News:

Create A Forum Installed

Author Topic: DATA PROTECTION ISSUE: Forum backup sold to non-admin  (Read 1171 times)

0 Members and 3 Guests are viewing this topic.

Offline norbe

  • Newbie
  • *
  • Posts: 4
  • Karma: 0
    • View Profile

Badges: (View All)
Level 2 Combination Topic Starter
DATA PROTECTION ISSUE: Forum backup sold to non-admin
« on: August 11, 2017, 09:40:37 pm »
Need some help here... Someone from my forum bought a backup of our entire forum database. This was done without permission from the forum admin.

Him buying the database happened on this thread: http://support.createaforum.com/8/backup-of-forum-5179

Is all the data on our forum now compromised? I have the download link that contains the backup of the database for download and seems unsecured, eg anyone who has had that link can now have an access to everything we've done. PLEASE DELETE THIS IMMEDIATELY.

I'm very concerned.

Our forum address, which we would like to maintain and keep using perfectly and securely as it has been for over 10 years : http://taurialliance.smfforfree2.com

Norbe

Share on Facebook Share on Twitter


Offline CreateAForum

  • Administrator
  • *****
  • Posts: 7186
  • Karma: 327
    • View Profile

Badges: (View All)
Avatar Linux User Tenth year Anniversary
Re: DATA PROTECTION ISSUE: Forum backup sold to non-admin
« Reply #1 on: August 11, 2017, 09:45:23 pm »
Removed. But how did you get the download link? Someone would have had to sent it to you. I would advise changing the passwords. They are stored hashed with sha1 with a salt.
Like Create A Forum? Support me at https://www.patreon.com/vbgamer45/

Offline norbe

  • Newbie
  • *
  • Posts: 4
  • Karma: 0
    • View Profile

Badges: (View All)
Level 2 Combination Topic Starter
Re: DATA PROTECTION ISSUE: Forum backup sold to non-admin
« Reply #2 on: August 11, 2017, 09:51:35 pm »
Removed. But how did you get the download link? Someone would have had to sent it to you. I would advise changing the passwords. They are stored hashed with sha1 with a salt.

Yes the link was sent to me. The user who bought it believed he was acting in our interest, but had not asked nor informed us before doing so.

A copy of our forum now exists on another host -this includes all our past posts, even in restricted access areas he did not have access to but far more importantly personal info such as IP addresses of all of our users.

I hope his actions do not turn out to be malicious, but I am sure there are others out there who would use this data maliciously if they got it.

It is unlikely I can change all passwords for all users, but will ensure admins are changed immediately.

Norbe

Offline CreateAForum

  • Administrator
  • *****
  • Posts: 7186
  • Karma: 327
    • View Profile

Badges: (View All)
Avatar Linux User Tenth year Anniversary
Re: DATA PROTECTION ISSUE: Forum backup sold to non-admin
« Reply #3 on: August 11, 2017, 09:57:15 pm »
Understand this was very unusual case and part of the reason we put a fee in place.
Like Create A Forum? Support me at https://www.patreon.com/vbgamer45/

Offline norbe

  • Newbie
  • *
  • Posts: 4
  • Karma: 0
    • View Profile

Badges: (View All)
Level 2 Combination Topic Starter
Re: DATA PROTECTION ISSUE: Forum backup sold to non-admin
« Reply #4 on: August 11, 2017, 10:15:55 pm »
All admins have now changed their passwords.

I'm sure it was an unusual case... The user who bought the database is fairly new to us, and is being open about having done it.

Is there anything else I can do to help secure the data and make sure no-one else gets hold of future copies?

Norbe
« Last Edit: August 11, 2017, 10:18:17 pm by norbe »

Offline CreateAForum

  • Administrator
  • *****
  • Posts: 7186
  • Karma: 327
    • View Profile

Badges: (View All)
Avatar Linux User Tenth year Anniversary
Re: DATA PROTECTION ISSUE: Forum backup sold to non-admin
« Reply #5 on: August 11, 2017, 10:21:16 pm »
Well I will not allow others to do so from your forum unless it is from an admin email on the forum.
Like Create A Forum? Support me at https://www.patreon.com/vbgamer45/

Offline norbe

  • Newbie
  • *
  • Posts: 4
  • Karma: 0
    • View Profile

Badges: (View All)
Level 2 Combination Topic Starter
Re: DATA PROTECTION ISSUE: Forum backup sold to non-admin
« Reply #6 on: August 11, 2017, 11:04:03 pm »
Well I will not allow others to do so from your forum unless it is from an admin email on the forum.

Good. Thanks. Shame someone already got hold of it, but good to know it won't happen in future.

Norbe

 

Related Topics

  Subject / Started by Replies Last post
4 Replies
2476 Views
Last post February 13, 2013, 11:46:18 pm
by Katey
1 Replies
679 Views
Last post April 05, 2016, 06:15:53 am
by Zen
1 Replies
463 Views
Last post September 11, 2016, 12:54:24 pm
by CreateAForum
0 Replies
514 Views
Last post May 29, 2017, 07:37:21 pm
by hudumapoa
11 Replies
732 Views
Last post July 08, 2017, 03:56:56 am
by CreateAForum