Notices
Racing & Drivers Education Forum
Sponsored by:
Sponsored by:

Clubregistration Hacked?

Thread Tools
 
Search this Thread
 
Old 10-20-2016, 11:35 AM
  #1  
Wild Weasel
Drifting
Thread Starter
 
Wild Weasel's Avatar
 
Join Date: May 2016
Posts: 2,025
Received 298 Likes on 170 Posts
Default Clubregistration Hacked?

Hmph.

I just got spammed "Re: Salary [$900 /week]" at an email address that I've ONLY ever used to register for events on Club Registration.

Anyone here have any sort of official capacity with them?
Old 10-20-2016, 12:39 PM
  #2  
jlanka
Drifting
 
jlanka's Avatar
 
Join Date: Oct 2012
Location: Merrick, Long Island NY (Jeff)
Posts: 3,242
Received 78 Likes on 39 Posts
Default

I got the same one, except mine was for $1000 a week.

Old 10-20-2016, 12:40 PM
  #3  
Wild Weasel
Drifting
Thread Starter
 
Wild Weasel's Avatar
 
Join Date: May 2016
Posts: 2,025
Received 298 Likes on 170 Posts
Default

WTF?? I drive a cheaper car and suddenly they think they can win me over with less money??

I'm being oppressed!!
Old 10-20-2016, 12:43 PM
  #4  
txhokie4life
Drifting
 
txhokie4life's Avatar
 
Join Date: Dec 2009
Location: Austin, Texas
Posts: 2,140
Received 75 Likes on 59 Posts
Default

Apparently my car is so lame -- I'm not even spam worthy :-)

M
Old 10-20-2016, 01:45 PM
  #5  
NYoutftr
Rennlist Member
 
NYoutftr's Avatar
 
Join Date: Mar 2015
Location: Apalachin, New York
Posts: 2,335
Received 422 Likes on 245 Posts
Default

Originally Posted by txhokie4life
Apparently my car is so lame -- I'm not even spam worthy :-)

M


ME TOO!!

No offers for me, I must be deplorable
Old 10-21-2016, 11:23 AM
  #6  
Chris Alvarado
Instructor
 
Chris Alvarado's Avatar
 
Join Date: Aug 2006
Location: Austin, TX
Posts: 140
Likes: 0
Received 0 Likes on 0 Posts
Default

Ah the joys of running a website. We've just become aware of this issue. Rest assured that we do NOT have access to any of your financial information nor is any of it stored on our servers. Now I'm off to figure out how to patch that hole so it doesn't happen again. If you have any questions, you can contact me directly at 512-431-3143.

Chris Alvarado
ClubRegistration.net
Old 10-21-2016, 12:19 PM
  #7  
Wild Weasel
Drifting
Thread Starter
 
Wild Weasel's Avatar
 
Join Date: May 2016
Posts: 2,025
Received 298 Likes on 170 Posts
Default

Happy to hear that Chris. I was wondering about it but didn't really want to bring it up in public.
Old 08-08-2018, 04:27 PM
  #8  
Wild Weasel
Drifting
Thread Starter
 
Wild Weasel's Avatar
 
Join Date: May 2016
Posts: 2,025
Received 298 Likes on 170 Posts
Default

Dragging this back from the dead.

I never received any official notification about this hack but recently I started getting emails to this address that also included my password.

I ignored them at first figuring they were just more generic phishing spam but today checked, and lo and behold, it actually WAS my clubregistration password.

I've gone and changed it and thankfully don't use the same passwords everywhere, but if your database was stolen and you're storing passwords in plain text and that's out in the wild, your users really deserve to know about it!
Old 08-08-2018, 04:51 PM
  #9  
Sean F
NASA Racer
Rennlist Member
 
Sean F's Avatar
 
Join Date: Jul 2005
Location: Westchester, NY
Posts: 4,778
Received 33 Likes on 19 Posts
Default

yup - happened to me too this week...and I'm wondering what else they got...profile stores address, phone etc.
Old 08-08-2018, 05:32 PM
  #10  
calvarado312
2nd Gear
 
calvarado312's Avatar
 
Join Date: Aug 2018
Posts: 2
Likes: 0
Received 0 Likes on 0 Posts
Default

Wild Weasel and Sean,

First to answer your question. Yes, the passwords are encrypted. We believe this to be a small incident. That is why a large scale broadcast message was not sent out. That said we will be recommending that our users change their passwords. As for what can be stolen from ClubReg rest assured it isn't much. We do not store, nor have access to any of your financial data. Event payments are handled 100% through our merchant account and not us. If you have any questions you are welcome to contact me directly at 512-431-3143.

Thanks,

Chris Alvarado
ClubRegistration.net, CEO
512-431-3143
Old 08-08-2018, 06:02 PM
  #11  
Wild Weasel
Drifting
Thread Starter
 
Wild Weasel's Avatar
 
Join Date: May 2016
Posts: 2,025
Received 298 Likes on 170 Posts
Default

If they’re encrypted, do you know how they gained access to them?

Do they have your private keys too?
Old 08-08-2018, 07:44 PM
  #12  
serickson
Rennlist Member
 
serickson's Avatar
 
Join Date: May 2009
Location: IL
Posts: 298
Received 4 Likes on 4 Posts
Default

I believe my info also taken was sent emails about 3-4 weeks ago with my username and password. Immediately changed password.
Old 08-08-2018, 08:37 PM
  #13  
okie981
Rennlist Member
 
okie981's Avatar
 
Join Date: Jan 2016
Location: On a pygmy pony over by the dental floss bush
Posts: 3,287
Received 607 Likes on 416 Posts
Default

If everything was encrypted like email addresses, how could a hacker obtain it? I am really sick of websites leaving themselves open to hacking like this. Why isn't everything encrypted?
Old 08-09-2018, 07:57 AM
  #14  
Sean F
NASA Racer
Rennlist Member
 
Sean F's Avatar
 
Join Date: Jul 2005
Location: Westchester, NY
Posts: 4,778
Received 33 Likes on 19 Posts
Default

putting aside financial data, you do store address and phone number - correct? So if they have passwords, i'm guessing they have that info as well.
Old 08-09-2018, 03:35 PM
  #15  
ZAPmobile
Rennlist Member
 
ZAPmobile's Avatar
 
Join Date: Jan 2007
Location: Hillsborough, North Carolina
Posts: 889
Received 6 Likes on 3 Posts
Default

My wife (also a PCA member) and I reported this to the national office 3-4 weeks ago, and she identified the spam as coming from the club registration site. She asked that someone get back to her (never happened), and that a notice should be sent out to ALL people potentially affected by this hacking. Further, she strongly suggested that this be done ASAP. Last night, I received a similar message to hers, so clearly, in the interim 3-4 weeks, nothing has been done. Needless-to-say, she was less than amused and called PCA headquarters again today.

She was able to directly identify the password (in our case) as being unique to the club registration site, just in case anyone is wondering. The new hack is trying to extort money from members so it won't be published that they are looking at **** sites. In many cases, we are sure that this is not the case, as they claim to have noted on the supposedly hacked computers.


Quick Reply: Clubregistration Hacked?



All times are GMT -3. The time now is 01:13 AM.