Cruisers Forum
 


Reply
  This discussion is proudly sponsored by:
Please support our sponsors and let them know you heard about their products on Cruisers Forums. Advertise Here
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 30-08-2016, 04:32   #46
Registered User
 
transmitterdan's Avatar

Join Date: Oct 2011
Boat: Valiant 42
Posts: 6,008
Re: OpenCPN Homepage hacked

Quote:
Originally Posted by CarCode View Post
A troll is usually a person who floods a forum with thousands of postings with nonsense. You have wrote already 7,329 such postings.

Gerhard
Gerhard,

I think that's enough with the senseless insults. It adds nothing to the forum. No one here is trolling and you know it. If you don't wish to collaborate with a diverse group of people then don't.

I suggest alll you web developer experts could discuss the arcane subject of web site security practices in PM's as 99.9% of the forum members have no idea what you are talking about.
transmitterdan is offline   Reply With Quote
Old 30-08-2016, 04:35   #47
Registered User
 
rgleason's Avatar

Join Date: Mar 2012
Location: Boston, MA
Boat: 1981 Bristol 32 Sloop
Posts: 17,766
Images: 2
Re: OpenCPN Homepage hacked

reCaptcha works and is used by many, but maybe using a version Honey with Nu Captcha would be better if it could be done. Of course I know nothing about this stuff.

Quote:
Wikipedia: In Internet slang, a troll is a person who sows discord on the Internet by starting arguments or upsetting people, by posting inflammatory,
[1] extraneous, or off-topic messages in an online community (such as a newsgroup, forum, chat room, or blog) with the deliberate intent of provoking readers into an emotional response[2] or of otherwise disrupting normal on-topic discussion,
[3] often for their own amusement.
Good Morning Gerhard, my dear, sweet natured friend, you've morphed the term as usual. Your most recent post is definitely a troll. This is a small troll, so you can learn to identify therm.
Attached Images
 
rgleason is offline   Reply With Quote
Old 30-08-2016, 05:33   #48
Marine Service Provider

Join Date: May 2013
Location: Norway
Posts: 722
Re: OpenCPN Homepage hacked

Quote:
Originally Posted by rgleason View Post
reCaptcha works and is used by many, but maybe using a version Honey with Nu Captcha would be better if it could be done. Of course I know nothing about this stuff.



Good Morning Gerhard, my dear, sweet natured friend, you've morphed the term as usual. Your most recent post is definitely a troll. This is a small troll, so you can learn to identify therm.
:biggrin :
petter5 is offline   Reply With Quote
Old 30-08-2016, 09:43   #49
Marine Service Provider
 
bdbcat's Avatar

Join Date: Mar 2008
Posts: 7,503
Re: OpenCPN Homepage hacked

Folks...

Website Status:

1. Bogus "news" items cleaned out. Lost a couple of recent items in the process, due to strange Drupal database cross-linking.

2. Implemented stricter IP blocking for those IPs identified as injecting the spam so far. This will be an ongoing exercise until we upgrade Drupal.

3. Changed captcha to "art" style, instead of easily machine-solved block ASCII type. We need a newer Drupal installation to move to reCaptcha, which is our goal.

4. Temporarily disabled "news" item posting by anyone.

5. Started Drupal upgrade process. This will take a while to implement and validate.

So, the website is safe for anonymous and register users, as it has always been. It is also no longer ugly.

More as we progress.

Dave
bdbcat is offline   Reply With Quote
Old 30-08-2016, 12:59   #50
Registered User
 
rgleason's Avatar

Join Date: Mar 2012
Location: Boston, MA
Boat: 1981 Bristol 32 Sloop
Posts: 17,766
Images: 2
Re: OpenCPN Homepage hacked

Thank you BDBCAT!
You're Awesome! as the kids say.
rgleason is offline   Reply With Quote
Old 30-08-2016, 15:45   #51
Registered User

Join Date: May 2015
Location: Auckland, NZ
Boat: Bristol Channel Cutter
Posts: 126
Re: OpenCPN Homepage hacked

Quote:
Originally Posted by rgleason View Post
The website was scanned for security using these tools (if registration is not required).
........
I don't know if I should reprimand you for irresponsible disclosure or educate you.

