boincstats: security problem or normal behaviour?

Message boards : Number crunching : boincstats: security problem or normal behaviour?

To post messages, you must log in.

AuthorMessage
Alexander Nagel

Send message
Joined: 11 Aug 06
Posts: 3
Credit: 2,020,149
RAC: 0
Message 69724 - Posted: 4 Mar 2011, 10:31:13 UTC

Hi @ all,

i have a link to my current stats banner embedded on my website. It was this link for month

http://www.boincstats.com/signature/user_818540.gif

Now the number changed and my banner has this link

http://www.boincstats.com/signature/user_75375.gif

Is this a normal behaviour or a security problem of boincstats server??

regards
Alex
ID: 69724 · Rating: 0 · rate: Rate + / Rate - Report as offensive    Reply Quote
mikey
Avatar

Send message
Joined: 5 Jan 06
Posts: 1895
Credit: 9,177,390
RAC: 3,144
Message 69725 - Posted: 4 Mar 2011, 11:10:12 UTC - in response to Message 69724.  

Hi @ all,

i have a link to my current stats banner embedded on my website. It was this link for month

http://www.boincstats.com/signature/user_818540.gif

Now the number changed and my banner has this link

http://www.boincstats.com/signature/user_75375.gif

Is this a normal behaviour or a security problem of boincstats server??

regards
Alex


That depends is your name Alex or geri? If it is Alex then change it back and see if it changes again, if so your account has been compromised and you should change the password IMMEDIATELY!! Boincstats IS having problems at the moment but the file name should not have changed on a website that is not theirs.
ID: 69725 · Rating: 0 · rate: Rate + / Rate - Report as offensive    Reply Quote
Alexander Nagel

Send message
Joined: 11 Aug 06
Posts: 3
Credit: 2,020,149
RAC: 0
Message 69726 - Posted: 4 Mar 2011, 11:28:32 UTC - in response to Message 69725.  

Hi @ all,

i have a link to my current stats banner embedded on my website. It was this link for month

http://www.boincstats.com/signature/user_818540.gif

Now the number changed and my banner has this link

http://www.boincstats.com/signature/user_75375.gif

Is this a normal behaviour or a security problem of boincstats server??

regards
Alex


That depends is your name Alex or geri? If it is Alex then change it back and see if it changes again, if so your account has been compromised and you should change the password IMMEDIATELY!! Boincstats IS having problems at the moment but the file name should not have changed on a website that is not theirs.


Thanks for your answer. I am Alexander and not geri. Perhaps I was not totally clear about this.
My current link to my banner, which is shown/proposed in the boincstats website is
http://www.boincstats.com/signature/user_75375.gif

But weeks ago it was the other one. And this other one is now geri.
By the way the website i copied the link into, wasn't compromised. I just checked that.
And I doubt that my boinc account was hacked because there is still my name and not "geri"


ID: 69726 · Rating: 0 · rate: Rate + / Rate - Report as offensive    Reply Quote
Link
Avatar

Send message
Joined: 4 May 07
Posts: 356
Credit: 382,349
RAC: 0
Message 69728 - Posted: 4 Mar 2011, 22:40:06 UTC
Last modified: 4 Mar 2011, 22:44:03 UTC

Had the same problem, my old 5xxxxx number (don't know it exactly anymore) changed to http://www.boincstats.com/signature/user_91632.gif.

I don't think this is normal behaviour or a security problem (no other details changed) but some weird problem with their server.

The strange thing is that our BOINCstats ID obviously changed to our "BOINC World position based on credit" at that moment... which must have been somewhere between the 2011-03-02 and 2011-03-03.
.
ID: 69728 · Rating: 0 · rate: Rate + / Rate - Report as offensive    Reply Quote
Tony DeBari

Send message
Joined: 13 Apr 06
Posts: 12
Credit: 2,944,090
RAC: 0
Message 69729 - Posted: 4 Mar 2011, 22:44:02 UTC

The same thing happened to me. I have my BoincStats page bookmarked in my browser, and a couple of days ago clicking on the bookmark opened someone else's stats page. From what I picked up by reading the "shout-out box" on BoincStats, they have recently recovered from some sort of serious database issue. It looks like everyone's BoincStats user ID has changed as a result. I was finally able to find my stats (and my new user ID) by doing a BoincStats search for my BOINC user name.

