Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

Hackergate part four - PLEASE READ!

993 replies

RebeccaMumsnet · 20/08/2015 10:12

Previous thread here and original thread here

We will post here throughout the day with updates and info, please do post any questions and we will get to them as soon as possible.

If you need to get in touch off of the boards, please email [email protected], we have a team of people working through the inbox now and will get back to you ASAP but please do bear with us, it's very busy.

There is also a specific thread about passwords here.

Thanks all
MNHQ

OP posts:
Thread gallery
10
cozietoesie · 20/08/2015 20:58

As he's in the States he ought to be even more circumspect.

BoreOfWhabylon · 20/08/2015 20:58

Mirror journo rang the number posted on SadSac website, I believe.

SadSac's American, apparently and not a father.

StephanieBeacham · 20/08/2015 20:58

One of his mates. Sounded a bit pathetic apparently. Like 'well Jeff said it was a sick idea and he's a mate so erm, yeah, and mumsnet is just really really mean about fathers, yeah, uhhh, um thanks'

ItsAllGoingToBeFine · 20/08/2015 20:56

If he's in the states as suspected things get more complicated re police etc

clam · 20/08/2015 20:54

Am I missing something here? How come a Mirror journo has interviewed Jeffrey (or one of his mates), yet the police haven't?

TiredButFineODFOJ · 20/08/2015 20:53

No I feel bad now in case I'm going to add to ruining a mner's day. I do think given Jeffrey's modus operandi it's probably a "victim's" number he is hoping sngry companies/mumsnetters will call. Though I was kind of hoping for a crazy dadsec clown voicemail (hence linking the Jeffrey with the number so the feds can do some proper late night arresting and not just hoax swatting)

excitedbutsick · 20/08/2015 20:53

I have also had strange issues with logging in. After I reset my password this morning and logged in it took me straight back to the login page with the advice to change to a secure password, the url was the correct one. Also when I open a new session it has the login button on the homepage but I can navigate to a talk page and it will have me as logged in, without actually using the login button.

BabCNesbitt · 20/08/2015 20:52

MrsMcGregor, I requested a password reset about three times last night because I thought the request hadn't worked, and then read a post here explaining that with the number of request involved, it was highly likely that for one reason or another, the reset email would probably take a while to come through. I got one reset email through last night, but the other two didn't arrive until this afternoon, and I just deleted those.

OneLittleLady, yep, got an email from Virgin East Coast today advising me to update my password. I just assumed it was as a reaction to the two reasonably newsworthy hacks this week, this and the Ashley Madison thing. Would probably go to the site to change it if you're concerned, rather than following a link in an email, though.

TiredButFineODFOJ · 20/08/2015 20:50

Google says that a Mirror journo has spoken to one of the group. I think they do like the publicity so that will make them easier to trace.

cozietoesie · 20/08/2015 20:49

Ah. I found Jeffrey's song - pretty well explains everything.

Arkkorox · 20/08/2015 20:48

tired did you call it?

WellWhoKnew · 20/08/2015 20:44

So it does! Thanks for the insight. I have never found URLs interesting until now. I am hoping, though, it's a passing fad...no disrespect.

VivaLeBeaver · 20/08/2015 20:42

I should be safe then.. I dnt have my real name on my profile and I'm ex directory.

ItsAllGoingToBeFine · 20/08/2015 20:40

Google a real name and quite often it will pop up on 192.com or similar

VivaLeBeaver · 20/08/2015 20:37

How does he get actual addresses to send the swat team to?

I'm on holiday anyway.

akkakk · 20/08/2015 20:34

Bore - not a problem :)

WellWhoKnew
this is how URLs are constructed...
there are different sections which all are of use to the server...

www.domain.com/folder/page?variable1=fred&variable2=mary

in the above, lets split it down:

https
is the protocol being used - http = Hyper Text Transfer Protocol or some such thing :) - basically it means pages linked together and is how the web started... the s bit at the end is a secure bit which encrypts the conversation between computer and server. You can have other bits here - e.g. ftp:// for file transfer protocol - which is a bit more technical...

://
don't worry about it! - usually your browser ignores it / hides it

www.domain.com
this is your 'domain' well sort of :) the domain is actually the domain.com bit... the world is split in top level domains (TLDs) - the .com bit and alternatives might be .co.uk or .uk for the UK - .com is american as that is where they started this process...

when you buy the domain - you can then choose the bits to go before it so you could have forum.domain.com / www.domain.com / etc. - www is a convention and not required, sometimes they all just end up at the same place...

