-
ripster
- Posts: 3809
- Joined: 09 Feb 2011, 07:04
- Location: Ugly American
- Main keyboard: As Long As It is Helvetica
- Main mouse: Mickey
- Favorite switch: Wanna Switch? Well, I Certainly Did!
- DT Pro Member: -
29 Jun 2012, 17:11
mkawa wrote:we're leaving vB behind entirely. the new platform will be the uber modern (and significantly more secure) SMF 2. it has most if not all the modern features one would want, is easy to extend, and still supports tapatalk ootb
EXCELLENT news!
Please keep the Orange/Black theme or my memes will be obsolete.
Last edited by
ripster on 29 Jun 2012, 17:12, edited 1 time in total.
-
Input Nirvana
- Posts: 376
- Joined: 19 Mar 2011, 05:58
- Location: San Francisco bay area, California, USA
- Main keyboard: Kinesis Advantage
- Main mouse: Rollermouse Free2
- DT Pro Member: -
29 Jun 2012, 17:12
DeathAdder wrote:If the entire database was saved, does that also mean accounts with their stored PMs will be avaiable again?
I sure hope so.
I'll be sure to find a way in the future to have ALL info copied somehow. This may become my new future opportunity!
Oh. Gotta earn money too. Problem.
-
domoaligato
- Posts: 58
- Joined: 01 Jun 2012, 23:27
- Location: Mountlake Terrace, WA ,USA
- Main keyboard: QFR with Reds
- Main mouse: SS Sensei
- Favorite switch: reds
- DT Pro Member: -
29 Jun 2012, 17:14
I have removed all references to imav's real name,blogger,facebook, etc...
it is not like it was hard to find. the whois information is accurate and that is all it takes to find out.
If you ever buy a domain get a business license first and buy it under the company name.
I am glad that the site is migrating off vBulletin to a more modern and secure platform.
that is great news.
The bad news is that by the time the migration is completed, GH will have no traffic left because of all the pissed off people that were in the middle of group buys/classifieds transactions.
-
mkawa
- Posts: 268
- Joined: 29 Mar 2012, 19:44
- Location: USA
- DT Pro Member: -
29 Jun 2012, 17:16
itznfb wrote:mkawa wrote:we're leaving vB behind entirely. the new platform will be the uber modern (and significantly more secure) SMF 2. it has most if not all the modern features one would want, is easy to extend, and still supports tapatalk ootb
That's all fine and dandy as long as mgmt realizes that this wasn't the fault of vB... it doesn't matter what software you're running if it isn't maintained and managed properly.
we were completely patched and imav is no stranger to computer security. the holes were in vB. we were close to localizing the exploit vector when they wiped everything out. it was in vB exclusively.
i will have to confirm with imav, but i believe private messages are included in the preserved db, and SMF has extensive tools for migrating data from vB 4
ps, thanks domo. however, don't be too hard on yourself. imav is well aware that this information is publicly and easily available.
Last edited by
mkawa on 29 Jun 2012, 17:19, edited 1 time in total.
-
mintberryminuscrunch
- Posts: 1225
- Joined: 29 Apr 2011, 12:58
- Location: Germany
- DT Pro Member: -
29 Jun 2012, 17:18
ripster wrote:mkawa wrote:we're leaving vB behind entirely. the new platform will be the uber modern (and significantly more secure) SMF 2. it has most if not all the modern features one would want, is easy to extend, and still supports tapatalk ootb
EXCELLENT news!
Please keep the Orange/Black theme or my memes will be obsolete.
Not sure why this behaviour by you is tolerated here
-
domoaligato
- Posts: 58
- Joined: 01 Jun 2012, 23:27
- Location: Mountlake Terrace, WA ,USA
- Main keyboard: QFR with Reds
- Main mouse: SS Sensei
- Favorite switch: reds
- DT Pro Member: -
29 Jun 2012, 17:20
didja wrote:GH1391401 wrote:sales engineer is typically not a technical role but the situation is somewhat ironic
On the contrary, sales engineers are often the best technical people a company has... that are capable of talking to people.
