📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

IMPORTANT! Have you received an email to your forum username?

1161719212295

Comments

  • Violetta_2
    Violetta_2 Posts: 3,588 Forumite
    I got 1 timestamped 7.17 am
    Booo!!!
  • I have recieved one just now, havent opened it though thankfully!!
    ***MSE...My.Special.Escape***
  • Mine was addressed to Frantic Female
    Wow, I got 3 *, when did that happen :j:T:p
    It is not illegal to open another persons mail unless you intend to commit fraud - this is frequently incorrectly posted:)
    I live in my head - I find it's safer there:p
  • davester
    davester Posts: 4,079 Forumite
    Part of the Furniture Combo Breaker
    I haven't got it ,I last recieved Martin's ,money tips at 12.16am this morning but that does not have the text shown. I checked spam its not there either. My forum name is not the same as the email address
    Survey earnings total 2009 £417, 2010 £875, 2011 £574
  • mr_fishbulb
    mr_fishbulb Posts: 5,224 Forumite
    Part of the Furniture Combo Breaker
    PhylPho wrote: »
    What's weird about the current mass posting of emails to MSE members is that the message text deliberately brings the almost-but-not-quite similarly named Moneyexpert.com into this by quoting every word of that website's 'About Us' page.
    It's a targeted attack to build up trust with the recipient of the email so they are more likely to open the malicious file.
    PhylPho wrote: »
    It's probably going to take a while to figure out if a vulnerability has been exploited in vBulletin or if the problem lies closer to MSE itself. But the fact that only MSE user names and their registered email addresses have been harvested shows that those responsible for today's continuing activity have *not* been able to penetrate any further than online IDs (as distinct from matching 'em to real-world identities.)
    That's just an assumption though. Even if the emails didn't contain peoples' real names, the email addresses were still obtained. This means potentially all of the user database was obtained, including date of birth, ICQ/AIM/MSN/Yahoo!/Skype IDs, website (if these were completed), plus a copy of the user's password (hopefully this was strongly hashed).
  • John_Gray
    John_Gray Posts: 5,844 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    edited 17 November 2010 at 5:56PM
    My longstanding (and unique) MSE email address ceased to exist on 5th November with the demise of the email forwarding service Emailias.com.

    I set up a replacement unique email address about five days later, and I haven't received any spam on that. (Yet?!)
  • Does anybody know, when the Usernames & Email addresses were "harvested" last year (I take it they mean stolen), were Passwords stolen too?

    I can't be the only (stupid) person who uses similar passwords on MSE and on other websites.

    I've changed a few of them already in the light of this breach :o

    Hi Tigsteroonie,

    We have no way of knowing definitively what they did or did not take and I can't go into the details of the system behind it but vBulletin double encrypts passwords. For someone to take the passwords and decrypt them would take quite a bit of effort.

    I would always recommend against using the same/similar passwords on multiple sites.


    Webby
  • NualaBuala
    NualaBuala Posts: 2,507 Forumite
    ive not had one ! but sadly the penis people seem to have targeted me too today . . . . .
    Me too ... (although I did get this spam one too).

    I think MSE should have emailed us about this and any other security breaches. It's not enough to assume we will see a thread about it. I was not aware that details had been harvested.
    Trying to spend less time on MSE so I can get more done ... it's not going great so far! :)
    Sorry if I don't reply to posts - I'm having MAJOR trouble keeping up these days!

    Frugal Living Challenge 2011

    Sealed Pot #671 :A DFW Nerd #1185
  • A._Badger
    A._Badger Posts: 5,881 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    Add me to the list. My user name is unique to this place and bears no relation to my e-mail address. The only way of connecting them is from information held my MSE.

    Looks like a hack.
  • Amilucky? wrote: »
    I wonder how many people that have received the emails have used the same username on various social networking sites and also may have openly shared social networking information on MSE and in doing so have tied there MSE user-name to there social networking accounts

    I definitely don't do any of those things and still got an email.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.3K Banking & Borrowing
  • 253.2K Reduce Debt & Boost Income
  • 453.8K Spending & Discounts
  • 244.3K Work, Benefits & Business
  • 599.5K Mortgages, Homes & Bills
  • 177.1K Life & Family
  • 257.8K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.