amiga.org
     
iconAll times are GMT -6. The time now is 09:13 AM. | Welcome to Forum, please register to access all of our features.

» Amiga.org » Amiga computer related discussion » Amiga News and Community Announcements » Amiga.org site announcements » Change your passwords

Amiga.org site announcements Announcements and news updates specifically about Amiga.org. Not for general discussion.

Reply
 
Thread Tools Display Modes
Old 01-13-2012, 06:23 PM   #1
Karlos
Sockologist
Points: 48,752, Level: 100 Points: 48,752, Level: 100 Points: 48,752, Level: 100
Activity: 8% Activity: 8% Activity: 8%
 
Karlos's Avatar
 
Join Date: Nov 2002
Location: I solve practical problems...
Posts: 16,606
Blog Entries: 18
Exclamation Change your passwords

Dear all,

Several accounts here have been compromised in recent days. We have no evidence at this time to suspect that the server itself has been compromised. So far the issue appears to be one brought about through the use of weak passwords used across multiple forums as all of the known compromised accounts have been misused on other forums already.

With that in mind, please change your passwords for this and every other amiga forum you visit, making sure each one is unique and as strong as possible (use mixed case, numbers and symbols where you can, the longer the better).

We apologise for any inconvenience.
__________________
OCA
This isn't SCSI... This is SATA!!!
I have CDO. It's like OCD except all the letters are in ascending order. The way they should be.
Core2 Quad Q9450 2.66GHz / X48T / 4GB DDR3 / nVidia GTX275 / Linux x64, AROS, Win64
A1XE 800MHz / 512MB / Radeon 9200 / OS4.1
A1200T BPPC 240MHz / 256MB / Permedia 2 / OS 3.1 - OS3.9, OS4
A1200T Apollo 1240 28MHz / 32MB / Mediator1200 / Voodoo 3000 / OS3.9
A1200D Apollo 1240 25MHz (ejector seat ROM edition) / 32MB
Karlos is offline   Reply With Quote
Old 01-13-2012, 06:46 PM   #2
Tripitaka
Defender of the Faith
Points: 9,010, Level: 63 Points: 9,010, Level: 63 Points: 9,010, Level: 63
Activity: 2% Activity: 2% Activity: 2%
 
Tripitaka's Avatar
 
Join Date: Jun 2005
Posts: 1,247
Default Re: Change your passwords

Done. I just hope I don't loose the paper I wrote it on, I've no chance of actually remembering it. XD
__________________
Falling into a dark and red rage.
Tripitaka is offline   Reply With Quote
Old 01-13-2012, 06:49 PM   #3
Matt_H
VIP / Donor
Points: 22,284, Level: 92 Points: 22,284, Level: 92 Points: 22,284, Level: 92
Activity: 36% Activity: 36% Activity: 36%
 
Matt_H's Avatar
 
Join Date: Mar 2003
Location: Boston, MA, United States
Posts: 4,989
Default Re: Change your passwords

Hypothesis: Wasn't one of the reasons Wayne moved away from Xoops the presence of some significant security holes? Maybe the AW.net server is the weak point. Is anyone in touch with the admins over there?

Fortunately, the only other place I'm registered is Morphzone, and my password there is so convoluted that even I can't remember it!

Just did a passwd Matt_H, nonetheless.
Matt_H is offline   Reply With Quote
Old 01-13-2012, 06:55 PM   #4
orange
Kindred of Babble-on
Points: 18,002, Level: 85 Points: 18,002, Level: 85 Points: 18,002, Level: 85
Activity: 1% Activity: 1% Activity: 1%
 
orange's Avatar
 
Join Date: Dec 2003
Location: Serbia
Posts: 2,532
Default Re: Change your passwords

Quote:
Originally Posted by Tripitaka View Post
Done. I just hope I don't loose the paper I wrote it on, I've no chance of actually remembering it. XD
I hope its not 'hunter2'
__________________
You`re here, Noŷs.
orange is offline   Reply With Quote
Old 01-13-2012, 07:24 PM   #5
LoadWB
Kindred of Babble-on
Points: 13,262, Level: 75 Points: 13,262, Level: 75 Points: 13,262, Level: 75
Activity: 11% Activity: 11% Activity: 11%
 
