Email Server was Compromised

Discussion in 'News' started by CyberKiller, Feb 25, 2015.

  1. CyberKiller

    CyberKiller Nyooks!

    Messages:
    1,107
    Likes Received:
    8
    Trophy Points:
    0
    UPDATE 2: It was actually the forum that was making the spam, I just had to disable "Email this Page" on the "Thread Tools" menu....
    Normal service has been resumed.

    UPDATE: It started happening again, I will have to take the email server down for a few days until I get to the bottom of it...

    Someone got into the email server and used it to send thousands of mass spam emails; but it does not look like any spam was sent to empires forum members.
    However, as a result of this a lot of email providers are going to recognise emails from the forum as spam now, so check your spam folders if you don't get any forum emails any more.

    EDIT: As and unrelated side note: I fixed some problems with the empires wiki relating to tmp dirs and re-enabled image uploads there too.
     
    Last edited: Feb 26, 2015
  2. BigTeef

    BigTeef Bootleg Headshot master

    Messages:
    7,036
    Likes Received:
    36
    Trophy Points:
    0
    Well that was nice of them.
     
  3. McGyver

    McGyver Experimental Pedagogue

    Messages:
    6,533
    Likes Received:
    31
    Trophy Points:
    0
    When did this happen? Reported post mails always went automagically into my spam folder since I have ascended to moderator.
     
  4. CyberKiller

    CyberKiller Nyooks!

    Messages:
    1,107
    Likes Received:
    8
    Trophy Points:
    0
    Roughly over the past two days.
     
  5. Neoony

    Neoony Member

    Messages:
    1,370
    Likes Received:
    106
    Trophy Points:
    0
    So they had a chance to see the list of email addresses of empiresmod forum users, btw?
    Or they only had access to send the emails?

    Just asking.
     
  6. CyberKiller

    CyberKiller Nyooks!

    Messages:
    1,107
    Likes Received:
    8
    Trophy Points:
    0
    Well after finding the cause of the spam it wasn't the anything had been compromised or hacked; it was that someone was spamming a button on the forum via a script (like 10,000 emails at once).
    More specifically the "email this page" button under "thread tools".
    Then it was just a case of changed the permissions of regular user and not logged in users to deny use of that button.
     
    Last edited: Feb 26, 2015

Share This Page