Project Management

Please login or join to subscribe to this thread

Were we hacked this November 25th?

linkedin twitter facebook  
avatar
Ivan Sergio De Sousa Jr Senior Program Manager| Klopotek Katy, Tx, United States
The discussion board is filled with junk with what seems to be from various sources (Rackspace, Yahoo, Aol, etc).
I'm not sure if there was an upload to the database that went terribly wrong or what, but the whole discussion board is messed up now.
Do you guys (from PM.com) need help in sorting this out? Please let us know. I'm sure in our community we have plenty of good people willing to help in cleaning things out and putting in place mechanisms to prevent this from happening again in the future.
Sort By:
< 1 2 >
avatar
Eric Simms Senior Program Manager Baltimore, Maryland, United States
I agree that some members here should have the ability to clean out junk posts.
I imagine if we were hacked we would suffered far worse than nonsense posts. The posts are complete garbage; I couldn't imagine a hacker wasting their time on something an Admin could delete with a keystroke.
avatar
Stéphane Parent Self Employed / Semi-retired| Leader Maker Prince Edward Island, Canada
It's been getting progressively worse over the last few months. I suspect someone, or some group, is working itself up to something nasty. I think this is still just testing the waters.

I also suspect administrators are off on weekends, which makes the attempts more visible to us.
...
2 replies by Drake Settsu and Markus Kopko
Nov 27, 2017 2:49 AM
Markus Kopko
...
You are so right, Stephane.

I do not know how PMI/projectmanagement.com is managing this site/board, but they could have seen this coming since weeks.

Lately, we got more and more fake registrations, and it seems that nothing was done to avoid and solve this.

I am running a website on my own (yes it is tiny and not comparable to this one here, but that makes it even more worth) and the first thing you do if you run a new website is taking measures to make the site secure and avoid spam and fake registrations.
On my WordPress site, there are plugins to do so, and it should be a straightforward thing for PMI/pm.com to do so on this site.

Now the discussion board is flooded by nonsense postings and who knows what is coming next?

And a critical question comes up now:

Are our data secure?

And no statement/posting from site owners anywhere ...

Well, I do love this site and community for years now, but what happens for a couple of weeks now is very disappointing.

The least thing what can be done is some straightforward measures like described by Kiron.

We will see what happens next ...

Regards,

Markus
Nov 27, 2017 7:53 AM
Drake Settsu
...
I agree Stephane. They could be looking for a way to crash the website by flooding it with nonsense posts and fake users. They are testing what they can get away with when no Admin is monitoring the website. That was just a sample of what they can get away with.
avatar
Kevin Coleman Subject Matter Expert, Author, Speaker and Strategic Advisor| - Insights Pa, United States
Lately we have seen individual accounts taken over and NASTY comments posted under the account holder's ID - that is becoming VERY COMMON
...
1 reply by Eric Simms
Nov 27, 2017 9:18 AM
Eric Simms
...
I wasn't aware of that; I only saw the nonsense posts on the 25th. If accounts are being compromised we're facing a serious problem.
avatar
Najam Mumtaz Retired Lahore, Punjab, Pakistan
it definitely is getting worse and projectmanagement.com team needs to work it out before it causes further damage
avatar
Kiron Bondale Retired | Mentor| Retired Welland, Ontario, Canada
A simple site enhancement would be to enable members to select multiple discussion threads and report them. Coupling that with the LinkedIn discussion group approach of hiding threads which have been flagged for review would help reduce the impacts of this.

Kiron
avatar
Najam Mumtaz Retired Lahore, Punjab, Pakistan
I guess it was not Nov 25th only, it continues
avatar
Ivan Sergio De Sousa Jr Senior Program Manager| Klopotek Katy, Tx, United States
I guess everything is solved now, but I haven’t seen an announcement on what it was and if we should worry that our credentials were compromised or not. Did I miss something?!?
avatar
Markus Kopko AI Enabler for Project & Program Mgmt | Founder PMotion.ai / The PM AI Coach| PMotion.ai Hamburg, Hamburg, Germany
Nov 25, 2017 3:39 PM
Replying to Stéphane Parent
...
It's been getting progressively worse over the last few months. I suspect someone, or some group, is working itself up to something nasty. I think this is still just testing the waters.

I also suspect administrators are off on weekends, which makes the attempts more visible to us.
You are so right, Stephane.

I do not know how PMI/projectmanagement.com is managing this site/board, but they could have seen this coming since weeks.

Lately, we got more and more fake registrations, and it seems that nothing was done to avoid and solve this.

I am running a website on my own (yes it is tiny and not comparable to this one here, but that makes it even more worth) and the first thing you do if you run a new website is taking measures to make the site secure and avoid spam and fake registrations.
On my WordPress site, there are plugins to do so, and it should be a straightforward thing for PMI/pm.com to do so on this site.

Now the discussion board is flooded by nonsense postings and who knows what is coming next?

And a critical question comes up now:

Are our data secure?

And no statement/posting from site owners anywhere ...

Well, I do love this site and community for years now, but what happens for a couple of weeks now is very disappointing.

The least thing what can be done is some straightforward measures like described by Kiron.

We will see what happens next ...

Regards,

Markus
avatar
Khawaja Saif ur Rehman Project Management Trainer & Consultant Lahore, Pakistan
For now, I think we should use "Send Feedback"; bottom right of the website; to report the incident and ask if our data is secure. I don't think the developers will be reading our discussion.

I have shared the link of this discussion thread in "Send Feedback" and have inquired about data security.
...
1 reply by Ken Bradshaw
Nov 28, 2017 1:35 PM
Ken Bradshaw
...
If you want to report an individual account, there are three dots next to Send a Message, with a selection for "Start a PMWar" and "Report This Person". If you select "Report This Person", there is a popup with selections for various reasons, including Spam.
avatar
Ivan Sergio De Sousa Jr Senior Program Manager| Klopotek Katy, Tx, United States
This was a good move Khawaja.
< 1 2 >

Please login or join to reply

Content ID:
ADVERTISEMENTS

The only people who find what they are looking for in life are the fault finders.

- Foster's Law

ADVERTISEMENT

Sponsors