CheckEmoji Community · the emoji forum
🏠 Home 🆕 What's new ❓ Unanswered 🔥 Popular 📡 RSS Members 👥 0 online log in · register
Home › Miscellaneous › Forum Help! › Identity theft on the forum

Identity theft on the forum

Started by Sandra Ward · · 👁 3 views · 22 replies

📡 Subscribe to replies

Participants Sandra WardJacob Foster11mellowseal27mistywolf17Paul Green31Zachary Barrett4dustypuma5
Sandra Ward Sandra Ward NewcomerOP
4 messages
joined Feb 2010
#1 ·
Hey everyone... looks like I’ve had my identity hijacked too, and right here on this forum. Someone was actually posting under my name and everything...

Does anyone know how to handle this without just getting slapped with an indefinite ban myself?!??!??
Jacob Foster11 Jacob Foster11 Active Member
132 messages
joined Nov 2007
#2 ·
I’m not entirely sure what you mean by that. Everyone on these forums is anonymous, so nobody actually has an identity beyond their handle. The only way someone could steal your username is if they managed to crack your password. Is that what you're getting at?
mellowseal27 mellowseal27 Member
24 messages
joined Apr 2015
#3 ·
If someone is posting under her name, then her password has clearly been compromised 🤷

Just go EDIT email → Edit Email & Password → Enter your current password along with the new one you want to use, then confirm everything via email
Sandra Ward Sandra Ward NewcomerOP
4 messages
joined Feb 2010
#4 ·
mellowseal27 said:If someone is posting under her name, then someone definitely cracked her password 🤷

To < click here → EDIT email & Password → Type in the current password along with the new one you want, then just confirm everything via email

Someone hijacked my email and my forum account... they're posting as me and all that.
I can't even get into my own account because they changed the password..

I reached out to the admins... but I haven't heard a peep back. I cleared all my cookies, reset every single password on my computer, everything except this one—since I physically can't access it..

They sent me a temporary password, but it doesn't even work. My main concern is—I assume they'll sort this out eventually...

BUT... is there some sneaky way this person can still get back into my private data?!??!?!?
Jacob Foster11 Jacob Foster11 Active Member
132 messages
joined Nov 2007
#5 ·
Sandra Ward said:WAIT, is someone else trying to pull some stunt and get into my private info again?!??!?!?

Your question is incredibly vague. What data specifically? Which information are you talking about?

If you're asking if it's possible for someone to crack your forum password or your email again, the answer is yes, it's possible.

How do you protect yourself? Use your own brain. Hackers don't just magically bypass everything; they guess passwords. They only succeed because of human stupidity.

This means you shouldn't pick passwords that are easy to guess. For instance, your handle is Sandra Ward. It would be incredibly stupid to use "sandraward," "barrymore," or anything like that as a password. Generally speaking, it is highly undesirable to have any actual words in a password; passwords should carry no meaning at all. An example of a solid password would be "7 Xy7z9aB". If you choose and remember a password like that, you can be fairly certain no one will ever crack it.

One more thing. Do not use the same password for the forum and your email. Don't do it, under any circumstances.
mistywolf17 mistywolf17 Active Member
67 messages
joined May 2007
#6 ·
Sandra Ward said:Someone stole my email password and my forum account... they're even posting things as if they were me..
I can't even log into my own account because they changed the password..

Well, could you please explain this a bit better? Are we talking about a different username of yours? 😕
Sandra Ward Sandra Ward NewcomerOP
4 messages
joined Feb 2010
#7 ·
mistywolf17 said:Could you explain that a bit better? Are we talking about some other username of yours? 😕

Alright, let me try to clarify...

It all started a few days ago. Basically... I got kicked out of my own account on one browser... then yesterday, it happened on a second one too... and now I can't get back into my own damn account at all!

And I mean on a different site, not this one.

My password was something so incredibly private that nobody could ever guess it—not even if they included my mom in the equation. It’s just a combination of my initials and the nickname my dad uses for me. No one would ever make that connection.

I'm assuming someone hijacked my cookies. At least, that's what some guy who claims to be an expert told me. As for how it happened—I have no clue. Apparently, it was through some link I carelessly clicked. It probably looked like a legitimate YouTube link or something similar, but it was actually... well, here's the explanation:

Based on what's written there, it looks like that person managed to grab my password through something like this. There was some issue with the server; I basically gave permission and it sent my data right to them. It's not like I'm a tech genius, but I know enough to be certain that even my best friend couldn't guess my password—never.

The password was the same for both my email on that portal and the forum itself. To change the existing one, they would have had to know what it currently was.

So, they changed it (somehow), and now I'm locked out of my own account.
And I can't seem to fix it...

Next time, I might as well just set my password to P3K5J6KF9mndiff.
I don't really care anymore if they can just read it via those cookies anyway.

What I really want to know is: is deleting my cookies every single day enough protection?!!?
And is there any other way that person can get back into my account once/if this gets resolved?!??!

