Skip to comments.
Old Freeper Accounts Hijacked?
Original Content
| 03/16/2025
| By Laz A. Mataz
Posted on 03/16/2025 6:09:41 AM PDT by Lazamataz
I've noticed, over the years, that very old Free Republic accounts, accounts that have been inactive for months or years, suddenly reactivate.... but their politics are suddenly suspect.
Be they Zeeper-oriented (that is, super-favorable to Ukraine) or, conversely, super-favorable to Russia, or even suddenly-liberal... these accounts reactivate with a flurry of posts that are contrary to conservatism.
Are these real Freepers who have had a change of heart about their politics? Are these real Freepers who feel the need to jump on the forum with propaganda and support for one side or the other per the Ukraine/Russia war?
Or are these hijacked accounts?
People will recall some time back, quite a few accounts of active Freepers were hijacked. It created a bit of a problem. When all was said and done, the accounts were returned to their rightful owners, and the site owner (and his moderator crew) pointed out that their passwords were very easy to guess. He instructed people to have stronger passwords.
I also have a friend on Facebook who no longer participates in the forum, but still reads it, who has seen a Freeper posting who he happens to know has been dead for more than a decade.
The problem is, we have far too insecure a login process, and enemies of the forum have been exploiting that.
At the login page, you can attempted unlimited login attempts. This will allow simple brute-force password cracking.
Also, the Forget Password option sends an email with your password in clear text. Emails can easily be sniffed with the right techniques. Passwords can easily be cracked that way.
My suggestions to mitigate these critical security concerns are:- -- Limit login attempts to five, after which the account is suspended until unlocked. What unlocking consists of can be anything. One suggestion is that the account is auto-disabled for a day. That means a hacker will only get five brute-force attempts in any given 24 hour period.
- -- Install two-factor authentication, in which a text number is sent to a phone the user possesses.
- -- Emails for Forget Password should not send the actual password, but instead, a link to a page on FR that allows a reset of the password.
These relatively-simple security changes will stop account-hijacking.
TOPICS: Chit/Chat; Conspiracy; Weird Stuff
KEYWORDS: bitchassstalker; comingafterustalker; cowardlystalker; diekeywordstalker; doxthestalker; freerepublic; hereiskeywordstalker; iwillfindustalker; karensunite; keywordstalker; keywordstalkerbitch; keywordstalkerpunk; keywordstalkers; nobodyshacked; papersplease; peoplegettignold; punkstalker; seeyourpapers; showyourselfstalker; stalkeriscoward; stupidvanity; yournextstalker
Navigation: use the links below to view more comments.
first previous 1-20 ... 81-100, 101-120, 121-140 ... 341-357 next last
To: NoLongerTrappedInNY
Same. It is like we have a leak.
To: NoLongerTrappedInNY; Lazamataz
... invariably, their profile shows them joining between 1998 to 2002.
A newer account can have the signup date modified with the simplest of SQL statements. I wonder how many people actually have access to do that.
102
posted on
03/16/2025 7:17:16 AM PDT
by
bankwalker
(Repeal the 19th ...)
To: madison10; 7thOF7th
This year was the first time I was called nasty stuff. I don’t think it was warranted. I thought it was against the rules. The person should have been zotted, but wasn’t.Speaking of being called nasty stuff, on this VERY THREAD I was accused of fanciestism.
I am a member of AntiFancy, so this was wounding to me.
103
posted on
03/16/2025 7:19:11 AM PDT
by
Lazamataz
(I'm so on fire that I feel the need to stop, drop, and roll!)
To: miniTAX
every combination doesn’t need to be tried ... only until you get a hit ...
104
posted on
03/16/2025 7:19:24 AM PDT
by
bankwalker
(Repeal the 19th ...)
To: bankwalker
A newer account can have the signup date modified with the simplest of SQL statements. Sure, but I'm fairly certain that SQL injection is covered here.
105
posted on
03/16/2025 7:19:57 AM PDT
by
Lazamataz
(I'm so on fire that I feel the need to stop, drop, and roll!)
To: Lazamataz
Hey! It took over a year to convince JR to let me back on. This is really me.
