|
|
---|---|
-LOCKED - Recent Maintenance | |
Posted on 2023-03-17 10:48:40
Apologies for the recent maintenance we have had to issue, but unfortunately we noticed some suspicious activity from our admin's account, Katze. On investigation, we deduced that her account had been compromised, and we immediately put the site into maintenance mode while we explored further. We believe only Katze's account and one moderator account was affected. This was caused by someone managing to pass a script into a modbox ticket which, when viewed, would send data to this script, including session data, enabling the attacker to hijack the user's session. We have patched this vulnerability, as well as reviewed other areas of the site to ensure no other areas were affected. We have logs of everything that was viewed or attempted to be accessed. We had found that messages had been sent from Katze's account, those have been deleted, and there was nothing compromising in them so if you received one of these messages there's nothing to worry about. We have no reason to believe that anyone's personal data was affected or retrieved in any way. Additionally, Lioden does not store any payment information, as all payment processing is handled by Paypal. However, in spite of this, as a precaution we have forced a password change for all users on the site. It is best practice to make sure you use a unique password for each site you have a login on. This way, if another site you use suffers a data breach, and you don't use the same password on that site as you do on another, then your accounts on other websites remain safe. We recommend using a password manager to create and store unique passwords for every site and service you use. For now: we are bringing the site back up and things should continue as normal. Katze's account being affected means that a majority of news posts have been deleted and are currently in the process of being recovered. They should be restored soon. 1615 players like this post! Like? |
orbz (#353568)
King of the Jungle View Forum Posts Posted on 2023-03-17 11:06:14 |
Firew♥️lfie | PM me melon! (#422037) Sapphic View Forum Posts Posted on 2023-03-17 11:06:22 |
Mochi (#415160)
Notable Lion View Forum Posts Posted on 2023-03-17 11:07:04 |
Daddy Satan (He/it) (#390931)
Bone Collector View Forum Posts Posted on 2023-03-17 11:07:44 |
Icarus (#393626)
Sapphic View Forum Posts Posted on 2023-03-17 11:08:45 |
Susurrus (#118978)
Bone Collector View Forum Posts Posted on 2023-03-17 11:08:46 |
☀️Sunshine☀️ (#99540)
Dreamboat of Ladies View Forum Posts Posted on 2023-03-17 11:09:35 |
chicken (#278059)
View Forum Posts Posted on 2023-03-17 11:09:57 |
Weredragon (#382508)
Scourge of Lions View Forum Posts Posted on 2023-03-17 11:11:07 |
Chiffawndue (#104851)
Bone Collector View Forum Posts Posted on 2023-03-17 11:11:36 |
Marcellium 🌖 G1 Withered (#158899) Resurgent View Forum Posts Posted on 2023-03-17 11:11:48 |
Also Cas || G2 Wepwawet (#172371) Maneater View Forum Posts Posted on 2023-03-17 11:12:29 |
Kit in a Box ~⚙️~ (#61637) View Forum Posts Posted on 2023-03-17 11:12:48 |
Hope both Katze and the moderator are alright, I can only imagine how they feel right now. It's very upsetting that someone would do this, to Lioden of all things, but I'm glad it was taken care of quickly. Much love to all of Lioden's staff. ;o;/ ♥ 0 players like this post! Like? |
Wolvesofthenight (#101070)
Resurgent View Forum Posts Posted on 2023-03-17 11:13:12 |
How do I change my sides password I don't remember the current one. At all. (I have 3 or 4 I probably could have used but I log in on my main) I was 18 when I created it so a password manager wasn't in my thoughts. Admin Response: You can log out of your side account and reset your password through the front page. If you experience issues with resetting your password, contact support@lioden.com! 0 players like this post! Like? |
Thalath {Side} (#43831)
Holy View Forum Posts Posted on 2023-03-17 11:13:30 |
"Did the user who hacked get banned! Or caught?" Since it was from a Modbox ticket, the person that sent it was likely caught immediately, although there is a possibility it was a shell account created for the sole purpose of taking advantage of this exploit. Thankfully, as the staff has stated it's been patched so even if it was a shell, this perpetrator can't keep exploiting. 0 players like this post! Like? |