well im afraid your sources maybe slightly screwed then mate.....Janglur said:Explain why there were dozens of 'I can't log in' posts right before it went down then, Code?
I fear that my sources tell me the server's been compromised on a massive scale.
SDWolf said:Also, has anyone else noticed that the forums are insanely slow right now? I'm even getting MySQL "too many connections" errors. DoS attack, or just too many furs wondering where their fapping materials went? (j/k!)
Take care, and good luck, Admins!
Sslaxx said:Wasn't it FA that had, unencrypted, passwords available via port 80 once? Why, Codewolf, should anyone believe that the passwords are in anything other than plain text or ROT13 at best?
Preyfar said:An administrative account was taken over...
The issue in question did not have to do with password strength -- it had to do with a vulnerability using public wireless networks.SDWolf said:Hrmmmm....
Lovely. Strong Passwords, anyone?Preyfar said:An administrative account was taken over...
*le sigh*
Sslaxx said:This looks like this could mean FA is down for a while, then... things are fitting together in a bad way indeed, Jangular! It looks like you're quite right that the security leak was more than the FA admin let on.
codewolf said:well im afraid your sources maybe slightly screwed then mate.....Janglur said:Explain why there were dozens of 'I can't log in' posts right before it went down then, Code?
I fear that my sources tell me the server's been compromised on a massive scale.
the reason it would have done that is that if a site is going down one of thae main thigs that goes first is the database or rather the connection to it...therefore if they tried to log in basically they'd be sending their passwords off into nowhere as there is nothing to reference the password to.....
and for those of you that dont know...if something has been stored in a database using MD5 encription the password field in the database would read something along the lines of 51D7FE4312 rather than your password ("fish" for example)
Sslaxx said:Wasn't it FA that had, unencrypted, passwords available via port 80 once? Why, Codewolf, should anyone believe that the passwords are in anything other than plain text or ROT13 at best?
Janglur said:Dr. Wil, if the DB has been compromised (and it sure fucking looks that way) then they can see your NEW password right now, too.
You're supposed to change it AFTER they regain control...
Sslaxx said:This looks like this could mean FA is down for a while, then... things are fitting together in a bad way indeed, Jangular! It looks like you're quite right that the security leak was more than the FA admin let on.
An administrator account was exploited, but the database is fine. You can not access the full database from an admin account -- you have to do it through a root account, and the root is fine. The DB is fine.Janglur said:Considering the DB leaked not once, but twice, unencrypted.. yyyeeaaahhh. Wouldn't surprise me if it wasn't encrypted now, either. And a metric buttload of people couldn't log in. Ten minutes later, errors came up, then moments later the site's down. I doubt a ten mintue timespan was JUST a case of server shutdown. Seems a bit too long
Janglur said:Are we all now paying for this oversight?
Janglur said:Sslaxx said:Wasn't it FA that had, unencrypted, passwords available via port 80 once? Why, Codewolf, should anyone believe that the passwords are in anything other than plain text or ROT13 at best?
Considering the DB leaked not once, but twice, unencrypted.. yyyeeaaahhh. Wouldn't surprise me if it wasn't encrypted now, either. And a metric buttload of people couldn't log in. Ten minutes later, errors came up, then moments later the site's down. I doubt a ten mintue timespan was JUST a case of server shutdown. Seems a bit too long.
And we all know that at least one account leaked today. I would not remotely doubt that it was more serious than admin are letting on, and the site defacement was only the tip of the iceberg.
After all, the stuff staff usually dismiss as unimportant seems to consistantly blow up in their face.
After all, the last security issue was 'not that big a deal', enough that they didn't feel it necessary to even casually mention it. Until another admin went batshit over the implications. That admin lost, plus the drama it ensued, was pretty big enough to have warranted more attention than was given (see: none). Now this security breach...
Are we all now paying for this oversight?
Thank god I changed my password when that drama happened, and took down all my art.
My account was the one that was jacked and admin accounts can not access the DB -- you can only do that through root, and root is fine. My root password is much more secure and is fine.Sslaxx said:And why, exactly, should we believe you Preyfar? Janglur points out that the things you dismissed as unimportant tended to backfire on you. One lesson should be, if you're humble enough to learn it, is that everything is important.
Preyfar said:The issue in question did not have to do with password strength -- it had to do with a vulnerability using public wireless networks.
Preyfar said:Snip.
We know WHO did it, too.