Tapatalk gibt aktuell eine Warnmeldung für das eigene Support-Forum aus. Es wurde von Tapatalk ein Drittanbieter-Plugin genutzt, welches mit einem Exploit von einem Angreifer ausgenutzt wurde. Der Angreifer hat E-Mail-Adressen der Mitglieder sowie die verschlüsselten Passwörter gestohlen.
Der Angriff soll kurz vor dem 9. Dezember stattgefunden haben und die Angreifer haben die Passwörter in Klartext entwendet, wenn ihr euch ab dem 9. Dezember in dem Support-Forum von Tapatalk eingeloggt habt. Es wird dringend gebeten das Passwort zu ändern.
Die Zugangsdaten der App sollen nicht betroffen sein.
Zitat
What happened was that someone used an exploit in a non-Tapatalk bit of code to gain access to the database on the support forum were they extracted from the database amongst things, encrypted passwords but they also modified Xenforo on the evening (US time) of December 10th so that it logged unencrypted passwords when you logged in. These were streamed off directly to a server in Sweden.Only the support forums were affected, not the admin panel (unless you use the same password everywhere, a very bad practice) and not the Tapatalk plugin installed onto your site or the app on your phone.
The timing wasn't great, I agree. I found the intrusion early European time over a weekend and sent out the emails as soon as I could, to be completely open and honest. The team on US time will be addressing issues as they roll in here.
ZitatAlles anzeigen
If you have a login on support.tapatalk.com then you are affected. If you last logged in over 4 days ago, then it is unlikely your password has been disclosed as it was encrypted. If you logged in on (or since) the 10th of December then your password has been available in clear text to a person operating a server from SwedenThe logins to support.tapatalk.com and every other tapatalk system are NOT related unless you used the same email address and password.
Affected
– support.tapatalk.comUnaffected
– terminus_hammerhead-ota-2014-12-13.zip - 181.5MB
– Admin control panels.
– Tapatalk plugins
– Tapatalk mobile appsIf you log in via the app using google+/facebook (etc), then I will have to ask the devs to provide an exact answer as to how the one time tokens are passed from the external authentication providers to forums and how they are stored and then authenticated back
Um das Passwort zu ändern geht hier zur [size=18]Tapatalk Login-Seite[/SIZE]!
Gruß
euer Soulfly999
[size=12]Quelle: [DLMURL="http://stadt-bremerhaven.de/tapatalk-forum-mail-adressen/"]Caschy [/DLMURL]| Tapatalk[/SIZE]