Author Topic: 2012-12-31 Flight Logger Problems  (Read 4448 times)

Offline EHM-0654 Murray

  • Administrator
  • Intergalactic!!
  • ***
  • Posts: 4,531
  • Karma: 5
  • VA Management
    • The Ponderings of PMUK
2012-12-31 Flight Logger Problems
« on: January 02, 2013, 09:15:57 pm »
Just to give everyone some information about what went on with the flight logger over the new year period:-

It turns out that our VPS was compromised (in some fashion) and as a result additional javascript was being added to the end of the some of our website pages (including the one that the Flogger talks to). It came at quite possibly the worst possible time, as the two of us that are "technical" were both on holiday (me with my parents in deeply rural France, and Alexander on a minimoon with his wife).

We've already corrected all the compromised files (daily backups are wonderful for that sort of thing) and deployed what we believe to be the fix for the attack vector, plus we've started to trawl through the logs to see was done after the initial compromise (if anything). At present, it appears that the compromise payload wasn't dangerous, but if you are the least bit concerned, we recommend changing your password both on the main site (your pilot password) and here in the forums - it just makes sense.
Murray Crane // EHM-0654 // Twitter
VA Management

KEEP CALM AND CARRY ON