Originally Posted by jaromanda
View Post
Announcement
Collapse
No announcement yet.
Security breach
Collapse
X
-
will everyone keep it in check please, especially telling people to STFU is not helpful.
as for the questions raised, i'm not going to answer them as i do not know the complete answer and so do not want to spread mis-information. as such what is officially provided is all there is to know on the matter though there may be further clarification (but i do not know and cannot confirm about that).
-daz
Comment
-
-
The only reasonable thing you have posted in this thread jarorama is everything from "my wife wants" in post #7.
You're not site admin, let them tell me what the breach was, what was taken (I understand databases and SQL injection so I sincerely doubt all they did was
edit: sorry mod, you posted while I was constructing this post.code:
SELECT email FROM usertable WHERE 1;
Comment
-
-
Originally Posted by Third_of_Five View PostAbout as hard as it is for you to STFU. If you don't want to answer the question that was asked, then don't answer at all.
no need to get your panties in a bunch, sweetheart"If you don't like DNAS, write your own damn system"
So I did
Comment
-
-
Originally Posted by labratofel View PostThe only reasonable thing you have posted in this thread jarorama is everything from "my wife wants" in post #7.
You're not site admin, let them tell me what the breach was, what was taken (I understand databases and SQL injection so I sincerely doubt all they did was
edit: sorry mod, you posted while I was constructing this post.code:
SELECT email FROM usertable WHERE 1;
I've admined fora over the years, and know what will and wont be disclosed by 99 out of a 100 admins in such circumstances
but, right now, I'll let the drama llama's carry on their whinging and whiningAttached FilesLast edited by jaromanda; 16 February 2011, 12:07."If you don't like DNAS, write your own damn system"
So I did
Comment
-
-
Originally Posted by DrO View Postwill everyone keep it in check please, especially telling people to STFU is not helpful.
If there was any amount of access to the DB, it is not unreasonable to assume it was more than just emails that were stolen.
Comment
-
-
Originally Posted by Third_of_Five View PostAnd neither is all the bull crap he is spouting, nor did I tell him/her to STFU, I was making an observation, which not the same thing. People like him/her are the bane of forums.
I'll stop if I'm told I'm doing anything wrong by admins ... not by someone who made two posts 4 years ago and hasn't been back since
thanks for your input, though, sweetheart
Originally Posted by Third_of_Five View PostIf there was any amount of access to the DB, it is not unreasonable to assume it was more than just emails that were stolen.
interesting observation ... the biggest DOOMSAYERS have less than 5 posts on the forum before today
just saying is all"If you don't like DNAS, write your own damn system"
So I did
Comment
-
-
Thanks to the admins at being honest here. Okay, that is a legal requirement when you get your database stolen, but how many other forums get quietly hacked and then everything covered up in secrecy?
Can I make a small suggestion? Any chance of making the "Contact an Admin" links a little easier to find? When I dropped by this website on Jan 8th at 20:47 hrs GMT NOD32 blocked a connection to ciriso9********/multi/jnaojtgpizin.jar (Don't be stupid enough to follow that link, I am typing it here purely as an example...) If I could have found a way to easily contact an Admin, I would have reported this. Trouble is, it was not clear how to report anything so instead of wading around an infected website I ran away.
Oh - and nice to see NOD32 in action. Often sit in all kinds of silly debates about the qualities of different AV products, and it is always fun to see NOD32 getting the gloves off.
Edit:Oooo - now that is nice to see. I typed the URL above of the virus that tried to hump my PC on that day. And now I see the domain name gets blocked. I think this is the same virus that got the BBC website ( http://www.theregister.co.uk/2011/02...veby_download/ ) From that nice place the cocos islands.
If the BBC, with its huge site and cash investments gets nailed, then I think Winamp Admins can be forgiven.
Comment
-
-
Must.. not.. feed.. the.. troll..
I have used Winamp for more years than I care to remember. Just because I haven't posted much doesn't mean that I don't know what I am talking about.
*expletive deleted* happens - I understand that. I just want clarification as to what was lost so I can assess the potential damage. I don't want some nobody from Deservesakicking, Illinois telling me what I should think.
Edit: I just looked over my very small posting history and saw one of my original posts that I joined the forum to create. It was a step by step guide to show people how to get shoutcast running as a Windows service.
Speak little, but when you do make sure the message is useful.
Maybe you should try that.
Comment
-
-
Originally Posted by jaromanda View PostI'll stop if I'm told I'm doing anything wrong by admins ... not by someone who made two posts 4 years ago and hasn't been back since
interesting observation ... the biggest DOOMSAYERS have less than 5 posts on the forum before today
Comment
-
-
Originally Posted by labratofel View Post*expletive deleted* happens - I understand that. I just want clarification as to what was lost so I can assess the potential damage. I don't want some nobody from Deservesakicking, Illinois telling me what I should think.
1) email address, stolen
2) suggest you change password
3) change password on other sites if same as here
all other possible stolen info is already public in your profile ... so it's not really stolen, is it
from 1) you MAY get spam ... I'm sure you do already
from 2) you change your password, no big deal
from 3) if applicable, you learn not to use the same password on different sites
not sure what else you want? class action lawsuit?"If you don't like DNAS, write your own damn system"
So I did
Comment
-
-
Originally Posted by Third_of_Five View PostYou were told to keep it in check, which you seem incapable of comprehending or doing.
Please, Mr 4 posts, don't think you can tell me what to do on this forum ... I'll take direction from admin/moderators ... but not from Chicken "the sky is falling" Little
Originally Posted by Third_of_Five View PostDid I mention DOOM? All I have done is question the statement that only our emails were leaked. All you have done is be disrespectful and unhelpful in nearly all your posts.
all other info possibly "stolen" was clearly visible in your public profile here ... so ... you going to sue AOL for leaking information you gave out willingly and publicly?
read my sig .... and take into consideration I'm also modest"If you don't like DNAS, write your own damn system"
So I did
Comment
-
-
Information in your profile could include your web address.
A whois search could then reveal your real name *edit* and address. Not Winamp's fault but a link in a chain.
The date of birth could be stored in the forum database so they can send you birthday greetings. It doesn't have to appear on your profile page ("Hide age and date of birth").
Now I potentially have a name, address, email and a date of birth. A little social engineering and I can get access to your ICQ account. Then I can take over the world. Or something.
It's been done before. Just not by me.
Comment
-
-
Originally Posted by jaromanda View Postno, sweetheart, that was directed at you .... telling someone to STFU is rude
read post above ... clearly the passwords would be stolen, but encrypted, so that's why it was recommended you change your password here
Comment
-
Comment