Homepage Visited by Indonesians

  • 48 Replies
  • 13994 Views
Homepage Visited by Indonesians
« on: October 27, 2017, 07:28:18 PM »
Came here to check on the status of the merger discussion, hit https://theflatearthsociety.org/home/ first and noticed that it looked somewhat different.


*

Rayzor

  • 12111
  • Looking for Occam
Re: Homepage Visited by Indonesians
« Reply #1 on: October 28, 2017, 12:17:15 AM »
That's the Indonesian branch of the Flat Earth Society.   

Stop gilding the pickle, you demisexual aromantic homoflexible snowflake.

*

Username

  • Administrator
  • 17680
  • President of The Flat Earth Society
Re: Homepage Visited by Indonesians
« Reply #2 on: October 28, 2017, 10:18:42 AM »
Monday, I will be hiring a consultant from Sword and Shield to look over our security and analyze this attack. You can look them over here, and see what you think: http://www.swordshield.com
« Last Edit: October 28, 2017, 10:27:34 AM by John Davis »
The illusion is shattered if we ask what goes on behind the scenes.

*

Rushy

  • 8971
Re: Homepage Visited by Indonesians
« Reply #3 on: October 28, 2017, 10:43:25 AM »
Are you really sure it takes the expertise of a third party enterprise infosec company to secure a forum homepage? Sure, they'll help you as long as you give them money, but I can't help wondering if this is a little excessive.

*

Username

  • Administrator
  • 17680
  • President of The Flat Earth Society
Re: Homepage Visited by Indonesians
« Reply #4 on: October 28, 2017, 10:48:37 AM »
I'm sure it is excessive. They have worked well for me in the past, and I'd like to see what kind of trail exists if any. I know several folks there on a personal level.  This is clearly one person who is repeatedly performing the attack. There is certainly a pattern on when it happens; I'll leave it up to our users to think about this.

If the issue is we'll have too much security, then so be it.



The illusion is shattered if we ask what goes on behind the scenes.

Re: Homepage Visited by Indonesians
« Reply #5 on: October 28, 2017, 11:05:35 AM »
There is certainly a pattern on when it happens; I'll leave it up to our users to think about this.

What is the pattern? I mean, I understand that you are implicitly blaming SexWarrior (or maybe tfes.org as a whole), but is there actually a pattern to these issues which indicates any particular person is to blame?
« Last Edit: October 28, 2017, 11:31:08 AM by Particle Person »

Re: Homepage Visited by Indonesians
« Reply #6 on: October 28, 2017, 11:25:25 AM »
I'm seeing a lot of 502: Bad Gateway errors when trying to load any page on the domain, probably once every 5 page updates or so.

Re: Homepage Visited by Indonesians
« Reply #7 on: October 28, 2017, 11:32:01 AM »
If the issue is we'll have too much security, then so be it.
I don't know what you've done, but I think you've just reached the point of too much security. Apparently my "password security has been upgraded" so hard that my usual password is no longer valid, just moments after I last posted.




When the site is not throwing incomprehensible errors at me, it simply asserts that my password is incorrect. Can I have my account back, or should I get used to being Pete?

As an aside, now that the implication has been made: I welcome the idea of getting someone who actually knows what they're doing involved. I look forward to your acknowledgement that I had nothing to do with this, or your desperate attempt at denying there was any implication in the first place!
« Last Edit: October 28, 2017, 11:41:00 AM by Pete Svarrior »

*

Username

  • Administrator
  • 17680
  • President of The Flat Earth Society
Re: Homepage Visited by Indonesians
« Reply #8 on: October 28, 2017, 11:47:10 AM »
There is certainly a pattern on when it happens; I'll leave it up to our users to think about this.

What is the pattern? I mean, I understand that you are implicitly blaming SexWarrior (or maybe tfes.org as a whole), but is there actually a pattern to these issues which indicates any particular person is to blame?
I am doing no such thing. Please don't put words in my mouth.

If the issue is we'll have too much security, then so be it.
I don't know what you've done, but I think you've just reached the point of too much security. Apparently my "password security has been upgraded" so hard that my usual password is no longer valid, just moments after I last posted.




When the site is not throwing incomprehensible errors at me, it simply asserts that my password is incorrect. Can I have my account back, or should I get used to being Pete?

