A few weeks ago, I wrote about a weak password hash algorythm.
Now it happend.
A few days ago, SHA-1 was proven as “broken”. and MD5 is allready easy to crack.
I wrote a mass email to everyone, asking to change your password. Many accounts are still using the old and weak algorythm. In the last days I recognized a higher rate of “wrong” login tries. – Somone tries to break into email accounts.
Since I don’t want a hacked email account on my server which people can use to send spam, I deactivated all email accounts with an old password algorythm.
So if you can’t login to your email account, don’t worry. Your email account is still there, but it is inactive. To gain access again, please create a ticket and provide your email address, AND the address you originally requested your email with or anything else to prove you are the legit account owner.
For example a screenshot of the configured email account in your email client or phone.
In the last days I receive a lot of emails like this one:
Dear Webmail User,
Due to excess abandoned Webmail Account, Our Webmaster has decided to refresh the database and to delete inactive accounts to create space for fresh users. To verify your Webmail Account, you must reply to this email immediately and provide the information below correctly:
Failure to do this will immediately render your Webmail Account deactivated from our system. Webmail Database refreshing shall commence once a response is not received within 48hrs.
Web Admin Support Center
DO _NOT_ REPLY!
Is-a-furry.org is NOT sending emails like this!
If you already replied to one of these emails, CHANGE YOUR PASSWORD IMMEDIATELY! If you can’t login anymore, OPEN A TICKET!
NEVER EVER is-a-furry.org will ask you for your password! If we need to login to your account to give you support, we ask you if you are ok with us changing your password to a newly generated one. – And this will only happen if YOU agree with it!
As some of you might know or recognized, is-a-furry.org is a bit more than just a furry.
I own a bit more domains then just “is-a-furry.org” So if you want, you can also request an email out of the following domains:
- 7ry.de (very short)
Just use the ticket system as explained in the wiki🙂
I added a few new sites to the wiki page. I will do some tutorial videos too, explaining a bit more, but for now it should work.
Tutorials added for:
- changing your email password
- setting up filters and rules for sorting emails
I try to fill the wiki with life. But since I don’t have an iMac, it would be very helpful if someone could do a small tutorial like my others about “How to configure your IAF email on iMail”
I think it’s time for a bigger update.
Is-a-furry.org moved to a new server (again). Reason? Same power for less money. While moving, you realized a downtime of the mail and messaging server.
I was quite busy. Not just moving all the files and stuff, I also configured A LOT of new cool shit.
- Now you can use a photo management service (https://pics.is-a-furry.org). This is not just to create an account and albums and stuff, its also useful for just uploading an image and share the link. Like tinypic.com or imageshack.us and stuff. There is just one difference: I don’t claim the copyright of YOUR pics. They are yours. Feel free to use it.
- Is-a-furry.org also has now a nextcloud instance. (https://cloud.is-a-furry.org) – You can request an account via ticket system. You can use nextcloud to synchronize your contacts and calendar on your phone without giving them all to Google/Microsoft/Apple, Or sync them between your phone and your eMail client.
- There is now a WIKI system. It’s not filled yet, but I will write articels now and then and explain how to do things.
There is also a lot of changes “backstage”:
- The eMail server now uses a new hashing algorythm. If you have an email account from iaf.org then you should already receiven an email on how to update your password.
- The whole webhosting switched to PHP 7 since older versions are outdated or lost their support
- A complete new SSL infrastructure – the mailserver and the chatserver have now an own set of certificates. Now you can ise imap.is-a-furry.org or smtp.is-a-afurry.org and you will not receive an SSL error.
- The ticket System received an update
- The chatserver refuses messages from contacts NOT in your list. means spammer which send you permanent Jabber SPAM will not be able to message you now. You have to add a contact to your buddy-list to receive messages from them.
I continue work on things espechially the wiki.
But SSLlabs reduces me to A-…
because IAF.org does not support forward secrecy with Windows Mobile 8.1.
but here: Mozillas Rating of Is-a-furry.org
I know I annoyed you a lot lately. But you have my word: it’s over.
What cause’d the trouble? Well let me explain.
The server for IAF.org changed a few weeks ago. Now it’s running on some shiny new SSDs with an awesome performance. But… I also had to reinstall the OS. Normally I get the new server, Install and configure everything and set my home-DNS Server so it points to the new server. This allows me to test everything before I do the big move to the new server.
Everything seemd to be fine and everything was working as a charm, and it was damn fast too.
Then I installed the first system updated and shit hit the fan. The webserver didn’t came up and some other services were not responding anymore. Bughunting revealed that the server was too fast.
- Boot up
- start network interfaces
- start webserver
- // webserver crash: network not ready
- network ready
I think you see the problem.
It took me hours of research, reading errorlogs and try things, reboot the server, reinstall the whole server, and so on.
Today I got it. Everything returned to normal.
At least now I understand systemd and how to handle its units…
Everything is up and running again.
due continuous errors and connection issues, I need to take the server down today.
Sorry for this. I try to keep the downtime as short as possible.
You might recognized it,
IAF.org has some issues lately.
I need to reinstall the host.
So Server will experience a downtime of a sewveral hours this thursday.
6pm to 2am CEST.