Open Side Menu Go to the Top
Register
Cardrunners (& possibly PTR) hacked Cardrunners (& possibly PTR) hacked

05-13-2011 , 02:12 PM
Quote:
Originally Posted by kratos
Without any real proof not really. Should get a comment from PTR if they have shared the emails with any external firm.. like Epsilon.
Read the 2 threads on this, more people are getting it from PTR associated emails than CR.

http://forumserver.twoplustwo.com/28...tolen-1035705/

Quote:
Originally Posted by Foxtorpedo
CR associated email is not getting these emails.

Email associated with PTR is being bombed, cant remember if I've used this with any other poker related things.
Cardrunners (& possibly PTR) hacked Quote
05-13-2011 , 03:33 PM
I have received the 'Gambler X' emails too, although now they seem to have stopped. I've never signed up for any Cardrunners but have PTR basic.

Presumably, getting spammed doesn't neccesarily prove passwords have been compromised, just user email details? It would be helpful if PTR would confirm if account details have been hacked and what info has been revealed.
Cardrunners (& possibly PTR) hacked Quote
05-13-2011 , 05:44 PM
Quote:
Originally Posted by jonK
It would be helpful if PTR said anything at all FFS
FYP
Cardrunners (& possibly PTR) hacked Quote
05-13-2011 , 10:13 PM
I have different emails for CR and PTR. The PTR email got the gambler spam, CR one didn't.
Cardrunners (& possibly PTR) hacked Quote
05-13-2011 , 10:59 PM
PTR sent a mass email about it. So yes PTR was hacked.
Cardrunners (& possibly PTR) hacked Quote
05-14-2011 , 12:00 AM
Quote:
Security Notice Regarding Your PTR Account
Dear Valued PokerTableRatings.com Member,
We have reason to believe that PokerTableRatings.com has been targeted as part of a recent attack on poker websites. For your security we want to bring this matter to your attention. We have addressed the issue and are actively improving security on our servers to prevent future intrusions.
As a result of this malicious activity, user information for a minority of users may have been compromised. No credit card information is at risk as we use Authorize.net, a secure third party payment processor, to handle all of our member's credit card transactions.
PTR takes your security and privacy very seriously. Although passwords are encrypted, we highly recommend you change your password on your next visit to PokerTableRatings.com. The password can be changed on your "My PTR" page.
We deeply regret this has taken place and apologize for any inconvenience this may have caused you. We will continue to work diligently to protect your personal information.
If you have any questions or concerns, please do not hesitate to contact us at info@pokertableratings.com.
Sincerely,
The PTR Team
Blah blah blah.

1. Which encryption method for the password tables?
2. Were email and IP addresses stored as plain text? If so, for which period of time?
Cardrunners (& possibly PTR) hacked Quote
05-14-2011 , 08:00 AM
Quote:
Originally Posted by 2ndUnit
I never had a Cardrunners account, but i am getting the gamblerxxx spam since yesterday.
I have a basic PTR account with that e-mail adress.
+1
Cardrunners (& possibly PTR) hacked Quote
05-14-2011 , 08:37 AM
I have a different email for PTR and just seen that it's been gambler spammed also.
Cardrunners (& possibly PTR) hacked Quote
05-14-2011 , 09:13 AM
Getting a ton of spam from GamblerX so changed all passwords just to be safe. As I was at it I changed all email passwords and master passwords. LastPass was in trouble last week and had to change passwords there too.

Using Lastpass is handy but also dangerous imo and judging by last week nobody is safe on da interweb anymore.

This site is probably a big target too I guess?
Cardrunners (& possibly PTR) hacked Quote
05-14-2011 , 09:39 AM
It's weird, myself and 2 friends all have accounts on both CR and PTR and none of us have any spam at all. Maybe because we're from the UK? Just seems weird...
Cardrunners (& possibly PTR) hacked Quote
05-14-2011 , 09:54 AM
Quote:
Originally Posted by TaliskerBA
It's weird, myself and 2 friends all have accounts on both CR and PTR and none of us have any spam at all. Maybe because we're from the UK? Just seems weird...
Nothing to do with region I'd say. Im from Ireland and got spam sent to 3/4 acc's. I use gmail and all of it was filtered to the spam folder so I found it in there. One of my email acc's had ~50 spam from gamblerX
Cardrunners (& possibly PTR) hacked Quote
05-14-2011 , 10:04 AM
Quote:
Originally Posted by Outcast10
Nothing to do with region I'd say. Im from Ireland and got spam sent to 3/4 acc's. I use gmail and all of it was filtered to the spam folder so I found it in there. One of my email acc's had ~50 spam from gamblerX
Yeah we've all checked our spam, nothing is in there. Maybe it's still to come...
Cardrunners (& possibly PTR) hacked Quote
05-14-2011 , 10:09 AM
Quote:
Originally Posted by TaliskerBA
Yeah we've all checked our spam, nothing is in there. Maybe it's still to come...
Maybe they didnt get around to you yet lol. Got an email from PTR this morning asking that I change my passwords. You should probably change yours just to be safe.
Cardrunners (& possibly PTR) hacked Quote
05-14-2011 , 10:26 AM
Quote:
Originally Posted by Outcast10
Getting a ton of spam from GamblerX so changed all passwords just to be safe. As I was at it I changed all email passwords and master passwords. LastPass was in trouble last week and had to change passwords there too.

