Forum Topic: --> Recent Account Security Issues

(4,948 views • 159 replies)

This topic is 6 pages long. [ 1 | 2 | 3 | 4 | 5 | 6 ]

<< < > >>
None

absent

Reply To Post Reply & Quote

Posted at: 7/14/09 10:50 AM

absent LIGHT LEVEL 30

Sign-Up: 04/11/05

Posts: 8,593

Re-creating Evark's thread. As an additional warning, I would like all of the users to read up on Cross-site scripting.

Here is the thread in its entirety, plus rules for posting here.

Since Wade's threads are now missing and I doubt he's the time to make a new one, I've decided to put up a new thread to ease General's baseless fears and explain what's happened.

This past week, a concerted effort has been made by some random nobodies to cause problems for NG. Thus far they've:
%u2028- Accessed 4 moderator accounts (including some BBS moderators, hence the deletion of a number of recent threads and thusly users' recent posts)%u2028- Accessed a number of user's accounts%u2028- Caused an unnecessary panic amongst the active members of the community.

How did they do this? Simply. VERY SIMPLY.

Phishing. For those uninterested in the wiki article, phishing is most commonly used to gain sensitive information for the purpose of stealing identify information or bank account access information.

- HOW DOES PHISHING WORK?%u2028Phishing is typically conducted by posting an identical copy of NG's layout on a non-NG domain name. A page may appear entirely as Newgrounds.com does, every link will link to normal NG.com URLs, everything appears ordinary EXCEPT the URL at the top of your page. The page will request your username and password, most notably in cases where you were already logged in to NG when you were directed to the phishing page.

- HOW CAN I PROTECT MYSELF?%u2028Be observant. If the URL at the top of your page does not say "newgrounds.com" for the domain, or is unrecognizable to normal NG URLs, DO NO ENTER YOUR INFORMATION.

That explains day 1's attack. You guys see accounts compromised, mods are alerted to the scheme, phishing is no longer a viable method of compromising accounts for these random nobodies. Panic abounds.

Day 2 is a different method. Also simple.

Brute force attack. A brute force attack is a method by which an account (usually email which doesn't restrict password attempts as NG does) is systematically cross-referenced with a database of common words, phrases, and variations therein.

- HOW DOES BRUTE FORCE WORK?%u2028A brute force attack works by running a program that tries password after password until it is successful. Kinda like asking "are we there yet?" on a long car ride nonstop for several hours.

- HOW CAN I PROTECT MYSELF?%u2028You can protect yourself by ensuring that your email account password is anything but common. Use a strongly secure password. A strongly secure password follows these rules:%u2028+++Contains alphabetical, numerical, and non-alphanumeric characters%u2028+++Contains a mixture of upper case and lowercase letters%u2028+++Is completely indecipherable and meaningless%u2028+++Does not follow an easily recognizable pattern of any sort

- UH, I HAVE NO IDEA WHAT YOU'RE SAYING, GIVE AN EXAMPLE%u2028Ok, well... if your password is, for instance: penis, you'll be compromised. If it's, for instance: p3n15, you'll be compromised. But, if you've got your password set as p3N0rD1i(l(z, (see penordicks and an additional number in there?) you're probably reasonably safe.

There are a number of sites online that you may find using a simple google search that can generate a decent password for you, or explain how to come up with your own (so you can remember it).

-------------------

Now then, that's all I've got to offer. I hope you all take heed of the warnings that have been heaped on you in the past few days, but go ahead and drop the useless panic. When YOUR account is compromised, you may Private Message an administrator with an alt and provide detailed information about the account's personal details (name, school, email addy signed up with, email addy before being compromised, old password, etc.) and they can get it back for you. If a moderator's account is compromised, you may message a moderator, preferably one that you know is online and active, and preferably using AIM or something similar so that they notice faster. PMs are great, but they tend to pile up quickly and if the mod isn't navigating to new pages on NG, they won't notice they've been contacted.
Thanks. Please try to keep conversation as non-sensational as possible. This is not the downfall of NG or anything like that. It's just a couple of lucky breaks for some annoying e-miscreants.

-------------------

THINGS I WILL NOT TOLERATE IN THIS THREAD:
- Posting of private mod-lounge information
- Rumors and misinformation
- Sensational mention of as-yet-unrealized threats
- Comments suggesting that we remain apprehensive about our accounts' security

Also: I'm deleting references to those responsible. It isn't important who is responsible, and I will not allow them to have their recognition.

