Victory Road

Victory Road (http://www.victoryroad.net/index.php)
-   Technology (http://www.victoryroad.net/forumdisplay.php?f=112)
-   -   Hacking of Pokémon sites (http://www.victoryroad.net/showthread.php?t=11287)

PHANTOMxTRAINER June 27, 2013 05:15:20 PM

Hacking of Pokémon sites
 
Has anybody heard of that hacker that hacked many Pokemon websites, and made I link to his twitter page and stuff like that?! He got some major websites too including Smogon, Serebii and ******* ********. I found out about this because of another forum I reside on got hacked by this hacker as well. Apparently the name is; Rootinabox

Magmaster12 June 27, 2013 06:03:53 PM

It's just another looser who has no life.

This site is no where near popular enough to get attacked.

Apparently everything got wiped from Smogon's server.

PHANTOMxTRAINER June 27, 2013 06:36:31 PM

Quote:

Originally Posted by Magmaster12 (Post 281577)
It's just another looser who has no life.

This site is no where near popular enough to get attacked.

Apparently everything got wiped from Smogon's server.

There's a rumor that they're using the downtime to upgrade the site, actually. However, that's JUST A RUMOR!

Twiggy June 27, 2013 11:05:59 PM

I've went and reset my password on Serebii Forums and GTS just in case. Hackers are everywhere, compromised sites are now the old new news. I guess sometimes you just can't be too safe.

Why would they want to hack Pokémon sites?

Cat333Pokémon June 27, 2013 11:31:42 PM

Quote:

Originally Posted by Magmaster12 (Post 281577)
This site is no where near popular enough to get attacked.

We've also got redundant backups going daily.

But for a site like Smogon to be hit so powerfully by something like this, they must either not be making routine backups (which is stupid) or as mentioned before using the downtime to finally roll out some updates.

PureAurorae June 28, 2013 02:37:34 AM

About this hacking thing, I believe we are safe as we are a fairly small community compared to sites such as Smogon and Serebii.

PHANTOMxTRAINER June 28, 2013 04:38:34 AM

It is confirmed that Smogon is doing perfectly fine, they are using this downtime to upgrade!

Twiggy June 28, 2013 08:34:37 AM

And just as we get to the news of Smogon back up, Bulbagarden got hacked.

Magmaster12 June 28, 2013 08:45:25 AM

I like this hacker, they banned the mods on Bulbagarden I don't like XD

Twiggy June 28, 2013 09:59:27 AM

I'm not much of a fan of what the sole hacker did on the Pokémon forums. It seems to be done to prove a point. For what, though? Leaking user data isn't the nicest thing you can do in such a situation.

It's like... The hacker knows what he is doing in a weird way. All this screams "script kiddie", but it's still bad when it cones to user data.

I don't even think smaller sites will be safe. Stay on your guard, everyone.

Reuniclus June 28, 2013 10:12:57 AM

Perhaps all this hacker wants is publicity. Unfortunately...people seem to be talking about him all over the place by now. I think the best thing anyone can do in this situation is to just ignore him.

This reminds me of the Conjopi incident that happened on Youtube a couple years ago. Back then, he would exploit Youtube's horrendous flagging system and falsely-flag LPer's videos to get them off Youtube. I remember people like Chugga and NCS were affected by this for nearly a week. Some other LPer I was watching at the time actually took down all of his videos and put them in private to avoid them getting falsely flagged.

PHANTOMxTRAINER June 28, 2013 03:00:22 PM

Quote:

Originally Posted by Twiggy (Post 281600)
And just as we get to the news of Smogon back up, Bulbagarden got hacked.

I was wondering why Bulbagarden was going to get hacked.. Yeah I expected it, they're one of the major ones as well.

Cat333Pokémon June 28, 2013 03:54:15 PM

I'm going to perform another security audit to make sure we're good to go.

By the way, I've gotten some more details about a certain other forum getting hacked. Apparently, they allowed their moderators the permission to modify user details, including their passwords. A moderator was hacked, and that account was used to modify an administrator's password. That administrator account was used to upload a plugin to the admin panel, which returned the login details for the forum user on the MySQL database server, effectively giving them access to the entire forum database.

Another thing to note: all of these sites are running vBulletin, so the plugin is practically universal.

Magmaster12 June 28, 2013 04:11:06 PM

So it doesn't matter we're still using the older version?

Cat333Pokémon June 28, 2013 04:13:52 PM

Yeah, the version of the software we're using doesn't matter. The biggest problem is that many of the sites entrusted their moderators (if even not deliberately) with those powers. There's a reason I wiped a lot of Freeze's stuff after he left. I don't need more backdoors for hackers.

Magmaster12 June 28, 2013 04:16:52 PM

If KYA was still an admin it'd be hard to believe if he was faking or not.

