Stay Out Super-Late Tonight ([info]copperbadge) wrote,
@ 2008-10-09 22:00:00
Previous Entry  Add to memories!  Tell a Friend  Next Entry
Entry tags:picking up the pieces

More hack info via [info]lazywriterbum, one of the maintainers of [info]bad_sex. The full info is beneath the cut below, but the relevant part for most of you is:

A number of people found keyloggers on their computers after they clicked the russian poetry site link. A few people actually attempted to translate it (the poem is about eating shit, apparently) and are regretting it. We are advising people to go to pack.google.com and download the free Spyware Doctor and run a scan, also running a scan via Housecall if they don't have an installed antivirus program on your computer.

I am so, so sorry, you guys.

[info]insafemode was hit worse than I was -- he lost access to his Gmail as well -- and [info]dreamingjen has been suspended for a post she didn't make.

Full comment from [info]lazywriterbum:

Hey so... I'm the one who mentioned about insafemode and dreamingjen (dreamingjen was never a mod of bad_sex, but the hacker used insafemode's account to make her a mod AFTER deleting everyone else). I'm actually a maintainer of bad_sex, and an LJ friend of mine linked me to your post after I made a post on my journal, and she told me she thought that this was the same person. Hence the connection being made.

I've been in contact with insafemode over on facebook, letting him know what's been up. He was pretty grateful to hear that we knew what was up and were trying to help.

In the meantime, LJ have restored the maintainers to bad_sex, except for insafemode, because, as with you, the email address linked to his account has been changed and he hasn't got it back yet. Beyond that, the hacker also DID have access to his gmail account, his proper account, and it was, for a couple of days, totally useless. It took him a while to get it back, and now that he has, he's started using his akamuu account and trying to restore some of his posts. Because he hasn't got insafemode back yet, he's restoring them onto a blogspot account. Unfortunately, everything that's left is from 2005 and earlier.

I think dreamingjen has been suspended because the post made by her "account" constitutes hate speech against homosexuals, was against community rules, etc. I'm sure once she figures this she'll attempt to fix it, but since she doesn't have many LJ friends and wasn't much of a visible presence, it's probably harder for her to find a way around it. Indeed, she might be sitting there with no idea that anything of this even relates to bad sex, just thinking her email address and LJ have been hacked at the same time. Part of the problem also was that the community was turned into a moderated community with no comments allowed on the post--on the off chance her email wasn't also compromised, she wouldn't have received any comments alerting her that people thought she'd posted something bigoted and horrid.

The hacker was smart. But it might be possible they've suspended dreamingjen simply because she's the only unknown variable in this, because everyone knows insafemode very well and love him, and can vouch for his journal having been real.

A number of people found keyloggers on their computers after they clicked the russian poetry site link. A few people actually attempted to translate it (the poem is about eating shit, apparently) and are regretting it. We are advising people to go to pack.google.com and download the free Spyware Doctor and run a scan, also running a scan via Housecall if they don't have an installed antivirus program on your computer.

(Mind you, I have Spyware Doctor pro running right now and it's more trouble than it's worth. It uses pretty much all of my RAM, refuses to shut down and always demands to turn on on start-up, regardless of how often I tell it to STFU.)

ETA: ALSO:

One way to protect yourself is to implement a voluntary security question: https://www.livejournal.com/set_secret.bml



(109 comments) - (Post a new comment)


[info]annemjw
2008-10-10 03:38 am UTC (link)
Oh my lord, this is just getting completely out of hand. Stay alert evryone, and change your emails on lj from hotmail ones!

(Reply to this) (Thread)


[info]schnoogle
2008-10-10 07:11 am UTC (link)
The issue is that simply changing your e-mail address doesn't fix the vulnerability. In fact, keeping the Hotmail address (if you're using one) and making sure it's secure and doesn't expire is a better course of action.

http://www.livejournal.com/tools/emailmanage.bml

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]annemjw, 2008-10-11 05:31 am UTC (Expand)

[info]twirlynoodle
2008-10-10 03:40 am UTC (link)
Ahaaa, I wondered if there was any sort of spyware attached to the poetry – otherwise what would be the point? Cunning. Cunning and eeeveil.

