User database posted online

Any other tech-related topics
Message
Author
Nozavi
Posts: 8
Joined: Mon Jun 06, 2011 4:01 am

User database posted online

#1 Post by Nozavi »

Hello

It seems the user database has been hacked and posted online: https://twitter.com/#!/ObSec_/status/106024604832768000

User avatar
webfork
Posts: 10821
Joined: Wed Apr 11, 2007 8:06 pm
Location: US, Texas
Contact:

Re: User database posted online

#2 Post by webfork »

Nozavi wrote:Hello

It seems the user database has been hacked and posted online: https://twitter.com/#!/ObSec_/status/106024604832768000
And I was just having a conversation with someone about the recent "because we can" hack-a-thon going on.

Hydaral
Posts: 194
Joined: Tue Mar 09, 2010 7:36 pm

Re: User database posted online

#3 Post by Hydaral »

I don't know what this is supposed to be, I just get a plain white page with the twitter bar at the top.

User avatar
Firewrath
Posts: 321
Joined: Mon Aug 28, 2006 2:36 pm

Re: User database posted online

#4 Post by Firewrath »

Seems like your browser isnt showing the twitter page correctly.

But crap like this is why i dont like signing up for anything on the web, -_-

User avatar
joby_toss
Posts: 2971
Joined: Sat Feb 09, 2008 9:57 am
Location: Romania
Contact:

Re: User database posted online

#5 Post by joby_toss »

This seems to be a serious problem!

Should we change our passwords, or ...?

Why the hell did this happen? Ooh...I'm having mixed feelings about this...I'd better stop writing until I say something I'll regret!

User avatar
I am Baas
Posts: 4150
Joined: Thu Aug 07, 2008 4:51 am

Re: User database posted online

#6 Post by I am Baas »

joby_toss wrote:This seems to be a serious problem!

Should we change our passwords, or ...?

Why the hell did this happen? Ooh...I'm having mixed feelings about this...I'd better stop writing until I say something I'll regret!
It is very serious... waiting for a word from Andrew... don't want to say anything just yet. I immediately changed my password. There's nothing useful in my profile information but I don't want anyone posting on my name.

User avatar
SYSTEM
Posts: 2043
Joined: Sat Jul 31, 2010 1:19 am
Location: Helsinki, Finland

Re: User database posted online

#7 Post by SYSTEM »

Thank you for the heads-up, Nozavi.

Password Safe both generated a new password and will remember it for me. What a great application...
My YouTube channel | Release date of my 13th playlist: August 24, 2020

Hydaral
Posts: 194
Joined: Tue Mar 09, 2010 7:36 pm

Re: User database posted online

#8 Post by Hydaral »

I disabled blocking on my browser, so now I can see the post, but both the pastebin links are dead.

It doesn't sound like it was that bad though, all our passwords are hashed, right?

User avatar
JohnTHaller
Posts: 716
Joined: Wed Feb 10, 2010 4:44 pm
Location: New York, NY
Contact:

Re: User database posted online

#9 Post by JohnTHaller »

joby_toss wrote:This seems to be a serious problem!

Should we change our passwords, or ...?

Why the hell did this happen? Ooh...I'm having mixed feelings about this...I'd better stop writing until I say something I'll regret!
Yes, everyone should change their passwords, especially if they use the same password and login on other sites. phpBB uses a hashed password table (as any application should), but once someone has the hash to your password, they could brute-force it to figure out your possible password. And if you share that password and login with other sites (think PayPal, your email account, banking, etc) bad things can happen. So, yes, you should change your password as well as any other sites you use the same password on. And you should use a different password for each site. Something like KeePass can generate very secure passwords for you and remember them.
Last edited by JohnTHaller on Wed Aug 24, 2011 1:08 pm, edited 1 time in total.
PortableApps.com - The open standard for portable software | Support Net Neutrality

User avatar
SYSTEM
Posts: 2043
Joined: Sat Jul 31, 2010 1:19 am
Location: Helsinki, Finland

Re: User database posted online

#10 Post by SYSTEM »

Hydaral wrote:I disabled blocking on my browser, so now I can see the post, but both the pastebin links are dead.

It doesn't sound like it was that bad though, all our passwords are hashed, right?
I saw the list and can confirm that the passwords are indeed hashed.

However, all email addresses were leaked as well.

In addition, cracking the passwords may be possible with rainbow tables.
My YouTube channel | Release date of my 13th playlist: August 24, 2020

User avatar
JohnTHaller
Posts: 716
Joined: Wed Feb 10, 2010 4:44 pm
Location: New York, NY
Contact:

Re: User database posted online

#11 Post by JohnTHaller »

SYSTEM wrote:However, all email addresses were leaked as well.
Right, forgot about that bit. I use a standard email account for all signups like this that is separate from my main ones to avoid excessive spam, but many other users may not.
PortableApps.com - The open standard for portable software | Support Net Neutrality

freakazoid
Posts: 1212
Joined: Wed Jul 18, 2007 5:45 pm

Re: User database posted online

#12 Post by freakazoid »

Time to update and patch phpBB!
is it stealth? ;)

User avatar
joby_toss
Posts: 2971
Joined: Sat Feb 09, 2008 9:57 am
Location: Romania
Contact:

Re: User database posted online

#13 Post by joby_toss »

Hmm...this attack happened on July 5th! A SQL injection method was used. Damn! :evil:
I don't remember exactly, but wasn't that the time we started to get those login captcha requests?
And why did it took so long to find this out? Damn!

@Nozavi: Multumim frumos! Abia acum mi-am dat seama ca esti roman! ;)

User avatar
webfork
Posts: 10821
Joined: Wed Apr 11, 2007 8:06 pm
Location: US, Texas
Contact:

Re: User database posted online

#14 Post by webfork »

EDIT: NickR just explained this post is inaccurate. Ignore.

SYSTEM wrote:However, all email addresses were leaked as well.


Actually only emails, usernames, and hashed passwords were leaked through A-M. If your username starts with N - Z you might want to change your password just to be safe, but your email address hasn't been exposed.

NickR
Posts: 105
Joined: Thu Aug 26, 2010 6:37 am

Re: User database posted online

#15 Post by NickR »

@webfork - There was a second file which cobtained the data for everyone else ie Michael84 to Zurgerok
and then circa 200 more entries which were not listed alphabeticaly

Post Reply