Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfsense forums data breach confirmed

    Scheduled Pinned Locked Moved Forum Feedback
    38 Posts 14 Posters 7.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator @Anonymous-5132
      last edited by johnpoz

      @anonymous-5132 said in pfsense forums data breach confirmed:

      Have you looked at the other thread? Have you looked at the evidence I presented?

      Yes - and there is no "evidence" you getting some email to some address "you" say has not been used elsewhere - or not leaked "elsewhere" or someone didn't specific add to a spam list, etc. etc.. is sure and the hell not "evidence" of a breach... When more than you come forward and say hey we all got this spam, from our only used on this forum you might have something worth talking about.

      My "EVIDENCE" show no spam to my private address - so clearly your email address was obtained elsewhere.. Do you see how thin you accusation is?

      getting email to the clearly unique and unknowable "pfsense" at some domain - yeah just screams their db has been compromised <rolleyes>

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      A 1 Reply Last reply Reply Quote 0
      • A
        Anonymous-5132 @johnpoz
        last edited by

        @johnpoz said in pfsense forums data breach confirmed:

        @anonymous-5132 said in pfsense forums data breach confirmed:

        Have you looked at the other thread? Have you looked at the evidence I presented?

        Yes - and there is no "evidence" you getting some email to some address "you" say has not been used elsewhere -

        So we're supposed to believe you at your word but not me? You who has yet to post anything but words and has given absolutely no reason whatsoever to be trusted and in fact has shown good reason not to be trusted? 🤔

        or not leaked "elsewhere" or someone didn't specific add to a spam list, etc. etc.. is sure and the hell not "evidence" of a breach...

        So I leaked my own email address, defeating my own system I put together to detect leaked email addresses? Or are you claiming I faked the email headers and server log lines I posted? And you think I'm the one being completely unreasonable? ROFL!

        When more than you come forward and say hey we all got this spam, from our only used on this forum you might have something worth talking about.

        You mean like the three other people who have posted? Did the two others who posted evidence so far fake their evidence as well?

        My "EVIDENCE" show no spam to my private address - so clearly your email address was obtained elsewhere.. Do you see how thin you accusation is?

        Your "evidence" is your word and absolutely nothing else. You claim that you haven't received spam, and quite frankly, I don't believe you. I, and two other people, have posted hard evidence. You have posted crazy assumptions and ignored facts.

        getting email to the clearly unique and unknowable "pfsense" at some domain - yeah just screams their db has been compromised <rolleyes>

        A data breach of the old pfsense forum is the simplest explanation given the facts. What else could explain multiple different people all receiving spam to an address only used in that one place? Do you honestly believe that three different people all decided to forge evidence to falsely claim that they got spam to a unique email used at a single website and then all chose the old pfsense forum out of millions of choices? Oh, but I'm the one being unreasonable. 🙄

        One of us has posted evidence, and one of us has not. One of us has read the evidence posted by two other people, and one of us has not. The fact is the evidence posted so far supports the theory that a list of email addresses used on the old pfsense forums has been leaked. No amount of words from a clearly unreasonable person will change that.

        tESting1

        J 1 Reply Last reply Reply Quote 0
        • J
          jdeloach @Anonymous-5132
          last edited by

          @anonymous-5132

          I think it's about time that a moderator LOCK this post as there has been no credible evidence that there has been a leak posted and lets quit feeding this troll.

          1 Reply Last reply Reply Quote 0
          • J
            Joolee
            last edited by

            The full (redacted) E-mail I received is:
            https://pastebin.com/ApKP3fmG

            kiokomanK 1 Reply Last reply Reply Quote 0
            • kiokomanK
              kiokoman LAYER 8 @Joolee
              last edited by johnpoz

              let me guess !! let me guess !!
              the email of @johnpoz johnpoz [snipped mod]
              🙄

              ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
              Please do not use chat/PM to ask for help
              we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
              Don't forget to Upvote with the 👍 button for any post you find to be helpful.

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @kiokoman
                last edited by

                @kiokoman no that is not private address that the forum knows about..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                kiokomanK 1 Reply Last reply Reply Quote 0
                • kiokomanK
                  kiokoman LAYER 8 @johnpoz
                  last edited by

                  @johnpoz
                  it was here
                  https://forum.netgate.com/topic/61267/minor-issue-with-client-export-config-commands
                  maybe you should clean that also
                  I wanted to show that it is not impossible to find them
                  also
                  https://marc.info/?l=pfsense-discussion&r=1&w=2
                  it's full of information about personal emails for example

                  ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                  Please do not use chat/PM to ask for help
                  we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                  Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                  johnpozJ 1 Reply Last reply Reply Quote 1
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @kiokoman
                    last edited by

                    @kiokoman thanks - from 2013, wow.. Not sure how I missed that way back then.

                    But yeah great example..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    J 1 Reply Last reply Reply Quote 0
                    • J
                      Joolee @johnpoz
                      last edited by Joolee

                      @johnpoz your email address is also exposed in your Redmine profile, in case you're wondering. You can set it to private in the settings.

                      bingo600B johnpozJ 2 Replies Last reply Reply Quote 0
                      • bingo600B
                        bingo600 @Joolee
                        last edited by bingo600

                        @joolee
                        Might be nice to edit the above to just say your mail address

                        If you find my answer useful - Please give the post a 👍 - "thumbs up"

                        pfSense+ 23.05.1 (ZFS)

                        QOTOM-Q355G4 Quad Lan.
                        CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                        LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator @Joolee
                          last edited by

                          @joolee thanks - but that is not the address tied to my forum account either.. But another great example on my part ;) showing that email can be harvested without a "breach".. ;)

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • provelsP
                            provels
                            last edited by

                            I get spam every day in my roadside mail box.
                            Who do I see about that?

                            Peder

                            MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                            BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                            johnpozJ 1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator @provels
                              last edited by johnpoz

                              @provels I would contact the Postal Service about their breach.. Since clearly that is the only explanation

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              1 Reply Last reply Reply Quote 0
                              • dennis_sD dennis_s locked this topic on
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.