SECURITY: change passwords, right now !

Dawn of Light related news and announcements.

Moderator: Developer Team

SECURITY: change passwords, right now !

Postby Graveen » Wed Sep 16, 2009 10:30 pm

Hello community,

Due to some problems in the website troubleshooting, it is HEAVILY suggested to change the following passwords:

- forum account
- daocportal account
- Storm ingame account (type /password to change it from ingame)


The risk is mainly an encrypted password catch, that could be break in a couple of hours.
Thanks for your understanding.
Image
* pm me to contribute in Dawn of Light: code, database *
User avatar
Graveen
Project Leader
 
Posts: 12660
Joined: Fri Oct 19, 2007 9:22 pm
Location: France

Re: SECURITY: change passwords, right now !

Postby brink668 » Thu Sep 17, 2009 12:40 am

The spam setting that is blocking gmail users from signing up is also preventing me from changing password. :confused:
Image
brink668
Support Team
 
Posts: 722
Joined: Tue Oct 18, 2005 2:54 am
Website: http://www.computerrich.com

Re: SECURITY: change passwords, right now !

Postby Tolakram » Thu Sep 17, 2009 1:01 am

brink668 wrote:The spam setting that is blocking gmail users from signing up is also preventing me from changing password. :confused:


I was able to change passwords with Firefox, no problem. ????
- Mark
User avatar
Tolakram
Storm / Storm-D2 Admin
 
Posts: 9189
Joined: Tue Jun 13, 2006 1:49 am
Location: Kentucky, USA

Re: SECURITY: change passwords, right now !

Postby johndoe » Thu Sep 17, 2009 5:42 am

phpBB encryption is one way only, there's no way to decrypt it back into original state.

daocportal account - whats that? :?

storm ingame account? hmm. sounds like you let someone else gain access to the database.

there's something you not telling us, not all of the truth :?:
Note: I'm not Johndoe in any game. Dont trust impersonators!
[Will PK for food.]
Apache/PHP/MySQL/VB6
User avatar
johndoe
DOL Experienced
 
Posts: 178
Joined: Sun Apr 27, 2008 7:46 am
Location: Cloud 9

Re: SECURITY: change passwords, right now !

Postby Dunnerholl » Thu Sep 17, 2009 6:51 am

johndoe wrote:phpBB encryption is one way only, there's no way to decrypt it back into original state.

daocportal account - whats that? :?

storm ingame account? hmm. sounds like you let someone else gain access to the database.

there's something you not telling us, not all of the truth :?:


its no encryption its simply hash values. and there are huge hashdatabases that u can use for reverse lookups, rainbow tables...and even if not u can create them.

i think the problem would be for people using the same pw for all kind of things, so if one is found it works for all
Dunnerholl
Developer
 
Posts: 1229
Joined: Mon Sep 08, 2008 8:39 pm

Re: SECURITY: change passwords, right now !

Postby johndoe » Thu Sep 17, 2009 12:01 pm

There're thing worth breaking in to, and there're things not worth the time spent on breaking in to. None of the mentioned above accounts are worth the time the hacker needs to spend to write a program to break into. Hackers do it for either fame or profit, nothing else. Most of the people that play on Storm, and have some value to their accounts have no idea what programming is, not even to mention that they are absolutely clueless about where even to begin about getting someone elses password. Its like getting paranoid about some nasty hacker breaking into your screen saver to readjust timer delay, and thus changing its password every week. In other words, all this fuss about mass password change is absolutely pointless; at least here.
I've been in the internet programming industry since spring 1995, and since that time I've never heard any hacker to to actually waste his/her time on something like what we have here. Unless, I repeat myself... there's something you not telling us, not all of the truth :wink:
Last edited by johndoe on Thu Sep 17, 2009 12:03 pm, edited 1 time in total.
Note: I'm not Johndoe in any game. Dont trust impersonators!
[Will PK for food.]
Apache/PHP/MySQL/VB6
User avatar
johndoe
DOL Experienced
 
Posts: 178
Joined: Sun Apr 27, 2008 7:46 am
Location: Cloud 9

Re: SECURITY: change passwords, right now !

Postby Wigberg » Thu Sep 17, 2009 12:02 pm

yep i agree with dunner

btw .. what about a new cms ? phpnuke, phpkit, joomla etc ..
with more security settings ?.. and lesser exploits..

phpbb is to known .. i think you know what i mean ..
but the mainproblem woulld be .. how to migrate the userdata from phpbb into the new cms ..
Image

Use this for linking to this Server if you want to make some promo for Storm
Code: Select all
[url=http://play.dolserver.net][img]http://wigberg.de/images/storm.gif[/img][/url]
User avatar
Wigberg
Server Team
 
Posts: 348
Joined: Mon Dec 24, 2007 3:12 am
ICQ: 273642582
Website: http://wigberg.de
Location: Germany

Re: SECURITY: change passwords, right now !

Postby Dinberg » Thu Sep 17, 2009 1:41 pm

johndoe wrote:and since that time I've never heard any hacker to to actually waste his/her time on something like what we have here.


Sadly it seems you've never had to deal with the few charming individuals who frequent DoL solely for the purpose of causing mayhem. The sad truth is we get alot of script kiddies come through here, who don't neccessarily have skill or intelligence but who have time on their hands and a grudge for a ban to boot. We don't announce when someone does try anything because they never get anywhere anyway and it would cause paranoia. People have tried in the past though, and I'm sure people will continue to.

