FFR Hacked.

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • Dinglesberry
    longing
    • Dec 2007
    • 2679

    #16
    Re: FFR Hacked.

    Development site = site we can go to and view and comment and help with the development of FFR??

    Am I dreaming

    Jk I realize now you just mean create a test environment so you can make changes without it affecting the main site

    As long as there's no code in it that causes it to crash when you try to change from debug -> release lol (I'm lookin at you, FFR engine...)

    Edit: also lol somehow didn't get pwned which is funny to me.. Honestly I'm not worried if they just have md5 hashes lol, hell if they get passwords from those I'll actually be happy, maybe then I can learn how lolz cause as far as I'm concerned it's impossible.

    Edit2: alright maybe not "impossible" but it's pretty likely nothing would come of it.. Lol makes me wonder why they even use md5 for passwords, oh well
    Last edited by Dinglesberry; 09-6-2016, 10:22 AM.

    Comment

    • PhantomPuppy
      Washed and Irrelevant D7
      • May 2012
      • 1808

      #17
      Re: FFR Hacked.

      february? ive changed my password twice since then lol. spose i shouldnt be too worried then.

      10th OT (D3): 13th
      11th OT (D6): 11th
      12th OT (D6): 6th
      13th OT (D7): 31st
      14th OT (D7): 25th
      15th OT (D7): LAST PLACE LOL
      16th OT (D7): LAST PLACE LOL


      Originally posted by Funnygurl555
      you know what they say

      under all the rust is really shiny...……… metal

      Comment

      • Fantasticone
        D7 Elite Keymasher
        • Aug 2006
        • 6003

        #18
        Re: FFR Hacked.

        Dam, hopefully they AAA things for me.

        Comment

        • DeBlackKnite
          FFR Player
          • May 2007
          • 1

          #19
          Re: FFR Hacked.

          Originally posted by Dinglesberry
          Honestly I'm not worried if they just have md5 hashes lol, hell if they get passwords from those I'll actually be happy, maybe then I can learn how lolz cause as far as I'm concerned it's impossible.
          MD5 is broken. There are rainbow tables available that will instantly reverse many passwords, and because the hash function is so cheap, tools like hashcat will rape MD5 even with salt. Say your password is "xsoekcnm" - random characters. But it's too short and can be instantly reversed, just search for md5 reverse and enter 4ecf096b453a0760b02bd0aa0f3740fa.

          Comment

          • Dinglesberry
            longing
            • Dec 2007
            • 2679

            #20
            Re: FFR Hacked.

            Originally posted by DeBlackKnite
            MD5 is broken. There are rainbow tables available that will instantly reverse many passwords, and because the hash function is so cheap, tools like hashcat will rape MD5 even with salt. Say your password is "xsoekcnm" - random characters. But it's too short and can be instantly reversed, just search for md5 reverse and enter 4ecf096b453a0760b02bd0aa0f3740fa.
            Well, the whole point of the salt is really to just slow down the rainbow tables that hash cat uses, or make it not work.

            For example, lets get a real example in here for what we want to do:

            Lets say we have a database of 1,954,977 members. If the password isn't salted, it's literally a matter of running your tool or whatnot, iterating through the list for each "word", and see if any passwords match.. Sure, we need to check almost 2 million data entries like 70 million times, but I mean, it's not TOO bad.. Not only that, since the passwords are represented in our table, we actually don't need to hash anything or call anything to check it -> we just access the table and make our comparisions

            Essentially, imagine: we check the first word in the table, scan the "leak" for matches in the list of hashes, if so, boom, easy.

            If the password is salted however, NOTHING in that table is going to match anymore. Obviously, we know the salt - it's written right in the MD5 hash (since salted hash is just hash:salt or salt:hash or whatever), the person trying to crack knows the salt.. Despite this, the amount of work that has to be done is like freakin n^2 compared to n! lol.. If the passwords are salted, your table mapping "xsoekcnm" -> 4ecf096b453a0760b02bd0aa0f3740fa suddenly does not match - xsoekcnm doesn't hash to that anymore, so you would need to calculate md5($salt, $plaintextpw), and remake the table.

