Svarbu, del alliedmodders

Kalbos apie viską kas nesusiję su kitais forumais.
Post Reply
sss
Flooderis arba specialistas
Posts: 621
Joined: 2010 Dec 22 20:00
Location: ey b0s

Svarbu, del alliedmodders

Post by sss »

AlliedModders Data Breach
Inbox


AlliedModders Security <[email protected]>
8:01 AM (9 hours ago)

to me
Hi (paslepta),

You are receiving this e-mail because you have an account registered at the AlliedModders forums (https://forums.alliedmods.net/). This week we discovered a data breach that affects all our registered users.

On June 7th we discovered some anomalous files on our webserver, and began investigating where they came from. From what we can tell, on March 16th, an administrator's account was accessed by an unidentified attacker. The attacker used an obscure feature in the forum control panel to upload arbitrary code to our webserver. Then, the attacker downloaded a portion of the forum database. The breached data contained three pieces of information:
* Account names
* E-mail addresses
* Hashed passwords
* Last login IP address

Unfortunately our forum software (vBulletin) used a password hashing scheme that is considered insecure by modern standards. We are therefore recommending that all our users change their passwords as soon as possible. If your AlliedModders password was used on other services, we recommend that you change your password on those services as well.

We do not believe the attacker compromised our systems in a way that would expose private messages, plaintext passwords, real names, or otherwise intercept private traffic. We also believe the March 16th incident was isolated in nature. Nonetheless, it is serious enough to warrant immediate action.

We are deeply apologetic for this incident - it's a black mark on what had been a perfect track record for over ten years. As a result we've attempted to identify and address each of the weaknesses that contributed to this attack. In particular:
* We have modified vBulletin to use more secure password hashing (bcrypt, instead of md5).
* We are now restricting the privileges of all administrator accounts.
* We have restricted vBulletin's file system privileges and added intrusion detection.

Again, we apologize for the inconvenience. If you have any questions, please contact us at [email protected].

-David Anderson

https://alliedmods.net/
"Give me control of a nation's money and I care not who makes it's laws" — Mayer Amschel Bauer Rothschild
Image

User avatar
aaarnas
Vyr. diskusijų administratorius
Posts: 3891
Joined: 2010 Aug 31 13:21
Skype: fiarno
Contact:

Re: Svarbu, del alliedmodders

Post by aaarnas »

md5? Really?
Palikau CS pasaulį ;/ . Nebepasiekiamas.

sss
Flooderis arba specialistas
Posts: 621
Joined: 2010 Dec 22 20:00
Location: ey b0s

Re: Svarbu, del alliedmodders

Post by sss »

aaarnas wrote:md5? Really?
nesitikejau is ju to, bent sha256 ar rsa 1024bit butu... Md5 per sekundes nukrekint galima turint minimaliausia 10gh/s mining rig'a ir tb's dictionary, bet jie siuo atveju naudoja bcrypt kuris nesiekia net sha saugumo lygio
"Give me control of a nation's money and I care not who makes it's laws" — Mayer Amschel Bauer Rothschild
Image

the7n
Gana aktyvus vartotojas
Posts: 368
Joined: 2014 Jan 13 02:28
Skype: darsksidecookie
Location: Vilnius

Re: Svarbu, del alliedmodders

Post by the7n »

ir svarbiausia kad veiksmų imasi tik tada kada kažkas nutinka.. kas juokingiausia kad naudojo md5.... :facepalm:
Last edited by the7n on 2014 Jun 12 21:07, edited 1 time in total.
Image

Kokybiški VPS serveriai su 50% nuolaida - DATANET.LT

Pigiausi, kokybiškiausi minecraft serveriai Lietuvoje - MINEHOST.LT

Post Reply

Who is online

Users browsing this forum: No registered users and 14 guests