Compromised e-mail addresses?

Status
Not open for further replies.

NyteOwl

Member
Premium Subscriber
Joined
Apr 2, 2009
Messages
8
Location
Nova Scotia, Canada
I just received a piece of SPAM e-mail sent to the e-mail address I used when I signed up on the forums. This address is unique to my registering on these forums and has not been used anywhere else. (No my profile is not set to receive e-mail from any but admins.)

The site admin might want to look into this.as it would seem somewhere along the line at least one and possibly other user e-mail addresses have been compromised.
 

slash

Member
Joined
Sep 1, 2006
Messages
76
Location
Michigan
I can confirm this as well - I have a unique e-mail address for RR only and i've been hit with spam starting yesterday.
 

blantonl

Founder and CEO
Staff member
Joined
Dec 9, 2000
Messages
9,662
Location
San Antonio, TX
I've received reports from a few folks this week that their uniquely registered email addresses have received SPAM. So it does appear that spammers might have crawled the forums exploiting a vulnerability that allowed them to harvest email addresses.

Since the reports we have applied the very latest security patch fixes to the forums and are actively monitoring with detailed tracing and logging what is happening across the site.

Thanks
 

kayi4cle

Member
Premium Subscriber
Joined
Aug 19, 2008
Messages
456
Location
Intermod Alley
Thanks Lindsay! I also received a couple spams yesterday. Thanks for taking prompt action on this, and thank you so much for everything else you do for our community.
 

protias

Member
Premium Subscriber
Joined
Apr 9, 2008
Messages
144
Accounts may have been compromised as well. Mine was locked out when I tried logging in around noon CST.
 

blantonl

Founder and CEO
Staff member
Joined
Dec 9, 2000
Messages
9,662
Location
San Antonio, TX
The login issue was due to some tracing that I put in place that caused a bug in the login system. That has been fixed.

We haven't received any reports of accounts being compromised, and all forums password are encrypted and salted.
 

mibzzer15

Member
Premium Subscriber
Joined
Apr 14, 2009
Messages
392
Location
Fremont, CA
I have been getting a lot more spam lately, while my email I use is NOT unique to these forums, it could still be a possibility from here....
 

GTR8000

NYS Database Guy
Database Admin
Joined
Oct 4, 2007
Messages
9,012
Location
BEE00
That would explain the random pieces of spam I got to my @radioreference.com email address yesterday, after never haven gotten spam to that address previously. Glad to see LB is right on top of things as always!
 

al95

Member
Premium Subscriber
Joined
Jun 8, 2006
Messages
751
Location
Brownsville,Texas
Is this the reason I received the login failed and had to wait 15 before trying to login to RR. This is the email I received from RR:

Someone has tried to log into your account on The RadioReference.com Forums with an incorrect password at least 5 times. This person has been prevented from attempting to login to your account for the next 15 minutes.
 

blantonl

Founder and CEO
Staff member
Joined
Dec 9, 2000
Messages
9,662
Location
San Antonio, TX
al95,

As indicated above, this issue was due to some tracing that I put in place that caused a bug in the login system for a very short period of time (about 30 minutes this afternoon CST). That was since resolved.

Thanks,
 

AB4BF

Member
Premium Subscriber
Joined
Apr 13, 2008
Messages
380
Location
EM93cs
You rock, Lindsay! :cool:

Many thanks for having one of the greatest websites on the internet.

Barry
 
Status
Not open for further replies.
Top