Man, I don't know what I'd do if someone hacked my Gmail. [shudder]

(probably get a lot more done, ha ha ha.)

(Reply to this) (Thread)


[info]copperbadge
2008-10-10 12:56 pm UTC (link)
I know I would :D

(Reply to this) (Parent)


[info]kitaloon
2008-10-10 03:41 am UTC (link)
Spybot didn't pick anything up; I'll run a deep scan with Ad-Aware tomorrow, just to be safe, but I'm cautiously hopeful. Thanks for the tip-off!

(Reply to this) (Thread)


[info]schnoogle
2008-10-10 04:20 am UTC (link)
AVG got nothing for me when I ran it a few days after clicking on the poetry (against my better judgement -__-), but I'll be updating and running all my scanning programs over the weekend. :S

(Reply to this) (Parent)


[info]almalthia
2008-10-10 03:48 am UTC (link)
Jesus christ, that's nuts.

(Reply to this)


[info]dr_is_in
2008-10-10 03:50 am UTC (link)
I've changed the email associated with my LJ because of your posts, because the email that was associated with it is used for a quite a few other things. I've had several "russians" friend me in the last week out of the blue, so its got me paranoid.

(Reply to this) (Thread)(Expand)


[info]schnoogle
2008-10-10 04:31 am UTC (link)
The old one will still be listed on your account, and I think it can potentially be used to compromise it.

http://www.livejournal.com/tools/emailmanage.bml

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]dr_is_in, 2008-10-10 04:32 am UTC (Expand)
(no subject) - [info]schnoogle, 2008-10-10 04:35 am UTC (Expand)
(no subject) - [info]dr_is_in, 2008-10-10 04:39 am UTC (Expand)
(no subject) - [info]schnoogle, 2008-10-10 06:57 am UTC (Expand)
(no subject) - [info]xenakat13, 2008-10-10 11:45 am UTC (Expand)
(no subject) - [info]copperbadge, 2008-10-10 12:49 pm UTC (Expand)
(no subject) - [info]schnoogle, 2008-10-11 12:41 am UTC (Expand)
(no subject) - [info]copperbadge, 2008-10-11 02:00 am UTC (Expand)
(no subject) - [info]schnoogle, 2008-10-11 02:19 am UTC (Expand)
(no subject) - [info]srevans, 2008-10-10 05:57 am UTC (Expand)
(no subject) - [info]schnoogle, 2008-10-10 06:54 am UTC (Expand)
(no subject) - [info]frenchroast, 2008-10-10 02:32 pm UTC (Expand)
(no subject) - [info]marginaliana, 2008-10-10 12:23 pm UTC (Expand)
(no subject) - [info]schnoogle, 2008-10-11 02:24 am UTC (Expand)
(no subject) - [info]evilstorm, 2008-10-10 02:46 pm UTC (Expand)
(no subject) - [info]copperbadge, 2008-10-10 02:53 pm UTC (Expand)
(no subject) - [info]evilstorm, 2008-10-10 03:08 pm UTC (Expand)
(no subject) - [info]christophem, 2008-10-10 05:44 am UTC (Expand)
(no subject) - [info]dr_is_in, 2008-10-10 05:46 am UTC (Expand)
(no subject) - [info]ladyblack888, 2008-10-10 07:09 am UTC (Expand)

[info]madripoor_rose
2008-10-10 03:53 am UTC (link)
Downloaded spyware doctor and it found a lot of things to fix...got rid of everything except tracking cookies.

That "Blaart' alarm when it's finished is fairly annoying.

(Reply to this) (Thread)


[info]copperbadge
2008-10-10 12:56 pm UTC (link)
It scared the bejesus out of me when it went off. I promptly turned off sounds on the program :D

(Reply to this) (Parent)


[info]hauntermooneyes
2008-10-10 04:00 am UTC (link)
That's terrible. What sort of person has this much time and maliciousness on their hands?

