|
Register or have you forgotten your password?
|
|
|
| Amiga.org site announcements Announcements and news updates specifically about Amiga.org. Not for general discussion. |
![]() |
|
|
Thread Tools | Display Modes |
|
|
#1 | ||||||||
|
Sockologist
![]()
|
Dear all,
Several accounts here have been compromised in recent days. We have no evidence at this time to suspect that the server itself has been compromised. So far the issue appears to be one brought about through the use of weak passwords used across multiple forums as all of the known compromised accounts have been misused on other forums already. With that in mind, please change your passwords for this and every other amiga forum you visit, making sure each one is unique and as strong as possible (use mixed case, numbers and symbols where you can, the longer the better). We apologise for any inconvenience.
__________________
OCA This isn't SCSI... This is SATA!!! I have CDO. It's like OCD except all the letters are in ascending order. The way they should be. Core2 Quad Q9450 2.66GHz / X48T / 4GB DDR3 / nVidia GTX275 / Linux x64, AROS, Win64 A1XE 800MHz / 512MB / Radeon 9200 / OS4.1 A1200T BPPC 240MHz / 256MB / Permedia 2 / OS 3.1 - OS3.9, OS4 A1200T Apollo 1240 28MHz / 32MB / Mediator1200 / Voodoo 3000 / OS3.9 A1200D Apollo 1240 25MHz (ejector seat ROM edition) / 32MB |
||||||||
|
|
|
|
|
#2 | ||||||||
|
Defender of the Faith
![]()
Join Date: Jun 2005
Posts: 1,247
|
Done. I just hope I don't loose the paper I wrote it on, I've no chance of actually remembering it. XD
__________________
Falling into a dark and red rage. |
||||||||
|
|
|
|
|
#3 | ||||||||
|
VIP / Donor
Join Date: Mar 2003
Location: Boston, MA, United States
Posts: 4,989
|
Hypothesis: Wasn't one of the reasons Wayne moved away from Xoops the presence of some significant security holes? Maybe the AW.net server is the weak point. Is anyone in touch with the admins over there?
Fortunately, the only other place I'm registered is Morphzone, and my password there is so convoluted that even I can't remember it! Just did a passwd Matt_H, nonetheless. |
||||||||
|
|
|
|
|
#4 | |||||||||
|
Kindred of Babble-on
![]()
Join Date: Dec 2003
Location: Serbia
Posts: 2,532
|
Quote:
__________________
You`re here, Noŷs. |
|||||||||
|
|
|
|
|
#5 | ||||||||
|
Kindred of Babble-on
![]()
Join Date: Jul 2006
Location: Tallahassee, FL
Posts: 2,104
|
Web security is fun. After reaching a total of 40-some passwords of my own I had to memorize, on top of customer passwords, I let Firefox save my passwords. In and of itself this is not secure, but I also encrypt my profile so obtaining the files without my private key is useless. Then each website uses a different password generated by apg, which creates NIST standard pronounceable passwords of whatever parameters you want, like 32 characters with special symbols and numbers, etc.
Default config (with -t to show pronunciations) creates something like this: CrobOkus (Crob-Ok-us)Or more complex, 32 character passwords which must contain capitals, lower-case, numbers, and special characters: TafApJekAdd$ocealavwycsodbekcor9 (Taf-Ap-Jek-Add-DOLLAR_SIGN-oc-eal-av-wycs-od-bek-cor-NINE)I love this utility. If I forget a password (yeah, I'm not remembering 32 character passwords, for the most part,) or Firefox's save password is defeated (it happens,) then I just go through the process to create a new one. (And I didn't use any of the above here hehehe) |
||||||||
|
|
|
|
|
#6 | ||||||||
|
Defender of the Faith
![]()
Join Date: Mar 2009
Posts: 1,268
|
Who is trying to hack Amiga sites anyway? Atari ST users?
|
||||||||
|
|
|
|
|
#7 | ||||||||
|
Premium Member
|
The Atari SF354 is the greatest, most useful and most reliable drive on the planet!
I also love the fact it requires it's own external power supply. So kewl!
