• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

PSA - Ubuntu Forums Hacked

lxskllr

No Lifer
Just to make you all aware. You should assume your password is compromised, so proceed accordingly.

Ubuntu Forums is down for maintenance

There has been a security breach on the Ubuntu Forums. The Canonical IS team is working hard as we speak to restore normal operations. This page will be updated regularly with progress reports.
What we know

Unfortunately the attackers have gotten every user's local username, password, and email address from the Ubuntu Forums database.
The passwords are not stored in plain text. However, if you were using the same password as your Ubuntu Forums one on another service (such as email), you are strongly encouraged to change the password on the other service ASAP.
Ubuntu One, Launchpad and other Ubuntu/Canonical services are NOT affected by the breach.

Progress report

2013-07-20 2011UTC: Reports of defacement
2013-07-20 2015UTC: Site taken down, this splash page put in place while investigation continues.

If you're using Ubuntu and need technical support please see the following page for support:

Finding Help.

If you're looking for a place to discuss Ubuntu, in the meantime we encourage you to check out these sites:

The Ubuntu subreddit
The Ubuntu Community on Google+
Ubuntu Discourse

http://ubuntuforums.org/announce.html

15u3X7V.png
 
As long as you only use the same password for Ubuntu AND anand forums, you're good to go!
(Joke).

I just can't understand the mindset of people who think it's clever to go messing about (hacking) with other peoples websites. It's probably the same as going round and pointlessly vandalizing places, just for the kicks.

A lot of the Linux resources, is really done by volunteers, who have dedicated some of their spare time to helping the wider community, and they (hackers) end up doing things like this, it's sad.
 
You're famous! :^D
I *think* I'm the first one that reported it (off-site).

Check the time on my Conky (1:11 USMST = 20:11 UTC).

Progress report

2013-07-20 2011UTC: Reports of defacement

I've been testing/lurking on their dev test forum, so I knew where they hang.

Learning a lot from them...
 
Last edited:
soo... were the ubuntu forums The same vbulletin 3.8.7 with the same vulnerability as ours?
They converted over to VB4, not too long ago.

Been having all sorts of sync problems, ever since. Not sure about any security issue(s)

AFAIK, the perps gained access to the server that it's sitting on. Not sure if they found a hole in VB4 or it's an Apache vuln, or whatever.
 
Some people have said something on the lines of, that you should NOT use your normal email address on forums, in case it gets hacked.
I'm beginning to think they had a good point, after all these hackings (some of the other forums I have used, have also been hacked, over the years).
 
Some people have said something on the lines of, that you should NOT use your normal email address on forums, in case it gets hacked.
I'm beginning to think they had a good point, after all these hackings (some of the other forums I have used, have also been hacked, over the years).

I don't think it matters too much as long as your email password isn't the same as your forum pass. The worst thing is you might get some spam, or a phishing attempt.
 
I don't think it matters too much as long as your email password isn't the same as your forum pass. The worst thing is you might get some spam, or a phishing attempt.

Ok.

I think it was related to the specifics of what the forum was, then.

It was a mainly gaming related forum, and many of the forum users (about 50% as PC platform covered as well) were xbox 360 owners/users.
So the problem was, when the forums were hacked, anyone whose xbox360 account had the same email address as the forum, were potentially in trouble.

Some xbox360 people had their xbox accounts stolen, as a result (it was thought).

---------------------------------------

It was about the time when the Sony PS3 hackings happened, so any admin accounts in PS3, who used the same id/passwords on other networks, was possibly how the cross hackings occurred.


----------------------------------------

Back on topic:
I'm tempted by the 'big' Linux community forums, but the "bad" attitudes I see in some threads, kind of puts me off.

E.g. Made up, but based on what I have seen.

NoobUser: How do you switch graphics mode using a gui, when the gui prog has bombed out ?
LinuxPro: Everyone knows you use terminal, SILLY!!!!
NoobUser: Ok, what to I type into terminal, what is it called, and what is the parameter ?
LinuxPro: Everyone who should be using Linux knows the answer, so silly question.
NoobUser: You are not helping, can anyone tell me ?
LinuxPro: Ok, I admit it, I can't remember myself what it is.
NoobUser: Anyone ?
SomeoneElse: xyzmodesSetupJOKE 123456789 -Jokes
----------------
So I need to be brave enough to join them, lol.
 