I don't know if any of you have dealt with this, but it's really not a pleasant feeling when someone starts posting under your name on a forum where you've been a member for years, insulting you and others, posting your photos and stuff...
Jacob Foster11 Jacob Foster11 Active Member
132 messages
joined Nov 2007
#8 ·
Aha, now it's getting a bit clearer...

Yes, obviously. Even if you have the most complex password on the planet, it means absolutely nothing if you just write it down on a scrap of paper and hand it directly to an attacker.

Okay, a few points. First off, never open suspicious links, especially when they come from shady sources. Every single time before you log into a site, check the URL in your browser. For example, if you want to log into Reddit, the domain at the top should be reddit.com, not something else. Where do you find the domain in the URL? See where I've highlighted it in red here:
Code:
http://www.reddit.com/r/technology

That is the domain. It’s the part between those two slashes—the right side of the first slash up to the second dot from the right. If you are logging into reddit.com, that specific spot must say reddit.com and nothing else.

As for cookies being stolen, honestly, I don't know much about that. I don't think a cookie can just be snatched like that, but I'm not entirely certain, so I won't dwell on it too much.

But one thing is for sure. Your password won't be sitting in your cookies unless you check "remember me" or something similar during login. So, just clear your cookies and don't use auto-login; then there won't be any passwords stored in them.

One more thing. If a website itself is poorly built (like some old forums), and it doesn't have SSL during login (meaning it uses the https protocol instead of http), someone can eavesdrop and intercept your password while you're sending it from your computer to, say, a forum's server. There isn't much you can do there, since it depends entirely on the site and its level of Security. Just know that any site you log into that doesn't start with https, is a potential danger.

And another thing. Don't blindly install programs you download from the internet from unverified sources. Someone could easily send you a keylogger—a little program that records every single keystroke you make on your keyboard and sends it to someone else.
mistywolf17 mistywolf17 Active Member
67 messages
joined May 2007
#9 ·
I suspect you might have logged into something suspicious, which is probably how they managed to snag your username and password.
I know there's this whole trick involving Facebook where someone sends you a link, and once you log in to check whatever it is, they "steal" your credentials. I think that's exactly what happened to a friend of mine; she had to change her passwords for both Facebook and her email immediately after it happened.
Jacob Foster11 Jacob Foster11 Active Member
132 messages
joined Nov 2007
#10 ·
mistywolf17 said:It looks to me like you logged into something shady, which is how they swiped your username and password.
I know there’s this whole thing with Facebook where someone sends you a link, you log in to see whatever it is, and then they "steal" your credentials. Pretty sure that happened to a friend of mine, so she had to change her password on Facebook and her email immediately.

Exactly. It happened specifically because she used the exact same password for both Facebook and her email. That’s why I keep stressing that passwords need to be unique. Your email is your only lifeline for recovering an account—whether it's on this forum or Facebook. You request a reset, and it goes to your inbox. If you lose control of that email, you're locked out of everything.
mistywolf17 mistywolf17 Active Member
67 messages
joined May 2007
#11 ·
Yeah, you're absolutely right. I'm going to go ahead and change my password immediately. 😳
Sandra Ward Sandra Ward NewcomerOP
4 messages
joined Feb 2010
#12 ·
Jacob Foster11 said:Okay, that makes a bit more sense now...

One more thing. If a website itself is poorly built (like an old local bulletin board or some outdated community site) and doesn't use SSL during login (meaning it uses http instead of the https protocol), someone could technically eavesdrop on your connection. They could intercept your password while it's traveling from your computer to, say, that site's server. There isn't much you can do about that specific issue, since it depends entirely on the site's own security standards. Just keep in mind that any site where you log in and don't see https at the start of the URL is a potential red flag.

Also, just a heads-up: don't blindly install software you find online from unverified sources. That's how people get hit with keyloggers—tiny little programs that record every single keystroke you make and beam them right back to a hacker.

Thanks, 😍

Basically... that site isn't safe. Clearly not any safer than the one you mentioned...

Right now, my main concern is just making sure that person doesn't grab my password again when they reset it for me... assuming they actually do... and honestly, I don't even want to think about what would have happened if they'd gotten into my Facebook or my Gmail or whatever else.

So, moving forward, I'm going to clear my cookies every day and I won't be using the "save password" feature. Up until now, I had everything saved on my computer and my brother's computer, so it’s very possible what you described actually happened.

As for software, I don't think I have an issue there. I usually download things myself from places like XY... not from random forums. But how am I supposed to check if I actually have a keylogger on my computer right now?!?!

I'm running Avast as my antivirus, I've got Malwarebytes for anything I might have downloaded, and my Windows firewall is turned on...
Is that enough?

