NonSports Forum

Net54baseball.com
Welcome to Net54baseball.com. These forums are devoted to both Pre- and Post- war baseball cards and vintage memorabilia, as well as other sports. There is a separate section for Buying, Selling and Trading - the B/S/T area!! If you write anything concerning a person or company your full name needs to be in your post or obtainable from it. . Contact the moderator at leon@net54baseball.com should you have any questions or concerns. When you click on links to eBay on this site and make a purchase, this can result in this site earning a commission. Affiliate programs and affiliations include, but are not limited to, the eBay Partner Network. Enjoy!
Net54baseball.com
Net54baseball.com
ebay GSB
T206s on eBay
Babe Ruth Cards on eBay
t206 Ty Cobb on eBay
Ty Cobb Cards on eBay
Lou Gehrig Cards on eBay
Baseball T201-T217 on eBay
Baseball E90-E107 on eBay
T205 Cards on eBay
Baseball Postcards on eBay
Goudey Cards on eBay
Baseball Memorabilia on eBay
Baseball Exhibit Cards on eBay
Baseball Strip Cards on eBay
Baseball Baking Cards on eBay
Sporting News Cards on eBay
Play Ball Cards on eBay
Joe DiMaggio Cards on eBay
Mickey Mantle Cards on eBay
Bowman 1951-1955 on eBay
Football Cards on eBay

Go Back   Net54baseball.com Forums > Net54baseball Main Forum - WWII & Older Baseball Cards > Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions

Reply
 
Thread Tools Display Modes
  #1  
Old 01-18-2021, 06:47 AM
autograf's Avatar
autograf autograf is offline
Tom Boblitt
Member
 
Join Date: Apr 2009
Location: Louisville, KY
Posts: 2,028
Default

My nonsports auction is with SSA. I have done three auctions a year for the last two years. 2021 is the third year. I'll do Feb, Jun and October this year. The hack hasn't caused me many problems other than I had to push my Jan auction back to Feb. It sounds easy to just hop over to another software but it is not quite that easy. All the historical data would have to be ported over somehow and you'd have to learn a completely new software for running your auctions. It may come to that at some point and I'm sure other SSA users are considering jumping ship, but, for now, I'm staying put. As for information gathered, other than address and phone number which is important, my site doesn't collect any payment info--only paid through the PayPal API or via check/money order. And passwords are not visible to me through the software. I hope that's the case as, like most of you all, I'm registered with a number of SSA sites too. Last word I got was that the sites would be back up this afternoon.
Reply With Quote
  #2  
Old 01-18-2021, 07:34 AM
MCyganik MCyganik is offline
M@++ Cyganik
Member
 
Join Date: Feb 2018
Location: Boston
Posts: 156
Default

I'm curious how these things work behind the scenes because for the layman like myself it sounds like a bad movie.

Auction Server gets taken hostage. Hacker claims responsibility, supposedly doesn't want info from the hostage, just wants money to release the hostage.

Server CEO has long-time IT experience, hires firm that specializes in internet hostage situations. "Never negotiate with terrorists!" customers say. They begin negotiating with the hackers.

Server CEO and hostage firm negotiate a settlement to release the hostage. "It's okay," they say, "in most situations the hacker just wants a lump sum and they'll go away".

The hacker releases the hostage. The Auction Server needs time to recuperate from the trauma but otherwise is intact and well-functioning. After a few days, life moves on.

3 Weeks Later

Auction Server is missing. Who is to blame?

Last edited by MCyganik; 01-18-2021 at 07:36 AM.
Reply With Quote
  #3  
Old 01-19-2021, 12:01 PM
SWinn SWinn is offline
member
 
Join Date: Jan 2021
Posts: 23
Default

Quote:
Originally Posted by MCyganik View Post
I'm curious how these things work behind the scenes because for the layman like myself it sounds like a bad movie.

Auction Server gets taken hostage. Hacker claims responsibility, supposedly doesn't want info from the hostage, just wants money to release the hostage.

Server CEO has long-time IT experience, hires firm that specializes in internet hostage situations. "Never negotiate with terrorists!" customers say. They begin negotiating with the hackers.

Server CEO and hostage firm negotiate a settlement to release the hostage. "It's okay," they say, "in most situations the hacker just wants a lump sum and they'll go away".

The hacker releases the hostage. The Auction Server needs time to recuperate from the trauma but otherwise is intact and well-functioning. After a few days, life moves on.

