about the database hack

Open forum for end-user questions about Wine. Before asking questions, check out the Wiki as a first step.
Forum Rules
Locked
Diego Xirinachs

about the database hack

Post by Diego Xirinachs »

Hi,

Just wanted to know if this also applies to the codeweavers website or only
wineHQ was affected? Being wine a hosted codeweavers project it leads me to
think the hackers may have compromised some of that info too.

thanks for the honesty on the announcement and hope you can get everything
sorted out :D

--
X1R1
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.winehq.org/pipermail/wine-us ... hment.html>
Mad-Halfling
Newbie
Newbie
Posts: 1
Joined: Tue Nov 30, 2010 3:05 pm

Post by Mad-Halfling »

Also, was this forum compromised - I (obviously) have a user on here, but my password wasn't reset, so I'm guessing not. However I'm not sure if I have a user on http://appdb.winehq.org - I've tried the password reset link on both my mail accounts but it doesn't reject the request if the e-mail isn't on the DB. I haven't had any mails yet, but just in case the mail doesn't arrive for some reason I didn't want to assume that my user didn't exist.
oiaohm
Level 8
Level 8
Posts: 1020
Joined: Fri Feb 29, 2008 2:54 am

Post by oiaohm »

Mad-Halfling I have heard nothing about the forum database being touched.

The appdb and bugzilla database were being given to appdb developers to enable better integration.

So there is a chance the forum data was not downloaded at all.

There are 4 databases user databases I know of here. wiki, forum, appdb bugzilla. I have recieved by resets for the bugzilla and appdb. But as far as I know there was no external developers working on the forum or wiki at the time of the breach so there is a chance they were not exported.

Basically Mad-Halfing if you have a message of more being breached please provide link.
User avatar
dimesio
Moderator
Moderator
Posts: 13367
Joined: Tue Mar 25, 2008 10:30 pm

Post by dimesio »

oiaohm wrote: So there is a chance the forum data was not downloaded at all.
I emailed Jeremy asking about the forum, and his response to me was:
We have no evidence that database was compromised, and our suspected attack vector would not allow the attacker access to that table.
Anyone who used the same password for the forum and the AppDB should obviously change it. As to whether others should bother to change their forum password, IMO, it's better to be safe than sorry.
Locked