Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Old Freeper Accounts Hijacked?
Original Content | 03/16/2025 | By Laz A. Mataz

Posted on 03/16/2025 6:09:41 AM PDT by Lazamataz

I've noticed, over the years, that very old Free Republic accounts, accounts that have been inactive for months or years, suddenly reactivate.... but their politics are suddenly suspect.

Be they Zeeper-oriented (that is, super-favorable to Ukraine) or, conversely, super-favorable to Russia, or even suddenly-liberal... these accounts reactivate with a flurry of posts that are contrary to conservatism.

Are these real Freepers who have had a change of heart about their politics? Are these real Freepers who feel the need to jump on the forum with propaganda and support for one side or the other per the Ukraine/Russia war?

Or are these hijacked accounts?

People will recall some time back, quite a few accounts of active Freepers were hijacked. It created a bit of a problem. When all was said and done, the accounts were returned to their rightful owners, and the site owner (and his moderator crew) pointed out that their passwords were very easy to guess. He instructed people to have stronger passwords.

I also have a friend on Facebook who no longer participates in the forum, but still reads it, who has seen a Freeper posting who he happens to know has been dead for more than a decade.

The problem is, we have far too insecure a login process, and enemies of the forum have been exploiting that.

At the login page, you can attempted unlimited login attempts. This will allow simple brute-force password cracking.

Also, the Forget Password option sends an email with your password in clear text. Emails can easily be sniffed with the right techniques. Passwords can easily be cracked that way.

My suggestions to mitigate these critical security concerns are:

  1. -- Limit login attempts to five, after which the account is suspended until unlocked. What unlocking consists of can be anything. One suggestion is that the account is auto-disabled for a day. That means a hacker will only get five brute-force attempts in any given 24 hour period.
  2. -- Install two-factor authentication, in which a text number is sent to a phone the user possesses.
  3. -- Emails for Forget Password should not send the actual password, but instead, a link to a page on FR that allows a reset of the password.

These relatively-simple security changes will stop account-hijacking.


TOPICS: Chit/Chat; Conspiracy; Weird Stuff
KEYWORDS: bitchassstalker; comingafterustalker; cowardlystalker; diekeywordstalker; doxthestalker; freerepublic; hereiskeywordstalker; iwillfindustalker; karensunite; keywordstalker; keywordstalkerbitch; keywordstalkerpunk; keywordstalkers; nobodyshacked; papersplease; peoplegettignold; punkstalker; seeyourpapers; showyourselfstalker; stalkeriscoward; stupidvanity; yournextstalker
Navigation: use the links below to view more comments.
first previous 1-20 ... 81-100101-120121-140 ... 341-357 next last
To: NoLongerTrappedInNY

Same. It is like we have a leak.


101 posted on 03/16/2025 7:17:04 AM PDT by madison10
[ Post Reply | Private Reply | To 83 | View Replies]

To: NoLongerTrappedInNY; Lazamataz
... invariably, their profile shows them joining between 1998 to 2002.

A newer account can have the signup date modified with the simplest of SQL statements. I wonder how many people actually have access to do that.
102 posted on 03/16/2025 7:17:16 AM PDT by bankwalker (Repeal the 19th ...)
[ Post Reply | Private Reply | To 83 | View Replies]

To: madison10; 7thOF7th
This year was the first time I was called nasty stuff. I don’t think it was warranted. I thought it was against the rules. The person should have been zotted, but wasn’t.

Speaking of being called nasty stuff, on this VERY THREAD I was accused of fanciestism.

I am a member of AntiFancy, so this was wounding to me.

103 posted on 03/16/2025 7:19:11 AM PDT by Lazamataz (I'm so on fire that I feel the need to stop, drop, and roll!)
[ Post Reply | Private Reply | To 98 | View Replies]

To: miniTAX

every combination doesn’t need to be tried ... only until you get a hit ...


104 posted on 03/16/2025 7:19:24 AM PDT by bankwalker (Repeal the 19th ...)
[ Post Reply | Private Reply | To 94 | View Replies]

To: bankwalker
A newer account can have the signup date modified with the simplest of SQL statements.

Sure, but I'm fairly certain that SQL injection is covered here.

105 posted on 03/16/2025 7:19:57 AM PDT by Lazamataz (I'm so on fire that I feel the need to stop, drop, and roll!)
[ Post Reply | Private Reply | To 102 | View Replies]

To: Lazamataz

Hey! It took over a year to convince JR to let me back on. This is really me.


106 posted on 03/16/2025 7:20:48 AM PDT by GingisK
[ Post Reply | Private Reply | To 1 | View Replies]

To: Lazamataz

I know! That is disgusting! You are not in the least fancy.