3 Weeks Later

Auction Server is missing. Who is to blame?
In my experience, it boils down to more common sense than IT experience. I know guys who have been in the industry for years but everything always, and I mean always, seems to fall apart (for some strange reason lol). If you're routinely getting attacked by ransomware I would be running like crazy in the other direction (as a customer).

There are many auction platforms out there. I come across them all the time in my own work. Many people opt for fully managed solutions because they don't want the IT headache on top of the logistics, understandably. It's a lot to manage.

But sometimes the best route is DIY for reasons like this. Hopefully the light is seen and all works out well.

Last edited by SWinn; 01-19-2021 at 12:02 PM.
Reply With Quote
  #4  
Old 01-19-2021, 12:21 PM
bobfreedman bobfreedman is offline
Member
 
Join Date: May 2009
Posts: 1,155
Default Hack

Board members, we were hacked once again however after the first hack, SpearTip was hired and prevented a second attempted attack Sunday Morning. A decision was made to take the servers offline and do a through check to determine how they were able to penetrate our servers (although no encryption nor data loss occurred). We have estimated that there was a Trojan Horse installed on the first hack. We decided to take everything offline and rebuild our environment and harden the security even more.

The decision was also made to install redundant security measures to prevent future attacks. This is why the servers of all our clients utilizing our software have been down. These additional layers of security have now been implemented, the servers are being tested and should be ready to be back online tonight.

We have gone through great expense to prevent the this again and we are being very proactive in hiring additional staff and hiring SpearTip on a full time basis. This has been a very trying time as you can imagine and I appreciate our customers loyalty and hope that we can once again provide you the level service you are accustomed too. Thank you

Also, from the first hack, a complete forensic analysis was done and determined that no data loss occurred

Bob Freedman

Last edited by bobfreedman; 01-19-2021 at 12:28 PM.
Reply With Quote
  #5  
Old 01-19-2021, 01:26 PM
RedsFan1941 RedsFan1941 is offline
Banned
 
Join Date: Feb 2016
Posts: 1,207
Default

Quote:
Originally Posted by bobfreedman View Post
We have estimated that there was a Trojan Horse installed on the first hack.

Also, from the first hack, a complete forensic analysis was done and determined that no data loss occurred

Bob Freedman
your people did a forensic analysis after the first hack and determined no data loss but somehow during this analysis a trojan horse was missed?
Reply With Quote
  #6  
Old 01-19-2021, 02:04 PM
GeoPoto's Avatar
GeoPoto GeoPoto is offline
Ge0rge Tr0end1e
Member
 
Join Date: Dec 2018
Location: Saint Helena Island, SC
Posts: 1,711
Default

Once upon a time I ran a company that almost ran out of cash (actually, we ran out of cash, but for a brief enough period that we were able to skinny through by stretching suppliers, delaying officer paychecks, and other things that would normally be unthinkable). At the next board meeting, the question came up whether we should be looking for another CFO. I took the position I would rather have the CFO who (almost) ran out of cash rather than the one that hadn't run out of cash -- yet. Nothing sharpens the mind like living through your own mistakes.
Reply With Quote
  #7  
Old 01-19-2021, 03:31 PM
UKCardGuy's Avatar
UKCardGuy UKCardGuy is offline
Gary
Member
 
Join Date: Jun 2020
Location: London, UK
Posts: 1,408
Default

Quote:
Originally Posted by bobfreedman View Post
Also, from the first hack, a complete forensic analysis was done and determined that no data loss occurred
No data loss occurred isn't the same as a secure environment. To me, "No data loss occurred" means that all the data was unencrypted and the records were restored.. Was the forensic analysis performed on just the data integrity or the entire environment?

Based on the fact that a trojan horse had been left, I'm guessing it was the former. That's extremely disappointing. I'd have expected the full security implications to have been considered after the first hack. At best, the approach seems very naive.

If someone takes over my house, changes the locks and demands a ransom for the new keys - I wouldn't simply trust that they didn't make copies of the keys or sabatoge other entrances.
__________________
Working on the following sets: 1916 and 1917 Zeenut, 1954B, 1955B, 1971T and 1972T
Reply With Quote
Reply




Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Ebay got hacked? Leon Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 52 09-16-2014 05:12 PM
Hacked account tbob Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 1 06-21-2012 08:49 PM
Facebook Account Hacked Jacklitsch Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 20 12-15-2010 11:37 AM
Paypal account hacked............ Archive Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 17 04-22-2009 09:45 AM
Is Ebay being hacked into ?? Archive Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 0 01-22-2007 06:57 AM


All times are GMT -6. The time now is 09:19 PM.


ebay GSB