To see less ads Register or Login ----- Daily Fantasy Sports games 18+

Hacked

News about, or comment on, the FISO forums. Post suggestions to Admin here!
User avatar
forestfan
FISO Jedi Knight
Posts: 36694
Joined: 13 Oct 2005, 18:27
Location: Between Westeros and Nova Scotia
FS Record: FISODAS Champion Season 34!

Re: Hacked

Post by forestfan »

blahblah wrote: 05 Oct 2021, 17:05 At the time it did seem obvious that they were just publicising the Hub thing. Not sure how banning me and others helped with that though.
I suspect it was those of us who got in their way by deleting their altered posts or reporting them etc. who they banned, probably along with other moderator accounts.

Think it’s the first time I’ve actually been banned from here anyway, though definitely come close on occasions when dealing with a few idiots :lol:

User avatar
baganboy
Comfortably Dumb(ledore)
Posts: 5874
Joined: 05 Aug 2008, 06:59
FS Record: 2011/12 - 212. 2019/20 - 222.
Altogether 6 top 10Ks. 8 top 20Ks. 9 top 50Ks.

Re: Hacked

Post by baganboy »

I do. I am of an age to be almost internet-native.

I have a 1password account given to me from office. Some personal usage is allowed. Google/gmail have 2-factor authentication anyway, as will most banks. I don't use any Fintech products - though they were once part of my sales portfolio :D

If you are planning to start blah, you can try Bitwarden. It is free, and I hear it is good enough.

User avatar
ajcairns
Grumpy Old Man
Posts: 1237
Joined: 05 Oct 2016, 14:40
FS Record: Still Decidedly Average.

Re: Hacked

Post by ajcairns »

baganboy wrote: 05 Oct 2021, 17:02 I understand. I was reading through this for the last couple hours.

How is it okay that one of the FISO mods was hacked by this (minor) terrorist organization? How is it okay that others' posts were tampered with? How is it okay that other posters (old timers such as yourself blah) were thrown out? How is it okay that for a few hours, they could eff order us to do what they wanted?
How is any of this okay?

Who have we bothered? what is anyone's botheration with us? why use and abuse us (because we are small and insignificant in the overall $c#m cesspit that is eff FPL community) in their whatever idealist war? Why eff us?

How is this okay?
Still think it's a FISO account holder involved somehow - they just didn't come here on the off chance looking to hijack a mods account to get a message out. They were already here. A quick cross check of the members list on FISO (at the bottom of the page) you can soon see the common names with the leaked lists and BFMs probably stuck out being in green as a Mod.

Considering what has happened across the community there is not much discussion about it. Why? Probably because everyone is shittin themselves that will be targeted.

User avatar
Beerfuelledman
FISO Knight
Posts: 13220
Joined: 13 Oct 2005, 18:26
Location: In Norn Iron
FS Record: FISO 17/18 FPL Cash Draft League Winner

Re: Hacked

Post by Beerfuelledman »

blahblah wrote: 05 Oct 2021, 17:03
Btw: do you have those Pwds saved on the likes of Dashlane, or do you type it in everytime for both?
I think I always tried to protect myself from my password being guessed. I never really assumed a site would get hacked and my password would be there to read in plain text and used to access other sites so I never thought about a password generator protector thing. I guess I need to find out what they are and which is best - and in my case, user friendly.

User avatar
blahblah
FISO Viscount
Posts: 108835
Joined: 13 Oct 2005, 18:46
Location: .. he thinks that he knows something which he doesn't, whereas I am quite concious of my ignorance.

Re: Hacked

Post by blahblah »

baganboy wrote: 05 Oct 2021, 17:09 I do. I am of an age to be almost internet-native.

I have a 1password account given to me from office. Some personal usage is allowed. Google/gmail have 2-factor authentication anyway, as will most banks. I don't use any Fintech products - though they were once part of my sales portfolio :D

If you are planning to start blah, you can try Bitwarden. It is free, and I hear it is good enough.
Ta, I'll have a look tomorrow along with Dashlane.

User avatar
forestfan
FISO Jedi Knight
Posts: 36694
Joined: 13 Oct 2005, 18:27
Location: Between Westeros and Nova Scotia
FS Record: FISODAS Champion Season 34!

