Welcome to Just Commodores, a site specifically designed for all people who share the same passion as yourself.

New Posts Contact us

Just Commodores Forum Community

It takes just a moment to join our fantastic community

Register

Compromised Account Passwords

Darren

Administrator
Staff member
Joined
Feb 2, 2003
Messages
3,002
Reaction score
431
Points
83
Age
44
Location
Adelaide
Website
www.justcommodores.com.au
Members Ride
BYD Atto 3 / RAV4 Hybrid
Hi All
We have recently noticed a number of legit accounts having been hijacked by spammers and posting unwanted content on the site, some not visited the site nor posted previously so some of these accounts are many years old.

I dare say this is due to poor complexity or should I say passwords which have been dumped out on the web after a site had been compromised.

A couple of suggestions which might seem blatantly obvious to some but others not so:
  • Use different passwords on each web site, don't use the same password for everything this is just asking for trouble.
  • Ensure passwords are complex, ie add a mixture of numbers, letters, symbols or even better use a password manager and/or password generator, Bitwarden, KeePass etc take your pick but most are free and offer browser extensions to save passwords along with the headache of remembering them all.
  • Enable 2FA / MFA (done through password and security under your profile), in short you use your password as normal but then have the added layer of security using a 6 digit number, I personally use Authy but take your pick here and feel free to post suggestions.
If you suspect your account has been compromised by all means reach out.

Cheers
Darren
 

Martbar

Well-Known Member
Joined
Dec 31, 2021
Messages
756
Reaction score
765
Points
93
Age
67
Location
New Zealand S.I. Otago.
Members Ride
2016 VF Series 2 SSV Redline.
Hi All
We have recently noticed a number of legit accounts having been hijacked by spammers and posting unwanted content on the site, some not visited the site nor posted previously so some of these accounts are many years old.

I dare say this is due to poor complexity or should I say passwords which have been dumped out on the web after a site had been compromised.

A couple of suggestions which might seem blatantly obvious to some but others not so:
  • Use different passwords on each web site, don't use the same password for everything this is just asking for trouble.
  • Ensure passwords are complex, ie add a mixture of numbers, letters, symbols or even better use a password manager and/or password generator, Bitwarden, KeePass etc take your pick but most are free and offer browser extensions to save passwords along with the headache of remembering them all.
  • Enable 2FA / MFA (done through password and security under your profile), in short you use your password as normal but then have the added layer of security using a 6 digit number, I personally use Authy but take your pick here and feel free to post suggestions.
If you suspect your account has been compromised by all means reach out.

Cheers
Darren
Cheers Darren, before they put a stop to it, in an alarming number of passwords where only numerals were required, the 6 digits were 1,2,3,4,5,6.
 

Fu Manchu

We’ll get together. Have a few laughs.
Joined
Mar 18, 2006
Messages
18,123
Reaction score
22,950
Points
113
Location
WA.
Members Ride
VZ Crewman, VZ Cross 8, & ya mum.
Cheers Darren, before they put a stop to it, in an alarming number of passwords where only numerals were required, the 6 digits were 1,2,3,4,5,6.
To quote SpaceBalls:
“1,2,3,4,5? That’s the kind of combination only an idiot would have on their luggage.”
 

vc commodore

Well-Known Member
Joined
Jun 18, 2014
Messages
10,764
Reaction score
12,778
Points
113
Location
Like the Leyland Brothers
Members Ride
VC, VH and VY
To quote SpaceBalls:
“1,2,3,4,5? That’s the kind of combination only an idiot would have on their luggage.”

Thanks for advertising my password....I've now got to change it to 1,3,2,5,4..... :)
 

vc commodore

Well-Known Member
Joined
Jun 18, 2014
Messages
10,764
Reaction score
12,778
Points
113
Location
Like the Leyland Brothers
Members Ride
VC, VH and VY
With my work pay advises, it's done over the net.

Every 3 months the password has to be changed...If it's what is considered as a week password, it refuses to accept the password...

When I log into the site, it also sends a code to either my email addy or my phone...

At first I thought it was overkill, but I soon realised how much they want to protect your information
 

Immortality

Can't live without smoky bacon!
Staff member
Joined
Apr 15, 2006
Messages
22,681
Reaction score
20,690
Points
113
Location
Sth Auck, NZ
Members Ride
HSV VS Senator, VX Calais II L67
We had a generic password at work on the production PC's Password1
 

Commo64

Well-Known Member
Joined
Aug 11, 2021
Messages
2,107
Reaction score
1,959
Points
113
Location
Victoria
Members Ride
2010 VE Omega
So I guess the issue is mainly to do with inactive accounts or very old accounts?

Some other forums that I'm on have a manual registration process, which means that your account isn't automatically approved... My suggestion might be worth looking at to reduce the number of spammers...
 

UTE042_NZ

Well-Known Member
Joined
Jul 26, 2017
Messages
734
Reaction score
3,911
Points
93
Location
New Zealand
Members Ride
MY17 Magnum Ute
Password managers can and often are compromised. Norton and LastPass were both "hacked" last year, with in excess of 30 million users affected globally. The ruse is often simply getting users to click on a link for a fake product update. Lazy fools get shafted easier. These recent ones might be from some of those farmings.
 
Top