That was just bad form. How would you like it if I posted the location of the hidden key to your house or boat? Please remove that post, or better yet can one of the moderators remove it?
Eben is offline   Reply With Quote
Old 30-08-2016, 16:24   #52
Registered User
 
rgleason's Avatar

Join Date: Mar 2012
Location: Boston, MA
Boat: 1981 Bristol 32 Sloop
Posts: 17,766
Images: 2
Re: OpenCPN Homepage hacked

Eben,

Come on, all I used was "opencpn.org" which is very public, just like the Driveway or the Front Door, or the Front steps. Evverybody uses the URL "opencpn.org" to get on the website. All I listed were the "results" from entering "opencpn.org". Anyone can do the same as what I did, anytime. Furthermore I have no "keys" pubilc, private or otherwise. So now, please do "educate" me, I am all ears.
rgleason is offline   Reply With Quote
Old 30-08-2016, 16:39   #53
Registered User

Join Date: May 2015
Location: Auckland, NZ
Boat: Bristol Channel Cutter
Posts: 126
Re: OpenCPN Homepage hacked

Quote:
Originally Posted by rgleason View Post
Eben,

Come on, all I used was "opencpn.org" which is very public, just like the Driveway or the Front Door, or the Front steps. Evverybody uses the URL "opencpn.org" to get on the website. All I listed were the "results" from entering "opencpn.org". Anyone can do the same as what I did, anytime. Furthermore I have no "keys" pubilc, private or otherwise. So now, please do "educate" me, I am all ears.
Start here: https://en.wikipedia.org/wiki/Responsible_disclosure
Eben is offline   Reply With Quote
Old 30-08-2016, 17:12   #54
Registered User
 
rgleason's Avatar

Join Date: Mar 2012
Location: Boston, MA
Boat: 1981 Bristol 32 Sloop
Posts: 17,766
Images: 2
Re: OpenCPN Homepage hacked

Very interesting, point, Eben. However I did not disclose some new unknown vulnerability here, I just used the front door mat (opencpn.org) and a little UFO Copter (the online programs) to see what was most vulnerable. These are all known vulnerabilities and some have been known for at least several years. I hadn't thought of doing this until now, although I have used similar scanners before.

Nevertheless, I have asked that the post be removed as you have asked, as it is prudent to do that. Hope you are happier about this now.

PS: This might be useful.
Netsparkere is free to Opensource
https://www.netsparker.com/blog/news...urce-projects/
FREE FOR OPENSOURCE
rgleason is offline   Reply With Quote
Old 30-08-2016, 17:50   #55
Registered User

Join Date: May 2015
Location: Auckland, NZ
Boat: Bristol Channel Cutter
Posts: 126
Re: OpenCPN Homepage hacked

Quote:
Originally Posted by rgleason View Post
Very interesting, point, Eben. However I did not disclose some new unknown vulnerability here, I just used the front door mat (opencpn.org) and a little UFO Copter (the online programs) to see what was most vulnerable. These are all known vulnerabilities and some have been known for at least several years. I hadn't thought of doing this until now, although I have used similar scanners before.

Nevertheless, I have asked that the post be removed as you have asked, as it is prudent to do that. Hope you are happier about this now.

PS: This might be useful.
Netsparkere is free to Opensource
https://www.netsparker.com/blog/news...urce-projects/
FREE FOR OPENSOURCE
Yes I am, one more person with awareness is always a good thing!
Eben is offline   Reply With Quote
Old 30-08-2016, 18:28   #56
Registered User
 
rgleason's Avatar

Join Date: Mar 2012
Location: Boston, MA
Boat: 1981 Bristol 32 Sloop
Posts: 17,766
Images: 2
Re: OpenCPN Homepage hacked

While looking over the website, I noticed that an entire page is missing that had AIS under Supplementary Hardware. I have tried to find this page but it seems to be missing. This was a good page, which had a good list of the primary AIS devices one might use, including a low cost AIS receiver called dAISy.
The page was http://opencpn.org/ocpn/Sup_Hardware_AIS
and http://opencpn.org/ocpn/node/176 (I believe).