Re: Hacked

Post by forestfan »

Apple devices have a good password manager/automatic strong password generator.

User avatar
baganboy
Comfortably Dumb(ledore)
Posts: 5874
Joined: 05 Aug 2008, 06:59
FS Record: 2011/12 - 212. 2019/20 - 222.
Altogether 6 top 10Ks. 8 top 20Ks. 9 top 50Ks.

Re: Hacked

Post by baganboy »

Here's a link. Wired(dot)com is kindasorta reliable, they do a lot of good tech journalism.

https://www.wired.com/story/best-password-managers/

User avatar
morganb
FISO Knight
Posts: 11227
Joined: 10 Aug 2009, 12:25
FS Record: Fantasy Advent Calendar 2012 Winner; The FISODAS Cup - Season 22 Winner; Ralfbergs EPL prediction game 2013/14 winner; FISO Goals 2022

Re: Hacked

Post by morganb »

I use something called "Post-Its" - they can't hack colourful little squares of paper! :wink:

User avatar
forestfan
FISO Jedi Knight
Posts: 36694
Joined: 13 Oct 2005, 18:27
Location: Between Westeros and Nova Scotia
FS Record: FISODAS Champion Season 34!

Re: Hacked

Post by forestfan »

morganb wrote: 05 Oct 2021, 17:19 I use something called "Post-Its" - they can't hack colourful little squares of paper! :wink:
The burglars/dodgy workmen etc. can though :wink:

User avatar
baganboy
Comfortably Dumb(ledore)
Posts: 5874
Joined: 05 Aug 2008, 06:59
FS Record: 2011/12 - 212. 2019/20 - 222.
Altogether 6 top 10Ks. 8 top 20Ks. 9 top 50Ks.

Re: Hacked

Post by baganboy »

BTW, no judgment calls here about any of you. Cyberterrorism is bloody eff scary, and most of you were not talking from behind a password manager. It's easy to be brave standing behind an army.

User avatar
blahblah
FISO Viscount
Posts: 108835
Joined: 13 Oct 2005, 18:46
Location: .. he thinks that he knows something which he doesn't, whereas I am quite concious of my ignorance.

Re: Hacked

Post by blahblah »

I think a fair few of us will be using a Pwd Manager very soon ..

User avatar
admin
FISO Administrator
Posts: 12125
Joined: 13 Oct 2005, 17:29
Location: Fantasy Sports Forum
FS Record: Won TFFO, 2nd/3rd TFF, Won BFF, Won FLGolf
Contact:

Re: Hacked

Post by admin »

blahblah wrote: 05 Oct 2021, 17:05 At the time it did seem obvious that they were just publicising the Hub thing. Not sure how banning me and others helped with that though.
The hacker (masquerading as BFM) started by banning all (but one - must have missed spinynorman) of the mods who, if around, could have banned BFM and removed the posts about the FFHub hack. There are 10 mods plus me (I can't be banned by a mod obviously). Then I assume the remaining 9 users banned (most done an hour later) were users online at the time for which he was editing their posts (which they could have edited back).

I've attached the record of the bans undertaken by BFM whilst asleep to show who was banned. I doubt the IP addresses will reveal where the hacker was really based.

(P.S. Can I thank those users that emailed me just after 10:30pm last night to warn me what was happening. I didn't see the emails until 11.30pm though and eventually got to bed about 1am after sorting everything out).
Beerfuelledman-mod-actions4Oct2021-crop.jpg
You do not have the required permissions to view the files attached to this post.

User avatar
forestfan
FISO Jedi Knight
Posts: 36694
Joined: 13 Oct 2005, 18:27
Location: Between Westeros and Nova Scotia
FS Record: FISODAS Champion Season 34!

Re: Hacked

Post by forestfan »

I presume it’s impossible for a hacker to ban the “admin” account? As we might really have been struggling then…

User avatar
Redsnout
Treebeard
Posts: 253
Joined: 06 Aug 2015, 18:39
FS Record: 676 - FPL (2016-17)

Re: Hacked

Post by Redsnout »

baganboy wrote: 05 Oct 2021, 17:02 I understand. I was reading through this for the last couple hours.

