This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Astaro.org

Hi Everyone,

we've been planning a migration to a newer and more capable forum site for some time now, and were just a few weeks away from kicking off this process. Unfortunately, a recent vulnerability has appeared in the wild, affecting vBulletin, the software we were using for the astaro.org communities site. Astaro.org was not compromised from this vulnerability, but as a precaution, we did take the site down, to protect our users. 

The site used a number of add-ons, and some custom plugins, which would need weeks of effort to convert and replace, if we were to upgrade the site and apply fixes for this vulnerability. As we were planning to migrate by that time anyway, we've made the decision to cut immediately to the new communities site, which has been running successfully for other Sophos products. To that end, we've spun up two forums quickly, where astaro.org users can again congregate. unfortunately, it will still take some time to complete the migration, so user accounts, and previously posted content has not yet been migrated. This process will take a matter of weeks to complete. In the interim, we will create a static view of the astaro.org, so content there will still be accessible. This should be completed later today.

This certainly wasn't the introduction we wanted for our new communities site, but we are excited about the new platform, and its capabilities. Please be patient as we step through this transition as quickly as we can. There will be some pain, but we will try our best to minimize it for you. 

Thanks everyone for your patience, and understanding!

Alan Toews

Technical Product Manager, Network Security, Sophos



This thread was automatically locked due to age.
  • What a nice excuse. You had been planning for quite some time yadda yadda. Unfortunately this has been typical of Sophos since the takeover of Astaro by sophos. I recognize this interface...it is a lot like...coperniicus! It takes 20 clicks to do what took less than 5 in vbull..kinda like copernicus vs. UTM. I know sophos intends to hard launch copernicus soon without even matching some basic functionality of UTM. The interface looks like it was designed along the US Common Core standards.

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • Oh you folks thought support was not good before it's about to get much worse because support is going to get absolutely hammered now. I hope Sophos gets the content migrated in the correct order not in short order..:)

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • the actual vulnerability isn't hard to patch it depends on how much the admins had customized the plugins or customization made to various other parts of the code. A UTM with form hardening would have stopped this in it's tracks though.

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • I actually got a tweet about it earlier. I was just trying to bait BAlfson to join the discussion and show the absurdity of pulling the plug on astaro.org. I laughed when I read today that they had mitigated the vulnerability and the not so read-only site is back ;-)

    All the other over the top comments of being a security company and not a car forum were entertaining considering that they unplugged the server as their first line of defense;-) Not to mention that the original hack was already available in the wild for almost 4 days before sophos noticed it.

    Anyone interested, you can check #vBulletin or on twitter

  • Astaro forum saved me several times(Thanks BAlfson!). Every time I had to contact Sophos support they took days to respond.( Do wonder if the support acctually knows whats comming)
    So far Ive been a happy costumer, but this is only because of the Astaro forum.
  • I know that this is a painful move, especially for people like me who only just installed a home system and now had a great resource taken away (I hope the content populates soon on the original site...I've got lots of questions that are answered in that sea of information). However, the vBulletin vulnerabilities are well known, and I've been through this earlier this year when the plex.tv forums were breached and information was leaked. In that case, the forums were down for weeks, and they finally reopened with a new forum system and all content migrated.

    I'm sure we'll have the content available again before long.
  • Forum post "dislike" option is missing, and please don't ever introduce it...;)

    I've just tried to find one while reading this AzRon post talking about security companies and comparing it with home cooking forums.
  • Does Zimbra offer any mods to make it look and act like vBulletin?
  • The system that Sophos has moved is fantastic for Sophos Support to answer questions directly by Users to Users and their answer can be selected and be quickly referenced. Granted, this makes a percentage of issues to be resolved Quick and [emphasis]Dirty[/emphasis].

    This system has been running on Microsoft for years, donkeys, dragons and elves. And you know what, for around 6-7 years of supporting and playing about with Win 7+ in a quasi-professional standpoint, the Community forums like sevenforums and eightforums have been more what I go to.

    This new Board sacrifices the community being able to easily discuss their problem for the "quick fix". Some issues are so complex and present the same symptoms that there is no one resolution that an "Answer" flag will actually suit what-so-ducking-ever. I hate the suggested and answered flag with a passion as it's abused by certain parties to artificially inflate their standing in the community, it may not happen here but some people like to be noticed for being a "Top Answerer". Including when an answer is selected when it's not actually answered the OP's issue and they still say they have a problem but the thread has been killed off because the answer has been selected.

    That is why forums are created to discuss articles and issues in (whaddya know) a forum. The system implemented here is not a forum, this is a support ticketing system that is more open to interaction by other third parties.

    I've not been with Astaro/Sophos/Cyberoam long and sometimes I can be a complete dunce, self admittedly, but there's a reason why vBulletin and others of the same ilk are so successful. This is because as forums, their design and sole purpose is community discussion. Not answering issues, not fixing a problem but for communities and their counterparts in the official world to discuss topics of relevance and help.

    Answering issues and fixing problems comes naturally to a forum.

  • Warum wird etwas "noch sehr Beta" als Ersatz für Astaro.org angeboten. Und wieso wurde sich nicht einmal die Mühe gemacht, die regionalen Bereiche einzurichten? Ich finde es bedauerlich, wie hier die Hilfesuchenden und -leistenden verprellt werden!