List of user email addresses compromised

If you find a bug please report it here

List of user email addresses compromised

Postby Ian » Thu Dec 06, 2018 4:13 pm

I registered here back in 2012 and haven't used the email address for anything else. It isn't (shouldn't be) visible to non-mods here either.

Today I get a 'I hacked the webcam you haven't got' attempted blackmail spam to that address, the first thing it's had in about six years.

I don't know what else is compromised here, but the email addresses of users very probably are.

It was a unique password used here too, but I'm still off to see how phpBB stores them...
Ian
 
Posts: 1
Joined: Fri Mar 16, 2012 10:16 am

Re: List of user email addresses compromised

Postby fantastory » Sun Feb 24, 2019 8:35 am

That is true, email address is seen when you hover on user name on his profile page.
There is an option to show email only to friends but it is off by default.

The quickfix would be to mark this field for all current players and making this option default.
fantastory
 
Posts: 55
Joined: Tue Jan 17, 2017 11:55 pm


Return to Bug reports

Who is online

Users browsing this forum: No registered users and 2 guests

cron
Not able to open ./cache/data_global.php