Join us on Discord!
You can help CodeWalrus stay online by donating here.

Important security notice about your CodeWalrus account

Started by Dream of Omnimaga, December 06, 2015, 04:31:35 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

brentmaas

90.11.159.131 and 80.119.166.103 were located as Billère and Tarbes to me, both southern france/pyrenées
Lel I glitched Omni

Dream of Omnimaga

Strange that WHOIS info is different for two of us ???

Where did you get that info Brentmaas? I used http://iptrace.in
  • Calculators owned: TI-82 Advanced Edition Python TI-84+ TI-84+CSE TI-84+CE TI-84+CEP TI-86 TI-89T cfx-9940GT fx-7400G+ fx 1.0+ fx-9750G+ fx-9860G fx-CG10 HP 49g+ HP 39g+ HP 39gs (bricked) HP 39gII HP Prime G1 HP Prime G2 Sharp EL-9600C
  • Consoles, mobile devices and vintage computers owned: Huawei P30 Lite, Moto G 5G, Nintendo 64 (broken), Playstation, Wii U

Keoni29

#47
A smart attacker would try to leave no trace back to his own ip. These suspicious ip's in the logs come from attacks carried out by infected machines, via a vpn or the attacker is not smart.
If you like my work, why not give me an internet?

Dream of Omnimaga

But how would an infected machine carry out such large scale attack without human intervention?
  • Calculators owned: TI-82 Advanced Edition Python TI-84+ TI-84+CSE TI-84+CE TI-84+CEP TI-86 TI-89T cfx-9940GT fx-7400G+ fx 1.0+ fx-9750G+ fx-9860G fx-CG10 HP 49g+ HP 39g+ HP 39gs (bricked) HP 39gII HP Prime G1 HP Prime G2 Sharp EL-9600C
  • Consoles, mobile devices and vintage computers owned: Huawei P30 Lite, Moto G 5G, Nintendo 64 (broken), Playstation, Wii U

Keoni29

Usually these infected machines are listening on an IRC channel waiting for the command to attack.
If you like my work, why not give me an internet?

brentmaas

Quote from: DJ Omnimaga on December 08, 2015, 08:34:52 AM
Strange that WHOIS info is different for two of us ???

Where did you get that info Brentmaas? I used http://iptrace.in
http://yougetsignal.com
It has a couple of tools which are free to use.
Lel I glitched Omni

alexgt

Do you think the attacker will be able to breach CW or no?

EDIT: it may be a little off topic but it was said in the first post something about a contest?
  • Calculators owned: Ti-84+, Ti-Nspire, Hp Prime, Broken HP Prime, HP 48SX

novenary

I don't think so, hopefully we reacted fast enough to change all of our passwords, at least for those who used the same as on omni. We should be fine.

As for the contest, yes, there is an upcoming contest.

alexgt

I thought so but is kinda weird that someone would go through all that effort just to get at the calc community. They must really hate us O.O
  • Calculators owned: Ti-84+, Ti-Nspire, Hp Prime, Broken HP Prime, HP 48SX

Ivoah

Quote from: DJ Omnimaga on December 08, 2015, 07:59:45 AM
I'm definitively thinking that 24.144.160.11 was a legit user (Ivoah most likely). It might be a public internet hotspot from which Ivoah is unable to post, which could explain why he has no single post on record from there. Pennsylvania seems plausible, considering where Ivoah comes from (not too far from Pennsylvania, New York and New Jersey AFAIK, and I heard from New York Rangers/Islanders fans that it doesn't take long to commute between those areas). So his account is safe.

But yeah, from what I recall, the main attacker IP is from Toulouse, Midi-Pyrenées, while the second is from Paris, Ile-de-France, both located in France.

