• Please review our updated Terms and Rules here

DLP Forums Got Nuked

NeXT

Veteran Member
Joined
Oct 22, 2008
Messages
8,178
Location
Kamloops, BC, Canada
I only heard about this today. the Dragons Lair Project forums' host got hit by ransomware and they responded by dumping everyone's data and their backups.

SEPTEMBER 2022 DATA LOSS

From Sep. 28 - Oct. 10, 2022, the Dragon's Lair Project website was offline, following the dismal failure of the hosting company Internap Holding LLC (INAP), whose response to a ransomware attack was to immediately and permanently abandon the multitenant hosting business and their clients' data losses. All messages ever posted to a dynamic message board / forum at this website are now lost, along with users' account data. All static website content online at the moment of the attack has been reinstated to a new server solely by the site's creators.

Please resend any email that you sent to the domains @dragons-lair-project.com or @d-l-p.com between Sep. 28 - Oct. 10, 2022.

The following is the service termination and data loss notice received by the Dragon's Lair Project without apology from web-hosting company INAP. The targeted, limited, and specific impact of the ransomware attack on INAP, and INAP's utter failure to cope with it, and also the month-end timing on the billing cycle, have very conveniently dissolved their contracts and facilitated their exit from small-to-mid-scale operations, allowing them greater focus on their premium corporate services, which they brazenly peddled to us in the termination notice.

Hello,

Management has provided us with a new update. This update is as follows:

On Wednesday, September 28th, between the hours of 2:11 am CDT and 5:41 am CDT, INAP was the target of a ransomware attack that affected the services we provide to you. One of our support technicians discovered the security issue at 8:00 am, CDT. INAP’s Chief Information Security Office was notified and invoked the incident response plan. The incident response team was able to determine the root cause and attack vector used, and quickly remediated the issue to prevent further damage. This was completed approximately at noon, Wednesday September 28th.

Unfortunately, your services are not recoverable because of this attack.

Additionally, multitenant website, database, and email hosting services will no longer be available following this event. We will be terminating these multitenant hosting services and removing the charges from your account effective immediately. The multitenant “GuestDNS” service was not impacted, and you can continue to make any DNS changes through the control panel.

Our recommended path forward is to re-create any affected services on a bare metal server and to upload your data from your local copies if available. If you do not have a bare metal server with INAP please feel free to reach out directly to csleadership@inap.com for immediate sales support.

Keep in mind the provided information is all that was given, If you have any additional questions in regards to this information don't hesitate to call or email the above mentioned.

----------------------------------------------------------
Thanks for choosing INAP!

Sincerely,
███████████████
Systems Administrator
INAP
Toll Free: +1 (877) 843-7627
Connect with us! www.inap.com

Posted on 10/4/2022 12:22:09 AM



Permanent data losses include:
- all messages that were posted to the message board and the message board archives from 1999-2022
- all user accounts and private messages
- the old registry / collectors forums content
- the old quick-vote polls and responses
- any other dynamic or SQL server content we'll find missing someday

We apologize for not having backed up this data ourselves with the rest of the site. If we discover that we somehow do have any of it, we will advise.

And for the record, we did not choose INAP as suggested at the end of the notice. They had recently acquired our hosting company and have now left themselves with their desired parts of it. We regret not recognizing the acquisition as a red flag.

Brutal. Everything, just gone.
 
Brutal. Everything, just gone.
Yeah, that's very sad. But running a site since 1999 and never doing any backup is irresponsible. Even if the hoster did automatic backups, you can never trust having those when something goes wrong, as this just shows.
 
Given the forum software I have seen, backing up the forums to an offline device is very difficult and takes up a lot of space for what generally is rather unimportant. Plenty of forums have lost archives just as a consequence of upgrading without much notice.

I have been a cloud skeptic. The cloud provider will never think my data is as valuable as I do.
 
Given the forum software I have seen, backing up the forums to an offline device is very difficult and takes up a lot of space for what generally is rather unimportant.
Really? Using e.g. mysql_dump from a remote system and having the dump gzip compressed is not what I call "difficult". Also, no argument against doing backups is valid anyway. If you care about your data, you must do it. The general rule is to have three copies of your data on two different media with one being in a different location (geographically). At least this is the 3-2-1 rule I have learned since I work in IT.
 
It would take a huge effort to restore what exists from there, but that's the price you pay for not making backups. If anybody here is in contact with them, they might want to point them to the internet archive...

A donation to Brewster Kahle's Internet Archive might also be in order.
Just saying... :)
 
Really? Using e.g. mysql_dump from a remote system and having the dump gzip compressed is not what I call "difficult". Also, no argument against doing backups is valid anyway. If you care about your data, you must do it. The general rule is to have three copies of your data on two different media with one being in a different location (geographically). At least this is the 3-2-1 rule I have learned since I work in IT.
I don't expect a free hobbyist website to devote as many resources* to maintaining an emergency offline copy as a major financial services company. It looks like there were some localized backups done which should provide the basis for a reconstituted website. The loss of most of the forum postings probably isn't a calamity. I am surprised that the user information was lost since that is generally a fairly small portion of the overall database.

*Seriously, if the admin has to spend an entire week downloading a complete image of the website, it won't happen. The admin won't purchase superfast personal internet just in case the cloud provider proves to be less than competent.
 
Back
Top