Announcement

Collapse
No announcement yet.

Security breach

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #31
    Originally Posted by labratofel View Post
    I can get access to your ICQ account. Then I can take over the world.
    ROFL

    see

    a little humour never hurt
    "If you don't like DNAS, write your own damn system"

    So I did

    Comment


    • #32
      Originally Posted by Third_of_Five View Post
      Both those statements are incorrect. Keep it in check was directed at everyone. I did not tell you to stfu, I made an observation / a comparison which is not the same. You however continue to be disrespectful, clearly you get some kind of kick out of it, which says a lot.
      .
      how was I disrespectful to you before you told me to STFU (I didn't say you told me, admin did)


      Originally Posted by Third_of_Five View Post
      It's not clear the passwords were stolen at all.
      so why were you told to change them?

      Originally Posted by Third_of_Five View Post
      And how do you know the passwords are encrypted? You don't.
      I'm the one that stole the database useless to me because the passwords are encrypted

      - or -

      I know a lot more about this forum than johnny come seldoms

      code:
      $password_hash = md5(md5($password_text) . $user_salt);
      sorry, I said encrypted ... but 99% of n00bs wouldn't understand "hashed"
      "If you don't like DNAS, write your own damn system"

      So I did

      Comment


      • #33
        Originally Posted by jaromanda View Post
        how was I disrespectful to you before you told me to STFU (I didn't say you told me, admin did)
        Waste of effort conversing with you as there seems some kind of language barrier, as you continually misinterpret plain English, which as Troll seems to be your primary language is probably not surprising.

        Comment


        • #34
          Originally Posted by Third_of_Five View Post
          Waste of effort conversing with you
          and yet, here you are
          Originally Posted by Third_of_Five View Post
          as there seems some kind of language barrier, as you continually misinterpret plain English,
          let me type it out SLOWLY for you

          I never claimed you told me to STFU ... I was not rude or disrespectful to you until you basically told me to stop posting

          not ONE admin/mod has corrected any points in any of my posts

          why do you think that is?

          because it's COMMON SENSE
          "If you don't like DNAS, write your own damn system"

          So I did

          Comment


          • #35


            ROFL

            look at all the users in the control panel

            hardly any are bitchin an moanin in this thread
            "If you don't like DNAS, write your own damn system"

            So I did

            Comment


            • #36
              Originally Posted by jaromanda View Post
              http://forums.shoutcast.com/online.p...members&pp=200

              ROFL

              look at all the users in the control panel

              hardly any are bitchin an moanin in this thread
              Yeah they are too busy changing their passwords.

              Comment


              • #37
                Originally Posted by labratofel View Post
                Yeah they are too busy changing their passwords.
                yeah, because it takes HOURS to do that
                "If you don't like DNAS, write your own damn system"

                So I did

                Comment


                • #38
                  As I understand it, the MD5 hashes which *MAY* have also been taken in addition to the emails (as written in the security bulletin), could be used to generate a collision (ie. something which has the same hash) and that could be used to login to your Winamp Forums account.

                  The odds of the collision being your actual password are minimal so your password will most likely be safe on other sites unless they also use MD5 hashes, but to err on the side of caution we've all been advised to change passwords on other sites if it's the same. At the very (very) least your Winamp forum password should be changed.

                  Hope that helps anyone who's still a bit confused.
                  Request: A little SmartView Query Language love.

                  Comment


                  • #39
                    MD5 Rainbow tables.
                    Ask google about them.

                    Says it all really.

                    Comment


                    • #40
                      Originally Posted by osmosis View Post
                      Hope that helps anyone who's still a bit confused.
                      I'll take "Common Sense on the Internet" for 400, please, Alex
                      "If you don't like DNAS, write your own damn system"

                      So I did

                      Comment


                      • #41
                        Originally Posted by labratofel View Post
                        MD5 Rainbow tables.
                        Ask google about them.

                        Says it all really.
                        So, change your password ... rainbows and unicorns can't get you then!!

                        category 5 cyclone in a tea cup averted
                        "If you don't like DNAS, write your own damn system"

                        So I did

                        Comment


                        • #42
                          Right, but was the salt compromised as well?
                          Request: A little SmartView Query Language love.

                          Comment


                          • #43
                            Originally Posted by osmosis View Post
                            Right, but was the salt compromised as well?
                            it's stored in the user table


                            so ... it's not AS secure as if the salt wasn't compromised

                            by the way ... I'd say if email addresses (stored in the user table) were compromised, hashed passwords and hash salts are also compromised

                            it's still a bit of work to retrieve A password (maybe not THE password), but far easier having the salt than without
                            "If you don't like DNAS, write your own damn system"

                            So I did

                            Comment


                            • #44
                              I recently had to do a full round of password changes after a similar compromise at Gawker Media a few months ago. Now, back at stage one doing it over again... thanks, Winamp.

                              It is unreasonable to expect people to use a unique password for each and every website. I visit hundreds of websites, and I imagine the average person has a few dozen they regularly go to as well. I do use many passwords, but hundreds?

                              I would advise others here who don't want to use a separate PW for each site to use password 'sets', where you use 1 PW for a group of similar sites, and spread your PWs out amongst the most important sites you use (example: don't use your online banking PW as the same as your paypal or other very important site, to lessen any possible damage from a breach.)

                              Regardless, in this day and age it is suicide for a trusted site to not properly protect valuable data like this. I do so hope it doesn't happen again.

                              Comment


                              • #45
                                Originally Posted by Zulithe View Post
                                I recently had to do a full round of password changes after a similar compromise at Gawker Media a few months ago. Now, back at stage one doing it over again... thanks, Winamp.
                                read the terms of service, and privacy policy before blaming winamp

                                Originally Posted by Zulithe View Post
                                It is unreasonable to expect people to use a unique password for each and every website.
                                sure, it may be unreasonable ... but winamp can't be held accountable for poor internet practices by users

                                Originally Posted by Zulithe View Post
                                Regardless, in this day and age it is suicide for a trusted site to not properly protect valuable data like this. I do so hope it doesn't happen again.
                                seriously? it was winamp forum that was compromised. the vulnerability is in the forum software = vBulletin.

                                I can guarantee there are thousands of chinese and russian spotty teens working on hacking vbulletin one handed whilst I'm typing this

                                build a more secure forum, someone somewhere will hack it eventually

                                welcome to the internet, you must be new
                                "If you don't like DNAS, write your own damn system"

                                So I did

                                Comment

                                Working...
                                X
                                😀
                                🥰
                                🤢
                                😎
                                😡
                                👍
                                👎