/
this is significant - everything to the left of the first single slash says which server to go looking for - everything to the right is about finding something on that server...

folder
you can now subdivide pages etc. so can have folders if you wish, you can also use this bit differently using htaccess rules, but roughly speaking if we think of each bit between slashes as being a method of categorising then that generally makes sense - used to make it legible for users, and easy to use for the computer...

page
eventually you have something to the right of the last slash - this is likely to be the actual page - it might have an ending such as php or aspx - or it might not :)

? &
this is the start of a list of variables to feed into that page, the first one is a question mark, the rest being ampersands.
between each is a variable and its value e.g. variable 1 = fred the page will suck that in and use it to personalise the experience...

so in your examples:
/talk/shite_stuff/123456-wot-is-going-on?trending=1
/talk/shite/123456-wot-is-going-on?#prettyphoto.

the ?trending=1 is simply a variable to be read by the page - and irrelevant -you can put your own in and see what happens - it used to be an earlier form of hacking - add &user=admin to the end and early web pages would let you be admin Grin

that is a very generalised overview of URLs - but maybe helpful - the key thing with hackers is to check the www.domain.com bit - if that is not as you expect then you are on someone else's website - if that is fine, then the rest may not matter...

of course you can use URLs in a far more complex way (look at Amazon) - but for now that will do :)

StephanieBeacham · 20/08/2015 20:33

Tired - maybe don't put that on here? I think most of us are sick of it Smile

TiredButFineODFOJ · 20/08/2015 20:30

Scary dadsec.lol page

Hackergate part four - PLEASE READ!
StephanieBeacham · 20/08/2015 20:28

Yes but what will you say when someone picks up the phone? I don't see the point. They will hardly tell you who they are if they're up to no good. And if it's some innocent person you're adding to the botheration they're having as well.

Don't do it.

TiredButFineODFOJ · 20/08/2015 20:27

Well it's not 0845 or anything, it's a "regular" phone number, if it's not mumsnet towers I guess it's either a crazy answerphone message, or a staffer's home number

StephanieBeacham · 20/08/2015 20:25

The rozzers were here two nights ago and they were quite nice. They would be no match for ds3 though.

The thing is about that sort of attack is that once people are aware of the threat and that it's likely to be a hoax rather than a real situation, they're not going to be nearly so freaked out as when it's unexpected.

I think it must have been appalling for poor old bear the other night, and Justine's 'staff', but it won't have the same impact if he does it again - plus the police are forewarned too, so may just double check every call of that nature anyway before they go in.

KitKat1985 · 20/08/2015 20:24

I bet TiredButFineODJOF it's just some random premium rate number.

HadToReregister · 20/08/2015 20:24

As my NN suggests I have had to re-register to post this. My username was one of those on the list. Below is a C&P of the email that I have sent to MNHQ as I cannot access my old account at all. That's not the only problem I am having either.

I logged on to Mumsnet last night and having read Justine's message about the DDOS issue, immediately changed my password. I had some problems getting it to work so requested a re-set and made sure that I updated it to a different password. I also changed the email address that I was using to one that I had set up specifically for social media and which contains no personal details.

I have tried to log into MN this evening and my new password will not work. I have tried my old one and it doesn't work either. So I requested another re-set to be sent to my new email account - only now I can't access that either. I absolutely KNOW that I am using the right password for it because I wrote it down and kept it somewhere safe.

So now I cannot access MN at all. I cannot access the email account that is associated with my MN profile. This seems like a hell of a coincidence when my MN username, IP address and password have just been published.

I have asked to be de-registered from MN and that MNHQ also erase all of my posting history back to when I originally joined in 2010. I feel that I have no option but to ask for MNHQ to do this because it seems that my data is not safe.

HarshbutfairTess33 · 20/08/2015 20:23

In the early days of Internet Forums, some users had passwords which could be easily guessed or deduced by knowing the names of their pets, or their football teams, or something?

Occaisionally someone would try to get into another users account by simply guessing a password.

That is why you should choose a complicated password.

TiredButFineODFOJ · 20/08/2015 20:19

I'm going down the phonebox to call the number

Swipe left for the next trending thread