Author Topic: Avast User Registration Data Base Compromise?  (Read 9887 times)

0 Members and 1 Guest are viewing this topic.

The Hammer

  • Guest
Avast User Registration Data Base Compromise?
« on: October 13, 2006, 03:37:33 AM »
Picked up a piece of spam in a protected (read used in 3 places) email account from this web forum.
This address was not used to create an account here, it was used to register a copy of Avast Free in 2004.


I'm unhappy to say the least.
« Last Edit: October 13, 2006, 08:32:18 AM by kubecj »

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re: Avast User Registration Data Base Compromise?
« Reply #1 on: October 13, 2006, 03:44:38 AM »
your email is sot been comprimised please see the many other threads on this issue
"People who are really serious about software should make their own hardware." - Alan Kay

trisha101

  • Guest
Re: Avast User Registration Data Base Compromise?
« Reply #2 on: October 13, 2006, 03:46:22 AM »
I received the same crap!
How do I stop this?

Thanks!

The Hammer

  • Guest
Re: Avast User Registration Data Base Compromise?
« Reply #3 on: October 13, 2006, 03:49:02 AM »
your email is sot been comprimised please see the many other threads on this issue
Did you fully read my post?
The address that was spammed is not the one used to register in the forum.
It was used 3 years ago to register a copy of Avast Free.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Avast User Registration Data Base Compromise?
« Reply #4 on: October 13, 2006, 03:57:48 AM »
The best things in life are free.

The Hammer

  • Guest
Re: Avast User Registration Data Base Compromise?
« Reply #5 on: October 13, 2006, 04:06:57 AM »
Follow here http://forum.avast.com/index.php?topic=24177
We hate spam  :P
I have, the IM spam is different from the spam I received.
I have not used it to register an account in your forum.
It's an administrative account I use to conduct business with my domain provider and communicate with CERT.
The address was also used to register a copy of Avast Free 3 years ago.
My bad trusting it to Avast.

The Hammer

  • Guest
Re: Avast User Registration Data Base Compromise?
« Reply #6 on: October 13, 2006, 04:24:54 AM »
I received the same crap!
How do I stop this?

Thanks!

"We" have little to no recourse other than kill the account used and don't register/use Avast.
I suspect the PHPbb is either behind on updates or misconfigured making it vulnerable to exploit.
Pretty bad for a security company IMO.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Avast User Registration Data Base Compromise?
« Reply #7 on: October 13, 2006, 04:30:27 AM »
My bad trusting it to Avast.
Why are you bashing avast? You're just making bad avast press here... why?  :P :'(
Please, stop blaming avast team. Help us (and they) to solve the trouble will be better and more friendly from you.
The best things in life are free.

The Hammer

  • Guest
Re: Avast User Registration Data Base Compromise?
« Reply #8 on: October 13, 2006, 04:41:27 AM »
My bad trusting it to Avast.
Why are you bashing avast? You're just making bad avast press here... why?  :P :'(
Please, stop blaming avast team. Help us (and they) to solve the trouble will be better and more friendly from you.
I'm sorry, I'm not bashing Avast the program. It is a wonderful thing to offer new users for basic AV protection.
I'm getting reports of more of this from other admins who have registered the product but have no forum account. This points to a data base compromise, if you don't understand the severity of that I don't know what else I can say to you.
Please get in touch with the site admin and have them fix the darn thing!
It's not like PHPbb exploits are new or that updating and proper configuration are unimportant.
http://pub.sinuspl.net/sanaldarbe.avi

ReneeDj3

  • Guest
Re: Avast User Registration Data Base Compromise?
« Reply #9 on: October 13, 2006, 04:45:05 AM »
 >:( I received the same from Edward.  THis is the info...
Subject: New Personal Message: URGENT MESSAGE FROM ADMIN!!!
Date: 10/12/2006 8:13:39 P.M. Central Daylight Time
From: webadmin@asw.cz

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Avast User Registration Data Base Compromise?
« Reply #10 on: October 13, 2006, 05:04:04 AM »
This points to a data base compromise, if you don't understand the severity of that I don't know what else I can say to you.
Well, I'm a common user, not an administrator like you seem to be.
So, you must convince Alwil team (specially the webmaster), not me  ::)
The best things in life are free.

Offline TedNelly

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1538
  • Trust No-One!
Re: Avast User Registration Data Base Compromise?
« Reply #11 on: October 13, 2006, 05:13:29 AM »
 I think we can all agree that the DH "Aussie term" (D..k Head) EdwardN behind this crap needs a good smacking.
Windows 10 Pro | Intel I7 CPU | 16 Gig 2133 RAM | Avast beta 17.5.2295 | Firefox 54 b9(64-bit) | Cyberfox 52.1 | T-Bird 52.1.1 | SpyWareBlaster 5.5 | MalwareBytes 3.0.0.865 | WinPatrol 35.5.2 | GlassWire 1.2.100 | Cybereason Ransomfree 2.2.7 |  Pulla-dePlug Final!

kubecj

  • Guest
Re: Avast User Registration Data Base Compromise?
« Reply #12 on: October 13, 2006, 08:35:23 AM »
Please send me the whole email with all the headers to my email address. Please zip it, otherwise my spamfilter will killfile it. But since this (forum) computer knows _nothing_ about registration database, it's highly unlikely that it can send emails to such addresses...

The Hammer

  • Guest
Re: Avast User Registration Data Base Compromise?
« Reply #13 on: October 13, 2006, 11:24:51 AM »
 I must apologize.
After pulling my complete email records I see I did use the spammed address for a forum account.
Thankfully the Reg data base is stored separately, though that's little relief to forum participants that were spammed or even worse have been compromised with malware.
I would think best practice would be to make member list function unavailable for general parsing.
« Last Edit: October 13, 2006, 11:45:21 AM by The Hammer »

felipevidal

  • Guest
Re: Avast User Registration Data Base Compromise?
« Reply #14 on: October 13, 2006, 05:34:53 PM »
Avast team:

Disable PM globally on all accounts and let users turn the feature ON if they select to do so.  I would imagine the vast majority of registered forum users have not ever used the PM feature.  Also see if limits on number of PMs or posts in a given day or maybe hour could be set so that automated PM attacks are not effective.

Thank you for listening,
-felipe