I've bought countless things where we wished we could keep working with the sales engineers once we purchased it but you get moved to a support team/professional services to get the install done and to get trained.
Domo, I would consider editing your post. Regardless of what you think of Geekhack and Imav, you shouldn't post people's real names or personal information even if it is publicly available elsewhere. That's bad form.
I removed his info.
-
mkawa
- Posts: 268
- Joined: 29 Mar 2012, 19:44
- Location: USA
- DT Pro Member: -
29 Jun 2012, 17:21
we know how important the forums are to everyone; group buys, personal transactions, something to shirk work with
we're working overtime (literally, i hacked on this yesterday until midnight then hacked on real work until 2) to get things back up and running. it's just as big a part of our lives, and we want it back too. as for the hacking group, screw 'em. as arnold once said: "[we'll] be back"
-
DanGWanG
- Posts: 292
- Joined: 11 Feb 2011, 18:21
- Location: Chicago | USA
- Main keyboard: KMAC Ti 62g Clears
- Main mouse: Razer DeathAdder Black
- Favorite switch: Ergo-Clears
- DT Pro Member: -
-
Contact:
29 Jun 2012, 17:28
So what is the ETA on the revival of GH?
-
ripster
- Posts: 3809
- Joined: 09 Feb 2011, 07:04
- Location: Ugly American
- Main keyboard: As Long As It is Helvetica
- Main mouse: Mickey
- Favorite switch: Wanna Switch? Well, I Certainly Did!
- DT Pro Member: -
29 Jun 2012, 17:28
Keep up the good work.
And make sure you restore the Ripster subforum too!
Some MightyFine shit in there, including backups of ALL the wikis. Or at least mine which is 90% of the good ones.
Backing up is ALWAYS good to do Geekhack Moderators.
-
mkawa
- Posts: 268
- Joined: 29 Mar 2012, 19:44
- Location: USA
- DT Pro Member: -
29 Jun 2012, 17:30
there are a lot of moving parts, so we can't say for sure. i'll continue checking in as things progress. personally, i'd like to have something available by very early next week, but it could go either way.
-
webwit
- Wild Duck
- Posts: 9333
- Joined: 28 Jan 2011, 00:27
- Location: The Netherlands
- Main keyboard: Model F62
- Favorite switch: IBM beam spring
- DT Pro Member: 0000
-
Contact:
29 Jun 2012, 17:37
On the contrary, sales engineers are often the best technical people a company has... that are capable of talking to people.
Hahahahahaha. Nice try, mr Sales Engineer.
-
Soarer
- Posts: 899
- Joined: 03 Jul 2011, 02:03
- Location: UK
- Favorite switch: F
- DT Pro Member: -
29 Jun 2012, 17:40
mkawa wrote:good news! all content is safe (save the attachments we lost in the initial battlestar galactica-ish attack). the wikis are safe.
That is good news! Thanks for the hard work!
Can you say more about how/why so many attachments have gone? I noticed that one of mine from end of Feb had gone... four months is an awful lot of attachments to lose
-
mkawa
- Posts: 268
- Joined: 29 Mar 2012, 19:44
- Location: USA
- DT Pro Member: -
29 Jun 2012, 17:43
the first attack was an indiscriminate rm -rf in the directory the attachments sat in. unfortunately, by coincidence this also managed to get the backups, which were mounted at the time. we were caught off guard (THOSE CYLON SCUM), but once imav realized what was happening, we managed to save everything else.
and yes, we're just as broken up about losing all that data as you are. the new platform will have a significantly more robust set of backup solutions.
