You can help CodeWalrus stay online by donating here. | New CodeWalrus | Old (dark mode) | Old (light) | Discord server
0
b/Website News publicado por u/Dream of Omnimaga December 06, 2015, 04:31:35 AM
We were supposed to have a programming contest and a newsletter tomorrow, but first, we have some much more important news for all of our forum members, which will also be included in the newsletter header, which will also exceptionally be sent to every member, regardless of if they have opted in or out of e-mail notifications:


Yesterday, Omnimaga got hacked and both KermMartian and Geekboy1011's accounts were compromised elsewhere. The Omnimaga website has since been restored after hours of downtime, but the database content has been leaked and compromised. This includes all members personal information, ranging from private messages to passwords. According to Eeems, it looks like SMF doesn't salt+hash their passwords in a very secure way, something very possible due to how quickly the hacker managed to get Kerm and Geek's password. The passwords were re-used to attempt logging in on Cemetech.

If you have an Omnimaga account, then we heavily recommend that you change your password on any website (including CodeWalrus) on which you used the same password and we recommend that you use different passwords everywhere. No matter how hard it is for the hacker to decrypt the passwords, it's better to be safe than sorry!

We do not know how the attack occurred, we know that Omnimaga was two SMF versions behind and Omnimaga was not the only place attacked, as one of KermMartian e-mail account was also hit. Also, according to the Omnimaga topic and their IRC logs, the IP address used by the hacker is from France (although we do not know what it is).

On our side, we are going to investigate about what the IP address is and if it was used on CodeWalrus and our servers.

Source:
https://www.omnimaga.org/news/downtime-22209/
http://chat.eeems.ca/?server=irc.omnimaga.org%206667&channel=omnimaga&date=Sat%20Dec%2005%202015
Last Edit: December 06, 2015, 04:40:58 AM by DJ Omnimaga
Inicia sesión o crea una cuenta para dejar un comentario
u/bb010g December 06, 2015, 04:43:01 AM
This is also a good time to bring up password managers. (Anytime is a good time, really.)

KeePass and KeePassX are solid.
pass is simple (in the Unix way) and on pretty much all platforms if you're willing to put in some setup.
1Password is very nice, but closed source and not on Linux.
u/Dream of Omnimaga December 06, 2015, 05:48:49 AM
We're out of luck so far to get the hacker IP address, because all Omni admins are offline. Ideally the other sites should do a forum scan of that IP in case it matches someone there. That's unless the hacker was using Tor or a proxy, though, then maybe we're out of luck.

I notified Planète-Casio of the attack because some of their members have Omnimaga accounts.

Thanks for the programs by the way. I just hope there is a way to retrieve the passwords from them so if my computer crashes and has to be reformated, then I am not locked out of all my Internet accounts.

EDIT: @Juju got one suspicious IP address, and is running scans on our server right now. Please report here once done.

He gave me the IP and I did scans on the forums. No matches could be found:
https://usercontent.irccloud-cdn.com/file/3EzvCLx2/
Last Edit: December 06, 2015, 07:31:14 AM by DJ Omnimaga
u/Yuki December 06, 2015, 08:10:45 AM
Found 2 matches in the logs, both seems to be images linked from Omnimaga or TI-Planet. Also me looking for that IP. Nothing found here, really.
u/Dream of Omnimaga December 06, 2015, 08:45:28 AM
Apparently, there was a lot of stuff on TI-Planet, though, in the server logs.

EDIT: According to Kerm, the password was freely given to the hacker. He also finds it weird that most recent community attacks and trolling always target Omni and Cemetech (eg Ephraim ban evasion, the sucks.fyi trolling via strange hostnames and now this) and never other sites.
Last Edit: December 06, 2015, 09:18:12 AM by DJ Omnimaga
u/Snektron December 06, 2015, 10:06:26 AM
Well, he suck.fyi guy was here too. Also i've updated my password too :)
u/novenary December 06, 2015, 10:17:04 AM
Quote from: bb010g on December 06, 2015, 04:43:01 AM
This is also a good time to bring up password managers. (Anytime is a good time, really.)