106
posted on
03/16/2025 7:20:48 AM PDT
by
GingisK
To: Lazamataz
I know! That is disgusting! You are not in the least fancy.
To: OwenKellogg
Um, holy crap. Grok analyzed my sarcastic and irreverent style rater well. That, frankly, amazes me.
108
posted on
03/16/2025 7:21:25 AM PDT
by
Lazamataz
(I'm so on fire that I feel the need to stop, drop, and roll!)
To: Lazamataz
how many people have access? mods, etc.?
109
posted on
03/16/2025 7:21:59 AM PDT
by
bankwalker
(Repeal the 19th ...)
To: GingisK
Hey! It took over a year to convince JR to let me back on. This is really me.How can we be sure you are you? You could be a fanciest.
110
posted on
03/16/2025 7:22:07 AM PDT
by
Lazamataz
(I'm so on fire that I feel the need to stop, drop, and roll!)
To: Lazamataz
I have a strong password generated by Apple iOS so I feel relatively safe.
111
posted on
03/16/2025 7:22:08 AM PDT
by
telescope115
(I NEED MY SPACE!!! 🔭)
To: Lazamataz
I just changed my password to something tougher. Thanks for the heads-up.
112
posted on
03/16/2025 7:22:15 AM PDT
by
Slings and Arrows
(My music: http://hopalongginsberg.com/ | http://mewe.com/i/hopalongginsberg)
To: OwenKellogg
That is hysterical. Laz is making unfancy fancy.
113
posted on
03/16/2025 7:22:20 AM PDT
by
Kudsman
(Democrats' brand is FRAUD. Elections, biology, climate, journalism, auto pen, peace, life and God. )
To: Lazamataz
114
posted on
03/16/2025 7:22:40 AM PDT
by
OwenKellogg
(...if my people, who are called by my name...)
To: Lazamataz
BTW, I think that the sign-on username should not be the Freeper name.
Meaning, I much prefer using a password generator to create each of:
- account username
- account password
Thus, both of those, are known only to the account holder.
To: Lazamataz; 7thOF7th
Congratulations Laz! You outed one with very little trouble. The quick temper and illogic reasoning are sure signs. We'll keep an eye for ol' No. 7.
116
posted on
03/16/2025 7:24:38 AM PDT
by
BipolarBob
(Whoever said "out of sight, out of mind" never had a snake disappear in their bedroom.)
To: telescope115; Slings and Arrows
I just changed my password to something tougher. Thanks for the heads-up.That's great, but be aware, your password can be sent to you IN CLEAR TEXT by email. Emails go through a lot of hands before you get it, and at any step, the email can be sniffed, and your password compromised. This is why I'm advising JohnRob to, instead, do password-reset links in emails. Maybe also password-recovery questions, like "What was the name of your first cat" and stuff like that.
117
posted on
03/16/2025 7:25:15 AM PDT
by
Lazamataz
(I'm so on fire that I feel the need to stop, drop, and roll!)
To: Lazamataz
“Within a day, I suddenly ‘bought’ Air Italia airline tickets and several expensive suits in Milan.
I’ve never been to Milan.
Lucky you. I never could afford a cool Italian suit. See, you really ARE a fanciest.
118
posted on
03/16/2025 7:25:42 AM PDT
by
Nik Naym
(It's not my fault... I have compulsive smart-ass disorder. )
To: linMcHlp
BTW, I think that the sign-on username should not be the Freeper name. Meaning, I much prefer using a password generator to create each of: - account username - account password Thus, both of those, are known only to the account holder.Great idea! Thanks!
(However, that might be a heck of a lot of development work)
119
posted on
03/16/2025 7:26:25 AM PDT
by
Lazamataz
(I'm so on fire that I feel the need to stop, drop, and roll!)
To: central_va
Traitor! You’ve given everyone my passwords. I’m screwed.
120
posted on
03/16/2025 7:26:33 AM PDT
by
BipolarBob
(Whoever said "out of sight, out of mind" never had a snake disappear in their bedroom.)
Navigation: use the links below to view more comments.
first previous 1-20 ... 81-100, 101-120, 121-140 ... 341-357 next last
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson