devkitPro Forums temporarily shut down due to database vandalization and leak

devkitlogo.png

If you are a homebrew developer then you're most likely familiar with devkitPro, the cross-compiler toolchain used to build virtually all homebrew projects for most of major home consoles out there. However, if you had registered an account on their forums you may want to take immediate action to protect yourself, as today their forums were hacked and suffered a data breach.

At around 5:27 AM (UTC) devkitPro admins alerted their users that an unknown individual managed to gain access to the forum's phpbb3 database, which was later stolen and vandalized. The database also contained the user's login credentials which were salted and hashed, so while they are not immediately accessible to the attacker, they are still vulnerable to other types of attacks. As such, it's highly recommended to change your passwords if you had registered an account on their forums and you reused the same one for other accounts.

In addition, the admins stated that their only working database backup is from 2017 so the forums were temporarily closed and are still down at the time of writing. It's currently unknown when they will become accessible again.

:arrow: Source

[UPDATE 8/2/19]: The forums are now back up.

[UPDATE 2 9/2/19]: The forum's stolen database has been posted publicly on Pastebin and Anonfiles. Again, if you haven't changed your own passwords already, do so now!
 
Last edited by RattletraPM,

Mythical

Well-Known Member
Member
Joined
May 11, 2017
Messages
2,153
Trophies
1
Age
25
XP
3,003
Country
United States
Whatever my point still stands. Don't assume it won't be hacked and make backups.
It was never about your point being valid. You asked a question and someone answered. Then you changed your own reply with an edit. I just thought it was funny because you said never mind forget what I said then went to declare your point valid anyways in the same post
 
  • Like
Reactions: lincruste

the_randomizer

The Temp's official fox whisperer
Member
Joined
Apr 29, 2011
Messages
31,284
Trophies
2
Age
38
Location
Dr. Wahwee's castle
XP
18,969
Country
United States
It was never about your point being valid. You asked a question and someone answered. Then you changed your own reply with an edit. I just thought it was funny because you said never mind forget what I said then went to declare your point valid anyways in the same post

Whatever you say.
 
  • Like
Reactions: Mythical

Kioku

猫。子猫です!
Member
Joined
Jun 24, 2007
Messages
12,023
Trophies
3
Location
In the Murderbox!
Website
www.twitch.tv
XP
16,195
Country
United States
  • Like
Reactions: the_randomizer

Ericthegreat

Not New Member
Member
Joined
Nov 8, 2008
Messages
3,455
Trophies
2
Location
Vana'diel
XP
4,312
Country
United States
QUOTE="VinsCool, post: 8499767, member: 343260"]Jesus, that's disgusting.
Why out of anything would they attack devkitpro?
That makes no sense at all.[/QUOTE]
Probably a angry dev.
 
  • Like
Reactions: Kioku

Ericthegreat

Not New Member
Member
Joined
Nov 8, 2008
Messages
3,455
Trophies
2
Location
Vana'diel
XP
4,312
Country
United States
A backup from 2017? gees. Why not use something like acronis always on backup. The shit makes no stop backups...
Eh sometimes you just get lazy after running a site or a app for a long time, I've made a few small games that no longer work due to needing to update a few small things, but you know, I'll do it tomorrow.
 

Captain_N

Well-Known Member
Member
Joined
Mar 29, 2010
Messages
1,909
Trophies
2
XP
2,055
Country
United States
Eh sometimes you just get lazy after running a site or a app for a long time, I've made a few small games that no longer work due to needing to update a few small things, but you know, I'll do it tomorrow.

Thats why i mentioned acronis always on backup. Its automatic. Does everything for you...
 

Captain_N

Well-Known Member
Member
Joined
Mar 29, 2010
Messages
1,909
Trophies
2
XP
2,055
Country
United States
For what price? Where is it backed up? How do you know the owner has the hard drives to support many backups?

I dont know what their setup is or how much space their hoster allows. I can only make assumptions based on commonly hosted sites and forums. The data can be dumped over a vpn, or ftp to their home pc. Their database cant be that large compressed, lets say 1 gig. Hard drives are hella cheap. 6 tb is about $130. As for the price well they can just torrent it or buy a copy. I suppose the backups can be copied to google drive as well to save home internet bandwidth restrictions. I cant see their database being 15 gigs..
Even 100 gigs is nothing now a days.
 
  • Like
Reactions: Ericthegreat

DayVeeBoi

Well-Known Member
Member
Joined
Aug 17, 2015
Messages
528
Trophies
0
Location
Canada
XP
968
Country
Canada
I'm aware. My Pacman repos didn't break or anything. It's just awful to see all discussion from the past two years being gone.
I apologize, I did not mean to imply that it was just forum discussion etc., on reading my reply again I can see why it may have seemed that way.
I was just in a hurry earlier and banged off a quick reply before I left. I am aware that many problems have been solved with a quick search of the right resource.
 
  • Like
Reactions: Ev1l0rd

Ev1l0rd

(⌐◥▶◀◤) girl - noirscape
Member
Joined
Oct 26, 2015
Messages
2,004
Trophies
1
Location
Site 19
Website
catgirlsin.space
XP
3,441
Country
Netherlands
Life sucks. As someone who suffers from depression and ADD, some things are hard to do. However, if you choose to maintain and operate a site like this, you have to know your limits. If you're incapable, hand it off to someone who can. Again, life sucks.
You severely underestimate the amount of work WM and the entire devKitPro team does to provide homebrew tools. Let me put it very simple: without devKitPro, homebrew on the Nintendo 3DS wouldn't exist. Without devKitPro, homebrew on the Switch would be reliant on libtransistor, a library made by RS that never ended up anywhere.

They know what they do and they provide a lot. It's understandable that backups aren't the immediate highest priority, given how they're maintaining several toolchains for Homebrew (Switch, 3DS, Wii, GBA, GameCube and the Gamepark G32), which takes up a lot of time, which isn't helped by the fact that a number of the "quick and easy" libraries (most famous is sf2d, but there's tons of them out there) end up with a lot of developers that blame devKitPro for the external library issues.

That results in a very heavy burden on devKitPro. So while it's awful that dKP doesn't have a recent backup, it's not something I'm entirely suprised by, given how backing up their forums isn't directly high priority compared to the other tools they provide.

A backup from 2017? gees. Why not use something like acronis always on backup. The shit makes no stop backups...
They're unlikely to use that, Acronis is proprietary software.

I'd personally advise something like restic or borg (restic is better if you're just needing something locally backed up to prevent you from shooting yourself in the foot, borg is better if you need multiple external locations). They provide automated incremental backups that are encrypted and can be send to an external location. Automating is just a matter of setting up a crontab on the server. It's also easily possible to put them on a "time machine" esque schedule where only recent backups are kept and older ones are consilidated.

Both are highly recommend tools.
 

Foxi4

Endless Trash
Global Moderator
Joined
Sep 13, 2009
Messages
30,844
Trophies
3
Location
Gaming Grotto
XP
29,929
Country
Poland
<-- *Nervously looks at what phpbb forums he's registered to* wololo, cough


https://twitter.com/davejmurphy/status/1092309304978432000
Ultimately it's an excuse. Backups can be automated and don't require much attention from a site admin, but they are an important duty. We're talking about a database full of login details, passwords and e-mails - maintaining it entails a certain degree of responsibility. He hasn't backed up the site since 2017, that's two years and no backup whatsoever. If he was in a bad headspace, he should've hired someone who wasn't, even if only for the purpose of protecting his community from unexpected data loss. There was no need to look for excuses, it's a clear slip-up. He should take this as a learning experience and improve in the future, making mistakes is what makes us human.
 

Ev1l0rd

(⌐◥▶◀◤) girl - noirscape
Member
Joined
Oct 26, 2015
Messages
2,004
Trophies
1
Location
Site 19
Website
catgirlsin.space
XP
3,441
Country
Netherlands
Last edited by Ev1l0rd,
  • Like
Reactions: RattletraPM

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    a_username_that_isnt_cool @ a_username_that_isnt_cool: @Xdqwerty, about to