Is the hacker just creating emails that are attached to the account, but dead, and then having resets sent there? For example, if I have a hotmail account, but it's still active and I use it, am I good to go? *wants to warn her own flist*

(Reply to this) (Thread)(Expand)


[info]schnoogle
2008-10-10 04:29 am UTC (link)
If it's secure (good password, good security question, etc), your computer is protected from viruses etc and is the only e-mail address validated for the LJ account, yes.

http://www.livejournal.com/tools/emailmanage.bml

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]hauntermooneyes, 2008-10-10 05:17 am UTC (Expand)
(no subject) - [info]copperbadge, 2008-10-10 12:55 pm UTC (Expand)
(no subject) - [info]hauntermooneyes, 2008-10-11 01:46 am UTC (Expand)

[info]rockangel7011
2008-10-10 04:11 am UTC (link)
Does anyone have any suggestions for antivirus software for use on a Mac?

I tried the Housecall scanner suggested by the post, which didn't pick up anything, but also only took about five seconds to complete, so I'm not sure about its thoroughness...

(Reply to this) (Thread)(Expand)


[info]ecaterin
2008-10-10 04:18 am UTC (link)
You're on a Mac - you're protected :) One of the best things about using OS X is that it's just not a target.

I'm spending most of my time on my Ubuntu machine these days and am SO happy I don't have to have any anti-malware software running :)

Short story - don't worry, your machine is fine :P

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]rockangel7011, 2008-10-10 04:25 am UTC (Expand)
(no subject) - [info]imaginarycircus, 2008-10-10 04:31 am UTC (Expand)
(no subject) - [info]miriellegrey, 2008-10-10 05:04 am UTC (Expand)
(no subject) - [info]penguin_attie, 2008-10-10 10:00 am UTC (Expand)
(no subject) - [info]joycelene, 2008-11-13 05:50 am UTC (Expand)

[info]luckyckljw
2008-10-10 04:17 am UTC (link)
I would also like to recommend, for anyone using Firefox, installing the Keyscrambler addon. It foils keyscramblers by scrambling your keystrokes at the kernel level, before loggers can read them, basically. I used it when I ran Windows, and loved it because it didn't take as many resources to run it as it did to run a spyware program + ff.

(Reply to this) (Thread)(Expand)


[info]iamshadow
2008-10-10 04:24 am UTC (link)
Oooh! I didn't know about this!

I use NoScript for Firefox, aVast and AdAware, but you can never be too careful, right?

*installs*

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]schnoogle, 2008-10-10 04:30 am UTC (Expand)
(no subject) - [info]twirlynoodle, 2008-10-10 04:32 am UTC (Expand)
(no subject) - [info]iamshadow, 2008-10-10 04:57 am UTC (Expand)
(no subject) - [info]iamshadow, 2008-10-10 05:00 am UTC (Expand)
(no subject) - [info]thisdaydreamer, 2008-10-10 05:23 am UTC (Expand)
(no subject) - [info]riari, 2008-10-10 05:52 am UTC (Expand)
(no subject) - [info]iamshadow, 2008-10-10 05:58 am UTC (Expand)
(no subject) - [info]aunty_marion, 2008-10-10 05:43 pm UTC (Expand)
(no subject) - [info]greenwitch, 2008-10-10 05:16 am UTC (Expand)
(no subject) - [info]luckyckljw, 2008-10-10 05:18 am UTC (Expand)
(no subject) - [info]riari, 2008-10-10 05:49 am UTC (Expand)
(no subject) - [info]luckyckljw, 2008-10-10 06:48 am UTC (Expand)
(no subject) - [info]riari, 2008-10-12 06:07 am UTC (Expand)
(no subject) - [info]luckyckljw, 2008-10-12 08:13 am UTC (Expand)
(no subject) - [info]riari, 2008-10-10 05:47 am UTC (Expand)
(no subject) - [info]luckyckljw, 2008-10-10 06:11 am UTC (Expand)

[info]vimeslady
2008-10-10 04:28 am UTC (link)
This thing is like watching the stock market - it just gets scarier and scarier.