-
jdcarpe
- Posts: 174
- Joined: 19 Mar 2012, 03:13
- Location: TX, USA
- Main keyboard: LZ-GH
- Main mouse: Logitech M570
- Favorite switch: 65g Linear MX
- DT Pro Member: -
29 Jun 2012, 17:45
Someone needs to DDoS attack the R00TW0RM site.
-
mkawa
- Posts: 268
- Joined: 29 Mar 2012, 19:44
- Location: USA
- DT Pro Member: -
29 Jun 2012, 17:48
i do not personally advocate any illegal or unethical electronic activity on internets. (but i am not the boss of you, either)
-
Soarer
- Posts: 899
- Joined: 03 Jul 2011, 02:03
- Location: UK
- Favorite switch: F
- DT Pro Member: -
-
domoaligato
- Posts: 58
- Joined: 01 Jun 2012, 23:27
- Location: Mountlake Terrace, WA ,USA
- Main keyboard: QFR with Reds
- Main mouse: SS Sensei
- Favorite switch: reds
- DT Pro Member: -
29 Jun 2012, 17:54
So to those that may learn something from this event. keep your backups offsite.
-
ripster
- Posts: 3809
- Joined: 09 Feb 2011, 07:04
- Location: Ugly American
- Main keyboard: As Long As It is Helvetica
- Main mouse: Mickey
- Favorite switch: Wanna Switch? Well, I Certainly Did!
- DT Pro Member: -
29 Jun 2012, 17:56
I did already. Why do you think I kept begging iMav to not permaban me for nuking Harrison?
But yeah, this Virus Infection Thing has been going on at Geekhack for YEARS.
I'm sure it'll be completely different now.
-
mkawa
- Posts: 268
- Joined: 29 Mar 2012, 19:44
- Location: USA
- DT Pro Member: -
29 Jun 2012, 18:05
yes, the new iteration will have multiple offsite backups
-
metafour
- Posts: 104
- Joined: 12 Feb 2012, 07:20
- Location: US
- Main keyboard: Leopold TKL
- Main mouse: G5
- Favorite switch: Red
- DT Pro Member: -
29 Jun 2012, 18:06
The rm -rf mention makes it sound like they had shell access whereas earlier it sounded like they just had the ability to inject arbitrary code into existing pages. In either case what was the rationale for keeping the site and the server up when it was known to be exploited? Standard operating procedure is to remove the server from the network, in this case the publicly accessible Internet, and then perform analysis. Even now the site and server is up.
-
boost
- Posts: 75
- Joined: 01 Jan 2012, 05:51
- Main keyboard: filco rkl
- Main mouse: g700
- Favorite switch: cisco
- DT Pro Member: -
29 Jun 2012, 18:07
jdcarpe wrote:Someone needs to DDoS attack the R00TW0RM site.
That wouldn't be a great idea.
Glad I don't have a gh email
-
Soarer
- Posts: 899
- Joined: 03 Jul 2011, 02:03
- Location: UK
- Favorite switch: F
- DT Pro Member: -
29 Jun 2012, 18:08
metafour wrote:The rm -rf mention makes it sound like they had shell access whereas earlier it sounded like they just had the ability to inject arbitrary code into existing pages. In either case what was the rationale for keeping the site and the server up when it was known to be exploited? Standard operating procedure is to remove the server from the network, in this case the publicly accessible Internet, and then perform analysis. Even now the site and server is up.
True... at least there might have been the opportunity to recover deleted files if it had shut down completely.
But what's done is done
-
webwit
- Wild Duck
- Posts: 9333
- Joined: 28 Jan 2011, 00:27
- Location: The Netherlands
- Main keyboard: Model F62
- Favorite switch: IBM beam spring
- DT Pro Member: 0000
-
Contact:
29 Jun 2012, 18:11
They bought an expensive flash drive for full local backup, instead of setting up offsite rsync for proper, more current backups using far less resources. At deskthority we save 6 rsynced snapshots each day, snapshots of the past 7 days, snapshots for each week of the past 5 weeks, and monthly snapshots, using incremental backup, to an old pc over adsl. We have total offsite replication. If the server is nuked, almost nothing will be lost, and in fact you could reach the replication server if I told you the ip, all the content would be there. I'm not a security expert, but a web developer. But this is basic stuff. The gh admin has been proven over and over again to be incompetent when it comes to server administration. I'm sure in their member base there are a number of people who can properly maintain a server and a web asset. They should get in and set up proper backups for starters. Otherwise it's waiting for the next fuckup.
