Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject:
PostPosted: Fri Nov 18, 2011 1:55 pm 
Offline
Senior Member

Joined: Fri May 02, 2008 8:44 pm
Posts: 1121
Piki wrote:
I'm certainly not asking for any sympathy. I just came on to post in case there was some sort of security exploitation. Getting all those emails at once was completely unexpected, and with them coming through over a period of roughly 20 minutes, it was rather annoying. With all the security hackings that have been happing with my friends, and the ones that happened to me several months before I discovered Linode, I'm a bit paranoid about my digital security.

Completely understood. You can't be too paranoid about security 8)

But I'm still suspecting that it was just another bug with the already bug-riddled member database code, rather than the result of malicious activity. Bugs like this can stay hidden for years, suddenly show up when there's a rare coincidence of user IDs, thread IDs, and the current phase of the moon, and then disappear again until the next time. Even as we speak, somebody somewhere might be wondering why he's not getting notification e-mails for threads he subscribed to. But that's a lot less noticeable than getting spammed, hence it doesn't get reported.

Since you posted the full headers including Message IDs, Linode staff may be able to track them down -- or at least change their settings so that any future incidence of this bug goes on the record. While they're doing so, just change your passwords and relax. If you get any more e-mails, please post those Message IDs, too.

Take it easy, life's too short to get all stressed up.


Top
   
 Post subject:
PostPosted: Fri Nov 18, 2011 2:14 pm 
Offline
Senior Member
User avatar

Joined: Thu Jun 16, 2011 8:24 am
Posts: 412
Location: Cyberspace
I'm not discounting a potential bug, nor am I discounting a potential security flaw in an old unmaintained forum software. It could be either one. I'll let Linode check that out. In the mean time, I'll save all the emails to my hard disk, in case Linode asks for them. After looking at the headers, though, I don't think they were forged; I think they were actually sent by the forum, and that it's a matter of if there's a bug in the forum that needs fixed.

And yes, all my passwords are changed. I also changed the email address I have on my forum profile.

_________________
Kris the Piki Geeker


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 6 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group