BBS Signature

Crying

Lagamuffin

Reply To Post Reply & Quote

Posted at: 7/14/09 10:52 AM

Lagamuffin FAB LEVEL 20

Sign-Up: 09/22/07

Posts: 4,056

I got hit.
:c

|MSN| <- ADD ME YOU JEW.
[Makeshift] Does like ALL of my sigs.<3
Also, this is totally not a ripoff of Jack's sig.

BBS Signature

None

absent

Reply To Post Reply & Quote

Posted at: 7/14/09 10:55 AM

absent LIGHT LEVEL 30

Sign-Up: 04/11/05

Posts: 8,593

At 7/14/09 10:51 AM, TheRatchnator wrote: Why the need to recreate Evark's thread if there was no phishing link in the original topic.

Because this is a warning to users who haven't been following recent events, plus is a place to hold all discussion related to the issue.

Also, sorry the OP is a little messed up. Still readable, I hope.

BBS Signature

Angry

Lagamuffin

Reply To Post Reply & Quote

Posted at: 7/14/09 10:55 AM

Lagamuffin FAB LEVEL 20

Sign-Up: 09/22/07

Posts: 4,056

At 7/14/09 10:54 AM, TheRatchnator wrote:
At 7/14/09 10:52 AM, Lagamuffin wrote: I got hit.
c
I checked to see if he was a mod for anything else and lucky that he is only a review mod.

And a BBS mod.

|MSN| <- ADD ME YOU JEW.
[Makeshift] Does like ALL of my sigs.<3
Also, this is totally not a ripoff of Jack's sig.

BBS Signature

None

Ejit

Reply To Post Reply & Quote

Posted at: 7/14/09 10:56 AM

Ejit LIGHT LEVEL 22

Sign-Up: 02/17/06

Posts: 10,924

Yeah cus we trust Evark's advice.

HE'S ONE OF THEM

God forbid I want an image in my sig that isn't a 2px thick horizontal line

BBS Signature

None

BananaBreadMuffin

Reply To Post Reply & Quote

Posted at: 7/14/09 10:56 AM

BananaBreadMuffin FAB LEVEL 38

Sign-Up: 07/08/03

Posts: 43,269

god damn NG and its lack of special character support

BBS Signature

None

Gagsy

Reply To Post Reply & Quote

Posted at: 7/14/09 10:58 AM

Gagsy NEUTRAL LEVEL 34

Sign-Up: 05/21/06

Posts: 25,985

At 7/14/09 10:52 AM, Lagamuffin wrote: I got hit.
c

I got my own special message when they review banned me. Something about being fat. I laughed.

It's just such a shame how ironic it was for Evark to get hit after his thread telling us all what to do. Here's hoping you'll be safer absent.

Shouldn't every user make sure their email security questions are hard to decode too? I mean one of my questions on a site is "What is your pets name?". Terrible as I mention the dog all the time online. Doesn't take a minute to update our questions so that no one can get the answers from anything we've mentioned here on NG. Better be safe then sorry eh.

Did your life flash before your eyes?
Cup of tea, cup of tea, almost got shagged, cup of tea.

BBS Signature

None

NEVR

Reply To Post Reply & Quote

Posted at: 7/14/09 11:00 AM

NEVR LIGHT LEVEL 33

Sign-Up: 06/29/05

Posts: 10,753

<3 absent

Thought we'd seen the last of this bullshit.

[ NG Review & BBS Moderator ] +++ @ @ @ +++ Backseat modding, clarified. +++ {<3 Karl for the sig}

BBS Signature

Misunderstood

BlueStripedd

Reply To Post Reply & Quote

Posted at: 7/14/09 11:00 AM

BlueStripedd LIGHT LEVEL 01

Sign-Up: 04/19/09

Posts: 11

At 7/14/09 10:52 AM, Lagamuffin wrote: I got hit.
c

Oh fuck, this is news to me, I just realised Evark was hacked.

BBS Signature

None

n00binator

Reply To Post Reply & Quote

Posted at: 7/14/09 11:00 AM

n00binator NEUTRAL LEVEL 02

Sign-Up: 05/30/03

Posts: 33

did anyone else get banned this time or was it just me?


None

Ejit

Reply To Post Reply & Quote

Posted at: 7/14/09 11:01 AM

Ejit LIGHT LEVEL 22

Sign-Up: 02/17/06

Posts: 10,924

BTW I'm pretty sure they're aiming for mods rather than users. So idc :P.