-
mkawa
- Posts: 268
- Joined: 29 Mar 2012, 19:44
- Location: USA
- DT Pro Member: -
29 Jun 2012, 18:12
it turns out that you can do a lot if you can inject arbitrary php. i'm not going to speak for imav, but he had his reasons for keeping the site accessible. personally, i believe they were fairly sound, but hindsight is always 20/20, etc.
i'm not sure of your history webwit, but on the off chance that it is productive to defend imav from your barbs, i would say that the issue is that imav is a nice but extremely busy guy who started a fun hobbyist website that got much larger much faster than anyone could have imagined. and yes, we have assembled a team now that is happy to support him in designing that fun hobbyist website for scale this time. if the gentle reader would like to join it, please feel free to pm me your credentials.
Last edited by
mkawa on 29 Jun 2012, 18:18, edited 1 time in total.
-
mmmty
- Posts: 9
- Joined: 29 Jun 2012, 16:47
- Location: USA
- Main keyboard: Filco Cherry Brown
- Main mouse: Logitech Performance Mouse MX
- Favorite switch: Ergo clear
- DT Pro Member: -
29 Jun 2012, 18:16
Same people, different place
-
ripster
- Posts: 3809
- Joined: 09 Feb 2011, 07:04
- Location: Ugly American
- Main keyboard: As Long As It is Helvetica
- Main mouse: Mickey
- Favorite switch: Wanna Switch? Well, I Certainly Did!
- DT Pro Member: -
29 Jun 2012, 18:23
mkawa wrote:yes, the new iteration will have multiple offsite backups
Can you guys recover Harrison's account for me?
Please?
I still feel a tad guilty about that.
And remember to push the button this time.
So.... is the new friendly Moderator team STILL gonna permaban me?
<ah the smell of burning bridges in the morning>
-
mkawa
- Posts: 268
- Joined: 29 Mar 2012, 19:44
- Location: USA
- DT Pro Member: -
29 Jun 2012, 18:27
harrison's posts were lost for good when you maliciously deleted them, ripster.
-
ripster
- Posts: 3809
- Joined: 09 Feb 2011, 07:04
- Location: Ugly American
- Main keyboard: As Long As It is Helvetica
- Main mouse: Mickey
- Favorite switch: Wanna Switch? Well, I Certainly Did!
- DT Pro Member: -
29 Jun 2012, 18:28
mkawa wrote:harrison's posts were lost for good when you maliciously deleted them, ripster.
So I take that as a NO?
Bummer. So much for cloud computing. He was ever a kind and gentle soul. BUT we digress, the details of that are in the appropriate thread.
http://deskthority.net/off-topic-f10/ba ... son#p55393
-
nthn
- Posts: 1
- Joined: 29 Jun 2012, 19:09
- Main keyboard: HHKB
- Main mouse: Mighty Mouse
- Favorite switch: Topre
- DT Pro Member: -
29 Jun 2012, 19:14
Does anyone know how to get in contact with Demik from GH? I want to make sure he received the board that I sent to him.
-
mintberryminuscrunch
- Posts: 1225
- Joined: 29 Apr 2011, 12:58
- Location: Germany
- DT Pro Member: -
29 Jun 2012, 19:15
nthn wrote:Does anyone know how to get in contact with Demik from GH? I want to make sure he received the board that I sent to him.
send him a letter.. or an email if he paid via paypal..