#1 by Cyph3r » Sat Oct 15, 2011 9:05 pm
Update 3: Even more super tight security was added. I'd be surprised if the hacker had any way to do anything anymore. Will be monitoring.
Update 2: Because of our security work yesterday, our hacker was only able to make a feeble attempt this morning, along with an equally pathetic server announcement. However, we're committed to keep him off completely. We spent all day working on closing any potential security holes, including making a core patch to block the exploit being used. The realms will be restarted to apply it, and we believe this will prevent the hacker from being able to issue any commands. Tomorrow evening, more security measures will be implemented as well. We've also noticed at least 5 other servers affected by the same hacker - all of which are unable to stop him - but we will. We are also in discussions with TrinityCore (the software our servers run on) in order to resolve the issue permanently. He may still be able to infiltrate through a security hole that even TrinityCore is unaware of, but our custom modifications will drastically (if not completely) make his entry harmless and boring.
Update: We didn't need to do a real rollback to fix the issues. We simply rolled back spell, skill, and talents 16 hours, which for most of you means nothing (just any talent tree changes you made over that period or skills learned, etc.), but for new characters that we're power leveled during that time, it will mean some extra effort. In summary, very minor issue for 99% of you. If you have any issues, please open a GM ticket and be patient. Thanks!
Hello everyone and thank you for your patience through this stressful situation.
As you all know we were targetted by a person or persons wanting to do harm to our server for profit, we have taken some necessary steps in prohibiting the abuse of these "persons" on our server in the future with some core-side modifications to prohibit further abuse on our servers.
We have stepped up our overall security tenfold and will continue to monitor the situation at hand.
To go into further detail they were able to access some commands to reset spells/talents for every character on our realms as well as add some donor items to some vendors and delete some guilds, the Talents/Spells are being restored to this morning as well as Guilds, we have deleted the items from vendors.
Our server personally was not compromised. We shut the realms down to prohibit any future abuse of the commands.
The universe is run by the complex interweaving of three elements: energy, matter, and enlightened self-interest.