• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

question about the "Breach"

sao123

Lifer
With respect to the security breach:

http://forums.anandtech.com/announcement.php?f=14&a=67


In the process, anyone who was logged in and accessed the forums during this period had their stored PMs accessed by this script. In addition, any user who manually logged in had their user name and password accessed (141 total users).

Is this speaking of only those who manually logged in (by typing in your userid and password... and not seemingly inclusive of those who accessed the forums, via a cached credentials (save my login via cookie)?
 
That is correct. Users who were already logged in did not have their passwords taken, just their PMs.
 
This was the "Test Announcement"?

I did click it, what are the consequences?
You're not on the list of compromised accounts that we recovered, so it doesn't look like your password was taken. However it's reasonable to assume your PMs were copied off to the remote server.
 
You're not on the list of compromised accounts that we recovered, so it doesn't look like your password was taken. However it's reasonable to assume your PMs were copied off to the remote server.

I wasn't logged in or clicked on anything but when I tried to log in my old password no longer worked. Perk has since fixed it but I was wondering if I was on that list of the 141?

I hadn't logged in since around April because I thought I was perma banned then.
 
I wasn't logged in or clicked on anything but when I tried to log in my old password no longer worked. Perk has since fixed it but I was wondering if I was on that list of the 141?

I hadn't logged in since around April because I thought I was perma banned then.

Why were you perma banned ?
 
You know... i believe I had seen a "test announcement" at the top of the screen at least 3 times over the past few weeks. Never thought anything about it until today.

This may go deeper than just yesterday when it was seen.
 
I actually have the same impression too. I think there was _something_ I noticed a few times but never payed any attention at all.
 
You know... i believe I had seen a "test announcement" at the top of the screen at least 3 times over the past few weeks. Never thought anything about it until today.

This may go deeper than just yesterday when it was seen.


I actually have the same impression too. I think there was _something_ I noticed a few times but never payed any attention at all.


Thank you finally people that confirm it for me. I told people about the breach way before hand.
 
Was my account compromised?

Can anyone help me?

I haven't manually logged in for quite sometime now I think. 😕
 
Never noticed the announcement but a little worrying PMs got grabbed. I'm actually surprised this doesn't happen more often on tech forums. Must be a good security team.
 
If any of you use the same password here as you do for other important things (like banking accounts, etc.), you'd be well advised to change those passwords, pronto!
 
This happened yesterday. So unless you told someone between 8:30am and 10:40am ET, you're barking up the wrong tree.

Its happened before ViRGE... Ive seen it at least 3 times over the last few weeks.


I actually have the same impression too. I think there was _something_ I noticed a few times but never payed any attention at all.

I remember this as well.
 
Last edited:
Back
Top