How is it okay that one of the FISO mods was hacked by this (minor) terrorist organization? How is it okay that others' posts were tampered with? How is it okay that other posters (old timers such as yourself blah) were thrown out? How is it okay that for a few hours, they could eff order us to do what they wanted?
How is any of this okay?

Who have we bothered? what is anyone's botheration with us? why use and abuse us (because we are small and insignificant in the overall $c#m cesspit that is eff FPL community) in their whatever idealist war? Why eff us?

How is this okay?
Hey BB :) This is not okay. And it feels shitty to get your personal info to get exposed, or like someone invading into your house. I know the feeling, my daily job is in cyber security :lol: It is easy to direct your anger towards the hackers now, but in this day and age, you need to have better security practices if you are hosting users' data. It is the website's responsibility. I think the best thing we can do is to have a proper security hygiene. Secure your internet presence, with password manager (can't recommend Bitwarden enough) and 2FA authenticators. As for FISO, though none is selling the user data here, but we gotta have better security practices. I would have thought at least admins would have 2FA enabled. Maybe we need a self reflection at FISO?

User avatar
Stena Bib
FISOhead
Posts: 749
Joined: 19 Aug 2013, 17:44
FS Record: Finished 530 FPL 2018/19

Re: Hacked

Post by Stena Bib »

baganboy wrote: 05 Oct 2021, 16:35 How is this okay?
001001.JPG

How the hell is this okay?
Why were we negotiating with terrorists? Why us? Why FISO? Who have we bothered?

We haven't bothered anyone. How can someone walk into our home, disturb our peace, and ask us to squeal so that someone else hears it?
OK BB i have not seen all of this.

But unfortunately its become the way of the world . its become "EVIL" that's the only word i can use to describe it. :shock: :shock: :shock:

User avatar
Beerfuelledman
FISO Knight
Posts: 13220
Joined: 13 Oct 2005, 18:26
Location: In Norn Iron
FS Record: FISO 17/18 FPL Cash Draft League Winner

Re: Hacked

Post by Beerfuelledman »

Redsnout wrote: 05 Oct 2021, 18:01 Secure your internet presence, with password manager (can't recommend Bitwarden enough) and 2FA authenticators.
Hi mate could you outline (briefly) how these work? Iv'e downloaded Bitwarden but step one is creating a password. I assume, since this will protect my other passwords that it should be very secure)(Ill need to write that down somewhere safe). How then does it move to protecting other passwords?

Sorry - noob.

User avatar
baganboy
Comfortably Dumb(ledore)
Posts: 5874
Joined: 05 Aug 2008, 06:59
FS Record: 2011/12 - 212. 2019/20 - 222.
Altogether 6 top 10Ks. 8 top 20Ks. 9 top 50Ks.

Re: Hacked

Post by baganboy »

Redsnout wrote: 05 Oct 2021, 18:01
Hey BB :) This is not okay. And it feels shitty to get your personal info to get exposed, or like someone invading into your house. I know the feeling, my daily job is in cyber security :lol: It is easy to direct your anger towards the hackers now, but in this day and age, you need to have better security practices if you are hosting users' data. It is the website's responsibility. I think the best thing we can do is to have a proper security hygiene. Secure your internet presence, with password manager (can't recommend Bitwarden enough) and 2FA authenticators. As for FISO, though none is selling the user data here, but we gotta have better security practices. I would have thought at least admins would have 2FA enabled. Maybe we need a self reflection at FISO?
Agree with everything you say, Redsnout.
I just hate the impunity with which these EVIL (you are right, Stena Bib, no other word fits) folks decided to walk in and do what they wanted. FISO is my home at FPL, and post facto, I feel like my personal space has been stepped into.
In the day and age, better security practices have to be the norm. You might not 100% win against the hackers, but you stand a better chance standing behind an army, than do a Jon Snow at the Battle of the bustards.
I was saying this to a friend at FISO - Hub is a bunch of fools. Seriously, how can one think of starting an online business while not understanding the basics cybersecurity (or simply getting someone in to advise who does). I don't doubt the Hub folks' integrity - or that they are nice folks, (Saw Will's short video, he was distraught) but they are absolutely too naive to be in business. That's like starting a bank on an open field, and keeping the money under a brick or something.
Last edited by baganboy on 05 Oct 2021, 18:24, edited 1 time in total.