That was probably me trying to log into my account on my dad's iPad while on a car trip to a college in Pensylvania
  • Calculators owned: TI-86 (now broken), TI SR-56, TI-Nspire CX CAS, TI-84+ SE, TI-84+ SE, TI-85, TI-73 Explorer VS, ViewScreen, TI-84+ CSE, TI-83+ SE

Dream of Omnimaga

  • Calculators owned: TI-82 Advanced Edition Python TI-84+ TI-84+CSE TI-84+CE TI-84+CEP TI-86 TI-89T cfx-9940GT fx-7400G+ fx 1.0+ fx-9750G+ fx-9860G fx-CG10 HP 49g+ HP 39g+ HP 39gs (bricked) HP 39gII HP Prime G1 HP Prime G2 Sharp EL-9600C
  • Consoles, mobile devices and vintage computers owned: Huawei P30 Lite, Moto G 5G, Nintendo 64 (broken), Playstation, Wii U

Dream of Omnimaga

#56
WARNING: I think HP Museum was also hit, but I am not sure.

Someone has changed my forum account there and it's entirely possible that I was using the same password there as I did on Omnimaga.

It took me multiple password reset attempts before the password reset tool finally works


You might want to check your HP Museum accounts at http://www.hpmuseum.org/forum/ in case you were attacked.

  • Calculators owned: TI-82 Advanced Edition Python TI-84+ TI-84+CSE TI-84+CE TI-84+CEP TI-86 TI-89T cfx-9940GT fx-7400G+ fx 1.0+ fx-9750G+ fx-9860G fx-CG10 HP 49g+ HP 39g+ HP 39gs (bricked) HP 39gII HP Prime G1 HP Prime G2 Sharp EL-9600C
  • Consoles, mobile devices and vintage computers owned: Huawei P30 Lite, Moto G 5G, Nintendo 64 (broken), Playstation, Wii U

Dream of Omnimaga

@Streetwalrus ever since we updated login security, I notice an increase in failed login attempts in the logs from legit users/IP addresses. @rwill also reported that he got incorrect password errors even when entering the right password until a few tries and while the latter might be due to Holidays, online users in the last 7 days have decreased from 70 to 50 in less than a week. Mind notifying @Sorunome so he investigates in case his mod might be the culprit?
  • Calculators owned: TI-82 Advanced Edition Python TI-84+ TI-84+CSE TI-84+CE TI-84+CEP TI-86 TI-89T cfx-9940GT fx-7400G+ fx 1.0+ fx-9750G+ fx-9860G fx-CG10 HP 49g+ HP 39g+ HP 39gs (bricked) HP 39gII HP Prime G1 HP Prime G2 Sharp EL-9600C
  • Consoles, mobile devices and vintage computers owned: Huawei P30 Lite, Moto G 5G, Nintendo 64 (broken), Playstation, Wii U

Sorunome

Quote from: DJ Omnimaga on December 29, 2015, 04:20:21 AM
[...]
Mind notifying @Sorunome so he investigates in case his mod might be the culprit?
In order to debug if it is related to the mod i'd need network logs of these failed login attempts, including timestamps and stuff. The password should be encrypted anyways but feel free to strip out the encrypted password on top of that.
  • Calculators owned: Too many (why are you even reading this?)
  • Consoles, mobile devices and vintage computers owned: Gamebuino!
This is a signature.
And now......give me an internet!

To be or not to be.........is that even a question? Who gets to decide this anyways?

Dream of Omnimaga

  • Calculators owned: TI-82 Advanced Edition Python TI-84+ TI-84+CSE TI-84+CE TI-84+CEP TI-86 TI-89T cfx-9940GT fx-7400G+ fx 1.0+ fx-9750G+ fx-9860G fx-CG10 HP 49g+ HP 39g+ HP 39gs (bricked) HP 39gII HP Prime G1 HP Prime G2 Sharp EL-9600C
  • Consoles, mobile devices and vintage computers owned: Huawei P30 Lite, Moto G 5G, Nintendo 64 (broken), Playstation, Wii U

Powered by EzPortal