[Theory] How the site was "hacked" and what you can do to stay safe

  • Thread starter Deleted User
  • Start date
  • Views 1,920
  • Replies 16
  • Likes 1
Status
Not open for further replies.
D

Deleted User

Guest
OP
I can almost guarantee that this was just a simple bruteforce to get passwords using a program called SentryMBA, and not an exploit. Similar. This is a similar method that people use to get access to netflix, hulu, and minecraft accounts. The same thing happened to Se7enSins a few months ago. So this is all coming from experience and what us and our staff team did to prevent as much damage as possible. While this method of attack is of course a theory. I do recommend that you do not take this suggestion lightly.

1. Change your password to something new. I recommend using this site to generate a secure password
2.
Enable 2 factor authentication. This is what the staff team here uses so even if your password gets compromised. No one can use your account unless they can get this second code either via google authenticator or the accounts email(Whomever generates this unique code will only have a limited amount of time to use it before it expires) You can find this in your account settings.

If you do one or both of these you will be perfectly fine. Although I doubt most of us will have any issues anyway since the script kiddies are only interested in popular/powerful accounts.

i.e Hundshammer, auroram and staff members
 
Last edited by ,
  • Like
Reactions: hobbledehoy899
D

Deleted User

Guest
OP
theres no 2FA on this site.
Its built into Xenforo. So an admin must of went out of their way in the ACP(admin control panel) and disabled it...ugh. Ill make a note thank you. I wasn't aware that they disabled it since that doesn't make much sense security wise.

Never seen F2A on this site

Have you been hacked?
No sir. Always have those unique passwords ;)
 
D

Deleted User

Guest
OP
Its built into Xenforo. So an admin must of went out of their way in the ACP(admin control panel) and disabled it...ugh. Ill make a note thank you. I wasn't aware that they disabled it since that doesn't make much sense security wise.


No sir. Always have those unique passwords ;)
Wow it got disabled

Let's just throw this site out next, shall we? I can't believe the admins would do that fuck.
 
D

Deleted User

Guest
OP
My iso and gba are different
That doesn't mean that users don't share usernames and passwords


I was hacked too remember. I am the one who first notified admins.... got called a troll and had my post moved to EOF
That still doesn't debunk a program like SentryMBA potentially being apart of this...I recommend reading up on that program and how it works before replying again. Not trying to cause an argument but you honestly seem like you don't quite understand the terminology of whats going on here. Your last reply to Zoogie gives some strength to that statement as well.

I apologize for saying that, especially since this is a theory. But you are trying to refute theories with statements that make no sense. :(
 

pwsincd

Garage Flower
Developer
Joined
Dec 4, 2011
Messages
3,686
Trophies
2
Location
Manchester UK
XP
4,465
ok cause our IRC channel and specifically my login was compromised and it carried the same password as here.. so it seems peoople are using the info gained.
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Psionic Roshambo @ Psionic Roshambo: https://www.youtube.com/watch?v=W6ckbBpSKhw