Back on topic:
I'm tempted by the 'big' Linux community forums, but the "bad" attitudes I see in some threads, kind of puts me off.

E.g. Made up, but based on what I have seen.

NoobUser: How do you switch graphics mode using a gui, when the gui prog has bombed out ?
LinuxPro: Everyone knows you use terminal, SILLY!!!!
NoobUser: Ok, what to I type into terminal, what is it called, and what is the parameter ?
LinuxPro: Everyone who should be using Linux knows the answer, so silly question.
NoobUser: You are not helping, can anyone tell me ?
LinuxPro: Ok, I admit it, I can't remember myself what it is.
NoobUser: Anyone ?
SomeoneElse: xyzmodesSetupJOKE 123456789 -Jokes
----------------
So I need to be brave enough to join them, lol.

My problem with the Ubuntu forums was the size. An endless stream of stupid questions drove the good questions off the front page quickly. Sometimes RTFM is the best answer to give. People ask stuff a basic DuckDuckGo search would easily answer, or search the Ubuntu forums themselves. It's rude taking up people's time without putting any effort in beforehand.

That said, if you've tried, and you get crap for your question, fsck 'em. Don't take it personally, and try asking again somewhere else. Personally, I like these forums. They aren't heavily trafficked, and answers may not be as quick as some places, but the answers are usually good, and I like the people.

For self help, Arch has excellent documentation, and it only requires slight translation for your distro of choice. For Ubuntu, Debian documentation will get you good results too.
 

Thanks!

My problem with the Ubuntu forums was the size. An endless stream of stupid questions drove the good questions off the front page quickly. Sometimes RTFM is the best answer to give. People ask stuff a basic DuckDuckGo search would easily answer, or search the Ubuntu forums themselves. It's rude taking up people's time without putting any effort in beforehand.

That said, if you've tried, and you get crap for your question, fsck 'em. Don't take it personally, and try asking again somewhere else. Personally, I like these forums. They aren't heavily trafficked, and answers may not be as quick as some places, but the answers are usually good, and I like the people.

For self help, Arch has excellent documentation, and it only requires slight translation for your distro of choice. For Ubuntu, Debian documentation will get you good results too.

Thanks, that is VERY useful information.

I can understand why people sometimes get VERY frustrated with Linux.

I am a very, very long term user of Suse (as well as windows incarnations and tests of other distros), I always liked it, because in the 'old' days, its distribution came on a big pile of CDs, and they included a rich set of "free" software packages.
The range of included packages was MIND BOGGLING, and this originally was at a time when the internet was in its infancy, so access was very expensive, slow and problematic.
In the 'old' days, downloading an entire CD was completely out of the question (at home!), and probably would have taken weeks or even a month, to accomplish.

Personally, I like these forums. They aren't heavily trafficked, and answers may not be as quick as some places, but the answers are usually good, and I like the people.

Absolutely BANG ON!, yes, that is EXACTLY what I thought, and part of the reason, I joined this forum in the first place.
 
Last edited:
My problem with the Ubuntu forums was the size. An endless stream of stupid questions drove the good questions off the front page quickly. Sometimes RTFM is the best answer to give. People ask stuff a basic DuckDuckGo search would easily answer, or search the Ubuntu forums themselves. It's rude taking up people's time without putting any effort in beforehand.

That said, if you've tried, and you get crap for your question, fsck 'em. Don't take it personally, and try asking again somewhere else. Personally, I like these forums. They aren't heavily trafficked, and answers may not be as quick as some places, but the answers are usually good, and I like the people.

For self help, Arch has excellent documentation, and it only requires slight translation for your distro of choice. For Ubuntu, Debian documentation will get you good results too.
I agree, it doesn't take long to outgrow the usefulness of the ubuntuforums and thier off topic subforums are policed w/ an iron fist. I've found the best help on stackexchange and nixcraft, usually by searching rather than asking.
 
Back
Top