account?

    Gerhard
  • Hillbilly-Hightech
    Options
    I got an email stating that I'd requested a password reset.  Because I know I didn't do that, someone else had to try to log into my account, then either requested the reset, or tried to guess my password so many times that it triggered a response from the admins.  

    Either way, it wasn't me who requested the reset.  If I were you all, I'd rather be safe than sorry & go ahead & reset your passwords as well.  
    Don't get set into one form, adapt it and build your own, and let it grow, be like water. Empty your mind, be formless, shapeless — like water. Now you put water in a cup, it becomes the cup... Now water can flow or it can crash. Be water, my friend. - Bruce Lee
  • Fred19Flintstone
    Options
    Good information.  I've reset.
    Flint, Michigan
  • The Cen-Tex Smoker
    Options
    Howdy,

    So some Einstein hacker wannabe has decided he'd try to access my forum account.  

    Just wanted to let ya'll know that you should reset your passwords - and please, do NOT use a password like "password" or your username, or anything like that.  

    You should use a password which means something ONLY to you, should be a combination of lowercase & uppercase letters, as well as numbers, and it should be a pass "phrase" (meaning, instead of a word, like "hello", it should be something like "HAhybhIDfowua43" which means "Hello A$$hole hacker you better hope I Don't find out who u are").  

    Anyway, this has been a friendly service announcement... 

    BTW Tweeve, think you could access my acct that easily, eh???



    Why do you think it was Tweev?
    Keepin' It Weird in The ATX FBTX
  • nolaegghead
    nolaegghead Posts: 42,102
    Options
    You might want to keep an eye on your other accounts.  I can't imagine any financial gain in hacking a cooking forum.  That server should have pretty good security for what it is.  Consider you might have a key-logger on your system - where a hacker would get urls/usernames/passwords and they just filter the data, go through the list and take over accounts, hoping to find personal data. 

    Also, I'd check if the email for the pw reset is real.  That's a common fishing method.
    ______________________________________________
    I love lamp..
  • nolaegghead
    nolaegghead Posts: 42,102
    Options
    If the server was hacked, we should see a pattern of users with the same problem.  Keep an eye out folks.
    ______________________________________________
    I love lamp..
  • nolaegghead
    nolaegghead Posts: 42,102
    Options
    Figgured it out.  You don't get an email if someone has your PW and is logged in and changes it.  You only get an email if you aren't logged in and someone enters in your username (mine is nolaegghead) and requests a PW change.  Anyone can do that.  And unless they control the email your account is attached to, they're not gonna be able to change your pw. 

    So, HH, you apparently are a victim of someone effin' wif ya.
    ______________________________________________
    I love lamp..
  • nolaegghead
    nolaegghead Posts: 42,102
    Options
    Now I'm realizing how drunk I am. :)  I didn't read your second post, HH. 

    I coded our company's web portal security.  Some of the best fun coding was creating obfuscated URLs for file security using regular old DES packages.  good times.  burp.
    ______________________________________________
    I love lamp..