While you've never heard of anyone wasting their time to try their 1337ness here, I certainly have over my time. They dont stand a chance, but for the sake of security I'd support Graveen in ensuring that we dont let them have more of a swing at it.


As a side note, daoc portal accounts are the worst. Thats not because people 'hack' them, its because admins cant seem to ever learn the difference between trustless and trustworthy. Why do people insist so heavily on giving their account details to seemingly anyone?
The Marvelous Contraption begins to stir...
User avatar
Dinberg
Inactive Staff Member
 
Posts: 4695
Joined: Sat Mar 10, 2007 9:47 am
Yahoo Messenger: dinberg_darktouch
Location: Jordheim

Re: SECURITY: change passwords, right now !

Postby roflson » Thu Sep 17, 2009 2:47 pm

johndoe wrote:There're thing worth breaking in to, and there're things not worth the time spent on breaking in to. None of the mentioned above accounts are worth the time the hacker needs to spend to write a program to break into. Hackers do it for either fame or profit, nothing else. Most of the people that play on Storm, and have some value to their accounts have no idea what programming is, not even to mention that they are absolutely clueless about where even to begin about getting someone elses password. Its like getting paranoid about some nasty hacker breaking into your screen saver to readjust timer delay, and thus changing its password every week. In other words, all this fuss about mass password change is absolutely pointless; at least here.
I've been in the internet programming industry since spring 1995, and since that time I've never heard any hacker to to actually waste his/her time on something like what we have here. Unless, I repeat myself... there's something you not telling us, not all of the truth :wink:


MD5 has embarrassingly large databases of precomputed hashes. It requires absolutely 0 time or effort on the part of the person checking passwords, a simple shell script can do it automatically over the course of a few hours (depending on # of users, likely faster with a small DB)

Sites (phpbb or otherwise) get compromised all the time, and taking pre-emptive security measures should be APPLAUDED, not whatever the hell it is you're currently doing. If more people took measures like this, maybe so much internet traffic wouldn't be compromised hosts.

And when you narrow the focus to a 'hacker site' itself (let's face it, server emulation has a bad reputation), you're likely to find at least a few people with an axe to grind.

I seriously can't believe your 1995 claim with the rest of your line of thinking there. Unless you haven't learned anything since then.
roflson
DOL Guest
 
Posts: 4
Joined: Thu Jul 16, 2009 12:58 am

Re: SECURITY: change passwords, right now !

Postby Graveen » Thu Sep 17, 2009 4:35 pm

/shrug... there are low but real chances someone get access to the website databases. For numerous reasons, theses dbs are containing some informations that could harm from forum accounts to Storm accounts.

Everyone change their passwords, that's all. My experience tends to proove exactly the reverse of what you are saying JD, concerning overall security: "if the worse is possible, the worse will happen."

I HOPE the risk is low, and i HOPE it won't happen :D
Image
* pm me to contribute in Dawn of Light: code, database *
User avatar
Graveen
Project Leader
 
Posts: 12660
Joined: Fri Oct 19, 2007 9:22 pm
Location: France

Re: SECURITY: change passwords, right now !

Postby Tolakram » Thu Sep 17, 2009 4:45 pm

In other words, all this fuss about mass password change is absolutely pointless; at least here.
I've been in the internet programming industry since spring 1995, and since that time I've never heard any hacker to to actually waste his/her time on something like what we have here. Unless, I repeat myself... there's something you not telling us, not all of the truth


Our security measures are based on past behavior specific to this community and not some grand worldwide hacking risk.

Some information was exposed that, if someone wanted to, could be used to do damage specific to us and DOL.

Your attitude is needlessly confrontational, again.

I'm sorry if you were hoping we'd provide step by step instruction for exactly what someone could do with information they may or may not have obtained. :mrgreen:
- Mark
User avatar
Tolakram
Storm / Storm-D2 Admin
 
Posts: 9189
Joined: Tue Jun 13, 2006 1:49 am
Location: Kentucky, USA

Re: SECURITY: change passwords, right now !

Postby baradien » Sat Oct 17, 2009 8:34 pm

well for me it's no problem if i don't change my password lol :)
i will still find it anyway.
baradien
Server Team
 
Posts: 950
Joined: Wed Jan 23, 2008 3:17 pm
Location: Belguim

Re: SECURITY: change passwords, right now !

Postby Graveen » Mon Mar 12, 2012 2:40 pm

Thread necro ! TY Tola to link this topic.

Here comes the real story: i was working on the new webserver. Precisely, Apache was not completly configured.

After a long time of work, i had to eat. Nice, i was hungry ! I had the genius idea to reboot, to check if all the services were starting fine. As i hate to lost my time, i rebooted just before going dinner.

When i get back, all services were ok, but... not php interpreter installed, so it displayed the *content* of .php files.... Argh !
At this moment, if someone tryed the to access config.php file (manually in the url bar), he would have catch the database password, which contains all hashed passwords in MD5:
- we were replicating Storm DB, so there was Storm accounts
- we are hosting Portal related tables, including server accounts
- and of course forum tables

It took me 25 minutes to eat, this was a non public server *but* internet accessible with URL (such test.dolserver.net), so guys, you know the only thing to do in such a case: full disclosure and damage control.

Remember, remember ! :)
Image
* pm me to contribute in Dawn of Light: code, database *
User avatar
Graveen
Project Leader
 
Posts: 12660
Joined: Fri Oct 19, 2007 9:22 pm
Location: France


Return to “%s” Announcements

Who is online

Users browsing this forum: No registered users and 1 guest