Author Topic: DATA PROTECTION ISSUE: Forum backup sold to non-admin  (Read 87 times)

0 Members and 0 Guests are viewing this topic.

Offline norbe

  • Newbie
  • *
  • Posts: 4
  • Karma: 0
    • View Profile
DATA PROTECTION ISSUE: Forum backup sold to non-admin
« on: August 11, 2017, 09:40:37 pm »
Need some help here... Someone from my forum bought a backup of our entire forum database. This was done without permission from the forum admin.

Him buying the database happened on this thread: http://support.createaforum.com/8/backup-of-forum-5179

Is all the data on our forum now compromised? I have the download link that contains the backup of the database for download and seems unsecured, eg anyone who has had that link can now have an access to everything we've done. PLEASE DELETE THIS IMMEDIATELY.

I'm very concerned.

Our forum address, which we would like to maintain and keep using perfectly and securely as it has been for over 10 years : http://taurialliance.smfforfree2.com

Norbe

Social Buttons


Offline CreateAForum

  • Administrator
  • *****
  • Posts: 4441
  • Karma: 261
    • View Profile
Removed. But how did you get the download link? Someone would have had to sent it to you. I would advise changing the passwords. They are stored hashed with sha1 with a salt.

Offline norbe

  • Newbie
  • *
  • Posts: 4
  • Karma: 0
    • View Profile
Removed. But how did you get the download link? Someone would have had to sent it to you. I would advise changing the passwords. They are stored hashed with sha1 with a salt.

Yes the link was sent to me. The user who bought it believed he was acting in our interest, but had not asked nor informed us before doing so.

A copy of our forum now exists on another host -this includes all our past posts, even in restricted access areas he did not have access to but far more importantly personal info such as IP addresses of all of our users.

I hope his actions do not turn out to be malicious, but I am sure there are others out there who would use this data maliciously if they got it.

It is unlikely I can change all passwords for all users, but will ensure admins are changed immediately.

Norbe

Offline CreateAForum

  • Administrator
  • *****
  • Posts: 4441
  • Karma: 261
    • View Profile
Understand this was very unusual case and part of the reason we put a fee in place.

Offline norbe

  • Newbie
  • *
  • Posts: 4
  • Karma: 0
    • View Profile
All admins have now changed their passwords.

I'm sure it was an unusual case... The user who bought the database is fairly new to us, and is being open about having done it.

Is there anything else I can do to help secure the data and make sure no-one else gets hold of future copies?

Norbe
« Last Edit: August 11, 2017, 10:18:17 pm by norbe »

Offline CreateAForum

  • Administrator
  • *****
  • Posts: 4441
  • Karma: 261
    • View Profile
Well I will not allow others to do so from your forum unless it is from an admin email on the forum.

Offline norbe

  • Newbie
  • *
  • Posts: 4
  • Karma: 0
    • View Profile
Well I will not allow others to do so from your forum unless it is from an admin email on the forum.

Good. Thanks. Shame someone already got hold of it, but good to know it won't happen in future.

Norbe

 

Related Topics

  Subject / Started by Replies Last post
16 Replies
1267 Views
Last post November 17, 2010, 04:48:14 pm
by CreateAForum
4 Replies
883 Views
Last post February 13, 2013, 11:46:18 pm
by Katey
1 Replies
392 Views
Last post April 05, 2016, 06:15:53 am
by Zen
1 Replies
136 Views
Last post September 11, 2016, 12:54:24 pm
by CreateAForum
0 Replies
143 Views
Last post May 29, 2017, 07:37:21 pm
by hudumapoa