LoadWB's Avatar
 
Join Date: Jul 2006
Location: Tallahassee, FL
Posts: 2,104
Default Re: Change your passwords

Web security is fun. After reaching a total of 40-some passwords of my own I had to memorize, on top of customer passwords, I let Firefox save my passwords. In and of itself this is not secure, but I also encrypt my profile so obtaining the files without my private key is useless. Then each website uses a different password generated by apg, which creates NIST standard pronounceable passwords of whatever parameters you want, like 32 characters with special symbols and numbers, etc.

Default config (with -t to show pronunciations) creates something like this:
CrobOkus (Crob-Ok-us)
lidMuenn (lid-Muenn)
ciQuegsId9 (ci-Quegs-Id-NINE)
ubcorak$ (ub-cor-ak-DOLLAR_SIGN)
athGhakfum (ath-Ghak-fum)
dodMiuv[ (dod-Mi-uv-LEFT_BRACKET)
Or more complex, 32 character passwords which must contain capitals, lower-case, numbers, and special characters:
TafApJekAdd$ocealavwycsodbekcor9 (Taf-Ap-Jek-Add-DOLLAR_SIGN-oc-eal-av-wycs-od-bek-cor-NINE)
ucQuipsurrakbuzopp4ovVajDinchaj# (uc-Quips-urr-ak-buz-opp-FOUR-ov-Vaj-Dinch-aj-CROSSHATCH)
ScijyotNoimyatyeydPoodEwon1cylf& (Scij-yot-Noim-yat-yeyd-Pood-Ew-on-ONE-cylf-AMPERSAND)
~Ozvaujkent8OzdiCoiljevpanwogLoi (TILDE-Oz-vauj-kent-EIGHT-Oz-di-Coilj-ev-pan-wog-Loi)
TydTeogvalegHywridik/odJatovjan5 (Tyd-Te-og-val-eg-Hy-wrid-ik-SLASH-od-Jat-ov-jan-FIVE)
uskingAg3KigByldEegEdReejOckcur< (usk-ing-Ag-THREE-Kig-Byld-Eeg-Ed-Reej-Ock-cur-LESS_THAN)
I love this utility. If I forget a password (yeah, I'm not remembering 32 character passwords, for the most part,) or Firefox's save password is defeated (it happens,) then I just go through the process to create a new one. (And I didn't use any of the above here hehehe)
LoadWB is offline   Reply With Quote
Old 01-13-2012, 07:31 PM   #6
bbond007
Defender of the Faith
Points: 8,821, Level: 63 Points: 8,821, Level: 63 Points: 8,821, Level: 63
Activity: 28% Activity: 28% Activity: 28%
 
bbond007's Avatar
 
Join Date: Mar 2009
Posts: 1,268
Default Re: Change your passwords

Who is trying to hack Amiga sites anyway? Atari ST users?
bbond007 is offline   Reply With Quote
Old 01-13-2012, 07:47 PM   #7
save2600
Premium Member
Points: 17,757, Level: 84 Points: 17,757, Level: 84 Points: 17,757, Level: 84
Activity: 4% Activity: 4% Activity: 4%
 
Join Date: Jul 2006
Location: Southern, WI USA
Posts: 3,007
Send a message via Yahoo to save2600
Default Re: Change your passwords

Quote:
Originally Posted by bbond007 View Post
Who is trying to hack Amiga sites anyway? Atari ST users?
The Atari SF354 is the greatest, most useful and most reliable drive on the planet!

I also love the fact it requires it's own external power supply. So kewl!
__________________
Cash paid or will trade for loose and CIB Amiga games I need. Game manuals and boxes only too! Will purchase in large lots as well.

