View Full Version : How to protect your password
EVERYONE should do this. Click on Preferences at the top of the page, then click the link that says "delete all cookies stored by totse.com" and then click the radio button that says "No" for "Store passwords and login info for one month?"
That is how people are getting your passwords. If you view your cookies, from totse.com there is an entry called Password with your UNENCRYPTED password. I am going to talk to Jeff ASAP about fixing this problem. Through other webpages people can write code that steals cookies from this site. In other words, someone can link you somewhere and find your password in a matter of seconds.
Everyone should change their password and password preferences NOW.
http://www.totse.com/bin/bbs/ubbmisc.cgi?action=setprefs
Wow, new news! I mentioned something about the unencrypted passwords a while ago in NS&H, you should really look into encrypting the passwords into salted MD5's. Vbulletin uses that method, and its tight!
angusyetanotherwhitemeat
2007-03-02, 16:22
quote:Originally posted by DriftAway:
Well, I got got.
My angustheotherwhitemeat acc't as well as my first backup angusyetanotherwhitemeat (utilizing, I know I know, the same password) have both been compromized and the email changed.
Zok, or any other admin, if there is any way you can help, please drop me a line at amoshaas@yahoo.com or PM me in IRC, I'm in #bltc and #totse now.
Oh, and second post http://www.totse.com/bbs/wink.gif (http://www.totse.com/bbs/wink.gif)
-Angus
NVM I still got this one.
And to any curious parties, I changed the p/w, Zok my inquisition still stands if there's any way you can get at me about it.
Thanks man, and still
Second post http://www.totse.com/bbs/wink.gif (http://www.totse.com/bbs/wink.gif)
-Angus
I didn't even know there was a password stealing problem.
Edit: Never mind.
[This message has been edited by Source (edited 03-02-2007).]
Satanz Handicapped Helper
2007-03-02, 17:46
http://www.totse.com/bbs/frown.gif (http://www.totse.com/bbs/frown.gif)
Edit: http://www.totse.com/bbs/smile.gif (http://www.totse.com/bbs/smile.gif)
[This message has been edited by Satanz Handicapped Helper (edited 03-02-2007).]
conjuror
2007-03-02, 17:52
Damn kids. They're all alike!
Anyways, thanks for the advice. And yeah, I remember that thread from a while back saying how exactly this would happen.
con (http://caught22.com/)juror
robinhoody
2007-03-02, 18:07
dis acct h4x0red by teh l337 totse army
angusyetanotherwhitemeat
2007-03-02, 18:21
quote:Originally posted by angusyetanotherwhitemeat:
NVM I still got this one.
And to any curious parties, I changed the p/w, Zok my inquisition still stands if there's any way you can get at me about it.
Thanks man, and still
Second post http://www.totse.com/bbs/wink.gif (http://www.totse.com/bbs/wink.gif)
-Angus
Success!!!
It seems wargsm, the beautiful fuck, was saving p/ws too! And mine was one of them!
+∞ for the TOTSE brotherhood!
-Angus
I_am_god
2007-03-02, 18:31
*space reserved for future post*
I_am_god
2007-03-02, 18:33
Ok turned it off.
robinhoody
2007-03-02, 19:20
I can't believe it's taken this long for someone to exploit the glaring XSS vulns here...
The Great One
2007-03-02, 20:00
quote:Originally posted by I_am_god:
*space reserved for future post*
You're the lamest faggot on totse.
[This message has been edited by The Great One (edited 03-02-2007).]
The Death Monkey
2007-03-02, 20:49
quote:Originally posted by Senzuri:
Wow, new news! I mentioned something about the unencrypted passwords a while ago in NS&H, you should really look into encrypting the passwords into salted MD5's. Vbulletin uses that method, and its tight!
So... what you're saying is, is to fix the problem, Jeff should hurry the fuck up and bring vB up?
helladamnleet
2007-03-02, 21:09
quote:Originally posted by The Death Monkey:
So... what you're saying is, is to fix the problem, Jeff should hurry the fuck up and bring vB up?
Cool, I'm not the only one who read it that way.
ChaoticNature
2007-03-02, 21:22
I suppose this explains why my password was changed to orbitgum, nice.
Punk_Rocker_22
2007-03-02, 21:23
Sooo...vB coming anytime soon?
Isobutane
2007-03-02, 21:37
I don't have cookies but I changed my pass anyway, is that k?
gimna.blazed
2007-03-02, 22:33
quote:Originally posted by I_am_god:
Ok turned it off.
