Announcement

Collapse
No announcement yet.

Security breach

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #16
    Originally Posted by jaromanda View Post
    how hard is that?
    About as hard as it is for you to STFU. If you don't want to answer the question that was asked, then don't answer at all.

    Comment


    • #17
      will everyone keep it in check please, especially telling people to STFU is not helpful.

      as for the questions raised, i'm not going to answer them as i do not know the complete answer and so do not want to spread mis-information. as such what is officially provided is all there is to know on the matter though there may be further clarification (but i do not know and cannot confirm about that).

      -daz
      WACUP Project <‖> "Winamp Ramblings" - Indie Winamp Dev Blog

      Comment


      • #18
        The only reasonable thing you have posted in this thread jarorama is everything from "my wife wants" in post #7.

        You're not site admin, let them tell me what the breach was, what was taken (I understand databases and SQL injection so I sincerely doubt all they did was
        code:
        SELECT email FROM usertable WHERE 1;
        edit: sorry mod, you posted while I was constructing this post.

        Comment


        • #19
          Originally Posted by Third_of_Five View Post
          About as hard as it is for you to STFU. If you don't want to answer the question that was asked, then don't answer at all.
          I believe I've answered the question

          no need to get your panties in a bunch, sweetheart
          "If you don't like DNAS, write your own damn system"

          So I did

          Comment


          • #20
            Originally Posted by labratofel View Post
            The only reasonable thing you have posted in this thread jarorama is everything from "my wife wants" in post #7.

            You're not site admin, let them tell me what the breach was, what was taken (I understand databases and SQL injection so I sincerely doubt all they did was
            code:
            SELECT email FROM usertable WHERE 1;
            edit: sorry mod, you posted while I was constructing this post.
            but ... I can READ emails, and READ the FAQ ... so I UNDERSTAND

            I've admined fora over the years, and know what will and wont be disclosed by 99 out of a 100 admins in such circumstances

            but, right now, I'll let the drama llama's carry on their whinging and whining
            Attached Files
            Last edited by jaromanda; 16 February 2011, 12:07.
            "If you don't like DNAS, write your own damn system"

            So I did

            Comment


            • #21
              Originally Posted by DrO View Post
              will everyone keep it in check please, especially telling people to STFU is not helpful.
              And neither is all the bull crap he is spouting, nor did I tell him/her to STFU, I was making an observation, which not the same thing. People like him/her are the bane of forums.

              If there was any amount of access to the DB, it is not unreasonable to assume it was more than just emails that were stolen.

              Comment


              • #22
                Originally Posted by Third_of_Five View Post
                And neither is all the bull crap he is spouting, nor did I tell him/her to STFU, I was making an observation, which not the same thing. People like him/her are the bane of forums.
                they're called facts, sweetheart

                I'll stop if I'm told I'm doing anything wrong by admins ... not by someone who made two posts 4 years ago and hasn't been back since

                thanks for your input, though, sweetheart
                Originally Posted by Third_of_Five View Post
                If there was any amount of access to the DB, it is not unreasonable to assume it was more than just emails that were stolen.
                yeah, encrypted passwords and all the info you put on your PUBLIC profile page too ... oh noes, they got info you already made public!!! what to do what to do!!!

                interesting observation ... the biggest DOOMSAYERS have less than 5 posts on the forum before today

                just saying is all
                "If you don't like DNAS, write your own damn system"

                So I did

                Comment


                • #23
                  Thanks to the admins at being honest here. Okay, that is a legal requirement when you get your database stolen, but how many other forums get quietly hacked and then everything covered up in secrecy?

                  Can I make a small suggestion? Any chance of making the "Contact an Admin" links a little easier to find? When I dropped by this website on Jan 8th at 20:47 hrs GMT NOD32 blocked a connection to ciriso9********/multi/jnaojtgpizin.jar (Don't be stupid enough to follow that link, I am typing it here purely as an example...) If I could have found a way to easily contact an Admin, I would have reported this. Trouble is, it was not clear how to report anything so instead of wading around an infected website I ran away.

                  Oh - and nice to see NOD32 in action. Often sit in all kinds of silly debates about the qualities of different AV products, and it is always fun to see NOD32 getting the gloves off.