As an aside, now that the implication has been made: I welcome the idea of getting someone who actually knows what they're doing involved. I look forward to your acknowledgement that I had nothing to do with this, or your desperate attempt at denying there was any implication in the first place!
I don't know man. Have you tried resetting your password?

The illusion is shattered if we ask what goes on behind the scenes.

Re: Homepage Visited by Indonesians
« Reply #9 on: October 28, 2017, 11:48:45 AM »
I don't know man. Have you tried resetting your password?
Yes. It was rather fruitless.

So, simple question, simple answer: will you give me my account back, or is it permanently "upgraded"? No need for idle chit-chat, we both know you don't like it.

*

Username

  • Administrator
  • 17680
  • President of The Flat Earth Society
Re: Homepage Visited by Indonesians
« Reply #10 on: October 28, 2017, 11:50:11 AM »
Why was it fruitless? I can reset your password for you to your registered email, if you'd like.
The illusion is shattered if we ask what goes on behind the scenes.

*

Username

  • Administrator
  • 17680
  • President of The Flat Earth Society
Re: Homepage Visited by Indonesians
« Reply #11 on: October 28, 2017, 11:50:44 AM »
Are any other users experiencing this '2 secure 2 login' issue?
The illusion is shattered if we ask what goes on behind the scenes.

Re: Homepage Visited by Indonesians
« Reply #12 on: October 28, 2017, 11:51:08 AM »
Why was it fruitless? I can reset your password for you to your registered email, if you'd like.
I received no e-mail, which leads me to suspect that the address may have also been upgraded.

Re: Homepage Visited by Indonesians
« Reply #13 on: October 28, 2017, 11:51:41 AM »
There is certainly a pattern on when it happens; I'll leave it up to our users to think about this.

What is the pattern? I mean, I understand that you are implicitly blaming SexWarrior (or maybe tfes.org as a whole), but is there actually a pattern to these issues which indicates any particular person is to blame?
I am doing no such thing. Please don't put words in my mouth.

Apologies if I misinterpreted your meaning. Can you tell us about the pattern you mentioned?

*

Username

  • Administrator
  • 17680
  • President of The Flat Earth Society
Re: Homepage Visited by Indonesians
« Reply #14 on: October 28, 2017, 11:55:05 AM »
Why was it fruitless? I can reset your password for you to your registered email, if you'd like.
I received no e-mail, which leads me to suspect that the address may have also been upgraded.
If it was, it surely wasn't by me. It looks like PP account has his email set to e@e.com. Does this ring any bells?
The illusion is shattered if we ask what goes on behind the scenes.

Re: Homepage Visited by Indonesians
« Reply #15 on: October 28, 2017, 11:56:25 AM »
If it was, it surely wasn't by me. It looks like PP account has his email set to e@e.com. Does this ring any bells?
It does not. My account was linked to a largely unused, but still active address just a few days before it got "upgraded".

*

Username

  • Administrator
  • 17680
  • President of The Flat Earth Society
Re: Homepage Visited by Indonesians
« Reply #16 on: October 28, 2017, 11:57:19 AM »
Odd, I seem to remember that being your address when I looked at your profile last week.
The illusion is shattered if we ask what goes on behind the scenes.

Re: Homepage Visited by Indonesians
« Reply #17 on: October 28, 2017, 11:58:15 AM »
Odd, I seem to remember that being your address when I looked at your profile last week.
That would be consistent with me changing it a few days ago.

*

Username

  • Administrator
  • 17680
  • President of The Flat Earth Society
Re: Homepage Visited by Indonesians
« Reply #18 on: October 28, 2017, 11:59:32 AM »
Are you suggesting that the hackers attacked specifically your account and nobody else to revert your email to the same address it was a few days ago?

I don't know man. Seems oddly specific.
The illusion is shattered if we ask what goes on behind the scenes.

Re: Homepage Visited by Indonesians
« Reply #19 on: October 28, 2017, 12:01:23 PM »
Are you suggesting that the hackers attacked specifically your account and nobody else to revert your email to the same address it was a few days ago?
No. To quote myself: "I don't know what you've done".

But we also know that "the hackers" mysteriously reverted some other things, the version of the software of this forum being one that you've named. So, even if this is "the hackers" and not you, your question seems spurious.