Using Lastpass is handy but also dangerous imo and judging by last week nobody is safe on da interweb anymore.

This site is probably a big target too I guess?
Lastpass was fine once you followed advice about having a good master password and even safer if you had a Ubikey.

It is certainly much safer than remembering passwords for each site. Also their security breach showed that even if the PW were taken it was still safe.
Cardrunners (& possibly PTR) hacked Quote
05-14-2011 , 10:37 AM
Google Chrome is flagging the renewal page as non-secure (on Cardrunners). Need to renew in the next 3 days, any idea on if/when it's safe to do so?
Cardrunners (& possibly PTR) hacked Quote
05-14-2011 , 04:35 PM
Quote:
Originally Posted by one_lion
Google Chrome is flagging the renewal page as non-secure (on Cardrunners). Need to renew in the next 3 days, any idea on if/when it's safe to do so?
Might as well go with bluefirepoker
Cardrunners (& possibly PTR) hacked Quote
05-14-2011 , 04:39 PM
I am no longer getting the Gambler emails... they started on Tuesday and ended on Thursday.
Cardrunners (& possibly PTR) hacked Quote
05-14-2011 , 07:28 PM
Quote:
Originally Posted by SuttonS
Right click the e-mail, rules, create rule, advanced options, with specific words in the sender's address, click "specific words" in the lower box. Type "gambler" then click add, type "casino" then hit add. Click next, check move it to the specified folder, click "specified" in the bottom box, Junk E-mail (or where ever) then OK. Then you can make exceptions if you want (I didn't) Then click next, then finish.

To run the rule, you may have to right click, rules, manage rules, "run rules now." I'm not quite sure yet if they run automatically.

BTW this is all in Outlook 2010, not sure how to do it in other versions.
I did sorta the same thing with my Yahoo account ages ago since no gaming company I'm associated with would use terms like "gamble" "gambler" "casino" "slots" etc etc... Not just to filter to a spam folder, but they are instantly sent to the trash. I just looked through my spam folder and I don't see any of the "gambler xxxx" spam emails, and nothing with attachments. I had a CR account from ages ago that I have never really used, but do have an active PTR account.

While I'm not getting spam, I did change my PW for all important sites since had I changed them all to the same thing when my drug use kept me from remembering anything complicated. Before that I'd used absurdly complex passwords, then one day I ended up washing jeans with my last password list in the pocket...

So basically... Use strong passwords and don't use the same one twice for any account that could give a hacker access to more important info (that includes being connected to the email address you use for poker or banking). Also, don't do stupid amounts of drugs.
Cardrunners (& possibly PTR) hacked Quote
05-14-2011 , 07:34 PM
Quote:
Originally Posted by one_lion
Google Chrome is flagging the renewal page as non-secure (on Cardrunners). Need to renew in the next 3 days, any idea on if/when it's safe to do so?
Should be no problems here but I will check to make sure.
Cardrunners (& possibly PTR) hacked Quote
05-14-2011 , 10:08 PM
Quote:
Originally Posted by wellju
Blah blah blah.

1. Which encryption method for the password tables?
2. Were email and IP addresses stored as plain text? If so, for which period of time?
I got this too. The unsubscribe addy and domains names don't match PTR though....phishing?.
Cardrunners (& possibly PTR) hacked Quote
05-15-2011 , 01:08 PM
Quote:
Originally Posted by one_lion
Google Chrome is flagging the renewal page as non-secure (on Cardrunners). Need to renew in the next 3 days, any idea on if/when it's safe to do so?
Just make sure you are viewing the page with "https" instead of "http" -- we haven't heard of any issues with this but check on that and you should be fine.
Cardrunners (& possibly PTR) hacked Quote
05-15-2011 , 01:56 PM
it says https but it's crossed out

chrome's explanation for the crossing out is here

http://www.google.com/support/chrome...95617&hl=en-US

Quote:
The site uses SSL, but Google Chrome has detected either high-risk insecure content on the page or problems with the site’s certificate. Don’t enter sensitive information on this page. Invalid certificate or other serious https issues could indicate that someone is attempting to tamper with your connection to the site.
Cardrunners (& possibly PTR) hacked Quote
05-15-2011 , 02:31 PM
Very poor response from PTR. They took forever to say anything, and they haven't clarified what information was compromised.
Cardrunners (& possibly PTR) hacked Quote
05-15-2011 , 03:09 PM
Quote:
Originally Posted by JoeyJoJo Shabadu
I got this too. The unsubscribe addy and domains names don't match PTR though....phishing?.
No, that's just because they're lazy, greedy and possibly handling customer data with no regard to security/privacy at all.

You can use the link to unsubscribe.

Quote:
Originally Posted by NoahSD
Very poor response from PTR. They took forever to say anything, and they haven't clarified what information was compromised.
They're basically pulling an Sebok on us.

Acting as white knight to go trough the swamps of corruption in this industry while only trying to make profit for them selves.
Cardrunners (& possibly PTR) hacked Quote
05-15-2011 , 04:08 PM
Looks like the Gambler email spam has stopped? Was getting several a day, haven't got one since a few days ago now? Anyone else?
Cardrunners (& possibly PTR) hacked Quote

      
m