I take it, then, that this database issue and subsequent aftermath haven't been widely publicized, so I'm sure there are an awful lot of confused BoincStats user out there right now...


-- Tony D.


ID: 69729 · Rating: 0 · rate: Rate + / Rate - Report as offensive    Reply Quote
Link
Avatar

Send message
Joined: 4 May 07
Posts: 356
Credit: 382,349
RAC: 0
Message 69730 - Posted: 4 Mar 2011, 22:57:26 UTC - in response to Message 69729.  

I have my BoincStats page bookmarked in my browser, and a couple of days ago clicking on the bookmark opened someone else's stats page.

Use your CPID in the bookmark, than that won't happen, even if the BOINCstats ID changes. Yours would be http://boincstats.com/stats/boinc_user_graph.php?pr=bo&id=2ab6d12b4a2abd595198381028dac738


_
.
ID: 69730 · Rating: 0 · rate: Rate + / Rate - Report as offensive    Reply Quote
TPCBF

Send message
Joined: 29 Nov 10
Posts: 111
Credit: 5,085,161
RAC: 1,288
Message 69733 - Posted: 5 Mar 2011, 6:05:03 UTC

The maintainer of the boincstats site stated in a news/forum post that after a recent server crash a few days ago, the IDs of the graphics have been renumbered and since then, there seems to be a major mixup with those stats graphics links...

Ralf
ID: 69733 · Rating: 0 · rate: Rate + / Rate - Report as offensive    Reply Quote
Profile Chilean
Avatar

Send message
Joined: 16 Oct 05
Posts: 711
Credit: 26,694,507
RAC: 0
Message 69734 - Posted: 5 Mar 2011, 6:55:17 UTC

BOINCStats showed some pretty high RAC coming from me in climateprediction... I checked my account there and had the RAC @ 0.

They must be having some problems.
ID: 69734 · Rating: 0 · rate: Rate + / Rate - Report as offensive    Reply Quote
Tony DeBari

Send message
Joined: 13 Apr 06
Posts: 12
Credit: 2,944,090
RAC: 0
Message 69744 - Posted: 6 Mar 2011, 7:21:00 UTC - in response to Message 69730.  

I have my BoincStats page bookmarked in my browser, and a couple of days ago clicking on the bookmark opened someone else's stats page.

Use your CPID in the bookmark, than that won't happen, even if the BOINCstats ID changes. Yours would be http://boincstats.com/stats/boinc_user_graph.php?pr=bo&id=2ab6d12b4a2abd595198381028dac738

_


I didn't know you could do that. Thanks for the tip!


-- Tony D.

ID: 69744 · Rating: 0 · rate: Rate + / Rate - Report as offensive    Reply Quote
Alexander Nagel

Send message
Joined: 11 Aug 06
Posts: 3
Credit: 2,020,149
RAC: 0
Message 69746 - Posted: 6 Mar 2011, 10:10:33 UTC - in response to Message 69744.  

Thank you everybody for the feedback. I didn't know that there was a database issue. At least nice to know that I was not the only one suffering with this problem.

I have my BoincStats page bookmarked in my browser, and a couple of days ago clicking on the bookmark opened someone else's stats page.

Use your CPID in the bookmark, than that won't happen, even if the BOINCstats ID changes. Yours would be http://boincstats.com/stats/boinc_user_graph.php?pr=bo&id=2ab6d12b4a2abd595198381028dac738

_


I didn't know you could do that. Thanks for the tip!
-- Tony D.

me too. Thanks for th tip from here as well.

Alex
ID: 69746 · Rating: 0 · rate: Rate + / Rate - Report as offensive    Reply Quote

Message boards : Number crunching : boincstats: security problem or normal behaviour?



©2024 University of Washington
https://www.bakerlab.org