Shoutbox

what's up with the forums? - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: General (/forumdisplay.php?fid=11)
+---- Forum: Forum & Website (/forumdisplay.php?fid=13)
+----- Thread: what's up with the forums? (/showthread.php?tid=23235)

what's up with the forums? by tomfletcherman on 04-01-2004 at 06:47 PM

what the subject says:P

they've been acting up a while, and what attacks have been going on?


RE: what's up with the forums? by WDZ on 04-01-2004 at 06:54 PM

The server has been getting DDOSed for the last couple days.

Read this thread: http://shoutbox.menthix.net/showthread.php?tid=23167

Right now it's not as bad as it was. I dunno if the attacks have stopped or they're just getting blocked, but the server is obviously not back to normal yet. wj is working hard to keep the forums up, so just be patient... :p


RE: what's up with the forums? by tomfletcherman on 04-01-2004 at 07:05 PM

thanx, i didn't see these threads


RE: what's up with the forums? by Pr0xY on 04-05-2004 at 06:28 PM

WDZ, do you know if this has anything to do with the forum being hacked??


RE: what's up with the forums? by Menthix on 04-05-2004 at 07:00 PM

The forums being hacked!? When? As far as i know the attack was targeted to the server itself, not the forums. Just lame DDoS to make the server go down :-@

Patchou.com was hacked some weeks ago tough. And the IRC server has been attacked too, so i guess somebody just has no idea what todo with his life.


RE: what's up with the forums? by kao on 04-05-2004 at 07:24 PM

the forums were hacked quite a while ago aswell, a couple of months ago... using a MyBB exploit afaik. gave themservles admin, de-admin'd everyone else and changed loads of shit, then wj got it all back i think. wj = (Y) to us all (A)


RE: what's up with the forums? by WDZ on 04-06-2004 at 05:19 AM

quote:
Originally posted by Kao
the forums were hacked quite a while ago aswell, a couple of months ago...
It was the middle of February. :p

quote:
using a MyBB exploit afaik.
An exploit could have been involved, though we think the whole thing started on IRC with passwords getting stolen. :dodgy:

quote:
Originally posted by pr0xy_nuk3r
WDZ, do you know if this has anything to do with the forum being hacked??
No, I don't know if there's a connection... :-/ It's possible, though the two attack methods were quite different...
RE: what's up with the forums? by kao on 04-06-2004 at 02:17 PM

quote:
Originally posted by WDZ
It was the middle of February.
thats 2 months ago :refuck:

quote:
Originally posted by WDZ
An exploit could have been involved, though we think the whole thing started on IRC with passwords getting stolen.
i forgot about that bit :dodgy:
RE: RE: what's up with the forums? by sock on 04-07-2004 at 12:52 AM

quote:
Originally posted by WDZ
An exploit could have been involved, though we think the whole thing started on IRC with passwords getting stolen. :dodgy:
You think wrong, apparently: All the forum admins who registered their nicknames on IRC said they were using two different passwords...
RE: what's up with the forums? by wj on 04-07-2004 at 02:22 AM

Thats what they say.... Though it may not have been a "Direct" connection between the two, One could have been used to obtain the other (password reset???)


RE: what's up with the forums? by WDZ on 04-07-2004 at 04:10 AM

quote:
Originally posted by sock
You think wrong, apparently: All the forum admins who registered their nicknames on IRC said they were using two different passwords...
I am 95% sure that Patchou was using the same password. I just compared the password stolen from IRC with the one from the latest pre-hacking forum user backup, and they match. :tongue:
RE: what's up with the forums? by Wabz on 04-07-2004 at 12:05 PM

quote:
Originally posted by WDZ
I am 95% sure that Patchou was using the same password. I just compared the password stolen from IRC with the one from the latest pre-hacking forum user backup, and they match.

:dodgy:  We need some more security here then :P  Arent the irc passwords hashed now anyways :P

RE: what's up with the forums? by Menthix on 04-07-2004 at 12:07 PM

Patchou.com was probally hacked because of the same reason then? Do we know who did it? Do we have prove?


RE: what's up with the forums? by Wabz on 04-07-2004 at 05:23 PM

quote:
Originally posted by MenthiX
Patchou.com was probally hacked because of the same reason then? Do we know who did it? Do we have prove?

Last thing i knew is they'd recovered the logs and Patchou was going to take Legal action dunno if it's been confirmed though

RE: what's up with the forums? by sock on 04-07-2004 at 09:21 PM

quote:
Originally posted by WDZ
I am 95% sure that Patchou was using the same password. I just compared the password stolen from IRC with the one from the latest pre-hacking forum user backup, and they match. :tongue:
wtf. :dodgy: He told DX that he uses different passwords everywhere... :dodgy: And how the hell did you get his IRC password? :dodgy:

Besides, other admin accounts were used as well... Are you saying that the hacker changed their passwords using Patchou's admin rights? :-/ Doesn't myBB log admin activity or something? :-/



quote:
Originally posted by Wabz
Arent the irc passwords hashed now anyways :P
Mind you, if the hacker has access to the services database, he can cause great damage to the server even when the passwords are encrypted (for example, delete the databases and the configuration files, or corrupt them otherwise).

Also, a password's encryption can be cracked in a few days if the password is weak (ie. short and non-complex). Password encryption may help security, but it's far from being completely safe.

When I was running the IRC services, I used a version in which the password encryption was "experimental", so I thought it would be better to keep it disabled (which was the default). I was afraid of data loss bugs that DX warned me about. And since password encryption doesn't make things 100% safe anyway, it seemed okay to do so back then. :undecided:
RE: what's up with the forums? by MC Inferno on 04-07-2004 at 10:11 PM

I dont think patchou would be too happy with you getting his IRC password. I defo wouldnt :S


RE: what's up with the forums? by surfichris on 04-07-2004 at 11:24 PM

quote:
Originally posted by sock
Doesn't myBB log admin activity or something?
Yes but the logs were cleared.
quote:
Originally posted by sock
I was afraid of data loss bugs that DX warned me about. And since password encryption doesn't make things 100% safe anyway, it seemed okay to do so back then.
Hashing makes things alot more secure though, because hashes cannot be reversed back to plain text, only really bruteforced.
RE: what's up with the forums? by Wabz on 04-07-2004 at 11:57 PM

quote:
Originally posted by Chris Boulton
Hashing makes things alot more secure though, because hashes cannot be reversed back to plain text, only really bruteforced.

Yeah hashing only takes a few days though to be broken !!By brute force :P