Jump to content


  • Posts

  • Joined

  • Last visited

  • Days Won


Everything posted by Sheldon

  1. I'm not certain Howie would know how to accomplish that.
  2. She doesn't have the usergroup colors of either staff group. Has "Big Board" color....
  3. By my count, that's 8 known that has AdminCP access. Why on earth that many is needed for a 25 post a day forum......
  4. MattW added to staff not shown.
  5. Looks like TJA was fired. He was staff at one point as well. Likely when removed, he stopped posting there.
  6. Ozzy was removed...
  7. I know Morganna fired Jacquii as well as TrixieTang.
  8. Username change add-on. He's the SpongeBob dude. You'll see a quote below where it says "Daroldi".
  9. Changed his name to "Justin", no longer staff.
  10. He still staff as well?
  11. Amusing they have some not listed. Right off, I see 3 that are either Admin or staff not listed. Ryan Ashbrook Russ ChrisD MattW I suppose he's removed Hoodwinked's access, since he's yet to refund him :D.
  12. [ATTACH=full]262._xfImport[/ATTACH] [ATTACH=full]263._xfImport[/ATTACH]
  13. Checking to see if any of these should change, or people added.... hahahaha.
  14. .... and calling him a great American hero!!!!????!!!!! Ok. I respect his athletic abilities, his boxing, even the comedy he provided in those areas. I will not, however, acknowledge him as a great American hero. He was a draft dodger. For me, that kills any aspect of "hero".
  15. Bernie in a speech yesterday chided Trump for this: https://twitter.com/username/status/738950669927886848 View: https://twitter.com/realDonaldTrump/status/738950669927886848 Said Trump shouldn't say that, because he's prejudice against Muslims. No Bern, he's not. He doesn't like Muslim Extremists. I hope Trump calls him out and blasts him. Oh, Sheriff David Clarke agrees as well.
  16. Glad he felt the need to be in the news. I seriously don't think his endorsement means squat. Who cares who this dipshit is behind. He needs to crawl back into his corner.
  17. I'm taking a trip to the Midwest. I want to be able to leave you 1*.
  18. Second? I count 4th or 5th.
  19. On May 5th, 2016, TAZ had its security breached for the second time. Unlike the previous intrusion, this was a sophisticated attack where the hacker was somehow able to upload a malicious file onto TAZ's test board (perhaps by exploiting a Brivium add-on installed on the old Admin Extra site which was still on the server) which then allowed them to give themselves SFTP access to the nginx user account and run commands. They then altered several core XenForo files in order to begin logging member username/password combinations, logging out members forcing them to log in again, and finally by preventing the File Health Check from reporting the file modifications. Due to some of the safeguards we installed last time we were attacked, were were able to identify this intrusion almost immediately and take steps to block the hacker, limiting the time the login logger was operational to a matter of hours. We then forced a password reset for all members. It's certainly unfortunate that TAZ was hacked again and I take full responsibility for it - the test site should not have been kept on the primary TAZ server nor should the old TAZ sites have been there. The previous intrusion was a much simpler exploitation of a staff member's username/password being harvested from another site and being used to gain access to the AdminCP to alter the login templates. We took a number of steps to prevent this kind of thing from happening again - forced 2FA for staff members and htaccess on the AdminCP for example. There are good things to do, but in a way it gave us a false sense of security that left us vulnerable to the second, much more sophisticated attack. The hacker was not able to gain access to the server root. Using the logs we were able to see exactly what changes the hacker made and undo them. Many other security measures have been put in place to prevent this from happening again, and several more are planned. Please keep in mind that unlike commercial sites, TAZ does not collect sensitive data about its members - we don't collect your full name, address, social security number, or credit card numbers for example. All a hacker can get here is your username, password, and email address. You can protect yourself by using a unique password on each site (or at the very least, use unique passwords on all of your important sites), and not using your primary email address as your registration email address (better to use a secondary email address for forum registrations, a different one for really important sites like banking sites, government sites, etc. and perhaps even a third one for semi-important things like your server hosting, registrar, etc.). Finally, do not put any "secret" information (such as access codes for your server) into a forum's personal or private message system - use secure email for that. If you follow these simple steps on TAZ (or any discussion forum) you won't be at risk even if the site is hacked. Again, my apologies for this security breach. I made some mistakes which made TAZ vulnerable. We are doing everything possible to prevent any further intrusions. Howard (The Sandman)
  20. Fentanyl
  21. Announcement by Morganna May 29th, 2015 Important, please read! Potential Account Breach Announcement by The Sandman January 27th, 2016 Security Breach Announcement by The Sandman May 16th, 2016 TAZ Security Comments by Morganna, Steve (another Administrator) The Sandman about hackings from November that apparently didn't deserve a topic. January 27th, 2016 Security Breach Security Breach Security Breach .....will update/add as needed
  22. https://www.youtube.com/watch?v=UwY67LYzH7Q View: https://youtu.be/UwY67LYzH7Q
  • Create New...