Menu

Has this project been hacked?

Luke
2021-02-17
2021-03-09
  • Luke

    Luke - 2021-02-17

    Has Dream project/site been taken over?
    On the site linked from the sourceforge page I see a wiki with a line of foreign characters, a spammy link, and a bunch of spam in the recent changes:
    https://drm.sourceforge.io/wiki/index.php/Special:RecentChanges

    Do you know if this whole project has been compromised or perhaps just the hosted website?
    Have any maintainers been reviewing the code recently?

     
  • Mark J. Fine

    Mark J. Fine - 2021-02-18

    Edit: Originally thought you meant this area, not the wiki site.

    Wow... looks like the wiki was either hacked or their indexing got messed up.

    Edit 2: No, it's been definitely hacked (last edit was yesterday at 0921) by rotating web spammers. 13 edits by 10 authors in the last 91 days.

     

    Last edit: Mark J. Fine 2021-02-18
  • mahaju

    mahaju - 2021-03-09

    Looks like this is not fixed yet. Is there a way to report this? Does that wiki belong to sourceforge as well? Is this just the problem of the particular wiki, or should we be worried about our sourceforge accounts?

     

    Last edit: mahaju 2021-03-09
  • Mark J. Fine

    Mark J. Fine - 2021-03-09

    Don't think we should worry about your account, but you could change your password if you feel it may have been compromised.

    I certainly hope the Dream Team is ok.

    Edit: I'd suggest setting up 2FA if you haven't already (I hadn't) but it appears SF's 2FA set up has been broken a while. You scan the QRC into Google Authenticator, enter the 6-digit code, and it crashes. It's no wonder people are moving to Github...

     

    Last edit: Mark J. Fine 2021-03-09

Log in to post a comment.