Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Announcements

Showing Original Post only (View all)

Skinner

(63,645 posts)
Tue Nov 15, 2016, 01:12 PM Nov 2016

About the hack [View all]

This discussion thread was locked by Skinner (a host of the Announcements group).

This is an updated version of a message that appeared on our homepage while the site was offline this weekend, which provides a good overview of the hack and our efforts to get the site back online.

The site was first attacked around 4:30PM ET on Tuesday afternoon. This was not a "typical" hack like a DDoS or an attempt to gain control of our web server. Instead, the hacker had found a vulnerability in our forum software.

The hacker exploited that vulnerability in what appeared to be a politically-motivated act of vandalism: A large number of posts were removed and replaced with the words "God Emperor" (a reference to Donald Trump), and a ridiculously over-the-top pro-Trump video was served automatically to all of our visitors. If you're curious you can watch the video on YouTube (WARNING: HATE CONTENT).

The DU Administrators were online at the time when the attack occurred, so we immediately shut down the site in order to block out the hacker and limit their ability to disrupt.

As you know Tuesday was election day, our most important day of the year, so our biggest concern at the time was getting the site back online quickly so our members would have access that evening. We collected some preliminary evidence indicating how the hacker had managed to disrupt the site, and based on that evidence we made what we believed were the necessary changes in order to remove the vandalism, secure the site, and bring it back online. (During that time we put up an admin-only login box to block out the hacker. If you entered your username and password into that box, you did not expose your information to the hacker.)

After a few hours we brought the site back up, but it quickly became apparent that we had not sufficiently scrubbed the site and some malicious code placed by the hacker got executed again. So we took the site offline a second time. Since we had already failed once to secure the site, we agreed it would be irresponsible to bring the site back online again until we were confident that we knew exactly what the hacker had done, and we believed the site was secure. At that point we knew we were not going to be back online for election night, and we suspected it might take days.

It took most of the day Wednesday to figure out exactly how the hacker had managed to disrupt the site, and what user information may have been vulnerable.

It is likely that the hacker had access to certain member information on an account-by-account basis: Usernames, email addresses, and IP addresses. There is no evidence that the hacker had access to our database or the full table of user information.

We believe that the hacker was not able to see your passwords -- not even in encrypted format. But even if the hacker was not able to see your passwords, they may have been able to over-write passwords for some accounts. Put another way: The hacker doesn't know what your password was, but the hacker might have changed it to something that they did know. That is why we are requiring all members to change their passwords now that the site is back online.

We can say for certain that donor data, such as credit card numbers or addresses, were not compromised because that information is handled by PayPal and never passes through to our servers.

As most of you know, we have three employees at Democratic Underground, and only one of us (Elad) is a real programmer who could do the complicated back-end coding to deal with the hack. If our goal was to simply plug the specific vulnerability exposed in the hack, the site would likely have been back online in a couple days. But because we know that there is a sufficiently motivated and skilled individual somewhere out there who has already vandalized our website, we did a much more comprehensive security review to identify similar vulnerabilities to the one exposed in the hack.

We would be remiss if we did not recognize the invaluable assistance which DU member Lithos has provided during this security review. We are very grateful for his help. Thank you, Lithos.

We have updated the site on two levels: Elad has been fixing some of the code in our forum software (with help from Lithos), and we have been working with our web host to implement a higher level of security on their end. Now that the site is back up, we are temporarily limiting access to the site to Star Members only. We are taking this precaution because we want to make sure that we are receiving only legitimate traffic during the next couple days while our new security software “learns” what is legitimate traffic to the site. This limited opening period should only last two or three days.

We know that this has been a long and frustrating process, and the timing could not have possibly been worse. Thank you again for your patience and understanding. And thank you for the tremendous outpouring of encouragement we have received from so many of you.

--The DU Administrators
32 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
About the hack [View all] Skinner Nov 2016 OP
Silly question, perhaps: What is the likelihood of nabbing these basement dwellers? Eleanors38 Nov 2016 #1
Unlikely. Skinner Nov 2016 #3
It would be cool to post all the responses you had to yuiyoshida Nov 2016 #7
Its very easy to hide your IP address Travis_0004 Nov 2016 #27
Yes, I hope you found someone to prosecute. nt babylonsister Nov 2016 #2
I missed all of you so very much! In_The_Wind Nov 2016 #4
Was the hack reported to the FBI? jg10003 Nov 2016 #5
lemme tighten my tinfoil hat before i say this, but mopinko Nov 2016 #6
Dr. Ernest Partridge wrote an essay based on our hack. herding cats Nov 2016 #8
Thanks Skinner, you all did good.... sheshe2 Nov 2016 #9
Same here lillypaddle Nov 2016 #11
me too. I thanked him profusely. Great team, great pulling through... CTyankee Nov 2016 #19
yes a raise for Elad, for sure!!!! nt steve2470 Nov 2016 #21
Thank you, Skinner, EarlG, and especially Elad! Yeoman's work! lastlib Nov 2016 #10
1 red dog 1 Nov 2016 #22
criminal what was done to this site. I'd be happy to chipin for experts to capture them Sunlei Nov 2016 #12
Thank you for the explanation and all the hard work to get DU back online friendly_iconoclast Nov 2016 #13
I did some checking around Twitter when election day happened. Initech Nov 2016 #14
I think it was a generic reference Lithos Nov 2016 #15
They also hijacked Mac Tonight from the 80s. Joe Bacon Nov 2016 #16
Donald Trump is bringing out the worst in people. Initech Nov 2016 #17
Thanks and a question grantcart Nov 2016 #18
I told this site we were down, it's a well-known IT site steve2470 Nov 2016 #20
What happened to Discussionist? Mr.Bill Nov 2016 #23
You claiming you're a decent person??? groundloop Nov 2016 #24
Of course. Mr.Bill Nov 2016 #25
I remember logging in and was immediately asked to serve on a jury. dubyadiprecession Nov 2016 #26
Glad to be back. These past couple of weeks have been doo doo without DU. SCRUBDASHRUB Nov 2016 #28
Russians? Hacker did not want us comparing notes on election day! Madam45for2923 Nov 2016 #29
for those of us who clicked on DU when it was hacked napkinz Nov 2016 #30
Message auto-removed Name removed Dec 2016 #31
It'll come back eventually. Skinner Dec 2016 #32
Latest Discussions»Help & Search»Announcements»About the hack»Reply #0