                  Edit:Oooo - now that is nice to see. I typed the URL above of the virus that tried to hump my PC on that day. And now I see the domain name gets blocked. I think this is the same virus that got the BBC website ( http://www.theregister.co.uk/2011/02...veby_download/ ) From that nice place the cocos islands.

                  If the BBC, with its huge site and cash investments gets nailed, then I think Winamp Admins can be forgiven.

                  Comment


                  • #24
                    Your nothing more than a Troll jaromanda.

                    Comment


                    • #25
                      Must.. not.. feed.. the.. troll..

                      I have used Winamp for more years than I care to remember. Just because I haven't posted much doesn't mean that I don't know what I am talking about.

                      *expletive deleted* happens - I understand that. I just want clarification as to what was lost so I can assess the potential damage. I don't want some nobody from Deservesakicking, Illinois telling me what I should think.

                      Edit: I just looked over my very small posting history and saw one of my original posts that I joined the forum to create. It was a step by step guide to show people how to get shoutcast running as a Windows service.

                      Speak little, but when you do make sure the message is useful.

                      Maybe you should try that.

                      Comment


                      • #26
                        Originally Posted by jaromanda View Post
                        I'll stop if I'm told I'm doing anything wrong by admins ... not by someone who made two posts 4 years ago and hasn't been back since
                        You were told to keep it in check, which you seem incapable of comprehending or doing.

                        interesting observation ... the biggest DOOMSAYERS have less than 5 posts on the forum before today
                        Did I mention DOOM? All I have done is question the statement that only our emails were leaked. All you have done is be disrespectful and unhelpful in nearly all your posts.

                        Comment


                        • #27
                          Originally Posted by labratofel View Post
                          *expletive deleted* happens - I understand that. I just want clarification as to what was lost so I can assess the potential damage. I don't want some nobody from Deservesakicking, Illinois telling me what I should think.
                          you were told in the email

                          1) email address, stolen

                          2) suggest you change password

                          3) change password on other sites if same as here

                          all other possible stolen info is already public in your profile ... so it's not really stolen, is it


                          from 1) you MAY get spam ... I'm sure you do already

                          from 2) you change your password, no big deal

                          from 3) if applicable, you learn not to use the same password on different sites

                          not sure what else you want? class action lawsuit?
                          "If you don't like DNAS, write your own damn system"

                          So I did

                          Comment


                          • #28
                            Originally Posted by Third_of_Five View Post
                            You were told to keep it in check, which you seem incapable of comprehending or doing.
                            no, sweetheart, that was directed at you .... telling someone to STFU is rude

                            Please, Mr 4 posts, don't think you can tell me what to do on this forum ... I'll take direction from admin/moderators ... but not from Chicken "the sky is falling" Little

                            Originally Posted by Third_of_Five View Post
                            Did I mention DOOM? All I have done is question the statement that only our emails were leaked. All you have done is be disrespectful and unhelpful in nearly all your posts.
                            read post above ... clearly the passwords would be stolen, but encrypted, so that's why it was recommended you change your password here

                            all other info possibly "stolen" was clearly visible in your public profile here ... so ... you going to sue AOL for leaking information you gave out willingly and publicly?

                            read my sig .... and take into consideration I'm also modest
                            "If you don't like DNAS, write your own damn system"

                            So I did

                            Comment


                            • #29
                              Information in your profile could include your web address.

                              A whois search could then reveal your real name *edit* and address. Not Winamp's fault but a link in a chain.

                              The date of birth could be stored in the forum database so they can send you birthday greetings. It doesn't have to appear on your profile page ("Hide age and date of birth").

                              Now I potentially have a name, address, email and a date of birth. A little social engineering and I can get access to your ICQ account. Then I can take over the world. Or something.

                              It's been done before. Just not by me.

                              Comment


                              • #30
                                Originally Posted by jaromanda View Post
                                no, sweetheart, that was directed at you .... telling someone to STFU is rude
                                Both those statements are incorrect. Keep it in check was directed at everyone. I did not tell you to stfu, I made an observation / a comparison which is not the same. You however continue to be disrespectful, clearly you get some kind of kick out of it, which says a lot.

                                read post above ... clearly the passwords would be stolen, but encrypted, so that's why it was recommended you change your password here
                                It's not clear the passwords were stolen at all. And how do you know the passwords are encrypted? You don't.

                                Comment

                                Working...
                                X
                                😀
                                🥰
                                🤢
                                😎
                                😡
                                👍
                                👎