Server vulnerability 14 July 2013 - Database restored and passwords reset

Discussion in 'Frontpage news' started by Hilbert Hagedoorn, Jul 14, 2013.

  1. eclap

    eclap Banned

    Messages:
    31,497
    Likes Received:
    3
    GPU:
    Palit GR 1080 2000/11000
    Seeing as the forum only shows threads from the last 1 month by default and the forum was taken 4 weeks back, that's understandable
     
  2. Hilbert Hagedoorn

    Hilbert Hagedoorn Don Vito Corleone Staff Member

    Messages:
    39,171
    Likes Received:
    7,819
    GPU:
    AMD | NVIDIA
    The view limit is set at 1 month, I expanded most section to two months now.
     
  3. Loobyluggs

    Loobyluggs Ancient Guru

    Messages:
    3,857
    Likes Received:
    796
    GPU:
    EVGA 1070 FTW
    goddammit.

    I wrote a 3,000 word review of Man of Steel that's lost forever...

    /goes to pick a fight with someone.
     
  4. iancook221188

    iancook221188 Ancient Guru

    Messages:
    1,724
    Likes Received:
    8
    GPU:
    GTX 670 SLI / GTX 460 SLI
    OOO f**k... but sh*T happens deal with with it and move on
     

  5. The Laughing Ma

    The Laughing Ma Ancient Guru

    Messages:
    4,309
    Likes Received:
    741
    GPU:
    Gigabyte 2070 Super
    3,000 words to say 'sh*t happens' that be an awful lot of words.

    Ok time to own up, was anyone silly enough to actually put their credentials in to that pop up?
     
  6. Ghosty

    Ghosty Ancient Guru

    Messages:
    5,385
    Likes Received:
    100
    GPU:
    3200U
    What pop up?
     
  7. ricardonuno1980

    ricardonuno1980 Banned

    Messages:
    4,407
    Likes Received:
    0
    GPU:
    GTX 780Ti Classified :D
    Ok. :)
    But my thread "Rayman 3: still no too fast" is lost temporarily. :( I have changed passw. ;)
     
    Last edited: Jul 16, 2013
  8. Noisiv

    Noisiv Ancient Guru

    Messages:
    7,210
    Likes Received:
    812
    GPU:
    2070 Super
    Really? Regular browser login form.
    I'd like to hear about the guy that didn't.
     
  9. k1net1cs

    k1net1cs Ancient Guru

    Messages:
    3,783
    Likes Received:
    0
    GPU:
    Radeon HD 5650m (550/800)
    The pop-up window that asked for user/pass whenever you go into a sub-forum.

    This happened suddenly after a 'test announcement' was posted from a mod account.
    It only lasted for an hour or so, until it was discovered that the one causing the pop-up to show up whenever anyone went to a sub-forum was a script being slipped in the announcement post.
    Basically if you entered your user/pass into that login pop-up (which actually seemed legit) that info will be redirected to a website where the script was hosted.
     
  10. Dillinger

    Dillinger Master Guru

    Messages:
    654
    Likes Received:
    0
    GPU:
    GTX 950
    A few days ago there was a pop up on the forum.

    It said to view content on this website please sign in with the following (name/email/pw)

    Definitely looked sketchy.
     
    Last edited: Jul 14, 2013

  11. Ghosty

    Ghosty Ancient Guru

    Messages:
    5,385
    Likes Received:
    100
    GPU:
    3200U
    I must have missed that. But I have pop-up's blocked by default, so I wouldn't have seen it anyway.
     
  12. ---TK---

    ---TK--- Ancient Guru

    Messages:
    22,111
    Likes Received:
    2
    GPU:
    2x 980Ti Gaming 1430/7296
    yikes forum amnesia
     
  13. (.)(.)

    (.)(.) Banned

    Messages:
    9,094
    Likes Received:
    0
    GPU:
    GTX 970
    I'm still getting asked to change my password, the ol your password is 672 days old thing. I've done this twice tonight already, is the server still brokeded?

    Browsing the forums at the mo feels the same as when I forget to back up save games before a format.:bang:
     
  14. ricardonuno1980

    ricardonuno1980 Banned

    Messages:
    4,407
    Likes Received:
    0
    GPU:
    GTX 780Ti Classified :D
    You have the lack of attention - bad luck. :heh::heh: loooool! I have good warning to have done backup documents, games saved... before format HDD. :D
     
  15. Keitosha

    Keitosha Ancient Guru

    Messages:
    4,869
    Likes Received:
    111
    GPU:
    Vega56 8GB \ GT1030
    Yep, got that twice as well. Now the forum seems to "remember" my new password, although it forgets to save upon each visit. I need to retype my password everytime when I visit G3D, regardless of browser settings.
     

  16. Tat3

    Tat3 Ancient Guru

    Messages:
    11,695
    Likes Received:
    97
    GPU:
    GB GTX 1660 Ti OC
    First one was because after discovery of that attack HH made everyone to change the pswd. "Just incase"

    Second one came after the database was restored from backup with old information. This old information containing passwords and so was likely to be in the database which was used during the attack. And because of this restore, you still had the old password in use, which you had to change. So thats why the second password change ans server "forgetting" the new password.
     
  17. k1net1cs

    k1net1cs Ancient Guru

    Messages:
    3,783
    Likes Received:
    0
    GPU:
    Radeon HD 5650m (550/800)
    This is not a pop-up window that ads usually use, but rather a login pop-up, the one that pops up (heh) whenever you're trying to access a restricted webpage or your router.

    Hilbert did reset everyone's password twice.
    Before and after the database rollback.

    Try logging out to clear out cookies, then log in again while having the 'Remember Me' ticked.
     
  18. (.)(.)

    (.)(.) Banned

    Messages:
    9,094
    Likes Received:
    0
    GPU:
    GTX 970
    Ok, cheers guys.
     
  19. DSparil

    DSparil Ancient Guru

    Messages:
    3,261
    Likes Received:
    19
    GPU:
    ASUS ROG StriX RX480, 8GB
    Ohh ok, this explains what happened to all of the recent threads! It is unfortunate, but definitely better safe than sorry :)
     
    Last edited: Jul 14, 2013
  20. Gump

    Gump Master Guru

    Messages:
    655
    Likes Received:
    0
    GPU:
    ASUS Radeon HD 6850
    This thread clears things up a bit...

    I was curious why a got a message saying my password was 15,900 days old and had expired - so had to be changed.
    It also was strange why it looked like this was 17 June...

    like I said - it makes sense now.
     

Share This Page