KeePass and KeePassX are solid.
pass is simple (in the Unix way) and on pretty much all platforms if you're willing to put in some setup.
1Password is very nice, but closed source and not on Linux.
Indeed, it's high time I switched to something like that. Thanks for the recommendations.
u/Snektron December 06, 2015, 10:20:46 AM
We used KeePassX on my dad's linux computer. The problem was he deleted the database one time and said it was my own fault <_<
u/brentmaas December 06, 2015, 10:48:14 AM
I tried a bit of research into the IP, but all I could find was a physical adress.
u/novenary December 06, 2015, 12:44:17 PM
Just set pass up and changed most of my passwords for 32 character passwords, different for each site. I suppose that's enough to keep me covered. :P
u/Dream of Omnimaga December 06, 2015, 10:48:31 PM
32 chars is a bad idea imho. Some sites upgrade their softwares and end up lowering the max lenght in fields and I remember yAronet password or nickname change field allowed more chars than than the login fields and I was unable to login anymore. 24 chars is safer against such admin mishaps.
u/Travis December 06, 2015, 11:42:42 PM
Quote from: DJ Omnimaga on December 06, 2015, 05:48:49 AMThanks for the programs by the way. I just hope there is a way to retrieve the passwords from them so if my computer crashes and has to be reformated, then I am not locked out of all my Internet accounts.

KeePassX saves the database in a location you specify, so if you keep that file backed up and don't forget the master password to decrypt it, you should be fine. It can also export everything to a .txt file in case you need that.
u/critor December 06, 2015, 11:53:51 PM
Quote from: DJ Omnimaga on December 06, 2015, 08:45:28 AMAccording to Kerm, the password was freely given to the hacker. He also finds it weird that most recent community attacks and trolling always target Omni and Cemetech (eg Ephraim ban evasion, the sucks.fyi trolling via strange hostnames and now this) and never other sites.

How would he know about other sites ? Is he omniscient ?

And apparently, he quickly forgot about this :
https://codewalr.us/index.php?topic=647.0
u/Yuki December 07, 2015, 12:53:57 AM
Well, the most recent ones, as in, the last 3 incidents or so. He knows about other sites because we told him so.
u/Dream of Omnimaga December 07, 2015, 03:36:10 AM
Guys, I found something strange on Omnimaga: Netham45 account is no longer listed in the member list (even if we do a search) and he isn't in the staff list either. I don't know how long it has been like that, though:

https://www.omnimaga.org/team

His account is still intact, but he is no longer in the staff groups and his signature changed was changed to "Omnimaga admin" instead of the broken Space Invader animation. He also last logged in on December 4th 2015.


Normally, when an existing SMF forum account no longer shows up in the member list, this means it is currently banned. Did he ask that on request due to a long hiatus or was his account compromised?


EDIT: An attempt to break into @Ivoah forum account on CodeWalrus has been recorded over three hours ago:

QuoteIP address   Display name   Message   Date
90.11.159.131   Guest   Password incorrect - Ivoah
?action=login2   Today at 07:34:23 pm

EDIT: There was also an attempt by 80.119.166.103 to login into my account, but it doesn't match anything else out of the ordinary on the forums. Mind doing a scan on CW server @Juju and on TI-Planet @Adriweb ? It was over an hour before Ivoah account was hit.
Last Edit: December 07, 2015, 04:00:12 AM by DJ Omnimaga
Start a Discussion

b/Website News

This is where site-specific updates will be posted.

99
Topics
Explore Board
Website statistics


MyCalcs | Ticalc.org | Cemetech | Omnimaga | TI-Basic Developer | MaxCoderz | TI-Story | Casiocalc.org | Casiopeia | The Museum of HP Calculators | HPCalc.org | CnCalc.org | Music 2000 Community | TI Education | Casio Education | HP Calcs | NumWorks | SwissMicros | Sharp Calculators
Powered by EzPortal