(Reply to this) (Thread)


[info]twirlynoodle
2008-10-10 04:38 am UTC (link)
If by scary you mean EXCITING! Wheeeee!

I am joking about LJ, but only mostly joking about the stock market ... Admit it, is there not a shred of perverse entertainment value in the daily World Market Limbo?

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]thecolourclear, 2008-10-10 05:20 am UTC (Expand)
(no subject) - [info]luckyckljw, 2008-10-10 05:21 am UTC (Expand)
(no subject) - [info]copperbadge, 2008-10-10 12:58 pm UTC (Expand)

[info]imaginarycircus
2008-10-10 04:32 am UTC (link)
Which sign of the apocalypse is this?

(Reply to this) (Thread)(Expand)


[info]piperki
2008-10-10 11:14 am UTC (link)
I think it's the one that happens just before female northwestern moose-hunting red-pump-wearing governor goes on the vice presidential ticket.

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]imaginarycircus, 2008-10-10 02:16 pm UTC (Expand)
(no subject) - [info]copperbadge, 2008-10-10 11:27 am UTC (Expand)
(no subject) - [info]imaginarycircus, 2008-10-10 02:22 pm UTC (Expand)

[info]bleakwinters
2008-10-10 07:39 am UTC (link)
I know that my dear dear Havelock MacBook should protect me from a virus, but dear sweet god, if I lose my LJ... I know some people here are mentioning LJ Book and LJ Archive, so which one is the best? I'll make another post on my LJ about this, because I don't think it's just a random occurence! ._.

(Reply to this) (Thread)(Expand)


[info]iamshadow
2008-10-10 07:46 am UTC (link)
I found LJBook really quick and easy to use. I didn't have to install anything; all I did was follow the instructions, and I had a .pdf of five years of journalling in under ten minutes.

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]bleakwinters, 2008-10-10 07:55 am UTC (Expand)
(no subject) - [info]copperbadge, 2008-10-10 12:50 pm UTC (Expand)
(no subject) - [info]bleakwinters, 2008-10-10 03:08 pm UTC (Expand)
(no subject) - [info]copperbadge, 2008-10-10 11:20 am UTC (Expand)
(no subject) - [info]bleakwinters, 2008-10-10 12:23 pm UTC (Expand)
(no subject) - [info]forest_rose, 2008-10-10 04:31 pm UTC (Expand)
(no subject) - [info]forest_rose, 2008-10-10 04:42 pm UTC (Expand)
(no subject) - [info]aunty_marion, 2008-10-10 05:46 pm UTC (Expand)

[info]peanutgallery79
2008-10-10 08:38 am UTC (link)
here's another russian-related mess

http://nympholept.livejournal.com/277106.html

(Reply to this)


[info]brotherskeeper1
2008-10-10 09:48 am UTC (link)
For people who use Firefox, they have an anti-keystroke logger which I love. It's there on everything I write. Please give it a try.

(They also have a keystroke logger if any of you have children which need to be monitored.)

Both are free downloads.

(Reply to this) (Thread)


[info]cazrolime
2008-10-11 06:49 pm UTC (link)
Do you have a link, please? A google search is only turning up paid ones.

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]brotherskeeper1, 2008-10-11 07:37 pm UTC (Expand)
(no subject) - [info]cazrolime, 2008-10-12 02:30 am UTC (Expand)

[info]tienriu
2008-10-10 09:59 am UTC (link)
I'm sort of curious though what exactly the hacker is trying to achieve. I mean yes, keystroke loggers can be used as step one to identity theft (passwords and so forth) and possibly also as a way of infecting computers to create a zombie network... But it seems vaguely tenuous and largely ineffective.

Why target LJ comms and users - most of whom are internet-savvy and tend to know enough to clean their computers of adware, spyware and spamware or at least notice unusual spikes in internet connectivity?