And sorry everyone for the confusing messages earlier xD I was a bit shocked so I was just typing whatever came to mind without really proofreading afterward xD
Sandra Ward Sandra Ward NewcomerOP
4 messages
joined Feb 2010
#13 ·
Jacob Foster11 said:Yeah, exactly. That happened specifically because she used the exact same password for both Facebook and her email. This is why I keep stressing the importance of using unique passwords. Your email is basically your lifeline—it’s the only way to get back into your accounts, whether it's this forum or Facebook. You request a reset, and it goes to your inbox. If you lose control of that email, you're locked out of everything.

So yeah, that's pretty much it... I'm not entirely certain... but I think there wasn't even an option to change the email address... since the same password applies to the whole portal... I'm not 100% sure... but it was close enough...

Anyway... I'm going to set up a completely different email address... and obviously a password like xyi9485IidjfHJGH xD or something along those lines. 😁

Though, honestly... they probably didn't even "steal" it, it was just too easy to guess. xD

Which means it can happen on Facebook too... wow... I should probably prune my friend list even more. xD

I really don't get how anyone finds this interesting, or how someone can be so pathetic... poking around in other people's lives and data, trying to cause harm... it's just sad, really. 🙂 🙂

Not to mention how zero-morals that is... and man, if I actually knew who it was, I would have lost it last night. I would've been looking for them. xD😁
Jacob Foster11 Jacob Foster11 Active Member
132 messages
joined Nov 2007
#14 ·
Look, I’m not saying you can't save passwords on your computer or whatever. I keep mine saved and use cookies just fine. You just have to be careful what you're doing.

Regarding anything else related to this, you should probably head over to the IT Help Desk forum—specifically the Security subforum. There are people there who deal with this stuff constantly, so they might be able to help you out more effectively...
Sandra Ward Sandra Ward NewcomerOP
4 messages
joined Feb 2010
#15 ·
Jacob Foster11 said:Look, I’m not saying you should stop saving passwords on your PC or anything. I still have mine saved and I use cookies just like everyone else. You just have to be smart about how you handle things.

Regarding any other technical stuff related to this, you're probably better off heading over to the IT Help Desk subforum—specifically the Security section. There are people hanging out there who deal with this stuff all day, so they might actually be able to give you some real guidance...

Man, alright... I guess I'll just go ask them then. xD
Maybe I'll learn a thing or two from them too. 😁

Honestly, though, I've got them all sitting in a Notepad file... and I guess that's just how it's gonna be from now on. Everything is different—Facebook, the forums, my email, email, email... YouTube... everything is unique. If I keep using different ones for everything, even a locksmith couldn't crack my code. xD
Paul Green31 Paul Green31 Active Member
52 messages
joined Jun 2011
#16 ·
Sandra Ward said:Oh man... maybe I should just go ask them myself. xD
just to see if I can catch them 😁

I mean, even if I keep them all in a notepad... they're always changing. Facebook, forums, emails, emails, emails... YouTube... everything! xD It’s different every single time, it's enough to drive a guy crazy.

The admin could easily have a script on your computer that shoots those credentials straight to their email every time you log in.🙂
Get in touch with Security and have the guys take a look at it.👍
Sandra Ward Sandra Ward NewcomerOP
4 messages
joined Feb 2010
#17 ·
Paul Green31 said:The admin could have a script running on your computer that sends them an email every single time you log in.🙂
You should probably reach out to Security and have the guys there take a look at it.👍

Yeah... some kind of hacker nonsense xD

I could tell things were getting messy over there
😁 And honestly, if I ever caught that admin—that absolute clown who really needs to just go back to basics—I’d love to stomp all over him in my heels! Just saying.

😂
Paul Green31 Paul Green31 Active Member
52 messages
joined Jun 2011
#18 ·
Sandra Ward said:Yeah... caught up in some hacker nonsense again. xD

I heard it was a total disaster over there. 😁

If that absolute idiot ever crawled back to his tree, I’d personally stomp him under my high heels. Honestly, if I ever got my hands on him? Game over. 😂

You're better off just starting a new thread over there. But before you go hitting that "new topic" button, make sure you set it up exactly like this one. on this post Put those scenario logs in that thread.
Look, Dobrota will take a look at that for you and let you know what the next move is. 🙂
Sandra Ward Sandra Ward NewcomerOP
4 messages
joined Feb 2010
#19 ·
Paul Green31 said:It’s probably better if you just start a new thread over there. Before you do, set it up similar to this post and make sure to include the scenario logs in that new thread.
The Goodness forums staff will take a look at it then and let you know how to proceed. 🙂

I honestly have no clue what any of this means lol
but alright..

I guess I'll just link everything in a new thread then xD
assuming anyone actually understands me...
Zachary Barrett4 Zachary Barrett4 Member
22 messages
joined Jul 2010
#20 ·
It’s been happening more frequently over the last few days, and it seems like more and more users are getting caught up in it.

Does anyone know if there’s an official statement from Reddit regarding why people are suddenly losing access to their accounts?

You must log in or register to reply here.

Log in Register

🔗 Similar threads