Stay Out Super-Late Tonight ([info]copperbadge) wrote,
@ 2009-03-06 17:51:00
Previous Entry  Add to memories!  Tell a Friend  Next Entry
Entry tags:picking up the pieces

Okay, it looks like the "hackers" who got me are up to old tricks again. So.

NOTE ADDED 3/12: The hackers are now posting to comms they've hacked warning against hackers and linking to "me", as many other comm mods have done. Except the link goes to their creepy spampage instead, and they've hilariously mis-spelled my name. Note sarcasm.

I fucking hate how paranoid this sounds but: if you see a warning post, or a suspicious post of any nature, for god's sake hover your mouse over the link and check the URL that shows up in the lower left corner of your browser to make sure it's actually directing you where it says it is. If you don't recognise any part of the URL, don't click.

And onwards.

HOW TO PROTECT YOURSELF FROM LOW TECH FAIRLY INGENIOUS HACKERS
By Sam Starbuck, Age 29 1/2



PLEASE NOTE: These hackers usually target high-traffic journals and moderators of high-traffic communities. If you are either of the aforementioned, you are especially at risk. If you do not moderate any comms and have a relatively small flist you are not high-risk for this hack.

1. These hackers get your password by re-creating an email address that you have allowed to lapse (in my case, copperbadge@hotmail.com ). I did not have control of this hotmail account and hotmail had purged it, so they were able to register it. Because it was the originating email address on the account I could not remove it (this can now be done, see below). They had the password sent there, changed the password, and then hacked me.

TO REMOVE AN EMAIL ADDRESS YOU HAVE ALLOWED TO LAPSE: you will need to have a second validated email address for six months or more. Go here and remove any addresses that are no longer in your control, or re-register them so that you control them.

2. These hackers got my password because I did not have a security question enabled. If you enable a security question then anyone attempting to get your password sent to an email address will have to answer a security question first. This includes you, so REMEMBER THE ANSWER.

TO ENABLE SECURITY QUESTIONS: go here.

3. To report the hackage to LJ, go here and provide them with as much information as you can -- username, all known email addresses for the journal, communities you have moderating or posting access to. Do not report this to the ordinary complaints page, as your report will not be fast tracked. After I reported my hackage, it took them about a day to get back to me. I had no communication until they had restored control to me. Expect this.

Once you've reported the hack, contact any co-mods you have ASAP to remove you as moderator on comms you mod. If they still have control, tell them to post to any given community you're on to warn people you've been hacked and not to click the goddamn link. This may not come in time, as they also use your account to lock out other moderators and deny posting access to other community members.

If you have phone or email posting enabled, post an explanation and warning through that -- you should still be able to get your post through to your journal. It will probably show up under the hackerpost, because they postdate; nothing you can do about that.

4. Once they are in, these hackers systematically delete every entry you have ever made and put up a new one with a link to a site that may contain spyware. No, you will never get those entries back. I'm sorry. You may be able to recover the text from googlecache or wayback machine, or if you have a mirror on IJ/JF, or if you have a google feed. I used a combination of all four to get about 80% of my entries back, but did not get many comments back. I'm not going to post a bunch of links here; you can read through my picking up the pieces tag for more info on how I recovered my entries.

TO MAKE SURE YOUR LJ IS BACKED UP: look up LJSec or LJArchive. I've had more success with LJSec. These will download your journal entries and comments to your hard drive. You can also set up a google-reader feed to preserve your entries, but I've no idea how.

5. If you clicked a link from a hacked individual, it may have taken you to a page with spyware in it. You may have spyware on your computer, or a keylogger. It's that simple. Yes, even if the link appeared to be dead or you hit the back button rilly rilly quickly. Yes, even if you have virus-scan software. Look up AdAware and run it on your computer. Yes, a keylogger logs EVERYTHING YOU TYPE. No, it does not log things you type into LJ or email from ANOTHER COMPUTER. Yes, I really got that question, more than once.

I am leaving comments open but please be aware that I am not LJ Tech Support nor am I in contact with anyone else who has been hacked. If you ask a question that is answered in this post or that you could get the answer to from Google or the LJ FAQ, I will probably not reply, though someone else might. Mac users, I have minimal Mac experience; if you post here someone else might help you, but I can't.

If you would like to use this post as a messageboard to contact people who have been hacked or to let people know you have been hacked, please feel free.



Page 1 of 2
<<[1] [2] >>

(85 comments) - (Post a new comment)


[info]la_trombonista
2009-03-07 12:17 am UTC (link)
Thanks for the info. I just set my own security question.