God forbid I want an image in my sig that isn't a 2px thick horizontal line

BBS Signature

Shouting

naronic

Reply To Post Reply & Quote

Posted at: 7/14/09 11:01 AM

naronic DARK LEVEL 14

Sign-Up: 09/01/08

Posts: 570

DARN!!
HOW MANY MORE MODS ARE THEY GONNA GET??
this has gone waaaaaaaaaaaaaaaay out of hand ever since KSD's demodification and now every mod seems to be falling for this phishing scam

don't tell me you're next to walk the plank absent...


Expressionless

That-Guy64

Reply To Post Reply & Quote

Posted at: 7/14/09 11:01 AM

That-Guy64 NEUTRAL LEVEL 07

Sign-Up: 06/02/09

Posts: 80

I'm suprised the saddo's haven't gone after poozy or poxpower yet.

This sig has words in it.
Best troll ever.


None

yhar

Reply To Post Reply & Quote

Posted at: 7/14/09 11:02 AM

yhar NEUTRAL LEVEL 03

Sign-Up: 04/02/08

Posts: 1,772

can we have instructions for users who get banned by these people? I clearly don't deserve to be banned (lmao) so unban me kthanx!

citricsquid

THIS IS CITRICSQUID POSTING


None

BlueStripedd

Reply To Post Reply & Quote

Posted at: 7/14/09 11:03 AM

BlueStripedd LIGHT LEVEL 01

Sign-Up: 04/19/09

Posts: 11

At 7/14/09 11:00 AM, reviewer2 wrote: Seriously, we need to stop clicking random links.

Lol Zombo

At 7/14/09 11:00 AM, n00binator wrote: did anyone else get banned this time or was it just me?

I was banned as well. Er, my main, TheSilverGuitar was. 14 days for posting in the "Recognising Newgrounders" topic.

BBS Signature

Resigned

GigaBear

Reply To Post Reply & Quote

Posted at: 7/14/09 11:03 AM

GigaBear FAB LEVEL 03

Sign-Up: 07/01/09

Posts: 11

At 7/14/09 10:52 AM, Lagamuffin wrote: I got hit.
c

Same here...

Unless this was a legitimate ban, in which case I apologise for posting on an alt...

--&gt; Recent Account Security Issues

GigaBear is lookin' for some action.

BBS Signature

None

H-K-S

Reply To Post Reply & Quote

Posted at: 7/14/09 11:04 AM

H-K-S DARK LEVEL 16

Sign-Up: 03/10/06

Posts: 7,258

What I find pathetic is the fact is that newgrounds members and mods are now being hacked. Which isn't the problem, but they are being hacked by a bunch of fucking small time faggoty kids. We need to disable the link option for a while until we resolve this problem.

DumbassDude: "God forbid your mother should see your collection of amputee porn." to Davidzx

BBS Signature

None

luigipwnsmario

Reply To Post Reply & Quote

Posted at: 7/14/09 11:04 AM

luigipwnsmario DARK LEVEL 15

Sign-Up: 07/27/07

Posts: 1,505

At 7/14/09 11:02 AM, TheRatchnator wrote: I am offering to go into the phishing site and get any useful details weither it be the coding or any info from Tamper Data.

Go for it.

Of course I have no say in the matter though, so my opinion doesn't matter ;D

Click this link dammit.
Read this post dammit.

BBS Signature

None

Corky52

Reply To Post Reply & Quote

Posted at: 7/14/09 11:04 AM

Corky52 FAB LEVEL 07

Sign-Up: 06/29/09

Posts: 9

Lol, Main account banned.

Is there action being taken right now that is going to better help the situation? Something as simple as having mods to input another password just to get into the mod tools so even if an account is taken over it won't matter that much because they would have to get into the mod tools using another password. Then of course you could make it so that password would get locked after a certain amount of guesses.

BBS Signature

None

reviewer2

Reply To Post Reply & Quote

Posted at: 7/14/09 11:06 AM

reviewer2 NEUTRAL LEVEL 13

Sign-Up: 07/03/07

Posts: 2,378

ATTENTION MODS: I WOULD NOT EVEN CHECK YOUR PM'S

Also, if we're raided again, if you read this, say nothing at all about it afterwards.
No remarks about it.
Nothing.


Angry

reverend

Reply To Post Reply & Quote

Posted at: 7/14/09 11:07 AM

reverend LIGHT LEVEL 33

Sign-Up: 11/03/03

Posts: 1,364

At 7/14/09 11:00 AM, NEVR wrote: <3 absent

Thought we'd seen the last of this bullshit.

