Forum partially damaged - please read carefully and act ASAP accordingly
As some may have noticed again - some threads are broken or corrupt and do create error messages when attempting to reply to existing new posts.
why?
in past several days as well as all past months and year repeatedly some forum members created multiple accounts using same member name but different eMail address or same eMail address but different member names. The forum software apparently fails to handle such a mess properly and there is no forum-software-feature to clean up such invalid data in the forum SW at all. as you know the forum SW is commercial software and NO Open Source that can be repaired by any professional coder. Hence we have to live with what we all created.
Many tried to create second member ID because they forgot their password and failed to follow correct procedure to have temporary new password mailed to their registered eMail address to login and set a permanent and secure password.
many even may have changed their eMail address AND lost / forgot their password and have no way to receive a temporary password at all OR don't know which of the many eMail addresses they used for this forum.
the point now is:
this last night
from 17/Nov/2006:23:30:02 GMT until 18/Nov/2006:07:41:09
a professional hacker attempted for more than 8 continuous hrs to hack into Cyberspace Ashram online software - unsuccessfully because it happened under my permanent direct supervision and control. nevertheless it has once more shown that CA is a 24/7 job and security from ALL parties involved is a top priority.
fortunately FOR YOU forum members the attack focused on OTHER SW and NOT your forum accounts.
I counted exactly 115'331 log lines recorded from this hacker - that means he attempted some 155'000 times to crack passwords ...
If I look at YOUR forum passwords and see the requirements I have published in the registration page - then I know how LUCKY you all have been for one last night. some 90+% of your passwords are so easy to crack that it would have taken a minute or a few minutes to crack most of your accounts.
assuming that you have and apply the very same degree of negligence in all your password affairs
you can be sure that sooner or later your passwords GET cracked and you may receive full damage by hackers
unless
you take NOW immediately a few slid hours of hard work to go thru all your various online and offline accounts and CHANGE your passwords into a secure password!
a secure password consists of
at least 12 characters
MIXED numbers and letters
mixed again UPpeR-cAsE and loWeR-case
depending on software or portal there might be a minimum and / or maximum length of passwords. most SW accepts 12 characters - may accept much longer passwords.
TOTALLY insecure are passwords such as below examples:
godislove
GodisLove01
kriyayoga88
godgodgodgod1
salzmitbrezel
iloveyou
iamlove
123456
a1b2c3d4
medicus
emp1945
Dobson1980
hallo onlygowns people ...
onlygowns ( YOU are absolute Nr ONE - user=pwd=your_web_site !!! you are a danger to yourself and an accident just waiting to happen - FYI I have changed your password !)
so how would a secure password look alike ?
here an example
Uz7sOe9BmD3AlcO
LowEr-/UPPer-CaSe / alphanumeric
NO names
NO birthdates
NO words
NO word-variations
simple secure password should be in NO dictionary - else they become victim of so called "dictionary attacks - a system hackers use by attempting login with all variations INCLUDING common MIS-spells of words found in dictionaries )
and if password too short - then hackers do what they did some 7+ hours last night on a particular page - they just rotate ALL mathematically possible combinations of passwords until one matches.
here the kind of passwords that have been attempted last night on my site:
x87a686dc
xbe06571b
xc82011da
you see even "secure passwords too short may easily get cracked if a hacker software is allowed to run sufficient time or fast enough.
hence
your password should be at least 12 characters long!
by the time you receive THIS information - about half of the forum registrations will have been deleted for excessive risk to CA security. all with fake names, all with alias instead of true human names.
for all others receiving THIS post - please take your time now AND CHANGE your password immediately into a SECURE password ...
OR
eMail me to request a deletion of your forum registration. delete account is unfortunately impossible by members only by me. I will do it asap if you wish so or if you have no time for security aspects of life.
after all this above done
we still have a damaged forum - at least on part of the threads in our main forum.
what you ALL should do right now is to START NEW threads for any future posts
this may eventually solve the problem or leave our problem related on our past posts only.
Any and all of the current threads with unanswered posts are broken - hence NO reply from me possible.
there always are many ways to do things wrong - hence Murphy's law grabs full here in a software environment. to avoid Murphy's law we ALL have to do all as perfectly as possible NO matter the costs or efforts needed from the very beginning
or
we should do nothing at all and focus on those other things we are expert in.
to recapitulate briefly what YOUR next steps to do are
- Go to the forum-index page
- Click on Login link and login - if you forgot your password - have a new one sent to you by the forum software and check your mailbox within a minute or so the new password should be there
- CHANGE your OLD password OR your just sent temporary password into a SECURE password
- then you have 3 links - 1 to go to forum - that's for later
- next link is: Modify your registration - HERE we click and change our password
- here we also see a button to select to "Receive new posts in email" select or un-select according to your preferences. also check your eMail address or homepage if changes are needed
- 3rd link is "Edit your profile, such as signature" here you really should complete your profile with true and correct data to tell others a little about you and to establish a basis of mutual trust.
- if you have your own website and wish to add to each post a forum signature - to be added automatically at the bottom of each post - then that is the place to do so. your forum signature should be validated HTML4.01 code !! strictly NO fancy microsoft something code, NO xhtml code - but ONLY validated HTML4.01 only!
if that above is too much work for you,
then please eMail me with correct forum-username and eMail address and i will be glad to delete your account if you wish so. you can then bookmark your forum of choice or all 5 forums - or use any or all of my RSS feeds to keep in touch with the Cyberspace Ashram.
Once the forum membership deleted - of course you also lose your right to ask questions in writing - except by phone. the only right time for counseling by phone is exactly and sharp 1600 - 1700 hrs each day - PHT. that is the only ONE hour per day with lowest server load and hence with least online work for me and thus best suited to have exclusive minutes just for phone counseling with you.
Love and bliss
hans