Poster | Thread |
sibbi
|  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 11:31:02
| | [ #21 ] |
|
|
 |
Team Member  |
Joined: 18-Mar-2003 Posts: 687
From: Iceland | | |
|
| The problem also lies with anonymous proxy services which allows these users to hide their identity, and the fact that the proxy owners are not required by any law to keep any logs of their usage, meaning that the users are in fact, untraceable _________________ --- Sibbi
Disclaimer: The opinions stated do not neccesarily represent those of my employer.
|
|
Status: Offline |
|
|
kas1e
|  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 11:33:11
| | [ #22 ] |
|
|
 |
Elite Member  |
Joined: 11-Jan-2004 Posts: 3551
From: Russia | | |
|
| @sibby Its not that like someone just use some public proxy, which should or shouldn't have a logs. There is a lot of ppls with botnets, boxes of which infected and being as proxy do what owners of botnet want to do. There is also services which provide you hacked boxes with proxies per small amount from the same botnets. There is also hacked linux boxes, where you yourself can setup any kind of proxy and do whatever you want. I.e. its all pretty easy if you want be annonimouse, and real owners of proxie-bots even do not know what happens, not saying that they should or should't have a monitoring of that activity or save the logs.
Just what the fun to do it, and choice Trevor as victim, when you are adult, and when you have no betefits from it at all (as its pretty undestanable , that hoax will be hoax). Last edited by kas1e on 11-Jan-2012 at 11:39 AM. Last edited by kas1e on 11-Jan-2012 at 11:37 AM.
_________________ Join us to improve dopus5! zerohero's mirror of os4/os3 crosscompiler suites
|
|
Status: Offline |
|
|
Akiko
 |  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 12:03:46
| | [ #23 ] |
|
|
 |
Cult Member  |
Joined: 26-Mar-2004 Posts: 781
From: UK | | |
|
| Quote:
We are sorry to admit it but it seems AmigaWorld.Net was hacked today. |
Is there anything to suggest this breech originated from Amigaworld?
At least another 4 community related websites were accessed also , Amiga.org, MorphZone etc.. so assuming his password was the same for all, couldn't the source equally be from one of them sites?Last edited by Akiko on 11-Jan-2012 at 12:05 PM.
_________________ 4000T/BFG9060 CD32/Elsat ProModule, TF360 CD32/ Edu's CD32 <> A1200 Adapter, Vampire V2 CD32/ FMV Module
|
|
Status: Offline |
|
|
Toaks
|  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 12:11:29
| | [ #24 ] |
|
|
 |
Elite Member  |
Joined: 10-Mar-2003 Posts: 8042
From: amigaguru.com | | |
|
| BUT BUT BUT!!
my password is GOD , damn
i gotta changed it to GOD123 then.
---
damn i hate hackers and i hate changing passwords as they gotta be different on every site to be sure :(
Whats this thing about Trevor's account being hacked??? _________________ See my blog and collection website! . https://www.blog.amigaguru.com
|
|
Status: Offline |
|
|
zerohero
|  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 12:24:23
| | [ #25 ] |
|
|
 |
Team Member  |
Joined: 4-May-2004 Posts: 2524
From: Uddevalla, Sweden | | |
|
| @Taks
Quote:
Whats this thing about Trevor's account being hacked??? |
What we know is that someone got access to Trevor's account, and two more accounts at least. It was basically used to post some false information which quite quickly could be corrected. We have fixed Trevor's account so he has access to it again. It seems the hacker did not change the passwords of the other two users he posted from.
We're still looking into it and can't really say anything yet.
Regards, Joachim Birging
AmigaWorld.Net staff _________________ Common sense - So rare it's almost like a super power
|
|
Status: Offline |
|
|
Spectre660
 |  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 12:25:24
| | [ #26 ] |
|
|
 |
Elite Member  |
Joined: 4-Jun-2005 Posts: 3918
From: Unknown | | |
|
| This was not a joke. It has to be seen as an attempt of commercial sabotage using electronic means .
Quote:
Poster: OlafS25 Date: 11-Jan-2012 11:15:18 I do not know why people waste time by doing this kind of "jokes". (besides it is a crime but when noone know where the hacker got the password nobody can do anything) |
_________________ Sam460ex : Radeon Rx550 Single slot Video Card : SIL3112 SATA card
|
|
Status: Offline |
|
|
nikosidis
|  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 13:35:35
| | [ #27 ] |
|
|
 |
Cult Member  |
Joined: 9-Dec-2008 Posts: 995
From: Norway, Oslo | | |
|
| Spectre: My password was Money for nothing :P |
|
Status: Offline |
|
|
Spectre660
 |  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 13:47:07
| | [ #28 ] |
|
|
 |
Elite Member  |
Joined: 4-Jun-2005 Posts: 3918
From: Unknown | | |
|
| and I was going to use "chicks for free" Quote:
Spectre: My password was Money for nothing :P |
_________________ Sam460ex : Radeon Rx550 Single slot Video Card : SIL3112 SATA card
|
|
Status: Offline |
|
|
Cass
|  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 14:38:38
| | [ #29 ] |
|
|
 |
Regular Member  |
Joined: 18-Nov-2003 Posts: 481
From: Athens, Greece | | |
|
| The important thing is to change the passwords from the users that have extra privileges.