Last edited by save2600; 01-13-2012 at 07:53 PM..
save2600 is offline   Reply With Quote
Old 01-13-2012, 07:57 PM   #8
Duce
Off to greener pastures
Points: 5,312, Level: 46 Points: 5,312, Level: 46 Points: 5,312, Level: 46
Activity: 21% Activity: 21% Activity: 21%
 
Join Date: Jul 2009
Posts: 1,058
Default Re: Change your passwords

Thanks for the heads up, Karlos. Changed mine.

Anyone looking for a quick and easy complex PW generator, try:

https://www.grc.com/passwords.htm
Duce is offline   Reply With Quote
Old 01-13-2012, 09:00 PM   #9
Tripitaka
Defender of the Faith
Points: 9,010, Level: 63 Points: 9,010, Level: 63 Points: 9,010, Level: 63
Activity: 2% Activity: 2% Activity: 2%
 
Tripitaka's Avatar
 
Join Date: Jun 2005
Posts: 1,247
Default Re: Change your passwords

Quote:
Originally Posted by orange View Post
I hope its not 'hunter2'
Oh, you mean *******, hey that's odd, when I type it I just get stars. :/
__________________
Falling into a dark and red rage.
Tripitaka is offline   Reply With Quote
Old 01-13-2012, 09:00 PM   #10
amiman99
Lifetime Member
Points: 3,666, Level: 38 Points: 3,666, Level: 38 Points: 3,666, Level: 38
Activity: 28% Activity: 28% Activity: 28%
 
Join Date: Aug 2011
Location: San Antonio, TX
Posts: 541
Default Re: Change your passwords

Quote:
Originally Posted by Duce View Post
Thanks for the heads up, Karlos. Changed mine.

Anyone looking for a quick and easy complex PW generator, try:

https://www.grc.com/passwords.htm
Yes, I use similar website to generate my passwords.
Just changed mine on this and other forums, just to be safe and of course they are different across forums.
amiman99 is offline   Reply With Quote
Old 01-13-2012, 09:11 PM   #11
tomazkid
Too much caffeine
Points: 6,198, Level: 51 Points: 6,198, Level: 51 Points: 6,198, Level: 51
Activity: 4% Activity: 4% Activity: 4%
 
tomazkid's Avatar
 
Join Date: Sep 2004
Posts: 123
Default Re: Change your passwords

Quote:
Originally Posted by Matt_H View Post
Hypothesis: Wasn't one of the reasons Wayne moved away from Xoops the presence of some significant security holes? Maybe the AW.net server is the weak point. Is anyone in touch with the admins over there?

Fortunately, the only other place I'm registered is Morphzone, and my password there is so convoluted that even I can't remember it!

Just did a passwd Matt_H, nonetheless.

The obsolete part it the cms, the xoops is old and obsoleted, and will be replaced, it takes time though.
The OS the site runs on, was changed when aw.net moved to a new ISP, and is up to date.

Quoting Karlos regarding where the passwords come from:

"We have no evidence at this time to suspect that the server itself has been compromised. "

Same goes at aw.net, Sibbi has not found anything strange in the logs this far.
tomazkid is offline   Reply With Quote
Old 01-13-2012, 09:52 PM   #12
Pyromania
Head Amiga.org Chef
Points: 19,859, Level: 89 Points: 19,859, Level: 89 Points: 19,859, Level: 89
Activity: 23% Activity: 23% Activity: 23%
 
Join Date: Aug 2002
Location: Chicago
Posts: 1,422
Default Re: Change your passwords

Thanx Karlos
Pyromania is offline   Reply With Quote
Old 01-14-2012, 03:59 AM   #13
Karlos
Sockologist
Points: 48,752, Level: 100 Points: 48,752, Level: 100 Points: 48,752, Level: 100
Activity: 8% Activity: 8% Activity: 8%
 
Karlos's Avatar
 
Join Date: Nov 2002
Location: I solve practical problems...
Posts: 16,606
Blog Entries: 18
Default Re: Change your passwords

Quote:
Originally Posted by Tripitaka View Post
Oh, you mean *******, hey that's odd, when I type it I just get stars. :/


