Results 1 to 18 of 18

Thread: WARNING - PFA's internet provider could suspend the site due to Russian hacking - please read thread for contingency plan

  1. #1
    Owner Dan Druff's Avatar
    Reputation
    10136
    Join Date
    Mar 2012
    Posts
    54,732
    Blog Entries
    2
    Load Metric
    67284526

    WARNING - PFA's internet provider could suspend the site due to Russian hacking - please read thread for contingency plan

    Over the 10+ years of this site, I have had to deal with occasional hackings by Russian and Chinese groups. These hackings were never maliciously aimed at me or PFA. They were part of large, organized hacking efforts to hijack sites and use them as either spam servers or zombies. (A "zombie" is a computer taken over by hackers, which is used then to attack or scan other sites.)

    PFA is a loosely constructed structure of third party software, public domain freeware, and software/routines I wrote myself. For example, that little messaging box at the bottom right (which only shows on some devices) is a piece of third party software. The chat room we use during radio is (old) third party software which I shoehorned into working with PFA. The radio appears to broadcast through the forum, but is actually third party software which I integrated into the site.

    There are lots of different pieces of software running on the server here -- some visible to you, some not.

    The bad part of this is the fact that each of these opens up vulnerabilities to hackers.

    A recent hack has been using PFA as a zombie system, and our internet provider has gotten multiple complaints. There is no question that this is a result of a hacking, and they do not believe I am behind the zombie attacks. However, I have been given an ultimatum to fix this, or otherwise PFA will be suspended. I already thought this was fixed a few days ago, but apparently not.

    If this happens, you will see a suspension message, and will not be able to access either PFA or our sister site, Vegas Casino Talk.

    In addition, other sites I manage such as dandruffpoker.com and toddwitteles.com will also go down.

    Here is the plan if this occurs:

    1) I will be giving updates on https://twitter.com/PokerFraudAlert

    2) I will move all of the sites I manage to a different provider -- first with a temporary page explaining what's going on, and then I'll put everything back as before

    3) PFA might be taken down later tonight for purposes of doing backups, but this will only last for about 30 minutes.


    This might all take several days, so please be patient if it happens.

    I am hoping I can take care of this matter and a provider switch will not be necessary. Of course, even if I do switch providers, I'll need to kick the Russians off, because this problem will occur all over again once I restore from the backup.


     
    Comments
      
      Crowe Diddly: hope it works out painlessly

  2. #2
    Diamond BCR's Avatar
    Reputation
    2026
    Join Date
    Mar 2012
    Posts
    6,913
    Load Metric
    67284526
    Considering half the site are Putin fanboys, you’d think they’d cut you a break.

     
    Comments
      
      devidee: Don’t worry. Nancy is on it.

  3. #3
    Plutonium sonatine's Avatar
    Reputation
    7375
    Join Date
    Mar 2012
    Posts
    33,416
    Load Metric
    67284526
    this would never happen at sonatinep0ker.com.


    [redacted]? maybe.





    probably.
    "Birds born in a cage think flying is an illness." - Alejandro Jodorowsky

    "America is not so much a nightmare as a non-dream. The American non-dream is precisely a move to wipe the dream out of existence. The dream is a spontaneous happening and therefore dangerous to a control system set up by the non-dreamers." -- William S. Burroughs

  4. #4
    100% Organic MumblesBadly's Avatar
    Reputation
    94
    Join Date
    Jun 2015
    Location
    In the many threads of this forum
    Posts
    9,408
    Load Metric
    67284526
    Quote Originally Posted by BCR View Post
    Considering half the site are Putin fanboys, you’d think they’d cut you a break.
    Wondering whether this threat is a false flag op in case Druff has to explain away why he’d still vote for Trump when the Orange Man is wearing an orange jumpsuit courtesy of the Federal Bureau of Prisons.
    _____________________________________________
    Quote Originally Posted by Dan Druff View Post
    I actually hope this [second impeachment] succeeds, because I want Trump put down politically like a sick, 14-year-old dog. ... I don't want him complicating the 2024 primary season. I just want him done.
    Quote Originally Posted by Dan Druff View Post
    Were Republicans cowardly or unethical not to go along with [convicting Trump in the second impeachment Senate trial]? No. The smart move was to reject it.

