Quote from: RoflWaffle on January 16, 2012, 05:31:11 AMQuote from: Smt on January 16, 2012, 02:48:18 AMQuote from: Degtyarev on January 16, 2012, 12:35:32 AMMind explaining what you mean by "broke in"?I enjoy the specifics of things, and I think I ought to know what may/may not bring me issuesfrom what i heard no one changed the DB password since it was leaked 8 months ago, unless some of your admins are making up bull shit on the spotadmins are full of shit, not only did we change the password multiple times since then but its IP locked so it wouldn't matterwhat really happened was a certain group of kiddies got a hold of two admins passwords which happened to be incredibly insecure and decided to ban allNothing on CGs side was compromised.If nothing was compromised, why are we being told to change our passwords?
Quote from: Smt on January 16, 2012, 02:48:18 AMQuote from: Degtyarev on January 16, 2012, 12:35:32 AMMind explaining what you mean by "broke in"?I enjoy the specifics of things, and I think I ought to know what may/may not bring me issuesfrom what i heard no one changed the DB password since it was leaked 8 months ago, unless some of your admins are making up bull shit on the spotadmins are full of shit, not only did we change the password multiple times since then but its IP locked so it wouldn't matterwhat really happened was a certain group of kiddies got a hold of two admins passwords which happened to be incredibly insecure and decided to ban allNothing on CGs side was compromised.
Quote from: Degtyarev on January 16, 2012, 12:35:32 AMMind explaining what you mean by "broke in"?I enjoy the specifics of things, and I think I ought to know what may/may not bring me issuesfrom what i heard no one changed the DB password since it was leaked 8 months ago, unless some of your admins are making up bull shit on the spot
Mind explaining what you mean by "broke in"?I enjoy the specifics of things, and I think I ought to know what may/may not bring me issues
Quote from: Martinerrr on January 16, 2012, 06:20:06 AMQuote from: RoflWaffle on January 16, 2012, 05:31:11 AMQuote from: Smt on January 16, 2012, 02:48:18 AMQuote from: Degtyarev on January 16, 2012, 12:35:32 AMMind explaining what you mean by "broke in"?I enjoy the specifics of things, and I think I ought to know what may/may not bring me issuesfrom what i heard no one changed the DB password since it was leaked 8 months ago, unless some of your admins are making up bull shit on the spotadmins are full of shit, not only did we change the password multiple times since then but its IP locked so it wouldn't matterwhat really happened was a certain group of kiddies got a hold of two admins passwords which happened to be incredibly insecure and decided to ban allNothing on CGs side was compromised.If nothing was compromised, why are we being told to change our passwords?Using the SMF adminCP, assuming these admins had access to it, you can backup any sql table. And yes SMT, passwords are salted and hashed, but they can still be bruted.
Quote from: Smt on January 16, 2012, 02:48:18 AMQuote from: Degtyarev on January 16, 2012, 12:35:32 AMMind explaining what you mean by "broke in"?I enjoy the specifics of things, and I think I ought to know what may/may not bring me issuesfrom what i heard no one changed the DB password since it was leaked 8 months ago, unless some of your admins are making up bull shit on the spotwhat really happened was a certain group of kiddies got a hold of two admins passwords which happened to be incredibly insecure and decided to ban allNothing on CGs side was compromised.
My assumption was a lot of RTLK's scripts for handling bans were completely insecure and required no authentication, only a steamID. If he actually followed the new developer guidelines instead of assuming he's above them, as usual, that wouldn't be a problem. It's most likely that it was a type of SQL injection.
Quote from: Somone77 on January 16, 2012, 03:44:24 AMMy assumption was a lot of RTLK's scripts for handling bans were completely insecure and required no authentication, only a steamID. If he actually followed the new developer guidelines instead of assuming he's above them, as usual, that wouldn't be a problem. It's most likely that it was a type of SQL injection. Which one makes more sense? How could 2 admins out of the entire staff be the ones targeted. Blt is not a idiot to have a easy password. Acorn is also not that dumb. The question is how they got ahold of them. Someone77 made sense out of it but no one wants to make a confession.
And yes SMT, passwords are salted and hashed, but they can still be bruted.