The normal user account could be used to exploit security holes, but then again anyone from everywhere could create a normal user account, no need to use an existing one in order to do so. Check if there are security holes that can lead to system breach (even from simple accounts). There are plenty of sites that inform regularely for such exploits. _________________ Ordell Robbie: Is she dead, yes or no? Louis: Pretty much.
|
|
Status: Offline |
|
|
sibbi
|  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 15:00:03
| | [ #30 ] |
|
|
 |
Team Member  |
Joined: 18-Mar-2003 Posts: 687
From: Iceland | | |
|
| @Cass
The advice is mainly meant to protect users from someone having access to their private messages and/or posting in their name because they've somehow gained access to the user passwords. We don't know how, where or how many passwords they have, which is why this is just a general warning... _________________ --- Sibbi
Disclaimer: The opinions stated do not neccesarily represent those of my employer.
|
|
Status: Offline |
|
|
Sprocki
|  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 16:05:35
| | [ #31 ] |
|
|
 |
Regular Member  |
Joined: 18-Jul-2004 Posts: 212
From: Berlin - Germany | | |
|
| @ sibbi
Besides using too simple passwords for accounts is a risk of the individual user himself, a totally unsecured login as exists with amigaworld.net opens all doors for sniffing plaintext login data which is the by far bigger security issue than one single, too simple chosen user password. |
|
Status: Offline |
|
|
sibbi
|  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 16:26:31
| | [ #32 ] |
|
|
 |
Team Member  |
Joined: 18-Mar-2003 Posts: 687
From: Iceland | | |
|
| The login names on the portal don't have any relation to the server itself, they are only valid within the portal, access to the server management ports is blocked except for a select few IP addresses of the server adminstrators. Of course if someone has found a hole in our portal system they could have access to the server as the user that webserver runs under.
To sniff the traffic you would also require elevated privileges which would require you to have quite a bit more access to the server than the webserver does, it's not impossible, but would require another exploit to find some way of gaining elevated privileges through a known security bug in a server binary.
That being said we've discussed using SSL encryption for the login to the site, the main problem being the additional yearly cost for operating the site (the cost of applying for and renewing the certificate).
We do try our best to keep everything patched and up to date and we filter access to the server as much as possible, but of course it's never impossible that someone could gain access to it and no Internet site could ever make such a claim. _________________ --- Sibbi
Disclaimer: The opinions stated do not neccesarily represent those of my employer.
|
|
Status: Offline |
|
|
Swoop
 |  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 16:38:09
| | [ #33 ] |
|
|
 |
Elite Member  |
Joined: 20-Jun-2003 Posts: 2163
From: Long Riston, East Yorkshire | | |
|
| @Sprocki Quote:
......a totally unsecured login as exists with amigaworld.net opens all doors for sniffing plaintext login data which is the by far bigger security issue than one single, too simple chosen user password. | It's already been stated that the passwords are stored as md5 not plain text _________________ Peter Swallow. A1XEG3-800 [IBM 750FX PowerPC], running OS4.1FE, using ac97 onboard sound.
"There are 10 types of people in the world: those who understand binary, and those who don't."
|
|
Status: Offline |
|
|
tomazkid
 |  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 16:56:00
| | [ #34 ] |
|
|
 |
Team Member  |
Joined: 31-Jul-2003 Posts: 11694
From: Kristianstad, Sweden | | |
|
| @Swoop Quote:
It's already been stated that the passwords are stored as md5 not plain text |
Yes, the Database is MD5 encrypted, but the login itself is plain text. To encrypt that, SSL is needed. _________________ Site admins are people too..pooff!
|
|
Status: Offline |
|
|
Templario
 |  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 16:57:17
| | [ #35 ] |
|
|
 |
Elite Member  |
Joined: 22-Jun-2004 Posts: 3671
From: Unknown | | |
|
| And the big question, why all amiga sites was hacked? And for what someone our passwords? And what security have this Amiga sites? |
|
Status: Offline |
|
|
kas1e
|  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 17:26:11
| | [ #36 ] |
|
|
 |
Elite Member  |
Joined: 11-Jan-2004 Posts: 3551
From: Russia | | |
|
| |
Status: Offline |
|
|
amigadave
 |  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 17:49:09
| | [ #37 ] |
|
|
 |
Super Member  |
Joined: 18-Jul-2005 Posts: 1732
From: Lake Shastina, Northern Calif. | | |
|
| Any news today on where the hack originated from? Did it start here, or on another site, or can anyone tell where they got Trevor's password(s) from?
Were other member accounts also breached at the same time? If yes, this might help in determining if this site was the one that was attacked and broken into, or if they got the passwords from another site.  _________________ Amiga! The computer that inspired so many, to accomplish so much, but has ended up in the hands of . . . . . . . . . .
|
|
Status: Offline |
|
|
diegocr
|  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 18:10:30
| | [ #38 ] |
|
|
 |
Regular Member  |
Joined: 7-Jun-2006 Posts: 193
From: Unknown | | |
|
| Quote:
It's already been stated that the passwords are stored as md5 not plain text |
MD5 passwords are todays as secure as plain text ones, they can be cracked within seconds/minutes...(unless a salt is being used and that wasn't compromised..) |
|
Status: Offline |
|
|
m0lebrain
|  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 18:29:33
| | [ #39 ] |
|
|
 |
Regular Member  |
Joined: 21-Apr-2004 Posts: 368
From: South Western PA | | |
|
| I've changed my password to "password2012"
Do you think that is a secure enough password?
thank you  _________________ -- -- aka Tony Rocks
|
|
Status: Offline |
|
|
hotrod
|  |
Re: AmigaWorld.Net hacked! Posted on 11-Jan-2012 18:46:05
| | [ #40 ] |
|
|
 |
Elite Member  |
Joined: 11-Mar-2003 Posts: 3005
From: Stockholm, Sweden | | |
|
| Since this is the only site where the hacker(s) used my and PRs account as well one would think that they hacked this site first. My password was just a word but nothing related to me or the Amiga (or even computers in anyway). It wasn't something like "Qsjdflkgj80q2345jnovASRghu9348" though. |
|
Status: Offline |
|
|