  5. #5
    Gold Ryback_feed_me_more's Avatar
    Reputation
    168
    Join Date
    Oct 2012
    Location
    Sin City
    Posts
    1,461
    Load Metric
    67284526
    I know its a small hit to the jew wallet but would using cloudflare solve any issues. You can geoblock russian and Chinese IP addresses en masse from accessing the site for $20 a month I believe.

  6. #6
    Plutonium simpdog's Avatar
    Reputation
    1961
    Join Date
    May 2012
    Posts
    10,567
    Load Metric
    67284526
    Good luck Druff.

    Does your hosting have any security guys that can help you out?

    Maybe shut down everything except vbulletin for a bit?

  7. #7
    Platinum devidee's Avatar
    Reputation
    1172
    Join Date
    Mar 2012
    Posts
    4,591
    Load Metric
    67284526

  8. #8
    Owner Dan Druff's Avatar
    Reputation
    10136
    Join Date
    Mar 2012
    Posts
    54,732
    Blog Entries
    2
    Load Metric
    67284526
    Spent hours on this today but I think I wiped it all off.

    My first attempt last week was a fail. I only got some of it. I did a deeper search today.

    It looks like the breach occurred on January 31, 2020. It is unknown when they started actually using the zombie software they installed.


    Later on tonight, I will back up the site, so there might be some downtime then.

  9. #9
    Owner Dan Druff's Avatar
    Reputation
    10136
    Join Date
    Mar 2012
    Posts
    54,732
    Blog Entries
    2
    Load Metric
    67284526
    Quote Originally Posted by simpdog View Post
    Good luck Druff.

    Does your hosting have any security guys that can help you out?

    Maybe shut down everything except vbulletin for a bit?
    I haven't wanted to resort to this yet because:

    1) I'm a cheap Jew, and these services are expensive.

    2) I am actually competent at doing this myself.

    3) I am the most knowledgeable of anyone regarding what I installed/modified (and why), so I can quickly dismiss false positives, whereas any third party I hire cannot (without constantly coming back and asking me). Since there are various custom modifications on this site, I don't need some security guy just wiping off anything which doesn't match the standard package of the latest version of all the software, which is generally what they like to do.


    Hopefully I got it all this time.

    I am going to update some of the software in question, and hopefully that will stop future breaches like this.

  10. #10
    Platinum JimmyG_415's Avatar
    Reputation
    -81
    Join Date
    Mar 2012
    Posts
    2,521
    Load Metric
    67284526
    I'm sure it is just a total coincidence that that is when Entropy opened his account.

    Quote Originally Posted by Dan Druff View Post
    Spent hours on this today but I think I wiped it all off.

    My first attempt last week was a fail. I only got some of it. I did a deeper search today.

    It looks like the breach occurred on January 31, 2020. It is unknown when they started actually using the zombie software they installed.


    Later on tonight, I will back up the site, so there might be some downtime then.
    San Francisco crowned the ‘world’s best’ city to live: survey
    https://www.kron4.com/news/bay-area/...o-live-survey/

  11. #11
    Nova Scotia's #1 Party Rocker!!!!11 DJ_Chaps's Avatar
    Reputation
    939
    Join Date
    Mar 2012
    Location
    Halifax
    Posts
    6,604
    Load Metric
    67284526
    Quote Originally Posted by MumblesBadly View Post
    Quote Originally Posted by BCR View Post
    Considering half the site are Putin fanboys, you’d think they’d cut you a break.
    Wondering whether this threat is a false flag op in case Druff has to explain away why he’d still vote for Trump when the Orange Man is wearing an orange jumpsuit courtesy of the Federal Bureau of Prisons.


    HOW DO YOU MANAGE TO SHOEHORN TRUMP INTO EVERY DISCUSSION YOU WALTZ INTO ON HERE? YOU ARE LITERALLY TDS DEFINED X2, TRUMP AND TODD DERANGEMENT SYNDROME. SHUT IT DOWN.
    --------------------------------------------------------------------------------------------
    Chaps' 2017-18 NFL $$ Thread

  12. #12
    Platinum
    Reputation
    997
    Join Date
    Jul 2012
    Posts
    4,184
    Load Metric
    67284526
    Quote Originally Posted by JimmyG_415 View Post
    I'm sure it is just a total coincidence that that is when Entropy opened his account.
    Except, that is not when he opened his account

  13. #13
    Canadrunk limitles's Avatar
    Reputation
    1642
    Join Date
    Mar 2012
    Location
    In Todd's head
    Posts
    17,720
    Blog Entries
    1
    Load Metric
    67284526
    Quote Originally Posted by DJ_Chaps View Post
    Quote Originally Posted by MumblesBadly View Post

    Wondering whether this threat is a false flag op in case Druff has to explain away why he’d still vote for Trump when the Orange Man is wearing an orange jumpsuit courtesy of the Federal Bureau of Prisons.


