Yes, the forum got hacked. No, we don't think it was a via a vulnerability in the forum software. The XenForo software was completely up-to-date. We're pretty confident the problem was "OpSec" -- an improperly secured account with Admin access. That has of course been remedied.
The first thing the criminal black-hats did was e-mail some of the users with a "donation request":
Last night at 8:09 PM, I received the following PM from a legitimate user's account that has existed since 2014:
[to be continued and this thread will be unlocked for replies when I'm done posting]
The first thing the criminal black-hats did was e-mail some of the users with a "donation request":
So we put up a notice that is was a fake/scam. I suppose that angered them and things escalated from there.Hey [username] ([email address])! When I started Ross-Tech.com so long ago, I invisioned it to be a tool to help others in their journey through technical issues whether that be in college, university, or just work! I would love to keep this website free for anyone who needs help however it does cost quite a lot monthly to keep the website up and running. If you feel that you would like to support me and all the users at Ross-Tech.com, I encourage you to donate via the options below! All donations will be put towards Ross-Tech.com and all donators will recieve access to special giveaways, badges, ranks, etc. If you chose not to donate or wish to but are unable to it's perfectly fine, the website will still remain free just as it always has been.
Last night at 8:09 PM, I received the following PM from a legitimate user's account that has existed since 2014:
And at 8:20 PM:Hello, Uwe. We will make this short, we have the data of all 38,714 users on your website. This data includes but is not limited to; emails, usernames, userID's, IP Addresses, message count, etc. Now, all we need you to do is send $500 BTC to the address below and we will NOT release all of the aforementioned data. We all know the toll this could take on you and your company's reputation and we hope that you'll agree with us on this as we do not wish to release your information however we will if we do not receive the $500 USD in BTC. In the event you think we are 'bluffing', we have attached a small sample at the bottom of this message. Please take a moment to look at the data and ponder what steps you would like to take.
If you ban this account "[redacted]" or do not respond, we will take that as you are unwilling to pay the fee and we will release the information publicly.
We hope that you will make the right decision.
BTC Address - [redacted]
+SAMPLE+
[redacted]
At 8:41 PM, I replied:I see that you are currently online, you have 30 minutes to respond to this message.
Do not make us publicly reply with the above message, we are sure you would like to keep the data leak private from your users
I shut down the account this was coming from, but at 9:05 PM, I received another PM from another legitimate user's account:8:41 PM:
$500 is not very much money, but this is a matter of principle.
NO.
Oh, and none of the passwords you have for either my account or my old test account are or ever have been correct.
-Uwe-
At 9:06 PM, I replied:Hacker @ 9:05 PM:
You can ban all the accounts however we will keep doing this until we receive the money
And at 9:07 PM we shut down the entire forum.I will NEVER reward your criminal behavior.
-Uwe-
[to be continued and this thread will be unlocked for replies when I'm done posting]