(Reply to this) (Thread)


[info]amaterasu_no_ki
2009-03-18 06:37 pm UTC (link)
Same here, even though I'm not a mod of any high-profile communities.

(Reply to this) (Parent)


[info]delirieuse
2009-03-07 12:24 am UTC (link)
Thanks for this; I set a security question ages ago, but didn't realise I still had a scarcely used email account from ten years ago attached to my account! It's now been deleted.

(Reply to this)


[info]sometimescrazy
2009-03-07 12:45 am UTC (link)
Had emails and deleted and set up a security question. Thanks. :)

(Reply to this)


[info]brewsternorth
2009-03-07 01:40 am UTC (link)
Set a security question (fortunately my emails have not lapsed).

Ack all the same.

(Reply to this)


[info]swordage
2009-03-07 02:31 am UTC (link)
Thank you - I just cleared out an old email (which I'm fairly certain I still own, but better safe than sorry) which I had no idea was still linked to LJ. Not that I'm at risk, really, but it's good to be up-to-date.

(Reply to this)


[info]xenakat13
2009-03-07 02:42 am UTC (link)
I'd just like to suggest to people who enable the security question feature; DON'T fill in obvious answers. For example, if the question is "What is your mother's maiden name?" or "what is your pet's name?" don't use the real answer. Pick something that is completely off-the-wall counterintuitive (like "shampoo" or "gigglefart."

I went through a scare a few months ago with my bank...identity thieves often know these kinds of obvious answers. If they manage to install a keylogger on your system, it won't help, but it will stop casual hackers (like jerky siblings or vengeful ex's)

(Reply to this) (Thread)


[info]adina_atl
2009-03-07 04:32 am UTC (link)
Good point. I chose the "write your own question" option, and wrote something that can't be discovered using geneology websites.

(Reply to this) (Parent)


[info]dolimir_k
2009-03-07 03:16 am UTC (link)
I totally didn't know about LJ keeping old email addresses on file. I've now deleted my old one.

Thank you.

(Reply to this)


[info]imaginarycircus
2009-03-07 03:40 am UTC (link)
Dear God. You're almost 30!? Now I feel ancient and need to have a brandy and soda a cool cloth for my head.

(Reply to this)


[info]luckyckljw
2009-03-07 03:54 am UTC (link)
I don't recall if I've linked this before, but it may bear reposting:

In the past, I've made sure to have the Keyscrambler Firefox addon installed. Since in encrypts keystrokes at the kernel level, it defeats keyloggers and all they'll get is a jumbled mash. I know it's available for Windows, not for Linux, and have no idea about for Mac.

(Reply to this) (Thread)(Expand)


[info]rdlenix
2009-03-07 04:29 am UTC (link)
I love Firefox and all its add-ons.

(Reply to this) (Parent)

(no subject) - [info]afrocurl, 2009-03-07 06:40 am UTC (Expand)
(no subject) - [info]foofighter0234, 2009-03-09 10:50 pm UTC (Expand)
(no subject) - [info]luckyckljw, 2009-03-10 01:08 am UTC (Expand)
(no subject) - [info]foofighter0234, 2009-03-10 03:44 pm UTC (Expand)
(no subject) - [info]mixtape__murder, 2009-09-23 03:30 am UTC (Expand)
(no subject) - [info]ssha, 2009-09-23 07:28 am UTC (Expand)

[info]bobthemole
2009-03-07 04:29 am UTC (link)
Someone here at Sam's once recommended NoScript (http://noscript.net/) a Javascript/Java/Flash blocker add-on and I've been using it for months now.

It's warned me a few times when I was about to click on an unsafe link and it doesn't interfere too badly with my browsing experience (which really turned me off the earliest blockers).

(Reply to this)


[info]catalysted
2009-03-07 04:55 am UTC (link)
Thanks for this! I am glad I can take steps for prevention. :)

(Reply to this)


[info]katernater
2009-03-07 05:36 am UTC (link)
Thank you for this information.

(Reply to this)


[info]lostpoisoned
2009-03-07 06:20 am UTC (link)
Thank you for this, it's really helpful. I just want to add a little something.

For the security question, it might be wise for people who speak more than one language to create their own question and answer in another language than English.

(Reply to this)


[info]californiaquail
2009-03-07 06:57 am UTC (link)
You said Wayback Machine.

WIN.