Lacedwithdelight
2007-03-02, 22:39
For the love of totse start calling the admins and tell them to be extremely careful.
DesyphIX
2007-03-03, 00:46
I think it's time for VB.
Lacedwithdelight
2007-03-03, 00:50
Link us to the perpetrator!
deadclowneyes
2007-03-03, 04:36
Thanks.
Spike Spiegel
2007-03-03, 05:58
quote:Originally posted by robinhoody:
I can't believe it's taken this long for someone to exploit the glaring XSS vulns here...
I know.
robinhoody
2007-03-03, 06:10
quote:Originally posted by Spike Spiegel:
I know.I know you know.
BUT, and this is a big but, do you know that I know that you know?
Sentinel
2007-03-03, 06:57
HAHA, DISREGARD THAT, I SUCK COCKS!
[This message has been edited by Sentinel (edited 03-03-2007).]
quote:Originally posted by The Death Monkey:
So... what you're saying is, is to fix the problem, Jeff should hurry the fuck up and bring vB up?
Well not exactly. Vbulletin would be awesome, no doubt. But I was suggesting to use the same encryption process as what vbulletin forums have.
dark_rider_666
2007-03-03, 13:22
posts on first page of 3rd topic on n.o.t.t
doct0r_4rmo
2007-03-03, 16:24
k.
grusomhat
2007-03-03, 18:43
Thanks for the heads up Zok
Bastard Man
2007-03-04, 00:24
Will you be posting a list of the accounts that were affected by the security issue?
I would like to know if i need to change everything.
dark_rider_666
2007-03-04, 01:09
quote:Originally posted by robinhoody:
Originally posted by Spike Spiegel:
I know.I know you know.
BUT, and this is a big but, do you know that I know that you know?
that i know that you know.
Jeff I just sneezed out a lumpy piece of black snot, do you want it?
quote:Originally posted by Enter:
Jeff I just sneezed out a lumpy piece of black snot, do you want it?
You forgot "It's yours!"
DesyphIX
2007-03-04, 11:00
quote:Originally posted by Enter:
Sir Jeffery Huntarr, I just sneezed out a lumpy piece of black snot, would U lIEK it, its uRS?
Fixed.
Jeff I just shaved off my pubes and put 'em in a bag, along with some dog crap I found on the side of the road. Do you want it? It's yours!
Burn it up
2007-03-04, 12:51
Hmm, thats not good
Thanks for the heads-up Zok.
Oh BTW: "Jeff, I got aids from fucking my pet dog. Do you want it? It's yours!"
*Offers bloody syringe to Jeff*
Father Time
2007-03-04, 18:04
http://www.totse.com/bbs/smile.gif (http://www.totse.com/bbs/smile.gif)
The Death Monkey
2007-03-04, 21:36
quote:Originally posted by Senzuri:
Well not exactly. Vbulletin would be awesome, no doubt. But I was suggesting to use the same encryption process as what vbulletin forums have.
That seems to be a pretty inefficient fix to the problem though. Why not upgrade AND bring all the cool awesomeness that vB will bring while fixing the problem at the same time... all the while, not having to really do anything to fix the problem. The problem is fixed just in the change.
The Death Monkey
2007-03-04, 22:28
Jeff should put a super strict swear sensor on totse that makes it so that if you swear at all, you get banned for a week.
If I owned Totse, I'd do it for a while just for teh lulz.
KwinnieBogan
2007-03-04, 23:54
These kid's wouldn't be doing things like this if they had access to Where's Wally (Waldo to the North Americans)
As a sidenote, I wouldn't doubt this is part of a series of hack attacks against various forums on the web, such as sciencemadness.org
Something's up, and I don't know what it is. Be paranoid, people--be very paranoid.
ZOK
You may want to check if anyone has been trying to crack backdoors or any part of TOTSE. I have a feeling a lot of these things are related.
[This message has been edited by Genecks (edited 03-05-2007).]
robinhoody
2007-03-05, 06:33
quote:Originally posted by Genecks:
You may want to check if anyone has been trying to crack backdoors or any part of TOTSE.That's a good point.
You should also check the ground-floor windows to make sure they're not broken, and make sure they're locked. You can put a piece of wood between the window and frame to add extra strength, too (and it works on sliding doors, too).
I've been around since 2004. I know ZOK doesn't have the ability to check that stuff. Zok is a mediocre person with only linguistic skills. I doubt he could find a way to protect TotSE.
However, my comment was serious.
