ExpressionEngine CMS
Open, Free, Amazing

Thread

This is an archived forum and the content is probably no longer relevant, but is provided here for posterity.

The active forums are here.

Security Concern - Is this 3rd party?

April 07, 2012 7:40pm

Subscribe [6]
  • #1 / Apr 07, 2012 7:40pm

    Bransin

    157 posts

    Found this on google after searching my email address.

    I asked Pastebin to remove this entry and they did. Here is the cached google version.
    ** link has been removed by request **

    I could be wrong but isn’t Channel Files and Channel Images by DevDemon? I have purchased this addon.

  • #2 / Apr 07, 2012 9:54pm

    Enviromed

    375 posts

    Thank you for posting this.  Our e-mail is listed as well and we bought channel images..

  • #3 / Apr 07, 2012 10:51pm

    PhilBrienesse

    187 posts

    Spooky! My email is on there too and have also purchased channel images. Have you brought this to devdemons attention or any idea how this ended up here?

  • #4 / Apr 07, 2012 11:01pm

    Bransin

    157 posts

    I have notified Dev Demon via contact form.

    Being a weekend and Easter holiday, I don’t expect an immediate response. I am overall curious if this is related to an EE breach or custom addon commerce platform.

    My guess at this point is that these records are related to the DevDemon purchases.

  • #5 / Apr 08, 2012 12:41am

    Bransin

    157 posts

    I don’t intend on defacing what Brad has done for the community with addons and DevDemon.

    The response:

    This was created and should have been private. Since pastebin has removed, however you have found it in the google cache. Could you please remove the link from your EE post please. We are trying to remove it… However, removing from the google cache is not something done easily. - Brad Parscale

    I’m sorry, but when does a developer post an array list of all emails with a username of Untitled on Pastebin? Should I be treated as this gullible person, or this an ultimate mistake?

  • #6 / Apr 08, 2012 1:06am

    Bransin

    157 posts

    This being 3rd party - admins can move this.

  • #7 / Apr 08, 2012 8:26am

    Cem Meric

    210 posts

    Who would paste customer database to pastebin? Hope this was a human mistake not a hack.

    Ellislab, can we get this post removed from Google as well. Cache version still contains the link.

  • #8 / Apr 08, 2012 9:11am

    Brad Parscale

    196 posts

    Hello,

    This was a mistake by an employee of my company. Its intention was good but their use of a public system was a regretful mistake.  As soon as I recognized what had happened I immediately had pastebin remove the post. No data has been compromised and the list is actually an inaccurate accounting which is what the employee was displaying to the team.  It is just unfortunate how fast google will cache something.

    I apologize if your name showed here, but no other personal data was displayed.  After running businesses for 14 years you have to take the mistakes with the triumphs. This is obviously one of those duh moments.  I didn’t take this lightly and acted as swiftly and strongly as possible.

    Brad

  • #9 / Apr 08, 2012 10:14am

    Cem Meric

    210 posts

    Thanks for being upfront and honest about it Brad. Glad to know it wasn’t a case of breach.

    We appreciate what you provide to ExpressionEngine community.

  • #10 / Apr 08, 2012 11:35am

    PhilBrienesse

    187 posts

    Mistakes happen. No worries.

  • #11 / Apr 09, 2012 12:58pm

    Shane Eckert

    7174 posts

    Hey all,

    Just checking in to make sure all is well here.

    This looks solved and as if everyone is cool with moving on.

    Please let me know.

    Cheers,

.(JavaScript must be enabled to view this email address)

ExpressionEngine News!

#eecms, #events, #releases