User avatar
eastcentral1
Dumbledore
Posts: 7977
Joined: 30 Jul 2007, 16:38

Re: Hacked

Post by eastcentral1 »

ajcairns wrote:
baganboy wrote: 05 Oct 2021, 17:02 I understand. I was reading through this for the last couple hours.

How is it okay that one of the FISO mods was hacked by this (minor) terrorist organization? How is it okay that others' posts were tampered with? How is it okay that other posters (old timers such as yourself blah) were thrown out? How is it okay that for a few hours, they could eff order us to do what they wanted?
How is any of this okay?

Who have we bothered? what is anyone's botheration with us? why use and abuse us (because we are small and insignificant in the overall $c#m cesspit that is eff FPL community) in their whatever idealist war? Why eff us?

How is this okay?
Still think it's a FISO account holder involved somehow - they just didn't come here on the off chance looking to hijack a mods account to get a message out. They were already here. A quick cross check of the members list on FISO (at the bottom of the page) you can soon see the common names with the leaked lists and BFMs probably stuck out being in green as a Mod.

Considering what has happened across the community there is not much discussion about it. Why? Probably because everyone is shittin themselves that will be targeted.
Like I said above, you can easily find fiso by googling the username beerfuelledman. We can't assume the hacker has any connection to fiso.

User avatar
blahblah
FISO Viscount
Posts: 108835
Joined: 13 Oct 2005, 18:46
Location: .. he thinks that he knows something which he doesn't, whereas I am quite concious of my ignorance.

Re: Hacked

Post by blahblah »

Not to mention Private Leagues.....

User avatar
forestfan
FISO Jedi Knight
Posts: 36694
Joined: 13 Oct 2005, 18:27
Location: Between Westeros and Nova Scotia
FS Record: FISODAS Champion Season 34!

Re: Hacked

Post by forestfan »

baganboy wrote: 05 Oct 2021, 18:17 You might not 100% win against the hackers, but you stand a better chance standing behind an army, than do a Jon Snow at the Battle of the bustards.
(Spoiler alert) Worked out OK for him, didn’t it? Helps when you have some reinforcements riding to the rescue in Fergie time though :wink:

User avatar
baganboy
Comfortably Dumb(ledore)
Posts: 5874
Joined: 05 Aug 2008, 06:59
FS Record: 2011/12 - 212. 2019/20 - 222.
Altogether 6 top 10Ks. 8 top 20Ks. 9 top 50Ks.

Re: Hacked

Post by baganboy »

Haha true... I was just thinking that when writing this. But well, the hero can't die in the season before last, not even in GOT. :D :D

User avatar
forestfan
FISO Jedi Knight
Posts: 36694
Joined: 13 Oct 2005, 18:27
Location: Between Westeros and Nova Scotia
FS Record: FISODAS Champion Season 34!

Re: Hacked

Post by forestfan »

baganboy wrote: 05 Oct 2021, 18:35 Haha true... I was just thinking that when writing this. But well, the hero can't die in the season before last, not even in GOT. :D :D
Not after the writers had already played one particular card a series or so before, at least :wink:

Anyway, helps not to know nothing…
Last edited by forestfan on 05 Oct 2021, 18:43, edited 1 time in total.

User avatar
Beerfuelledman
FISO Knight
Posts: 13220
Joined: 13 Oct 2005, 18:26
Location: In Norn Iron
FS Record: FISO 17/18 FPL Cash Draft League Winner

Re: Hacked

Post by Beerfuelledman »

Beerfuelledman wrote: 05 Oct 2021, 18:14
Redsnout wrote: 05 Oct 2021, 18:01 Secure your internet presence, with password manager (can't recommend Bitwarden enough) and 2FA authenticators.
Hi mate could you outline (briefly) how these work? Iv'e downloaded Bitwarden but step one is creating a password. I assume, since this will protect my other passwords that it should be very secure)(Ill need to write that down somewhere safe). How then does it move to protecting other passwords?