So, what will it be, John? Am I settling in as Pete, or will you bring my account back from the dead?

*

Username

  • Administrator
  • 17680
  • President of The Flat Earth Society
Re: Homepage Visited by Indonesians
« Reply #20 on: October 28, 2017, 12:02:47 PM »
I'm happy to help you regain access to your account. I didn't touch anything, and your attitude in this matter when it seems you just forgot your password is puzzling.
The illusion is shattered if we ask what goes on behind the scenes.

*

Username

  • Administrator
  • 17680
  • President of The Flat Earth Society
Re: Homepage Visited by Indonesians
« Reply #21 on: October 28, 2017, 12:05:40 PM »
I'm going to set the email to your account to an email of Parisfals. This way I know you aren't just some random person trying to gain access to PPs account. Is this acceptable to you?
The illusion is shattered if we ask what goes on behind the scenes.

Re: Homepage Visited by Indonesians
« Reply #22 on: October 28, 2017, 12:10:05 PM »
I'm happy to help you regain access to your account.
Awesome stuff.

I didn't touch anything, and your attitude in this matter when it seems you just forgot your password is puzzling.
There are a few reasons why I doubt that it was a simple case of a forgotten password:
  • I was already logged in when I lost access. My login cookies got invalidated on all browsers. My memory can be funky, but not funky enough to log me out of a powered-off laptop.
  • As you might have noticed in one of my screenshots, I let Chrome manage my passwords.
  • If it was a simple case of me forgetting my password, what does the "password security upgraded" message mean? Surely it would just be a case of the password being incorrect.

Regarding your involvement, the only reason I suspected you was your cryptic message regarding degraded performance and yourself dealing with "issues". It seemed reasonable that you did, in fact, touch something since you announced you would be touching things.

I'm going to set the email to your account to an email of Parisfals. This way I know you aren't just some random person trying to gain access to PPs account. Is this acceptable to you?
Fine by me. I'll just run it by Parsifal before confirming.

Re: Homepage Visited by Indonesians
« Reply #23 on: October 28, 2017, 12:10:42 PM »
Fine by me. I'll just run it by Parsifal before confirming.
Confirmed.

*

Username

  • Administrator
  • 17680
  • President of The Flat Earth Society
Re: Homepage Visited by Indonesians
« Reply #24 on: October 28, 2017, 12:13:25 PM »
I'd have to look at the source to see what that message refers to. At any rate, I certainly didn't change your email address. As far as it not being a lost password, I believe you, and I'll add this to the list of things I'll discuss Monday.

I'll update your email in a few minutes. I'm currently in the middle of something else.
The illusion is shattered if we ask what goes on behind the scenes.

*

Username

  • Administrator
  • 17680
  • President of The Flat Earth Society
Re: Homepage Visited by Indonesians
« Reply #25 on: October 28, 2017, 12:14:48 PM »
Is there anybody else who has had their email reverted to one from a week ago?
The illusion is shattered if we ask what goes on behind the scenes.

*

Username

  • Administrator
  • 17680
  • President of The Flat Earth Society
Re: Homepage Visited by Indonesians
« Reply #26 on: October 28, 2017, 12:36:05 PM »
Whenever Parisfal gets a chance, tell him to drop by and give me an email he hasn't used for an account here.
The illusion is shattered if we ask what goes on behind the scenes.

Re: Homepage Visited by Indonesians
« Reply #27 on: October 28, 2017, 01:02:52 PM »
I believe he's PM'd you now

*

Username

  • Administrator
  • 17680
  • President of The Flat Earth Society
Re: Homepage Visited by Indonesians
« Reply #28 on: October 28, 2017, 01:21:06 PM »
It looks like somebody already changed the email to sw@tfes.org

Does this make any sense to you?
The illusion is shattered if we ask what goes on behind the scenes.

Re: Homepage Visited by Indonesians
« Reply #29 on: October 28, 2017, 01:25:19 PM »
It looks like somebody already changed the email to sw@tfes.org

Does this make any sense to you?
That's the e-mail for the account I'm posting from right now, and the e-mail I was expecting to be set for PizzaPlanet to begin with. Unless you accidentally looked at the wrong account, this is very strange.