I thought so too. Some people just need to get a fucking life.


None

n00binator

Reply To Post Reply & Quote

Posted at: 7/14/09 11:08 AM

n00binator NEUTRAL LEVEL 02

Sign-Up: 05/30/03

Posts: 33

the mods are getting brute forced obviously. they're not that dumb. we need to start requiring voice and retina scans as part of the log in process.


None

Barrelsfox

Reply To Post Reply & Quote

Posted at: 7/14/09 11:10 AM

Barrelsfox DARK LEVEL 19

Sign-Up: 02/23/07

Posts: 324

Can anybody explain this to me, cause I don't get it?

LEFT 4 DEAD 2

BBS Signature

None

H-K-S

Reply To Post Reply & Quote

Posted at: 7/14/09 11:10 AM

H-K-S DARK LEVEL 16

Sign-Up: 03/10/06

Posts: 7,258

At 7/14/09 11:08 AM, n00binator wrote: the mods are getting brute forced obviously. they're not that dumb. we need to start requiring voice and retina scans as part of the log in process.

That or we need to memorize a phrase to type down.

DumbassDude: "God forbid your mother should see your collection of amputee porn." to Davidzx

BBS Signature

None

n00binator

Reply To Post Reply & Quote

Posted at: 7/14/09 11:13 AM

n00binator NEUTRAL LEVEL 02

Sign-Up: 05/30/03

Posts: 33

At 7/14/09 11:10 AM, H-K-S wrote:
At 7/14/09 11:08 AM, n00binator wrote: the mods are getting brute forced obviously. they're not that dumb. we need to start requiring voice and retina scans as part of the log in process.
That or we need to memorize a phrase to type down.

you can't brute force a laser retina scanner though! i cracked the case on the first day. now we just need someone to pay for the scanners for all our computers. *looks at advertisers..*


newnerdproductionsTM FAB LEVEL 08

Sign-Up: 07/06/08

Posts: 935

At 7/14/09 11:06 AM, reviewer2 wrote: ATTENTION MODS: I WOULD NOT EVEN CHECK YOUR PM'S

Also, if we're raided again, if you read this, say nothing at all about it afterwards.
No remarks about it.
Nothing.

No, we need to be vocal about it. If you erase the past, you are bound to repeat it.


None

Barrelsfox

Reply To Post Reply & Quote

Posted at: 7/14/09 11:14 AM

Barrelsfox DARK LEVEL 19

Sign-Up: 02/23/07

Posts: 324

At 7/14/09 11:10 AM, Barrelsfox wrote: Can anybody explain this to me, cause I don't get it

Ok I get it, but thanks anyways

But why are people doing this?

LEFT 4 DEAD 2

BBS Signature

None

That-Guy64

Reply To Post Reply & Quote

Posted at: 7/14/09 11:17 AM

That-Guy64 NEUTRAL LEVEL 07

Sign-Up: 06/02/09

Posts: 80

At 7/14/09 11:14 AM, Barrelsfox wrote:
At 7/14/09 11:10 AM, Barrelsfox wrote: Can anybody explain this to me, cause I don't get it
Ok I get it, but thanks anyways

But why are people doing this?

Because they are sad little 13 year olds who think this stuff is cool.

This sig has words in it.
Best troll ever.


Resigned

naronic

Reply To Post Reply & Quote

Posted at: 7/14/09 11:18 AM

naronic DARK LEVEL 14

Sign-Up: 09/01/08

Posts: 570

At 7/14/09 11:02 AM, TheRatchnator wrote: I am offering to go into the phishing site and get any useful details weither it be the coding or any info from Tamper Data.

I've already been there
you'll literally crap you're pants at how similar it looks to newgrounds


None

ILovePepsi

Reply To Post Reply & Quote

Posted at: 7/14/09 11:18 AM

ILovePepsi NEUTRAL LEVEL 02

Sign-Up: 07/14/09

Posts: 4

Like 2 minutes ago my main account got banned (AlmostDead1) So is it happening now?


All times are Eastern Standard Time (GMT -5) | Current Time: 07:58 PM

<< Back

This topic is 6 pages long. [ 1 | 2 | 3 | 4 | 5 | 6 ]

<< < > >>
You need a Grounds Gold Account to post on the NG BBS! If you don't have one, click here to sign up now! It's fast, free, and easy — and opens up tons of great NG features!