107 posted on 03/16/2025 7:20:52 AM PDT by madison10
[ Post Reply | Private Reply | To 103 | View Replies]

To: OwenKellogg

Um, holy crap. Grok analyzed my sarcastic and irreverent style rater well. That, frankly, amazes me.


108 posted on 03/16/2025 7:21:25 AM PDT by Lazamataz (I'm so on fire that I feel the need to stop, drop, and roll!)
[ Post Reply | Private Reply | To 99 | View Replies]

To: Lazamataz

how many people have access? mods, etc.?


109 posted on 03/16/2025 7:21:59 AM PDT by bankwalker (Repeal the 19th ...)
[ Post Reply | Private Reply | To 105 | View Replies]

To: GingisK
Hey! It took over a year to convince JR to let me back on. This is really me.

How can we be sure you are you? You could be a fanciest.

110 posted on 03/16/2025 7:22:07 AM PDT by Lazamataz (I'm so on fire that I feel the need to stop, drop, and roll!)
[ Post Reply | Private Reply | To 106 | View Replies]

To: Lazamataz

I have a strong password generated by Apple iOS so I feel relatively safe.


111 posted on 03/16/2025 7:22:08 AM PDT by telescope115 (I NEED MY SPACE!!! 🔭)
[ Post Reply | Private Reply | To 100 | View Replies]

To: Lazamataz

I just changed my password to something tougher. Thanks for the heads-up.


112 posted on 03/16/2025 7:22:15 AM PDT by Slings and Arrows (My music: http://hopalongginsberg.com/ | http://mewe.com/i/hopalongginsberg)
[ Post Reply | Private Reply | To 1 | View Replies]

To: OwenKellogg

That is hysterical. Laz is making unfancy fancy.


113 posted on 03/16/2025 7:22:20 AM PDT by Kudsman (Democrats' brand is FRAUD. Elections, biology, climate, journalism, auto pen, peace, life and God. )
[ Post Reply | Private Reply | To 99 | View Replies]

To: Lazamataz

A little scary.


114 posted on 03/16/2025 7:22:40 AM PDT by OwenKellogg (...if my people, who are called by my name...)
[ Post Reply | Private Reply | To 108 | View Replies]

To: Lazamataz

BTW, I think that the sign-on username should not be the Freeper name.

Meaning, I much prefer using a password generator to create each of:

- account username
- account password

Thus, both of those, are known only to the account holder.


115 posted on 03/16/2025 7:23:13 AM PDT by linMcHlp
[ Post Reply | Private Reply | To 63 | View Replies]

To: Lazamataz; 7thOF7th
Congratulations Laz! You outed one with very little trouble. The quick temper and illogic reasoning are sure signs. We'll keep an eye for ol' No. 7.


116 posted on 03/16/2025 7:24:38 AM PDT by BipolarBob (Whoever said "out of sight, out of mind" never had a snake disappear in their bedroom.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: telescope115; Slings and Arrows
I just changed my password to something tougher. Thanks for the heads-up.

That's great, but be aware, your password can be sent to you IN CLEAR TEXT by email. Emails go through a lot of hands before you get it, and at any step, the email can be sniffed, and your password compromised. This is why I'm advising JohnRob to, instead, do password-reset links in emails. Maybe also password-recovery questions, like "What was the name of your first cat" and stuff like that.

117 posted on 03/16/2025 7:25:15 AM PDT by Lazamataz (I'm so on fire that I feel the need to stop, drop, and roll!)
[ Post Reply | Private Reply | To 111 | View Replies]

To: Lazamataz

“Within a day, I suddenly ‘bought’ Air Italia airline tickets and several expensive suits in Milan.

I’ve never been to Milan.

Lucky you. I never could afford a cool Italian suit. See, you really ARE a fanciest.


118 posted on 03/16/2025 7:25:42 AM PDT by Nik Naym (It's not my fault... I have compulsive smart-ass disorder. )
[ Post Reply | Private Reply | To 86 | View Replies]

To: linMcHlp
BTW, I think that the sign-on username should not be the Freeper name. Meaning, I much prefer using a password generator to create each of: - account username - account password Thus, both of those, are known only to the account holder.

Great idea! Thanks!

(However, that might be a heck of a lot of development work)

119 posted on 03/16/2025 7:26:25 AM PDT by Lazamataz (I'm so on fire that I feel the need to stop, drop, and roll!)
[ Post Reply | Private Reply | To 115 | View Replies]

To: central_va

Traitor! You’ve given everyone my passwords. I’m screwed.


120 posted on 03/16/2025 7:26:33 AM PDT by BipolarBob (Whoever said "out of sight, out of mind" never had a snake disappear in their bedroom.)
[ Post Reply | Private Reply | To 85 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 81-100101-120121-140 ... 341-357 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson