Warning black magic forum being hacked!!!

Got something to discuss that's not about Blackmagic products? Then check out the Off-Topic forum!
  • Author
  • Message
Offline

HaveBlue

  • Posts: 130
  • Joined: Mon Nov 12, 2018 2:03 am
  • Real Name: Lars Dennert

Warning black magic forum being hacked!!!

PostSat Feb 29, 2020 3:29 pm

Please be advised that someone has set up a duplicate forum and is sending phishing emails to obtain usernames and passwords. If you get a topic response that doesn't point to a black magic subdomain but instead an ip, do not try to log in.


Hello HaveBlue,

You are receiving this notification because you are watching the topic,
"Cant play any media without crash" at "Blackmagic Forum". This topic has
received a reply by turbo2ltr since your last visit. You can use the
following link to view the replies made, no more notifications will be sent
until you visit the topic.

If you want to view the newest post made since your last visit, click the
following link:
http://54.172.192.242/viewtopic.php?f=2 ... 8&e=598568

If you want to view the topic, click the following link:
http://54.172.192.242/viewtopic.php?f=21&t=108355

If you want to view the forum, click the following link:
http://54.172.192.242/viewforum.php?f=21

If you no longer wish to watch this topic you can either click the
"Unsubscribe topic" link found at the bottom of the topic above, or by
clicking the following link:

http://54.172.192.242/viewtopic.php?uid ... atch=topic


--
Thanks, Blackmagic Design
W10Pro, Resolve Studio, Ryzen 7 3700X, 32GB RAM, SSD and platter drives, GTX 1070 8GB, LG 10bit 4K 32" monitor with two 20" HD monitors
Offline
User avatar

Xtreemtec

  • Posts: 4344
  • Joined: Wed Jan 02, 2013 11:48 am
  • Location: The Netherlands

Re: Warning black magic forum being hacked!!!

PostMon Mar 02, 2020 11:17 am

WOW they did a good job by cloning the whole forum including themes :o
Daniel Wittenaar .:: Xtreemtec Media Productions ::. -= www.xtreemtec.nl =-
4K OBV Trailer, ATEM TVS HD, 4M/E Broadcast Studio 4K, Constelation 8K, Hyperdeck Studio 12G, Ursa Broadcast 4K, 4K fiber converters with Sony Control
Offline

codedeltajames

  • Posts: 2
  • Joined: Mon Mar 02, 2020 11:30 am
  • Real Name: James Goodwin

Re: Warning black magic forum being hacked!!!

PostMon Mar 02, 2020 11:31 am

Xtreemtec wrote:WOW they did a good job by cloning the whole forum including themes :o


Even more amazing is they cloned it onto the same IP address as the real forum :o :o
Offline
User avatar

Joshua Helling

Blackmagic Design

  • Posts: 853
  • Joined: Wed Aug 22, 2012 4:58 pm

Re: Warning black magic forum being hacked!!!

PostMon Mar 02, 2020 5:34 pm

We've already reported this to the team. We'll have to wait to hear from them this afternoon.

It's a good catch.

I'm not sure it's accurate to say we've been hacked because it looks like a phishing attempt. This means our server is likely fine.

But people definitely do need to pay attention.

We'll give an update as soon as we have one.
Joshua Helling

Director of World Wide Support
Blackmagic Design Inc.
Offline

BMD Web Engineering

Blackmagic Design

  • Posts: 43
  • Joined: Fri Feb 27, 2015 3:58 am

Re: Warning black magic forum being hacked!!!

PostMon Mar 02, 2020 11:25 pm

The above message referring to http://54.172.192.242/ is forum.blackmagicdesign.com as suggested by codedeltajames- that is why it looks exactly like our forum.

Topic notification messages use https://forum.blackmagicdesign.com/ in them; so the advice to not click on messages containing IP addresses and using http rather than https is good.

So, in summary: The message does not refer to a duplicate forum, but clicking on http links to IP addresses is not a good idea.
Offline

Howard Roll

  • Posts: 566
  • Joined: Fri Jun 03, 2016 7:50 am

Re: Warning black magic forum being hacked!!!