__________________
Cash paid or will trade for loose and CIB Amiga games I need. Game manuals and boxes only too! Will purchase in large lots as well. Last edited by save2600; 01-13-2012 at 07:53 PM.. |
||||||||
|
|
|
|
|
#8 | ||||||||
|
Off to greener pastures
Join Date: Jul 2009
Posts: 1,058
|
Thanks for the heads up, Karlos. Changed mine.
Anyone looking for a quick and easy complex PW generator, try: https://www.grc.com/passwords.htm |
||||||||
|
|
|
|
|
#9 | ||||||||
|
Defender of the Faith
![]()
Join Date: Jun 2005
Posts: 1,247
|
Oh, you mean *******, hey that's odd, when I type it I just get stars. :/
__________________
Falling into a dark and red rage. |
||||||||
|
|
|
|
|
#10 | |||||||||
|
Lifetime Member
Join Date: Aug 2011
Location: San Antonio, TX
Posts: 541
|
Quote:
Just changed mine on this and other forums, just to be safe and of course they are different across forums. |
|||||||||
|
|
|
|
|
#11 | |||||||||
|
Too much caffeine
![]()
Join Date: Sep 2004
Posts: 123
|
Quote:
The obsolete part it the cms, the xoops is old and obsoleted, and will be replaced, it takes time though. The OS the site runs on, was changed when aw.net moved to a new ISP, and is up to date. Quoting Karlos regarding where the passwords come from: "We have no evidence at this time to suspect that the server itself has been compromised. " Same goes at aw.net, Sibbi has not found anything strange in the logs this far. |
|||||||||
|
|
|
|
|
#12 | ||||||||
|
Head Amiga.org Chef
![]() ![]()
Join Date: Aug 2002
Location: Chicago
Posts: 1,422
|
Thanx Karlos
|
||||||||
|
|
|
|
|
#13 | |||||||||
|
Sockologist
![]()
|
Quote:
![]() For those not following, see: http://bash.org/?244321
__________________
OCA This isn't SCSI... This is SATA!!! I have CDO. It's like OCD except all the letters are in ascending order. The way they should be. Core2 Quad Q9450 2.66GHz / X48T / 4GB DDR3 / nVidia GTX275 / Linux x64, AROS, Win64 A1XE 800MHz / 512MB / Radeon 9200 / OS4.1 A1200T BPPC 240MHz / 256MB / Permedia 2 / OS 3.1 - OS3.9, OS4 A1200T Apollo 1240 28MHz / 32MB / Mediator1200 / Voodoo 3000 / OS3.9 A1200D Apollo 1240 25MHz (ejector seat ROM edition) / 32MB |
|||||||||
|
|
|
|
|
#14 | |||||||||||
|
Sockologist
![]()
|
Quote:
The decision to move to vB was down to a choice between an updated version of XOOPS that would work after the update but be problematic for all the old amiga browsers, or some other platform. The only reason the site stuck with it's ancient version XOOPS for so long in the first place was for classic amiga browser compatibility (that and the fact that there was no upgrade path for most of the installed modules, either). With that consideration being out of the window regardless, alternatives were evaluated and vB was chosen as it scored better on a number of critical areas, including security. Quote:
Quote:
So once again folks, change your passwords if you haven't already and under no circumstances use the same password on more than one forum!
__________________
OCA This isn't SCSI... This is SATA!!! I have CDO. It's like OCD except all the letters are in ascending order. The way they should be. Core2 Quad Q9450 2.66GHz / X48T / 4GB DDR3 / nVidia GTX275 / Linux x64, AROS, Win64 A1XE 800MHz / 512MB / Radeon 9200 / OS4.1 A1200T BPPC 240MHz / 256MB / Permedia 2 / OS 3.1 - OS3.9, OS4 A1200T Apollo 1240 28MHz / 32MB / Mediator1200 / Voodoo 3000 / OS3.9 A1200D Apollo 1240 25MHz (ejector seat ROM edition) / 32MB Last edited by Karlos; 01-14-2012 at 05:34 AM.. |
|||||||||||
|
|
|
|
|
#15 | ||||||||
|
Kindred of Babble-on
![]()
Join Date: Dec 2003
Location: Serbia
Posts: 2,532
|
thank God its not Doomy, or this would have turned into amiga2000.org !
__________________
You`re here, Noŷs. |
||||||||
|
|
|