denise: Image: Me, facing away from camera, on top of the Castel Sant'Angelo in Rome (Default)
Denise ([staff profile] denise) wrote in [site community profile] dw_maintenance2020-05-08 06:31 pm

(no subject)

In March, we posted several entries about an increase in people breaking into old accounts and using them for spam purposes.

Today has seen another wave of zombie accounts having their profile edited to link to spam and then subscribing to many people. If you see this happen, you don't need to report it to us: we're identifying them automatically and suspending them until their owners can resecure them. If your account is one of the ones suspended, please change your password and edit the profile to remove the spam link from the Website field, then open a support request in the Terms of Service category and we'll get back to you ASAP to unsuspend your account.

We continue to believe the source of the password information is another social media site that many Dreamwidth users also have accounts on. The site in question has declined to investigate the reports we've made to them or to investigate whether the information we've found is legitimate. We will continue not to publicly name them in top-level posts until we're positive we've done everything we can to protect Dreamwidth users who may also have accounts on the site in question, after which point we'll let you know what we know. We're trying to avoid doing that until we think we've caught the vast majority of vulnerable accounts, however.

If you have not changed your Dreamwidth password since May of 2014, we strongly recommend that you change your password. Again: We have no evidence that our servers were compromised, and we have strong evidence that the source of account breakins is another social media site's as-yet-undisclosed breach. However, today's wave of breakins has included a number of accounts that our available methods of figuring out who may be vulnerable didn't catch, so we may need to look more widely for potentially vulnerable accounts.

To verify any email from us about your Dreamwidth password is actually from us, log into your Dreamwidth account and visit the homepage or the [site community profile] dw_news journal. Every email we send you about your account password from here on out will repeat these instructions.
frith: Yellow & pink cartoon pony with her hoof over her mouth (FIM Fluttershy full body)

[personal profile] frith 2020-05-08 11:03 pm (UTC)(link)
Oh those spammers! Keep up the good work rooting them out!

[personal profile] jtthomas 2020-05-08 11:05 pm (UTC)(link)
Hey, seems these are different- one of the ones I got was empty entirely. (like, zero posts, hadn't followed anyone ever before today, unless it was wiped in the process of takeover.)
Edited 2020-05-08 23:09 (UTC)
peoriapeoriawhereart: line art Ecto-1 (Ecto-1)

[personal profile] peoriapeoriawhereart 2020-05-08 11:12 pm (UTC)(link)
That seems to be what often happens.
peoriapeoriawhereart: ao3 symbol with added conical party hat (party hat ao3)

[personal profile] peoriapeoriawhereart 2020-05-08 11:15 pm (UTC)(link)
Thanks so much for keeping us in the loop, being on top of these things and being All the Bag of Chips.
havocthecat: the lady of shalott (Default)

[personal profile] havocthecat 2020-05-08 11:29 pm (UTC)(link)
I did wonder if I had been followed by another spammer, but hoped not. Should be interesting. Good luck at rooting them all out!
ayebydan: (sw: rey stern)

[personal profile] ayebydan 2020-05-08 11:32 pm (UTC)(link)
thank you!
juniperberry: AD/HD (Default)

[personal profile] juniperberry 2020-05-08 11:38 pm (UTC)(link)
I had wondered why someone would follow me, after their DW hadn't been touched since 2013...
muccamukk: Jupiter looking down skeptically as Caine hovers 10cm above the floor. (JA: Grav Boots?)

[personal profile] muccamukk 2020-05-08 11:55 pm (UTC)(link)
I got followed one that hasn't been suspended yet. Should I report to you? Or just wait for you to catch it?
myrmidon: (Default)

[personal profile] myrmidon 2020-05-09 01:02 am (UTC)(link)
Hey so I tried using updated lj juggler on my pc to log in and it didnt do it. Fine, it hiccups sometimes. Tried logging in manually with the correct password and was IP blocked after a single attempt to log in.

Is there a reason this might have happened? (I had to use mobile to post this, which I hate doing, and the same password logged in just fine?)
kareila: Taking refuge from falling debris under a computer desk. (computercrash)

[personal profile] kareila 2020-05-09 01:23 am (UTC)(link)
The IP blocks don't last for long, they're just to prevent brute force password guessing attempts.

Have you updated your LJ Juggler to use an API key instead of your password? The steps described here for Semagic should also work for LJ Juggler: https://dw-dev.dreamwidth.org/221358.html

(no subject)

[personal profile] myrmidon - 2020-05-09 01:29 (UTC) - Expand

(no subject)

[personal profile] myrmidon - 2020-05-09 02:32 (UTC) - Expand
knewaguy: (Default)

[personal profile] knewaguy 2020-05-09 03:03 am (UTC)(link)
Are suspended accounts emailed to notify them? Just curious how best to go through old accounts that I might've forgotten about to ensure they're secured and that nothing's happened to them.
kore: (Default)

[personal profile] kore 2020-05-09 05:37 am (UTC)(link)
So you guys are actually fighting zombies!
moonhare: (thumper)

