Stooky 6th Gear February 20, 2018 Share February 20, 2018 JUST IN: HardwareZone Forum hit by security breach, 685,000 registered user profiles affected, police report lodged Here is the statement from SPH Magazines, which owns the HardwareZone Forum site, in full: "Arising from a suspicious posting on HardwareZone (HWZ) Forum website on 18 February, an investigation was immediately launched to ascertain whether a security breach on the HardwareZone (HWZ) Forum site occurred. The investigation found that: A Senior Moderator’s account had been compromised by an unidentified hacker and used to view approximately 685,000 registered user profiles since September 2017. The hacker used the compromised credentials to impersonate the Senior Moderator to retrieve user profile data which comprised name, email address and user ID, and possible optional data fields. The HWZ database does not contain NRIC numbers, telephone numbers and addresses as these were purged in line with the Personal Data Protection Commission (PDPC) Guidelines in July 2015. As a matter of precaution, forum users were advised to change their forum account password. SPH Magazines, which owns the HWZ site, has also engaged security consultants to conduct a thorough review of the system. A police report has been lodged and PDPC has been informed. SPH Magazines and HWZ sincerely apologise to HWZ users for this breach of security. We remain committed to protecting all personal data shared with us." http://www.straitstimes.com/singapore/st-now-news-as-it-happens-feb-20-2018 MCF got tio bo? Also under SPH, right? ↡ Advertisement 4 Link to post Share on other sites More sharing options...
DACH Supersonic February 20, 2018 Share February 20, 2018 MCF moderators, please look into this and take necessary precautions, if possible. @pchou @kobayashigt @babyblade Thank you. 1 Link to post Share on other sites More sharing options...
Xers007 Supercharged February 20, 2018 Share February 20, 2018 This forum got all our critical info... Better start to delete the info before something happens... 1 Link to post Share on other sites More sharing options...
Vid Hypersonic February 20, 2018 Share February 20, 2018 I remember someone said SSL would be implemented here but till now no sound no action. Link to post Share on other sites More sharing options...
Kusje Supersonic February 20, 2018 Share February 20, 2018 This forum got all our critical info... Better start to delete the info before something happens...Uh. What critical info did you give them? They have my email address, IP address and password (which is the same as my email). Hopefully they at least salted the password so hackers can't just download it Willy nilly.... But even if they did have my password, they wouldn't be able to access my email account as it is protected with 2fa. I remember someone said SSL would be implemented here but till now no sound no action.What's ssl? Link to post Share on other sites More sharing options...
meowc4tz 3rd Gear February 20, 2018 Share February 20, 2018 They have my car information and address. Later come steal my car ): 1 Link to post Share on other sites More sharing options...
Unltd 5th Gear February 20, 2018 Share February 20, 2018 (edited) MCF did implement ssl, just not fully. They implemented it only for profile Need to correct the above, they didn’t implement properly for profile as well, when they said implemented and I visited profile pages, can see the https, now it’s gone. I think errr... need improvement la... quickly and properly done... Edited February 20, 2018 by Unltd Link to post Share on other sites More sharing options...
Xers007 Supercharged February 20, 2018 Share February 20, 2018 Uh. What critical info did you give them? They have my email address, IP address and password (which is the same as my email). Hopefully they at least salted the password so hackers can't just download it Willy nilly.... But even if they did have my password, they wouldn't be able to access my email account as it is protected with 2fa. What's ssl? Full name, address, mobile number and car number plate. Link to post Share on other sites More sharing options...
Unltd 5th Gear February 20, 2018 Share February 20, 2018 I worry for those with yellow p, i remember having to give full and verifiable personal data to get it, didn’t dare to have it on cause was worried about security. 1 Link to post Share on other sites More sharing options...
Kusje Supersonic February 20, 2018 Share February 20, 2018 Full name, address, mobile number and car number plate.Better delete. Or give fake info next time. Link to post Share on other sites More sharing options...
Vid Hypersonic February 20, 2018 Share February 20, 2018 What's ssl? https... the tiny lock you see beside the URL. Link to post Share on other sites More sharing options...
Kopites Supersonic February 20, 2018 Share February 20, 2018 (edited) Full name, address, mobile number and car number plate.I did not sign as premium member. Free gift come with a risk. My opinion only. Don't flame me. Edited February 20, 2018 by Kopites 3 Link to post Share on other sites More sharing options...
Xers007 Supercharged February 20, 2018 Share February 20, 2018 Better delete. Or give fake info next time.Removed Link to post Share on other sites More sharing options...
Tianmo Hypersonic February 20, 2018 Share February 20, 2018 If HWZ was hit in Sept 2017, and news only surface now, i am not going to be surprise that MCF is already hit, just a matter of will this news surface or not. 2 Link to post Share on other sites More sharing options...
Vid Hypersonic February 20, 2018 Share February 20, 2018 I worry for those with yellow p, i remember having to give full and verifiable personal data to get it, didn’t dare to have it on cause was worried about security. Actually got ssl or not is not the major issue. Usually hacks happen at server level. It is how secured a server is. There is hardly any information passed between user and website for MCF. Even in plain text, it will take a hacker a long time to accumulate a lot of user logins. 1 Link to post Share on other sites More sharing options...
Xers007 Supercharged February 20, 2018 Share February 20, 2018 (edited) I did not sign as premium member. Free gift come with a risk. My opinion only. Don't flame me. There is much more info they will have as some folks use their service.If HWZ was hit in Sept 2017, and news only surface now, i am not going to be surprise that MCF is already hit, just a matter of will this news surface or not. You no worries lah... No hacker dare touch you... Edited February 20, 2018 by Xers007 1 Link to post Share on other sites More sharing options...
Unltd 5th Gear February 20, 2018 Share February 20, 2018 Actually got ssl or not is not the major issue. Usually hacks happen at server level. It is how secured a server is. There is hardly any information passed between user and website for MCF. Even in plain text, it will take a hacker a long time to accumulate a lot of user logins. Yup, I am assuming the servers are properly secured so there should be little to no vector attack vulnerability, so intrusion will be from site. So pen test, code review and vulnerability assessment is the way to go. Pen test being one of the most important especially by good qualified white hats. Link to post Share on other sites More sharing options...
Tianmo Hypersonic February 20, 2018 Share February 20, 2018 There is much more info they will have as some folks use their service. You no worries lah... No hacker dare touch you... they hack my account also dont gain anything mah. At most they get to see all the little demons and devils only, who want sia. Mayb @radx acct nong nong time ago tio hack liao. ↡ Advertisement Link to post Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In NowRelated Discussions
Related Discussions
My CAT Forum
My CAT Forum
World’s first trillionaire may emerge in 10 years, disparity report finds
World’s first trillionaire may emerge in 10 years, disparity report finds
Environment Building evacuated due to ‘security situation’; no threat items found so far: Grace Fu
Environment Building evacuated due to ‘security situation’; no threat items found so far: Grace Fu
Test forum upg
Test forum upg
Any MX5 forum?
Any MX5 forum?
New thread from testing
New thread from testing
Hit and Run at MSCP
Hit and Run at MSCP