            Regardless, it's gonna slow it the hell down.. Now suddenly instead of:

            - for each word in the rainbow table
            - Parse hashes for match

            you are suddenly:

            - for each word in the rainbow table
            - calculate what hash would be generated using a given salt
            ---> (note, you might realise - in order to calculate what the hash would be for a given salt, they would need to know #1 a plaintext password and #2 the hash that is generated that corresponds to this plaintext password)
            - parse hashes for matches

            Regardless, I doubt anyone would bother doing this for this game.. there is literally no motivation behind trying to access anyone account here, to be honest. I can see if someone would want to hack the admins password or something, but even so, there really isn't a gain to that - what you should be worried about is using the same password for different websites, registered with that username/email.

            To be honest, I don't even think the leak was specifically regarding flashflashrevolution, but obviously I don't know for sure - probably related to this:

            Every breached website added to Have I Been Pwned appears here on the Who’s Been Pwned page. As of today, there are 986 breached sites listed.


            EDIT: lol nvm theres a specific section for just FFR
            Every breached website added to Have I Been Pwned appears here on the Who’s Been Pwned page. As of today, there are 986 breached sites listed.


            INTERNET FAMOUS BOIZ
            Last edited by Dinglesberry; 09-6-2016, 12:27 PM.

            Comment

            • rushyrulz
              Digital Dancing!
              FFR Simfile Author
              FFR Music Producer
              • Feb 2006
              • 12985

              #21
              Re: FFR Hacked.

              I'm CS so all this IA talk is making my head spin. Do I need to set my account on fire or not?


              Comment

              • Rapta
                🡸Index🡻Is🡹Fun!🡺
                Profile Moderator
                FFR Simfile Author
                Global Moderator
                • Dec 2010
                • 1948

                #22
                Re: FFR Hacked.

                I was compromised but I changed all my passwords and made them all stronger so bleh.
                Old Quotes
                Originally posted by IwasAsquidOnce
                Note the left hand pinky. It stretches out into attack mode to make etienne's hand appear larger, an intimidation technique for the arrows.
                Originally posted by Mourningfall
                [3:51 PM] Mourningfall: i spent the second half of that song getting face fucked by a fly
                Originally posted by Xiz
                Hi I see rapta come play TWG next game
                Originally posted by xXOpkillerXx
                Rapta thinks alot about memes and fonts. I'd be inclined to think he's town because wolves wouldn't have time to meme would they ?
                Originally posted by Prawnskunk
                if we keep releasing engines that work on 1/4 of people's computers, we'll get there
                Originally posted by gold stinger
                do u even agrabah
                Originally posted by gold stinger
                Today at 12:53 AM
                I have no fucking idea how you were able to identify that specific line from meme show so you are basically an elder god of memes
                Originally posted by Psychotik
                When I think Mother’s Day, I think Venetian Snares.
                Originally posted by Haku
                have you heard someone mention eating pancakes to negate friday 13th?




                Originally posted by Prawnskunk at 10:53:56pm on 10/26/11
                OMFG VC! I want your programming fingers in or around my mouth OnO
                Originally posted by Storn at 3:03 PM
                We have so many batches open. Its like a backlog clearance sale. ALL FILES MUST GO!!
                Originally posted by ToonE156 at 11:07 PM
                You've never felt intimacy until you've practiced Jiu Jitsu ground techniques with the only girl in class

                Comment

                • Lambdadelta
                  D7 Elite Keymasher
                  • Oct 2012
                  • 1152

                  #23
                  Re: FFR Hacked.

                  Good thing I've not changed this password since way back when people were randomly logging into eachother's accounts back in like 2014.
                  I should be fine in other places since I regularly change those passwords every couple months.
                  Last edited by Lambdadelta; 09-6-2016, 12:48 PM.