Sorry - noob.
Also - how does it work say if I need to sign into my Playstation account on my playstation - do I need Bitwarden on my playstation to sign in? Do I need Bitwarden on everydevice I want to use? Say Im on Holiday in Greece and want to sign in to something in an internet cafe - Can I do this if I dont know my password because its BitWarden generated?

User avatar
Vid
Head Moderator
Posts: 21756
Joined: 13 Oct 2005, 18:33
FS Record: winning is a distant memory

Re: Hacked

Post by Vid »

admin wrote: 05 Oct 2021, 17:55
I've attached the record of the bans undertaken by BFM whilst asleep to show who was banned. The IP address is for a proxy server based in Venezuela.
Looking at the logs a number of different IPs were used during the assault, one of the earliest being from a much reported (over 4k instances) IP in the US, likely the original hacker's IP, surprised the US authorities have done nothing given the number of reports :roll:

User avatar
Redsnout
Treebeard
Posts: 253
Joined: 06 Aug 2015, 18:39
FS Record: 676 - FPL (2016-17)

Re: Hacked

Post by Redsnout »

Beerfuelledman wrote: 05 Oct 2021, 18:14
Redsnout wrote: 05 Oct 2021, 18:01 Secure your internet presence, with password manager (can't recommend Bitwarden enough) and 2FA authenticators.
Hi mate could you outline (briefly) how these work? Iv'e downloaded Bitwarden but step one is creating a password. I assume, since this will protect my other passwords that it should be very secure)(Ill need to write that down somewhere safe). How then does it move to protecting other passwords?

Sorry - noob.
No worries mate. I was once.

One of the reasons i recommended Bitwarden over other password manager is, they are open source. I like they have the code transparency and anyone can audit. If I'm going to trust anyone with all my passwords, I wanna make sure there is no backdoor installed. Not that other password managers aren't reliable, i just trust open source more.

As for the Bitwarden password. Yes, you have to remember one password. I would recommend a passphrase. for eg: "MyFirstCarWas2005HondaAccord". Or some random 4 words you can remember. or if that is too long to type, start with something like: "I Would Like To Go See Manchester United Game 2021", :wink: use your password as "IwltgsMUg2021". and maybe add a symbol somewhere. Longer passphrases seem to be harder to crack than complex password though, so i would use a passphrase. If you have it your phone, touch id or face id to login afterwards.

So a passphrase is a first step. Second is, enable 2FA for Bitwarden login (https://bitwarden.com/help/article/setu ... tep-login/). You can generate an authenticator code using a generator like 'Authy' or Google Authenticator. If you install this in your phone, you can use your touch id or phase ID to login later, instead of typing passwords each time. At least this way, you are not trusting all your passwords with one company. Hackers would have to hack both your Authy and Bitwarden to access your passwords. All we can do is put guardrails.

User avatar
Redsnout
Treebeard
Posts: 253
Joined: 06 Aug 2015, 18:39
FS Record: 676 - FPL (2016-17)

Re: Hacked

Post by Redsnout »

Beerfuelledman wrote: 05 Oct 2021, 18:42
Beerfuelledman wrote: 05 Oct 2021, 18:14
Redsnout wrote: 05 Oct 2021, 18:01 Secure your internet presence, with password manager (can't recommend Bitwarden enough) and 2FA authenticators.
Hi mate could you outline (briefly) how these work? Iv'e downloaded Bitwarden but step one is creating a password. I assume, since this will protect my other passwords that it should be very secure)(Ill need to write that down somewhere safe). How then does it move to protecting other passwords?

Sorry - noob.
Also - how does it work say if I need to sign into my Playstation account on my playstation - do I need Bitwarden on my playstation to sign in? Do I need Bitwarden on everydevice I want to use? Say Im on Holiday in Greece and want to sign in to something in an internet cafe - Can I do this if I dont know my password because its BitWarden generated?
Most of the Password Mangers have their browser extension and Mobile app versions available, Bitwarden too. I recommend installing both in browser and your phone. It helps to autofill when you visit a website. If you are in a cafe in Greece, you can log into your browser and you would have your all extensions available. or type the password manually checking your phone. If it is a smart device like your playstation or a tv, I'm afraid you would have to type it manually by checking your phone app. Unless the smart devices have Bitwarden app in their appstore.
But yeah, it is inconvenient. Some times you would have to type things manually by checking your phone or PC. I guess that is the price you have to pay for better security.