PostTue Mar 03, 2020 3:39 pm

How does the Phisherman know what threads I’m following if there’s no security breach? Is that information public somewhere?

Thanks
Offline
User avatar

Xtreemtec

  • Posts: 4344
  • Joined: Wed Jan 02, 2013 11:48 am
  • Location: The Netherlands

Re: Warning black magic forum being hacked!!!

PostTue Mar 03, 2020 4:10 pm

To get the Theme, and general setup of the forum page.. They probably hashed a copy of the database and folders containing all files..

If you have that info.. You have names of users, topic names.. And just random send users a message based on what topic you reacted on.. ;)

Not sure how much someone would be able to pull from a database copy. For sure login info is encrypted.. But settings on what topic you subscripted might not be..
Daniel Wittenaar .:: Xtreemtec Media Productions ::. -= www.xtreemtec.nl =-
4K OBV Trailer, ATEM TVS HD, 4M/E Broadcast Studio 4K, Constelation 8K, Hyperdeck Studio 12G, Ursa Broadcast 4K, 4K fiber converters with Sony Control
Offline

HaveBlue

  • Posts: 130
  • Joined: Mon Nov 12, 2018 2:03 am
  • Real Name: Lars Dennert

Re: Warning black magic forum being hacked!!!

PostTue Mar 03, 2020 6:15 pm

When I clicked on the links originally, I got a message "Topic does not exist" and also my browser refused to auto-fill login info. I therefore assumed someone had cloned the board to capture people logging in and then gain access into the board. If an Admin did this on a duplicated board, their credentials would have been compromised and the board could easily be hacked.

I think best practices is not to use the ip in the url for notification emails. It leaves an opening for someone to duplicate the board and send phishing emails with a different ip and it will go unnoticed. It would be trivial to follow an admin around the board, even in this thread, and send them notification emails on their board that redirects to a phpBB clone I loaded on a linux server.
W10Pro, Resolve Studio, Ryzen 7 3700X, 32GB RAM, SSD and platter drives, GTX 1070 8GB, LG 10bit 4K 32" monitor with two 20" HD monitors
Offline

BMD Web Engineering

Blackmagic Design

  • Posts: 43
  • Joined: Fri Feb 27, 2015 3:58 am

Re: Warning black magic forum being hacked!!!

PostTue Mar 03, 2020 11:17 pm

Thank you HaveBlue for bringing this to our attention.

To clarify my earlier response:

54.172.192.242 is forum.blackmagicdesign.com.

You can verify this for yourselves by using "nslookup forum.blackmagicdesign.com" or
"dig forum.blackmagicdesign.com"

Code: Select all
$ nslookup forum.blackmagicdesign.com

Non-authoritative answer:
Name:   forum.blackmagicdesign.com
Address: 54.172.192.242


This issue does not indicate a breach.

The questionable links do not refer to a duplicate forum.

Howard Roll wrote:How does the Phisherman know what threads I’m following if there’s no security breach? Is that information public somewhere?

Thanks


Howard, it was not a Phisherman sending the message, it was this forum. The message format was not in it's typical form.


Http access was previously allowed to the forum- this has been changed and we now only allow https connections.

The http access made it possible to post messages to a thread, that would send the 'odd' looking notfications to people subscribed to the thread. It should no longer be possible to do this.

Hope this clarifies the situation,
regards,
Martin
Offline

HaveBlue

  • Posts: 130
  • Joined: Mon Nov 12, 2018 2:03 am
  • Real Name: Lars Dennert

Re: Warning black magic forum being hacked!!!

PostWed Mar 04, 2020 5:21 am

Thank you so much. I've had websites hacked and it's a pain. Wanted to catch the possibility as early as possible for you.
W10Pro, Resolve Studio, Ryzen 7 3700X, 32GB RAM, SSD and platter drives, GTX 1070 8GB, LG 10bit 4K 32" monitor with two 20" HD monitors

Return to Off-Topic

Who is online

Users browsing this forum: No registered users and 22 guests