    HOW DO YOU MANAGE TO SHOEHORN TRUMP INTO EVERY DISCUSSION YOU WALTZ INTO ON HERE? YOU ARE LITERALLY TDS DEFINED X2, TRUMP AND TODD DERANGEMENT SYNDROME. SHUT IT DOWN.
    Because it never gets old. The chance to remind anyone of their support for the criminal president should gone be ignored. These truth deniers
    have not given up so game on.

    Why do you care as much as you do?

  14. #14
    Gold 1dollarboxcar's Avatar
    Reputation
    1653
    Join Date
    May 2022
    Posts
    1,711
    Load Metric
    67284526

    Cool

    it was probably one of Christopher Mitchell's employees under his huge payroll. like one of his highly paid consultants or one of his highly paid investigators but most likely one of his highly paid hackers that disguised their attack from China and Russia since he has clients from all over the world.....

  15. #15
    Canadrunk limitles's Avatar
    Reputation
    1642
    Join Date
    Mar 2012
    Location
    In Todd's head
    Posts
    17,720
    Blog Entries
    1
    Load Metric
    67284526

    Cool

    Quote Originally Posted by 1dollarboxcar View Post
    it was probably one of Christopher Mitchell's employees under his huge payroll. like one of his highly paid consultants or one of his highly paid investigators but most likely one of his highly paid hackers that disguised their attack from China and Russia since he has clients from all over the world.....
    Watch out for this guy a real thnker

  16. #16
    Canadrunk limitles's Avatar
    Reputation
    1642
    Join Date
    Mar 2012
    Location
    In Todd's head
    Posts
    17,720
    Blog Entries
    1
    Load Metric
    67284526
    Quote Originally Posted by limitles View Post
    Quote Originally Posted by 1dollarboxcar View Post
    it was probably one of Christopher Mitchell's employees under his huge payroll. like one of his highly paid consultants or one of his highly paid investigators but most likely one of his highly paid hackers that disguised their attack from China and Russia since he has clients from all over the world.....
    Watch out for this guy a real thnker
    Ban Entropy the Russian.

  17. #17
    Bronze turdzilla's Avatar
    Reputation
    23
    Join Date
    Dec 2017
    Posts
    152
    Load Metric
    67284526
    Time to display my ignorance.

    I used an enhanced security product offered by GoDaddy for my site.

    Why can't you do the same?

  18. #18
    Owner Dan Druff's Avatar
    Reputation
    10136
    Join Date
    Mar 2012
    Posts
    54,732
    Blog Entries
    2
    Load Metric
    67284526
    Quote Originally Posted by turdzilla View Post
    Time to display my ignorance.

    I used an enhanced security product offered by GoDaddy for my site.

    Why can't you do the same?
    Every piece of software installed has its own potential security vulnerability. There is no way around that, though "best practices" involve always making sure you have the latest versions and patches. For reasons explained on my show, I can't do that, so the site is always a little bit vulnerable.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. *WARNING* BONDBET.COM IS A SCAM SITE *WARNING*
    By drufdajewgod in forum Scams, Scandals, and Shadiness
    Replies: 5
    Last Post: 12-27-2019, 04:35 PM
  2. Replies: 69
    Last Post: 06-08-2017, 01:59 AM
  3. Caesars kicked out of attempt to get Boston casino, due to Russian mob ties
    By Dan Druff in forum Scams, Scandals, and Shadiness
    Replies: 6
    Last Post: 12-12-2013, 06:28 PM
  4. Replies: 12
    Last Post: 10-25-2013, 02:36 AM
  5. Warning Please Read!
    By Ricky in forum Flying Stupidity
    Replies: 24
    Last Post: 09-10-2012, 04:53 PM