• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Have I been hacked here?

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    Have I been hacked here?

    I recently found an email in my spam folder that I was unaware of but when I read it, was a bit concerned. The mail quoted my password from CUK. It is only used here at CUK. The mail threatened to encrypt my PC if I didn't pay a ransom. I haven't paid, and I haven't been encrypted. But should I be concerned that either my PC or my CUK account has been compromised? Thanks.

    By the way - Windows 10 latest version, Windows firewall switched on, router firewall enabled, Sophos Home AV installed. Scans with Malwarebytes and Sophos show nothing untoward. As an aside, I also occasionally access CUK from an Android device, that also has Sophos Home installed.
    Last edited by Fred Bloggs; 21 July 2018, 01:36.
    Public Service Posting by the BBC - Bloggs Bulls**t Corp.
    Officially CUK certified - Thick as f**k.

    #2
    See if the email contains any identifiers in the headers etc that are found in google to identify a possible perp if it's a known scammer group. That will give you info on how likely it is to be followed up or if it may be someone trying it on.

    Change all important passwords in case there's been any others key logged (or whatever mechanism they may have used for obtaining the password) from your PC or android device.

    I'd expect CUK to be storing passwords in an encrypted state that can't be reversed if say their database was hacked, so hopefully you are a lone target rather than it being anything CUK and it's members have to worry about.

    To avoid worrying about losing data through encryption, have a backup offline that can be used to restore data after a reformat and rebuild. Perps can't blackmail you if you don't fear losing what they threaten to take.
    Maybe tomorrow, I'll want to settle down. Until tomorrow, I'll just keep moving on.

    Comment


      #3
      Thanks for thoughts. Though cannot be a key logger? I haven't keyed my PW in for ages, CUK auto logs me in. I immediately deleted the mail, but yes, passwords are changed. Edited to add - It was gmail that had automatically sent the mail to the spam folder, if that is of any significance.
      Last edited by Fred Bloggs; 21 July 2018, 08:17.
      Public Service Posting by the BBC - Bloggs Bulls**t Corp.
      Officially CUK certified - Thick as f**k.

      Comment


        #4
        I'm guessing that the password is stored in a cookie by the browser then for CUK site to access. Not sure how safe cookies or passwords remembered by the browser for auto completion of the login page really are from malicious sites/apps.
        Maybe tomorrow, I'll want to settle down. Until tomorrow, I'll just keep moving on.

        Comment


          #5
          Originally posted by Hobosapien View Post
          I'm guessing that the password is stored in a cookie by the browser then for CUK site to access. Not sure how safe cookies or passwords remembered by the browser for auto completion of the login page really are from malicious sites/apps.
          That's what I am guessing at this point in time. Though the spam came to my normally used mail address so this person knows my email addy AND my CUK password. Worrying?
          Public Service Posting by the BBC - Bloggs Bulls**t Corp.
          Officially CUK certified - Thick as f**k.

          Comment


            #6
            Originally posted by Hobosapien View Post
            I'm guessing that the password is stored in a cookie by the browser then for CUK site to access. Not sure how safe cookies or passwords remembered by the browser for auto completion of the login page really are from malicious sites/apps.
            What's stored is the MD5 hash of the logged in user's password. It's extremely difficult to recover the password from the hash alone.

            I've passed Fred Blogg's concern to admin.
            Down with racism. Long live miscegenation!

            Comment


              #7
              Originally posted by NotAllThere View Post
              What's stored is the MD5 hash of the logged in user's password. It's extremely difficult to recover the password from the hash alone.

              I've passed Fred Blogg's concern to admin.
              Thank you.
              Public Service Posting by the BBC - Bloggs Bulls**t Corp.
              Officially CUK certified - Thick as f**k.

              Comment


                #8
                Originally posted by NotAllThere View Post
                What's stored is the MD5 hash of the logged in user's password. It's extremely difficult to recover the password from the hash alone.

                I've passed Fred Blogg's concern to admin.
                Just Google "Rainbow Tables".
                More than likely already been "cracked" unless you're salting them.
                Don't believe it, until you see it!

                Comment


                  #9
                  Originally posted by darrylmg View Post
                  Just Google "Rainbow Tables".
                  More than likely already been "cracked" unless you're salting them.
                  Is there any concern on my part that the person who mailed knows my email address AND my CUK password (now changed)?
                  Public Service Posting by the BBC - Bloggs Bulls**t Corp.
                  Officially CUK certified - Thick as f**k.

                  Comment


                    #10
                    Did you ever log on to CUK from a computer other than your own?
                    Down with racism. Long live miscegenation!

                    Comment

                    Working...
                    X