The Death Monkey
2007-03-05, 06:50
quote:Originally posted by Genecks:
I've been around since 2004. I know ZOK doesn't have the ability to check that stuff. Zok is a mediocre person with only linguistic skills. I doubt he could find a way to protect TotSE.
However, my comment was serious.
You are such a raging douche I think you're on the nominee list for biggest douche in the universe. Congrats.
That insult was mainly directed at Zok. Zok, along with a lot of other moderators/admins, know I'm a jackass. (I'm Kamisama)
I've studied these people and I know what they know. Zok studies German, took various CLEP tests, has an interest in linguistics, and etc. etc.
But he isn't that talented in the end. Sure, he's college educated; but he's not much from my opinion.
ragesoadrules
2007-03-05, 06:59
Why the fuck would someone hack &T?
Douchebag
quote:Originally posted by Genecks:
That insult was mainly directed at Zok. Zok, along with a lot of other moderators/admins, know I'm a jackass. (I'm Kamisama)
I've studied these people and I know what they know. Zok studies German, took various CLEP tests, has an interest in linguistics, and etc. etc.
But he isn't that talented in the end. Sure, he's college educated; but he's not much from my opinion.
At least he isn't a butthole like you.
shun siney
2007-03-05, 18:59
zok, my original account, has been deleted over the weekend, how would I go about getting it back?
quote:Originally posted by Genecks:
That insult was mainly directed at Zok. Zok, along with a lot of other moderators/admins, know I'm a jackass. (I'm Kamisama)
I've studied these people and I know what they know. Zok studies German, took various CLEP tests, has an interest in linguistics, and etc. etc.
But he isn't that talented in the end. Sure, he's college educated; but he's not much from my opinion.
wait a second you actually spent time studying him?? WTF dont have more importantt hings to do. just liket hat thread you made about spending all that time trying to manipulate that girl. WTF
I_am_god
2007-03-07, 23:58
quote:Originally posted by The Great One:
You're the lamest faggot on totse.
FUCKER RESPECT YOUR ELDERS!!!
Dr. Ol Raw
2007-03-08, 00:43
quote:Originally posted by shun siney:
zok, my original account, has been deleted over the weekend, how would I go about getting it back?
It was never deleted, you were just banned.
robinhoody
2007-03-10, 03:07
quote:Originally posted by Vega:
This is fucked up, when I logged in and clicked on NOTT, I could only see the replacement for UBB thread, but when I logged out, I saw the other threads.
http://www.totse.com/bbs/eek.gif (http://www.totse.com/bbs/eek.gif)Because it was set to only show threads from the last day.
At the top of the forum, there is a selection box that says "SHow posts from the last day". You can change that to any one of the options, and you'll see the other threads.
mouser55
2007-03-10, 19:17
ok, when will VB be arriving?
Jeff I just farted in an empty coke bottle. Do you want it? It's yours!
ytter_man
2007-03-19, 20:15
deleted all my cookies. i do it on a regular basis anyway.
What the hell is wrong with SG and IFIOTW? Or is it just me?
Edit: Ok, now IFIOTW is fine, but SG says it has -1 posts. When I click on the forum, it never loads. It's been like this since yesterday. Is it like this for anyone else? Or did my shit get hacked? I'm confused http://www.totse.com/bbs/frown.gif (http://www.totse.com/bbs/frown.gif)
[This message has been edited by Shizno (edited 03-19-2007).]
rasta_rider
2007-03-20, 20:48
quote:Originally posted by Shizno:
What the hell is wrong with SG and IFIOTW? Or is it just me?
Edit: Ok, now IFIOTW is fine, but SG says it has -1 posts. When I click on the forum, it never loads. It's been like this since yesterday. Is it like this for anyone else? Or did my shit get hacked? I'm confused http://www.totse.com/bbs/frown.gif (http://www.totse.com/bbs/frown.gif)
haha i don't envy the SG kiddies, I don't know how anyone can read more than one thread in that shit hole.
ak-kapocsi
2007-03-22, 01:08
how do i change my password?
I_am_god
2007-03-25, 05:38
quote:Originally posted by ak-kapocsi:
how do i change my password?
Your fucking kidding me.
ak-kapocsi
2007-03-26, 04:51
no i'm not
what is a password?
i dont get it what is the point of this "password" thing
[This message has been edited by ak-kapocsi (edited 03-26-2007).]
granite erection
2007-04-04, 18:49
I didn't even know there was a password stealing problem.
Edit: Never mind.
[This message has been edited by Source (edited 03-02-2007).]
lol niether did i, and i have been here on and off for 8 years.
thanks for bringing that to our attention.