(Reply to this) (Thread)


[info]copperbadge
2009-03-07 04:20 pm UTC (link)
Well, that's what it's called....*perplexed look*

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]cageyklio, 2009-03-07 08:16 pm UTC (Expand)
(no subject) - [info]copperbadge, 2009-03-07 08:21 pm UTC (Expand)
(no subject) - [info]cageyklio, 2009-03-07 08:30 pm UTC (Expand)

(Anonymous)
2009-03-07 07:21 am UTC (link)
Look up AdAware and run it on your computer

Except AdAware operates by installing spyware onto your computer. The 'spyware' it claims to detect is the spyware it comes with. That's how any of those online so-called spyware programmes work. The best way to remove spyware from your computer is to take it into a certified computer technician to have to removed.

(Reply to this) (Thread)(Expand)


[info]copperbadge
2009-03-07 04:19 pm UTC (link)
I've had a poke round Google and can't confirm this re: AdAware -- can you point me to a link documenting how that works?

I'm not highly knowledgeable about these things, but I know that AdAware has had the highest success rate in getting rid of this hack's keyloggers, and I used it for years with no ill effects.

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]veronicamae, 2009-03-08 04:50 am UTC (Expand)
(no subject) - [info]cleversimon, 2009-03-08 10:12 pm UTC (Expand)
(no subject) - [info]copperbadge, 2009-03-08 10:17 pm UTC (Expand)
(no subject) - [info]cork118, 2009-09-22 05:26 pm UTC (Expand)
(no subject) - [info]teadragon, 2009-09-23 03:30 am UTC (Expand)
OT - [info]ssha, 2009-09-23 07:31 am UTC (Expand)
(no subject) - [info]cleversimon, 2009-09-23 04:05 pm UTC (Expand)
(no subject) - [info]copperbadge, 2009-09-23 05:29 pm UTC (Expand)
(no subject) - [info]cleversimon, 2009-09-23 05:35 pm UTC (Expand)
(no subject) - [info]copperbadge, 2009-09-23 05:36 pm UTC (Expand)
(no subject) - [info]ssha, 2009-09-24 04:42 pm UTC (Expand)

[info]loveohlovelove
2009-03-07 08:14 am UTC (link)
thank you.

(Reply to this)


[info]gemxpink
2009-03-07 01:48 pm UTC (link)
thanks.

(Reply to this)


[info]mariposaluna
2009-03-07 02:26 pm UTC (link)
Thanks for the heads up!

While my little Journal is of no consequence, I did go and set up my secret question because I had forgot all about it being available now.

(Reply to this)


[info]essayel
2009-03-07 03:49 pm UTC (link)
You're a star, Sam. I little shimmering twinkle in the deeps of the internet!!

No I haven't been drinking.

(Reply to this)


[info]jannedoe
2009-03-07 08:07 pm UTC (link)
Thanks for the help! My journal is really valuable to me and I'd be pretty distraught if some douchebag got in it and deleted all my entries.

(Reply to this)


[info]txrabbit
2009-03-07 11:19 pm UTC (link)
Thanks for this. I found three old email addresses were still attached to my account, and I had not set my security question.

I appreciate you taking the time to write this up. I sent the link to the moderator of one of the communities that I belong to, as we are rather big and noticeable.

(Reply to this)


[info]rainkatt
2009-03-07 11:59 pm UTC (link)
Thanks. I came here from, um, someone on my flist. I had an ancient email address still sitting there, which I deleted. I know that I looked, when I got rid of that account, and I couldn't find anything. I'm pretty sure I had a secret question, already, but I set it up, anyway.

(Reply to this)


[info]tarzanic
2009-03-08 12:37 am UTC (link)
Thanks for the advice. I set my security question and removed an email address.

(Reply to this)


[info]veronicamae
2009-03-08 04:48 am UTC (link)
I'm curious how they figure out the old email addresses so they know what to use to hack with. I mean, if your email is your LJ SN, then it's easy, but I doubt the majority's are.

Thank you so much for the info tho! I would be devastated if it happened to me. I've taken all the precautions you recommend. :)

(Reply to this) (Thread)


[info]copperbadge
2009-03-08 04:59 am UTC (link)
You'd be surprised -- at least three people who've been hacked, me included, have usernames and email names that are the same. I suspect others might list their old emails somewhere?

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]veronicamae, 2009-03-08 05:22 am UTC (Expand)

[info]biweasley
2009-03-08 05:52 am UTC (link)
Thanks for the post :D

I'm gonna do all this xD

(Reply to this)


(85 comments) - (Post a new comment)

Page 1 of 2
<<[1] [2] >>

Create an Account
Forgot your login or password?
Login w/ OpenID
English • Español • Deutsch • Русский…