For those not following, see: http://bash.org/?244321
__________________
OCA
This isn't SCSI... This is SATA!!!
I have CDO. It's like OCD except all the letters are in ascending order. The way they should be.
Core2 Quad Q9450 2.66GHz / X48T / 4GB DDR3 / nVidia GTX275 / Linux x64, AROS, Win64
A1XE 800MHz / 512MB / Radeon 9200 / OS4.1
A1200T BPPC 240MHz / 256MB / Permedia 2 / OS 3.1 - OS3.9, OS4
A1200T Apollo 1240 28MHz / 32MB / Mediator1200 / Voodoo 3000 / OS3.9
A1200D Apollo 1240 25MHz (ejector seat ROM edition) / 32MB
Karlos is offline   Reply With Quote
Old 01-14-2012, 05:26 AM   #14
Karlos
Sockologist
Points: 48,752, Level: 100 Points: 48,752, Level: 100 Points: 48,752, Level: 100
Activity: 8% Activity: 8% Activity: 8%
 
Karlos's Avatar
 
Join Date: Nov 2002
Location: I solve practical problems...
Posts: 16,606
Blog Entries: 18
Default Re: Change your passwords

Quote:
Originally Posted by Matt_H View Post
Hypothesis: Wasn't one of the reasons Wayne moved away from Xoops the presence of some significant security holes?
There were a number of issues. The version of XOOPS that this site used previously (which I believe was even more obsolete than the install at AW) had weak hashing for passwords. However, the main impetus for moving to vB was that the hosting provider was set to remove all support for older PHP versions and associated libraries as part of a managed update to 5 (again, for security reasons). The version of XOOPS that was installed, which was extremely outdated by then proved to be incompatible (bits worked, other bits didn't, basically a classic legacy PHP4 style application struggling with changes to the Zend engine since PHP5) with the updates.

The decision to move to vB was down to a choice between an updated version of XOOPS that would work after the update but be problematic for all the old amiga browsers, or some other platform. The only reason the site stuck with it's ancient version XOOPS for so long in the first place was for classic amiga browser compatibility (that and the fact that there was no upgrade path for most of the installed modules, either). With that consideration being out of the window regardless, alternatives were evaluated and vB was chosen as it scored better on a number of critical areas, including security.

Quote:
Maybe the AW.net server is the weak point. Is anyone in touch with the admins over there?
Yes, we're in touch and cooperating on the problem.

Quote:
Fortunately, the only other place I'm registered is Morphzone, and my password there is so convoluted that even I can't remember it!

Just did a passwd Matt_H, nonetheless.
That's for the best. No matter how strongly we salt and hash your password, if it is the same as you use on half a dozen other sites and one of those is the weak link, there's not a lot we can do other than reset it for you.

So once again folks, change your passwords if you haven't already and under no circumstances use the same password on more than one forum!
__________________
OCA
This isn't SCSI... This is SATA!!!
I have CDO. It's like OCD except all the letters are in ascending order. The way they should be.
Core2 Quad Q9450 2.66GHz / X48T / 4GB DDR3 / nVidia GTX275 / Linux x64, AROS, Win64
A1XE 800MHz / 512MB / Radeon 9200 / OS4.1
A1200T BPPC 240MHz / 256MB / Permedia 2 / OS 3.1 - OS3.9, OS4
A1200T Apollo 1240 28MHz / 32MB / Mediator1200 / Voodoo 3000 / OS3.9
A1200D Apollo 1240 25MHz (ejector seat ROM edition) / 32MB

Last edited by Karlos; 01-14-2012 at 05:34 AM..
Karlos is offline   Reply With Quote
Old 01-14-2012, 06:11 AM   #15
orange
Kindred of Babble-on
Points: 18,002, Level: 85 Points: 18,002, Level: 85 Points: 18,002, Level: 85
Activity: 1% Activity: 1% Activity: 1%
 
orange's Avatar
 
Join Date: Dec 2003
Location: Serbia
Posts: 2,532
Default Re: Change your passwords

thank God its not Doomy, or this would have turned into amiga2000.org !
__________________
You`re here, Noŷs.
orange is offline   Reply With Quote
Reply

Bookmarks

Tags
change , passwords
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump