ROM Hack PSA: "That ISO site" was hacked, exposing emails, usernames, IP addresses, and salted passwords!

yacepi15

Well-Known Member
Member
Joined
Aug 15, 2015
Messages
1,023
Trophies
0
XP
1,883
Country
Germany
Information has recently come to light that "that ISO site" has been hacked (both the Wii U and 3DS variants), leaking emails, usernames, IP addresses, and salted MD5 passwords. This breach occurred in September of 2015. While this is a big deal, you're probably wondering, why post this here?

I realize that, even though we don't like to admit it, a lot of people download CIAs and ISOs from that site. From that, you can make a logical connection that most people are probably going to share their username and password with their GBATemp account and their "that ISO site" account, and sometimes even their email account. With that being said, this is a warning; if you use the password you use on "that ISO site" ANYWHERE else, you need to change the password immediately, or risk your account being compromised. I personally think that getting hacked because of a piracy site leaking details is a terrible way to go, but that's up to you if it happens.

"But Rhapsody," you ask, "you said the passwords are encrypted with MD5 and salted. There's nothing to worry about, right"? In a way, yes; CrackStation puts it best;



In other words, while your passwords aren't technically out there in plain text, it's still a good idea to change them. On the off-chance "that ISO site" was salting improperly, your password is easily crackable. To be safe, you should take the following steps;
  1. Use a password manager like KeePass or LastPass so you can use unique passwords on each site.
  2. Change your password on any site where you shared a password with "that ISO site", especially your email and GBATemp account if they do.
  3. Ensure that your account hasn't been hacked. If it has, assess the damage, and, if possible, start cleaning it up.
  4. Subscribe to https://haveibeenpwned.com/ on any email addresses you use to be aware of new major breaches.
I know that this is a lot more effort than normal internet users will want to put forward, but for the sake of keeping your accounts secure, you should really change your passwords now and make sure they're all unique, so something like this won't worry you. It's a lot easier when it's all set up.
I have forgotten my password when GW 9.2 was launched and i used one that was sent to my email, only for the 3DS site. In the WiiU site i used directly that password. That website wrotten by the OP says me that only my WiiU site account its compromised. Im safe.
 
Last edited by yacepi15,

Thunder Kai

#TeamRem
Member
Joined
Sep 4, 2015
Messages
1,394
Trophies
0
Location
with Rem
XP
864
Country
United States
I have forgotten my password when GW 9.2 was launched and i used one that was sent to my email, only for the 3DS site. In the WiiU site i used directly that password. That website says me that only my *delet* Site account its compromised. Im safe.
Edit out the site names, it's against the rules
 
Last edited by Thunder Kai,

Rhapsody

Well-Known Member
OP
Member
Joined
Jan 4, 2016
Messages
252
Trophies
0
Age
27
Location
United States
Website
www.google.com
XP
870
Country
United States
I have forgotten my password when GW 9.2 was launched and i used one that was sent to my email, only for the 3DS site. In the WiiU site i used directly that password. That website wrotten by the OP says me that only my WiiU site account its compromised. Im safe.

The website says only one of them, but they both use the same login details; if you sign up for one, you're signed up for the other. You're compromised.
 

Sliter

Well-Known Member
Member
Joined
Dec 7, 2013
Messages
3,264
Trophies
0
Location
ᕕ( ᐛ )ᕗ
XP
1,797
Country
Brazil
Haveibeenpwned is a site that looks through information leaked in large website breaches, and tells people who search their email address what leaks they were involved in. It doesn't provide any of this information to anyone else.
They will send you emails about all breaches they know about
nice! thanks
 
  • Like
Reactions: Deleted-379826

Rhapsody

Well-Known Member
OP
Member
Joined
Jan 4, 2016
Messages
252
Trophies
0
Age
27
Location
United States
Website
www.google.com
XP
870
Country
United States
Why did it take a year for this to come to light?
Sometimes there's a delay between when someone releases the info they hacked the site for, and sometimes there's a delay from when the site owners inform the users about it. It happened that one of those two conditions took a year to come to light. I took a look through the site to see if the webmasters even informed people about this, and it seems like they didn't; chances are they weren't even aware they were hacked.
 

Rhapsody

Well-Known Member
OP
Member
Joined
Jan 4, 2016
Messages
252
Trophies
0
Age
27
Location
United States
Website
www.google.com
XP
870
Country
United States
I got problem on tumblr, linkedin (this sheet only serve do disturb me xp) adobe and that wiiu ... i had account on wiiu site? õ3o lol
Logins between the two ISO sites (for Wii U and for 3DS) are shared since they're run by the same people. If you're compromised on one, you're compromised on both.
 
Last edited by Rhapsody,

migles

All my gbatemp friends are now mods, except for me
Member
Joined
Sep 19, 2013
Messages
8,033
Trophies
0
Location
Earth-chan
XP
5,299
Country
China
glad that i started to use a stupid dumb basic passwords on sites that i barely use like that 3ds iso site, if someone gets my password from there, hope it's good use for ya

bugmenot is a really cool website, i don't get the "you must login or create an account to download one file"
a "guest account" is a really good idea, it prevents spam and you don't need to create an entire new account to use it for 5 minutes...
i know, they want people to participate and show some support for free stuff but come on.. if i require 5 posts or 10 posts to download just that single file, either i go away or create 5 "almost helpfull" with no real content coments...
 
Last edited by migles,

Luckkill4u

4 guys in a car ( ͡° ͜ʖ ͡°)
Member
Joined
Jul 13, 2008
Messages
1,028
Trophies
1
Age
30
Location
Insomnia
Website
www.gbatemp.net
XP
1,131
Country
Canada
It's funny because I created a thread on that iso site about the breach quite a while ago but the admin deleted my thread.
Kinda gave me a feeling that either the site owner doesn't care or was in on it.

Sent from my Samsung Galaxy S7
 
  • Like
Reactions: Deleted User

Futurdreamz

Well-Known Member
Member
Joined
Jun 15, 2014
Messages
2,276
Trophies
1
Age
32
XP
2,128
Country
Canada
Which site? Are we talking about R*****t***? I checked haveibeenpwned and my email address is still clear. I checked it's home page and there's no indications of a hack.
 
Last edited by Futurdreamz,

BADDINOROX99

Well-Known Member
Member
Joined
Sep 9, 2015
Messages
782
Trophies
0
XP
1,093
Country
United States
I barely joined this year in January I think....so I'm pretty sure it's fine since it happened last year anyway why post until now if nothing has happened to anyone here as far as I can tell

Sent from my Nexus 6 using Tapatalk
 

AgentChet

Trunks, The Man.
Member
Joined
Oct 2, 2012
Messages
104
Trophies
0
Location
Secret Island
XP
126
Country
United States
All ISO sites were hacked and released. A better source to find this info is https://www.leakedsource.com/
For only pennies, you can see your real password, email address, IP address, etc. from the database breach.

Very disappointed in the management of the site over there. No public announcement to alert the users. Really a lot of CHAOS if you ask me.
From now on folks, if you see a site running Vbulletin, RUN!

Update: Actually glad Gbatemp moved to Xenforo and away from VB honestly ;) Great call team
 
Last edited by AgentChet,

Hanafuda

Well-Known Member
Member
Joined
Nov 21, 2005
Messages
4,502
Trophies
2
XP
6,982
Country
United States
I just registered there last week. I'm just ..
200.gif
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Veho @ Veho: https://i.imgur.com/7bH4YgV.mp4