There is now one AIS device list in a new page.
Titled "Cheap AIS Receiver" Cheap AIS receiver | Official OpenCPN Homepage
This was created 8/300/2010 by "AISsee" who has been a member for 4 days and has edit access to the User Documentation.

I believe this person is connected to Quark-Elec who offers the AIS device. I cannot confirm it. I also believe this user may have deleted the entire AIS page which I have been unable to retrieve. I cannot confirm this, but if it is true, this is a problem.

I have recreated a page for dAISy but it is not nearly as complete as we had Vesper XB-8000 and others.

Does anyone have a clue where the old page went? Or why?
rgleason is offline   Reply With Quote
Old 30-08-2016, 19:19   #57
Marine Service Provider
 
bdbcat's Avatar

Join Date: Mar 2008
Posts: 7,503
Re: OpenCPN Homepage hacked

Rick...

I don't know where the old page went. Probably lost, but I will investigate.

Meanwhile, user AISee is now banned from editing pages. And I respectfully show him the door.

Brings up the point that I have been thinking about lately. We currently let just about anyone self-register, and thus get full access to the Wiki. All they have to do is execute the somewhat annoying captcha.

This of course will occasionally lead to not-so-nice activities by some members.

The alternative, of course, is to have some sort of active moderation of user's activities, as is done on this forum, for instance.

Active moderation is, on the surface, a good idea. But it places a real burden on volunteer moderators. And we have had trouble recruiting persistent volunteer help for this sort of thing in the past.

And, let's be plain, every minute I personally spend administering the Website is a minute that I am not fixing bugs in O4 and writing new code for OpenCPN Version 5.

I solicit opinions.

Dave
bdbcat is offline   Reply With Quote
Old 30-08-2016, 19:28   #58
Marine Service Provider
 
bdbcat's Avatar

Join Date: Mar 2008
Posts: 7,503
Re: OpenCPN Homepage hacked

Rick...

I was a bit hasty, it seems.

The dAISy page is:
dAISy AIS Receiver | Official OpenCPN Homepage

I see no trouble with the Supplementary Hardware chapter.
Supplementary Hardware | Official OpenCPN Homepage

Am I missing something?

ASIee is re-instated.
mea culpa

But above comments still valid...
Dave
bdbcat is offline   Reply With Quote
Old 31-08-2016, 04:30   #59
Registered User

Join Date: Oct 2014
Posts: 274
Re: OpenCPN Homepage hacked

The download page for plugins that work with OpenCPN 4.2 and newer is missing from opencpn.org.

Paul
.Paul. is offline   Reply With Quote
Old 31-08-2016, 05:21   #60
Registered User
 
rgleason's Avatar

Join Date: Mar 2012
Location: Boston, MA
Boat: 1981 Bristol 32 Sloop
Posts: 17,766
Images: 2
Re: OpenCPN Homepage hacked

Dave,
If you look at the revisions of this page, you will see that I just made that page to replace the one lost! I am afraid it is quite diiminished from the orginal.

--See my email please

We got two posts below deleted as Eben suggested.
rgleason is offline   Reply With Quote
Reply

Tags
enc, opencpn


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ericson homepage grover2 General Sailing Forum 5 20-05-2020 17:26
Homepage OCPN 4.2 Aart K. OpenCPN 0 08-03-2016 06:39
What's with the homepage? Vasco Forum Tech Support & Site Help 7 02-10-2008 08:26
Homepage... rubinum General Sailing Forum 19 04-01-2005 13:03

Advertise Here


All times are GMT -7. The time now is 22:19.


Google+
Powered by vBulletin® Version 3.8.8 Beta 1
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Social Knowledge Networks
Powered by vBulletin® Version 3.8.8 Beta 1
Copyright ©2000 - 2024, vBulletin Solutions, Inc.

ShowCase vBulletin Plugins by Drive Thru Online, Inc.