I wonder if there's some pimply teenager somewhere in Russia composing his 'I did it for the LOLZ' post now.

(Reply to this) (Thread)


[info]copperbadge
2008-10-10 11:26 am UTC (link)
Now I kind of want an icon that reads DID IT FOR THE LULZ in Russian :D

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]iamshadow, 2008-10-10 11:40 am UTC (Expand)
(no subject) - [info]bleakwinters, 2008-10-10 11:55 am UTC (Expand)
(no subject) - [info]svalar_unnir, 2008-10-10 04:11 pm UTC (Expand)
(no subject) - [info]iamshadow, 2008-10-11 10:37 am UTC (Expand)
(no subject) - [info]eofs, 2008-10-10 10:53 pm UTC (Expand)
(no subject) - [info]iamshadow, 2008-10-11 10:41 am UTC (Expand)
(no subject) - [info]air_ocean, 2008-10-11 11:00 am UTC (Expand)
(no subject) - [info]tienriu, 2008-10-10 09:09 pm UTC (Expand)
(no subject) - [info]copperbadge, 2008-10-13 02:32 pm UTC (Expand)
(no subject) - [info]tienriu, 2008-10-14 07:35 pm UTC (Expand)

[info]forest_rose
2008-10-10 10:05 am UTC (link)
Oh, sweetheart, don't be sorry. It's hardly your fault, and this has been way harder on you than it has on us! *snuggles*

(Reply to this)

(Deleted post)
Re: QUESTION
[info]copperbadge
2008-10-10 07:48 pm UTC (link)
It's quite possible, yes, and a very good idea -- thanks!

(Reply to this) (Parent)


[info]briebribeez
2008-11-20 08:17 pm UTC (link)
Is this an issue only with spyware, or with viruses? I'm on a mac and can't find a download for a virus scan...

(Reply to this)


[info]eucatastrophe
2008-11-20 10:27 pm UTC (link)
Does anyone know if Norton protects you from keyloggers?

(Reply to this)


(Anonymous)
2008-11-28 12:37 pm UTC (link)
So I have a question--if I wasn't logged into lj while clicking around on there, am I safe? Or, more specifically, is my gmail safe?

(Reply to this) (Thread)


[info]copperbadge
2008-11-28 01:55 pm UTC (link)
No. The keylogger interfaces directly with the computer, it is on your hard drive and records every single thing you type. Nothing is safe if you have entered a password to anything after having clicked around on the russian site. Download one of the suggested programs and run it; AdAware is good.

(Reply to this) (Parent)


(Anonymous)
2008-12-10 10:00 pm UTC (link)
Okay, so this is months after this happened to you, but I have a question regarding the email management system. I had a friend set up my LJ account, and she set it up with email address A, which I don't have any control over whatsoever. This was also years ago, so she's lost the password and everything and the account has probably been deactivated or deleted. Now, I really want to remove A from my email list because I don't have any control over it: is there any way LJ support would be able to help me do that?

My friend told me that it's possible the email address was deleted, would that mean that I'm safe from hackers? And finally, it's an AOL email, and I know the problem has been happening with hotmail ones.

Also, and I don't know if they'll affect this or anything, but after I found about the hacking thing, I changed my email from the one I have no control over to the one I now do. This was very recent; probably less than a few weeks ago. Would that effect me?

Thank you.

(Reply to this) (Thread)


[info]copperbadge
2008-12-10 10:03 pm UTC (link)
I suggest for your first question you actually ask LJ support, seeing as they're the ones you want to talk to about removing it.

As for the rest, the only way to be sure someone can't poach your address is to follow the link at the bottom of my post and set up a security question.

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - (Anonymous), 2008-12-10 10:50 pm UTC (Expand)
(no subject) - [info]copperbadge, 2008-12-10 11:45 pm UTC (Expand)

(109 comments) - (Post a new comment)

Create an Account
Forgot your login or password?
Login w/ OpenID
English • Español • Deutsch • Русский…