devkitPro Forums temporarily shut down due to database vandalization and leak

devkitlogo.png

If you are a homebrew developer then you're most likely familiar with devkitPro, the cross-compiler toolchain used to build virtually all homebrew projects for most of major home consoles out there. However, if you had registered an account on their forums you may want to take immediate action to protect yourself, as today their forums were hacked and suffered a data breach.

At around 5:27 AM (UTC) devkitPro admins alerted their users that an unknown individual managed to gain access to the forum's phpbb3 database, which was later stolen and vandalized. The database also contained the user's login credentials which were salted and hashed, so while they are not immediately accessible to the attacker, they are still vulnerable to other types of attacks. As such, it's highly recommended to change your passwords if you had registered an account on their forums and you reused the same one for other accounts.

In addition, the admins stated that their only working database backup is from 2017 so the forums were temporarily closed and are still down at the time of writing. It's currently unknown when they will become accessible again.

:arrow: Source

[UPDATE 8/2/19]: The forums are now back up.

[UPDATE 2 9/2/19]: The forum's stolen database has been posted publicly on Pastebin and Anonfiles. Again, if you haven't changed your own passwords already, do so now!
 
Last edited by RattletraPM,
I guess I'm outta the loop as of late. Is there any discussion anywhere regarding the incident that is fueling this speculation?
Not sure if Foxi4 is referring to a different incident but https://gbatemp.net/threads/collection-of-old-devkitpro-versions.526377/
The new devkitpro site/source repos removed all the old versions they had stored.
Fair enough. Their site so if they want to do that then so be it.
Various community members then mirrored versions they had collected.
DKP then DMCAs a whole bunch of them (causing a fair bit of trouble for some people as they were on shared hosts) and go around demanding things be taken down.
Various justifications are given for this (several in that link), apparently though they had lost the source to components of the older versions and thus by distributing the installer in their eyes amounted to a distribution of open source code where the licence demands that people have the code for it all made available. This is considered dubious by quite a few as many of said same agreements have provisions for lost source, but so far that is where we are at. When pressed on "what about legacy code made with older incompatible versions?" the answers were more or less "Tough shit, update the code or hack the program, we will help you if you come on our forums/where we are at". "All that effort for a minor variable tweak?" got replies in the affirmative too.
It is also unknown why they feel so compelled to play policeman in this case -- if indeed it is third party components without source, and that they care, it is presumably those third parties that would be aggrieved, not them.

I don't think anybody around here would have decided to take things out as a result -- far more likely the update levels did not match the levels the automated bots go around with, or maybe actually a zero day or something bled through from some other frontend.
 
infrequent backups and not staying current seem like poor management. I'm a stickler for such things, though I'd imagine it's considered somewhat insulting to users to not keep a tight ship.

Curious why this was done as well. I wonder if they were after someone or something specific, just wanted to take a dive and look around, or revenge for some slight.
 
Last edited by osaka35,
  • Like
Reactions: IncredulousP
@FAST6191 Thanks for the thorough explanation. I am surprised I had not heard anything at all about this. Thanks also, for the link to the discussion, what a rabbit hole.
 
I just can't help but wonder... "Why".

dKPs site doesn't have anything special on it, the passwords are salted, so REing them is nigh impossible.

Still, that's basically a large portion of the Switch scene gone since the last backup was in 2017. :/
 
I just can't help but wonder... "Why".

dKPs site doesn't have anything special on it, the passwords are salted, so REing them is nigh impossible.

Still, that's basically a large portion of the Switch scene gone since the last backup was in 2017. :/
It should mostly be the forums and possibly older tools as the newer versions are hosted on GitHub.
 
@FAST6191 Thanks for the thorough explanation. I am surprised I had not heard anything at all about this. Thanks also, for the link to the discussion, what a rabbit hole.
This debacle has been going on for many years. No developer wants their software's legacy versions to be circulated for obvious reasons, and I empathise with that, but in the case of devkitPro many developers don't have an alternative. I just found the timing to be curious - I'm not saying that it's necessarily self-inflicted, but revenge wouldn't be out of the question. Who knows, we'll probably never find out - chances are it was just some random exploiting a vulnerable forum.
 
  • Like
Reactions: MarkDarkness
I just can't help but wonder... "Why".

dKPs site doesn't have anything special on it, the passwords are salted, so REing them is nigh impossible.

Still, that's basically a large portion of the Switch scene gone since the last backup was in 2017. :/

they can still brut force the passwords (using wordbooks or markov chains etc.) the speed for phpass is around 150 MHashes/s per Unit.

So if you reused the password from devkitpro anywhere else you should change it.
 
Last edited by ichichfly,
That´s the point.Who else had interest than great Companies like maybe Nintendo.........and we know since Resident Evil 2 remake money can change the most ambitious hobby programmer.......

Ok i´ve watching too much X-Files.:wacko:

no, i had the same thought,
but then again, maybe i watch too much Alex Jones lmao
my thoughts were either a hired goon from a big company, i.e. Nintendon't, another company with the same interests/business, or, a white knight video game collector who hates everyone because his game room cost him 50k and here we are shopping for free.
 
Last edited by LowEndC,
Something like this happend with another forum. The forum also ran phpbb. THAT forum i had actually signed up on and millions were registered and it was active...it even had addresses and all that.

The forum belonged to the game Town of Salem. Search it up if you haven't heard about it.

Anyways...the point of this reply is that i'm saying it might be a problem with phpbb itself. Maybe hackers are targeting phpbb to tell the site owners that it's insecure and to move to another forum platform.
 
Something like this happend with another forum. The forum also ran phpbb. THAT forum i had actually signed up on and millions were registered and it was active...it even had addresses and all that.

The forum belonged to the game Town of Salem. Search it up if you haven't heard about it.

Anyways...the point of this reply is that i'm saying it might be a problem with phpbb itself. Maybe hackers are targeting phpbb to tell the site owners that it's insecure and to move to another forum platform.
PHPBB, as much as the creators try to maintain it, is grossly out of date, it's an old style BB system. It has been for a long time, so I wouldn't be surprised if this was an internal vulnerability. I find it hard to believe that the devkitPro team didn't do their due diligence, that's highly unlikely, they're some of the most skilled people on the scene.
 
  • Like
Reactions: MarkDarkness
<-- *Nervously looks at what phpbb forums he's registered to* wololo, cough

Yes, it sucks that this happened, but why in the blue blazes of hell did they think to not backup their data, you know, frequently?
 
Last edited by zoogie,
  • Like
Reactions: MarkDarkness

Site & Scene News

Popular threads in this forum