User avatar
Stevieste
Dumbledore
Posts: 9599
Joined: 19 Aug 2017, 10:28
FS Record: 24,360

Re: Hacked

Post by Stevieste »

blahblah wrote: 05 Oct 2021, 16:24
Stena Bib wrote: 05 Oct 2021, 16:21
baganboy wrote: 05 Oct 2021, 16:08 The more I think about it, the more livid I get.
Real-life: A terrorist organization decide that they have a beef with a major country. This feels like them occupying a tiny country who has not bothered anyone, punishing and torturing the residents - and asking them to cry loudly, so the big country can hear it. Bloody eff disgusting.

Hate is a word i use with discretion, but that's the only feeling I have at the moment, honestly.
Chill out BB its not like Blah has been taken hostage or anything !! :roll:
I was Permanently Banned though 🤷‍♂️🤷‍♂️🤷‍♂️🤷‍♂️
No you was not and that’s my biggest gripe from last night fiasco 😂😂😂

User avatar
blahblah
FISO Viscount
Posts: 108835
Joined: 13 Oct 2005, 18:46
Location: .. he thinks that he knows something which he doesn't, whereas I am quite concious of my ignorance.

Re: Hacked

Post by blahblah »

Stevieste wrote: 05 Oct 2021, 19:11
blahblah wrote: 05 Oct 2021, 16:24
Stena Bib wrote: 05 Oct 2021, 16:21
baganboy wrote: 05 Oct 2021, 16:08 The more I think about it, the more livid I get.
Real-life: A terrorist organization decide that they have a beef with a major country. This feels like them occupying a tiny country who has not bothered anyone, punishing and torturing the residents - and asking them to cry loudly, so the big country can hear it. Bloody eff disgusting.

Hate is a word i use with discretion, but that's the only feeling I have at the moment, honestly.
Chill out BB its not like Blah has been taken hostage or anything !! :roll:
I was Permanently Banned though 🤷‍♂️🤷‍♂️🤷‍♂️🤷‍♂️
No you was not and that’s my biggest gripe from last night fiasco 😂😂😂
🤣😂🤣😂

User avatar
Redsnout
Treebeard
Posts: 253
Joined: 06 Aug 2015, 18:39
FS Record: 676 - FPL (2016-17)

Re: Hacked

Post by Redsnout »

blahblah wrote: 05 Oct 2021, 19:13
Stevieste wrote: 05 Oct 2021, 19:11
blahblah wrote: 05 Oct 2021, 16:24
Stena Bib wrote: 05 Oct 2021, 16:21
baganboy wrote: 05 Oct 2021, 16:08 The more I think about it, the more livid I get.
Real-life: A terrorist organization decide that they have a beef with a major country. This feels like them occupying a tiny country who has not bothered anyone, punishing and torturing the residents - and asking them to cry loudly, so the big country can hear it. Bloody eff disgusting.

Hate is a word i use with discretion, but that's the only feeling I have at the moment, honestly.
Chill out BB its not like Blah has been taken hostage or anything !! :roll:
I was Permanently Banned though 🤷‍♂️🤷‍♂️🤷‍♂️🤷‍♂️
No you was not and that’s my biggest gripe from last night fiasco 😂😂😂
🤣😂🤣😂
The fact that Blah was banned gives more weight to the theory that hacker is a FISO member :lol:

User avatar
Malrom
FISO Knight
Posts: 16524
Joined: 13 Oct 2005, 18:43
Location: Feet in Switzerland, Football heart in Leeds
Contact:

Re: Hacked

Post by Malrom »

I'm back .. at least right now.... I'm not even a mod....

Thank you, Sam and Spencer4 and whoever helped to clear that mess! 8-) :!:
Last edited by Malrom on 05 Oct 2021, 19:24, edited 1 time in total.

View Latest: 1 Day View Your posts
Post Reply

Return to “FISO Forum News”