GPWA Database Error

Shay

Affiliate Guard Dog Member
Joined
Nov 27, 2011
Messages
188
Reaction score
179
Same... few days running
 

BetOnlineUK

Affiliate Guard Dog Member
Joined
Jun 8, 2016
Messages
432
Reaction score
203
It is a bit hit and miss whether you can get access over there at the moment. Not sure if anyone is monitoring wasn't Anthony having surgery.
 

Batman

Affiliate Guard Dog Member
Joined
Jan 3, 2018
Messages
173
Reaction score
63
I've had no chance all Yesterday or today. Same database error as everyone by the look of it though, at least it's just not me!
 

AidanLCFC

Affiliate Guard Dog Member
Joined
Mar 8, 2012
Messages
750
Reaction score
451
It is a bit hit and miss whether you can get access over there at the moment. Not sure if anyone is monitoring wasn't Anthony having surgery.

Rick lives on there and and worships the place like some weird religion so I imagine he's been flapping like penguin getting messages across
 

MJM

Affiliate Guard Dog Member
Joined
Oct 22, 2019
Messages
31
Reaction score
36
I reached out to GPWA yesterday and was told the following:

"We have been hit by a very severe ransomware attack on our entire infrastructure and are working as fast as we can to get everything working. Right now I expect another day for repairs."

I wonder, not being too much of a techie myself - did the lack of SSL make them vulnerable to this attack or would it have likely happened regardless? Either way I appreciate GPWA for what it is (and ignore what it isn't), and wish them luck in sorting it out.
 

LandofOz

Affiliate Guard Dog Member
Joined
Mar 25, 2009
Messages
710
Reaction score
280
I thought it was a DDOS attack because I didn't realise that ransomware can attack websites in addition to PCs.
 

AussieDave

24 years & still going!
Joined
Nov 28, 2013
Messages
5,103
Reaction score
3,607
not being too much of a techie myself - did the lack of SSL make them vulnerable to this attack or would it have likely happened regardless?

If it was a DDoS (distributed denial-of-service) attack, SSL wouldn't make any difference.

Because the GPWA isn't using SSL, personal data transmitted to the server/database isn't encrypted. Hence, (and especially) passwords are sent as 'plain text'. So anyone with the skill set could intercept/capture that "data" being sent.

vBulletin - it's outdated. As forumsaddict_reboot commenced - it's a dying breed. When the SEO module was yanked, that was sign to change. AGD, CM and others have all opted for XenForo. It's far better forum software for today's market.

The forum should be using SSL. But it should also have a GDPR too, but it has neither :rolleyes:
 

DaftDog

Affiliate Guard Dog Member
Joined
May 15, 2007
Messages
701
Reaction score
458
I reached out to GPWA yesterday and was told the following:

"We have been hit by a very severe ransomware attack on our entire infrastructure and are working as fast as we can to get everything working. Right now I expect another day for repairs."

I wonder, not being too much of a techie myself - did the lack of SSL make them vulnerable to this attack or would it have likely happened regardless? Either way I appreciate GPWA for what it is (and ignore what it isn't), and wish them luck in sorting it out.
Thanks for updating us.
 

Mattbar

Affiliate Guard Dog Member
Joined
Jul 22, 2015
Messages
7
Reaction score
5
This now explains it, cheers for the update MJM, been trying to get into GPWA for two days. At least this has finally made me sign up to AGD and I agree XenForo is a much nicer forum software.
 

casinorobots

Affiliate Guard Dog Member
Joined
Oct 21, 2019
Messages
4
Reaction score
3
Still the same. I can't login and get Database Error. Hope they will fix it soon.
 

forumsaddict_reboot

Affiliate Guard Dog Member
Joined
Dec 5, 2018
Messages
64
Reaction score
18
Ransonware attacks happen when a hacker has actual access (root user/pass) to the server. Basically admin rights.

This is only possible 1.) someone from within the company gave out this info / or hacked 2.) the linux, php, or scripts being used are so outdated that when broken into gives full superuser access to the person.

Non-SSL attacks can only happen when the data is being snooped out between the DC and the user. This is highly improbable for normal users. These kind of "targeted" man-in-the-middle attacks happen to celebrities, intelligence agency members, politicians, or Mark Zuckerberg types. Not your everyday people.
 
Top