Anyone using weak passwords? You may want to change them if you are.
Currently, this forum and a lot of other forums are under sustained attack by spambots that are attempting to brute force logins to accounts. What they are doing is rocking up at a site, scanning posts for a bunch of usernames, and then attempting to guess the passwords so they can gain control of the accounts.
They are doing this by randomly running a variety of fairly simple possible passwords for all the account names they have scanned. Actual examples are: baseball1, master, princess, asdfg, asdf1 and lkjhg.
These attacks are coming from all over the world, and the real IP's cannot be traced because they are being hidden behind Tor proxies. There are
a lot of bots involved in this and they are being persistent.
It's always good practice to not use basic passwords that can be guessed by a dictionary attack, or very short strings of random characters. If anyone is using a fairly weak password they should think very seriously about changing it now.
This thing is rather handy if you want real security:
GRC | Ultra High Security Password GeneratorI use that gizmo to generate the passwords for our server.
ETA: Oh and to give an idea of the scale of the problem, we have had over 70 attempts on accounts here in the last five hours.