I Got a new email from our hacker today

More
11 years 3 months ago #54247 by Ari
Replied by Ari on topic I Got a new email from our hacker today
I got emails from them, too. The first was a few days before the hacker leaked email addresses to the Internet. This coincided with a massive brute force attempt on my admin login, which would not be possible unless the hacker knew the url with query string (protected with adminexile) that was in the joomdonation ticket system (since changed). l received 35,000 attempts to log in that night, again, just a couple days before the hacker went public.
Only a remote possibility. Not an irrefutable case yet. Innocent until proven guilty.

Please Log in or Create an account to join the conversation.

More
11 years 3 months ago #54262 by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic I Got a new email from our hacker today

Kostas wrote: Hello guys.

I just recieved the same email from MiwiSoft.com.

The funny is that they send that promotion email about MijoEvent to my corporate email which I used only on JoomDonation as second user. Never I sing up on their website, nether I know them.

So Tuan, in my opinion, they hacked your server.


Maybe so, at least somehow they got our users database. But we won't spend time on this anymore, we need to come back to the development to improve the product. Exciting time ahead.

Regards,

Tuan

Please Log in or Create an account to join the conversation.

More
11 years 3 months ago #54273 by Tim
Replied by Tim on topic I Got a new email from our hacker today
I am going to come in here and fully reiterate what Tuan has said.

Innocent until proven guilty. Users throwing around accusations of who has done what based on an email newsletter is dangerous. I know I have endless newsletters come in that I could swear I have never signed up for. By accusing another company of hacking you are likely to cause just as much damage to Tuan, and it would not be the first time the internet has got it wrong.

I know it is frustrating and this whole saga has been a worry for everyone. Be thankful it has turned out to be largely a non event. It is Tuan who has really felt the pain here and if he wishes to push forward with development and put this behind him then he should be allowed to do so, rather than have to spend his time defending other companies because frankly, who knows who hacked him. All I know is they clearly weren't idiots, but you would have to be an idiot to email everyone afterwards with your company's newsletter.

Lets just learn some important lessons from this:
  • Change your password after sharing it with anyone
  • Keep backups, lots of them
  • Apply updates
  • Keep a watch on your servers activity, and actively check and respond to any changes

Please Log in or Create an account to join the conversation.

Moderators: Tuan Pham Ngoc