Glad to see BCUK back online

david1

Nomad
Mar 3, 2006
482
0
sussex
Thank you for visiting BuschraftUK

Sorry, we're currently performing essential site maintenance and will be back online shortly.

is what I get if I try to go to bushcraftuk.com
I got here by following a link off google all very strange
 

SJStuart

Settler
Jan 22, 2013
997
2
Suffolk Coast
Boy am I glad to see the forum is back online.

I really missed my evening fix :rolleyes:

Likewise! I was tracking a dozen or so threads, and I've had to clear the cache just to get the forum to load... otherwise I still get the maintenance page. Clearly the redirect isn't properly configured, and the maintenance.php page should have a no-cache setting!
 

Tony

White bear (Admin)
Admin
Apr 16, 2003
24,326
1
2,040
54
Wales
www.bushcraftuk.com
We had the site down because of an exploit that came to light recently, it was a precaution till we could ascertain the danger to Bushcraft UK, it turns out that we'd already instigated security measures that prevent the forums getting hacked but it was better to be cautious than sorry and have to go through all the hassle of sorting out the aftermath.

Thanks for your patience everyone
T
 

VANDEEN

Nomad
Sep 1, 2011
351
1
Newcastle Upon Tyne
As I understand it,
.
There was a zero day attack launched against some forums running V Bulletin software.
Inject0r ( a hacking group ) claimed The breach gave the hacker full access to "shell, database & root server" on the compromised forums. This included access to the hashed password & user name files. Alledgedly they were selling the hack for $7 online along with screenshots proving the vulnerability was real.
.
Tony took the forum offline until he was happy with the situation.
Ashley, has done the same to NB & still has an explanation page up.
.
As a precaution in such situations I prrsonally change my "low level passwords" which I use for forums etc. as they often match each other.
.
I know generally you shouldn't use the same password for different logins but as I class a compromise of my forum accounts as a low priority compared to say banking it's a risk I take.
.
V Bulletin aren't making the sort of noises I would like them to make to keep me happy, so my read on it is they were caught out, time will tell.


Cross post with Tony, must type faster....
 

John Fenna

Lifetime Member & Maker
Oct 7, 2006
23,306
3,089
67
Pembrokeshire
I still get the "maintenance" message if I try to log in normally ... and I cannot click on "new messages" without going back to that message....
 

Tony

White bear (Admin)
Admin
Apr 16, 2003
24,326
1
2,040
54
Wales
www.bushcraftuk.com
john, you'll need to clear your history/cache, it's a pain I know but the computer is remembering there's no access when in fact there is
 

slowworm

Full Member
May 8, 2008
2,174
1,108
Devon
john, you'll need to clear your history/cache, it's a pain I know but the computer is remembering there's no access when in fact there is

Is it worth adding that to the "Thank you for visiting BuschraftUK Sorry, we're currently performing essential site maintenance and will be back online shortly." message?
 

SJStuart

Settler
Jan 22, 2013
997
2
Suffolk Coast
john, you'll need to clear your history/cache, it's a pain I know but the computer is remembering there's no access when in fact there is

This is why you need to add the "no-cache" parameter to the site... since the content of a forum is changing all the time anyway, there's no real benefit to caching the pages. Then when you go to maintenance mode, the pages should return a HTTP 302 code so the browser knows it's just a temporary redirect.
That way, the moment you come out of maintenance mode, people can get back on the site without having to wipe their cache (which I'd hazard many in here don't know how to do)

Not a criticism or complaint, just a suggestion from a systems architect :)
 

Swallow

Native
May 27, 2011
1,552
4
London
As I understand it,
.
There was a zero day attack launched against some forums running V Bulletin software.
Inject0r ( a hacking group ) claimed The breach gave the hacker full access to "shell, database & root server" on the compromised forums. This included access to the hashed password & user name files. Alledgedly they were selling the hack for $7 online along with screenshots proving the vulnerability was real.
.
Tony took the forum offline until he was happy with the situation.
Ashley, has done the same to NB & still has an explanation page up.
.
As a precaution in such situations I prrsonally change my "low level passwords" which I use for forums etc. as they often match each other.
.
I know generally you shouldn't use the same password for different logins but as I class a compromise of my forum accounts as a low priority compared to say banking it's a risk I take.
.
V Bulletin aren't making the sort of noises I would like them to make to keep me happy, so my read on it is they were caught out, time will tell.


Cross post with Tony, must type faster....

And possibly check your PMs.

If you have been buying or selling anything on classifieds here then likely you have a PM history which details your name and address and possibly your paypal email address.

Some sellers also PM their Bank Account Details for BACs payments as well.
 

VANDEEN

Nomad
Sep 1, 2011
351
1
Newcastle Upon Tyne
And possibly check your PMs.

If you have been buying or selling anything on classifieds here then likely you have a PM history which details your name and address and possibly your paypal email address.

Some sellers also PM their Bank Account Details for BACs payments as well.

That's a very good point mate, my PM folder contains a couple of members bank details etc. from previous group buys/purchases, unfortunately it is their PM's that will contain my details so we all should maybe be a little prudent in clearing them out.

Web link to one of the many online articles starting to surface

http://www.theregister.co.uk/2013/11/18/vbulletin_hacked/
 
Last edited:

BCUK Shop

We have a a number of knives, T-Shirts and other items for sale.

SHOP HERE