[personal profile] moonhare 2020-05-09 09:51 am (UTC)(link)
I’m always suspicious when someone new follows my quiet little account. I looked at the profile for last night’s arrival and saw they had been here since 2014 and had never even put up one post or comment. Thanks for removing them!
madfilkentist: My cat Florestan (gray shorthair) (Default)

[personal profile] madfilkentist 2020-05-09 10:23 am (UTC)(link)
"Another social media site that many Dreamwidth users also have accounts on." Best euphemism of the day! :)

Seriously, though, I'm glad you're staying ahead of the spammers.
damerell: NetHack. (normal)

[personal profile] damerell 2020-05-11 11:28 am (UTC)(link)
I'll be Frank, I think you may know who they mean, if they're not just trying to get our goat. ;-)

(no subject)

[personal profile] silkensteel - 2020-05-13 03:47 (UTC) - Expand
calliopes_pen: (sheliak Alphonse art 2)

[personal profile] calliopes_pen 2020-05-09 12:58 pm (UTC)(link)
Thank you for everything you've done when it comes to this situation!
runpunkrun: Pride flag based on Gilbert Baker's 1978 rainbow flag with hot pink, red, orange, yellow, sage, turquoise, blue, and purple stripes. (Default)

[personal profile] runpunkrun 2020-05-09 07:08 pm (UTC)(link)
Thanks for keeping us updated!
ruuger: My hand with the nails painted red and black resting on the keyboard of my laptop (Default)

[personal profile] ruuger 2020-05-09 11:04 pm (UTC)(link)
Is this perhaps a social media site with a mascot that is of caprine persuasion? Because I just got a email from them prompting me to change the password for an old account that I had forgotten about.
azurelunatic: LiveJournal: I yell because I care.  (yelling about LJ)

[personal profile] azurelunatic 2020-05-09 11:11 pm (UTC)(link)
>_>
<_< I couldn't *possibly* confirm that.
Edited (Oh, html. ) 2020-05-09 23:12 (UTC)

(no subject)

[personal profile] spodlife - 2020-05-10 09:47 (UTC) - Expand

(no subject)

[personal profile] squirrelitude - 2020-05-11 01:34 (UTC) - Expand

(no subject)

[personal profile] squirrelitude - 2020-05-11 20:37 (UTC) - Expand

(no subject)

[personal profile] squirrelitude - 2020-05-12 01:08 (UTC) - Expand
killerweasel: (homerscreaming by peacefully)

[personal profile] killerweasel 2020-05-10 07:46 pm (UTC)(link)
This has nothing to do with what's in the post, but I crosspost from here to my livejournal and the last couple of days, it hasn't been doing it, even if I have it set to default. I go back to edit the entry here and the boxes are unchecked? Maybe it's just me. :-/

(no subject)

[personal profile] yourlibrarian - 2020-05-14 14:47 (UTC) - Expand

(no subject)

[personal profile] yourlibrarian - 2020-05-15 22:17 (UTC) - Expand

(no subject)

[personal profile] hrrunka - 2020-05-16 08:43 (UTC) - Expand

(no subject)

[personal profile] pritkiy_kaban - 2020-05-18 12:14 (UTC) - Expand

(no subject)

[personal profile] hrrunka - 2020-05-18 13:06 (UTC) - Expand
jimmydragon: (gotta wear shades)

[personal profile] jimmydragon 2020-05-10 11:47 pm (UTC)(link)
Ah, they just got my main muse account. Just sent in a ticket and changed all my other passwords again. Thanks for keeping us posted.
jducoeur: (Default)

[personal profile] jducoeur 2020-05-11 05:48 pm (UTC)(link)
Hmm. This sounds suspiciously like my late wife's account, which was set up as a placeholder back in 2009. (She passed away about a year later, some time before I permanently transitioned here from LJ.) Nothing critical -- the account doesn't contain anything real -- but it would be a shame if it got grabbed by spammers. The password I have on file for it seems to be wrong, and trying to get a reset token isn't producing anything at our home domain, which leads me to suspect that she set it to point to our old Comcast address, or something else that I don't have access to.

Any recommendations of anything I should do? Is it worth opening a support request so y'all know that at this point it's basically just a memorial account?
silkensteel: (Default)

[personal profile] silkensteel 2020-05-13 03:49 am (UTC)(link)
Thank you for keeping up with this and being proactive!
spamsink: (Default)

[personal profile] spamsink 2020-05-14 05:11 pm (UTC)(link)
UTF8 in the inbox is broken since a few days ago. E.g.
New comment by [personal profile] username on subject in [personal profile] username. (filter to this entry)
Точно!


(no subject)

[personal profile] spamsink - 2020-05-16 05:01 (UTC) - Expand

(no subject)

[personal profile] pritkiy_kaban - 2020-05-18 12:08 (UTC) - Expand
graycardinal: Shadow on asphalt (Default)

A crossposting tip

[personal profile] graycardinal 2020-05-16 10:06 pm (UTC)(link)
I haven't seen this step mentioned specifically, but for those who are having trouble with crossposting entries directly from DW to LJ after changing passwords Over There: if you are *not* using a client, make sure you've updated DW's crossposting settings with your new LJ password(s). That may not solve all of the short-term IP blockages, but I'm pretty sure forgetting that step is what caused the one I triggered on one of my own journals.