                  Comment

                  • Dinglesberry
                    longing
                    • Dec 2007
                    • 2679

                    #24
                    Re: FFR Hacked.

                    Originally posted by rushyrulz
                    I'm CS so all this IA talk is making my head spin. Do I need to set my account on fire or not?
                    Eh I'd consider cryptography part of CS



                    (It's just forum with people begging for random leaks I found.. however, from this you can see that I guess people have known about it for a while?)

                    If you are worried about some chinese gold farmer maybe lol.. as far as I could find, it's a private database (l0l this makes me sound like im trying to find the list of password o_O Mark my words someday I will BECOME ETIENNE), so I don't know if anything would even come of it.

                    Should be fine tbh, worse leaks have happened to be fair.. I'd say yeah just change your password or w/e.

                    I'm just curious how it happened and why lol.. I swear, someone probably just tried to steal tons of random vB databases...

                    By the way, I also saw a website that was saying that of the accounts hacked, 300k~ of the passwords were actually encrypted and the rest were plaintext l0l gg, probably bs.
                    Last edited by Dinglesberry; 09-6-2016, 12:56 PM.

                    Comment

                    • rushyrulz
                      Digital Dancing!
                      FFR Simfile Author
                      FFR Music Producer
                      • Feb 2006
                      • 12985

                      #25
                      Re: FFR Hacked.

                      I did take a cryptography course... with the math department lmao. CS definitely does not go as in-depth as you would expect on the security protocols side of things.
                      Last edited by rushyrulz; 09-6-2016, 01:05 PM.


                      Comment

                      • j-rodd123
                        End of the road
                        • Oct 2006
                        • 3692

                        #26
                        Re: FFR Hacked.

                        if you enter your email and it says pwned twice, is there a way to see what the 2 sites were, or is it just to guess from the list they provide. clicking the 2 times or whatever doesnt show that

                        Originally posted by FictionJunction
                        wow

                        Comment

                        • inDheart
                          Picker @ JAX2
                          FFR Simfile Author
                          • Aug 2011
                          • 505

                          #27
                          Re: FFR Hacked.

                          Originally posted by j-rodd123
                          if you enter your email and it says pwned twice, is there a way to see what the 2 sites were, or is it just to guess from the list they provide. clicking the 2 times or whatever doesnt show that
                          it should tell you below with descriptions of the leaks, like so:

                          Comment

                          • devonin
                            Very Grave Indeed
                            Event Staff
                            FFR Simfile Author
                            • Apr 2004
                            • 10120

                            #28
                            Re: FFR Hacked.

                            Hard to take seriously a site that describes your information as having been pwned.

                            So the site tells me my email has been pwned 4 times in the past 8 years, and yet all four sites, that email address was tied to the same username, which it informs me has been pwned 0 times.

                            So I should panic because they got my email and username, except they've never gotten my username. Seems legit.
                            Last edited by devonin; 09-6-2016, 01:37 PM.

                            Comment

                            • blindreper1179
                              Vice President Of TGB
                              • Jun 2006
                              • 5900

                              #29
                              Re: FFR Hacked.

                              Pwned on here, MySpace, and tumblr, oh well.
                              Originally posted by thesunfan
                              absolutely I want to vomit on your face irl
                              Originally posted by choof
                              It was like trying to throw logic at a fuckin brick wall lmao
                              Originally posted by choof
                              whats more dense, a black hole or an icyworld file
                              Originally posted by Celirra
                              I've never been so disappointed by a man from Alabama than I am right now

                              Comment

                              • j-rodd123
                                End of the road
                                • Oct 2006
                                • 3692

                                #30
                                Re: FFR Hacked.

                                Originally posted by inDheart
                                it should tell you below with descriptions of the leaks, like so:
                                oh woops im dumb ok thank you

                                Originally posted by FictionJunction
                                wow

                                Comment

                                Working...