Cat333Pokémon June 28, 2013 04:19:24 PM

KYA is still an admin on the server, and he's pretty serious about system security.

PHANTOMxTRAINER June 28, 2013 10:04:24 PM

Quote:

Originally Posted by Cat333Pokémon (Post 281614)
I'm going to perform another security audit to make sure we're good to go.

By the way, I've gotten some more details about a certain other forum getting hacked. Apparently, they allowed their moderators the permission to modify user details, including their passwords. A moderator was hacked, and that account was used to modify an administrator's password. That administrator account was used to upload a plugin to the admin panel, which returned the login details for the forum user on the MySQL database server, effectively giving them access to the entire forum database.

Another thing to note: all of these sites are running vBulletin, so the plugin is practically universal.

Was the forum you are talking about ***? Cause they got hacked the other day as well. Forum had some downtime, but its safe now. They just urge us to change our passwords and stuff.

Cat333Pokémon June 28, 2013 10:09:27 PM

Quote:

Originally Posted by PHANTOMxTRAINER (Post 281641)
Was the forum you are talking about ***? Cause they got hacked the other day as well. Forum had some downtime, but its safe now. They just urge us to change our passwords and stuff.

Yes, I found information about how they were hacked mirrored on another news site, and the fact that they got hacked means that we could very easily be on the list of targets.

Twiggy June 28, 2013 10:23:47 PM

If *** can get hacked, I wonder about personal sites that are Pokémon themed or belonging to people with a notable presence in the Pokémon fandom.

Cat333Pokémon June 29, 2013 09:18:12 AM

I think the most likely candidates are those who know very little about security--typically those with a fairly new site and no record of previous webmaster work--and follow poorly-written guides for setting things up that include stuff like:
Code:

GRANT ALL PRIVILEGES ON *.* TO 'forumuser'@'%'
    IDENTIFIED BY 'password' WITH GRANT OPTION

Too many privileges, and too weak of a password. (You should never run that MySQL query on your own server unless you want to be hacked. It allows forumuser to access all databases and do anything they want to them, and the account has a very weak password to boot.)

Of course, that's a moot point because what happened with these other sites is (as I mentioned above) making their way through a small loophole to obtain the forum database password, which is absolutely required to have permissions to run SELECT (read information), INSERT (add information), UPDATE (change information), and DELETE (remove information) queries on the forum database.

PHANTOMxTRAINER June 29, 2013 12:07:32 PM

He/she hasn't updated the twitter page in over a day, so I'm assuming the terror is pretty much over. However, I wouldn't let my guard down. Well it seems Cat knows what he is doing so I feel safe here :)

Mistral June 29, 2013 04:25:30 PM

Yeah, I'm a member on ***, & I started to change my passwords when the hacking stuff started to happen. I'm going back & changing everything again since BMGf got hit.

The recommendation I've heard is to change all passwords associated with your email address on forums. I'm doing it 'cause I'd rather be safe than sorry.

Cat333Pokémon June 29, 2013 08:35:55 PM

I try to use one of my crappy passwords on sites I don't really care about. :P

hinorashi June 30, 2013 06:41:58 AM

Quote:

"hacking"
:giopalm:

I'm guessing some one who held common moderator positions on all of these sites was not very good with their password.

kakashidragon July 2, 2013 12:15:39 AM

My brothers PSN account got hacked the other day when this happened, i wounder if its the same guy.I called Playstation to help fix this and they did good thing to, the guy was playing on my brothers account. PSN=Playstation Network

Absol July 2, 2013 07:22:45 AM

:ibf: :ibf2: :ibf3:

Good to see Cat Triple Three has security and backups in place. It's nice to know we are at least not caught unprepared for this kinda thing. I don't use the other Pokemon websites unless I'm looking for Lopunny and Absol in a game, but other than that I just come here when I get a Pokemon itch.
I digress.
I know some users here are underage, so I'll reiterate: Guys, never give out your passwords. Oftentimes when someone says hacked in a website or game or something, it usually means they gave away the email cause they wanted free premium content, or a mysterious user that typew in disjointed Engrish wants to give YOU super secret admin powers for seemingly no reason at all. Be on the look out guys.

PHANTOMxTRAINER July 3, 2013 03:28:23 AM

Quote:

Originally Posted by kakashidragon (Post 281820)
My brothers PSN account got hacked the other day when this happened, i wounder if its the same guy.I called Playstation to help fix this and they did good thing to, the guy was playing on my brothers account. PSN=Playstation Network

I don't think your brother's PSN account has any connection to this problem.

Wolfbane5001 July 8, 2013 07:21:36 AM

Of all fandoms to be attacked... why Pokémon? There are far worse.... of which I shall not name as to not offend >.>

PHANTOMxTRAINER July 8, 2013 06:51:46 PM

Quote:

Originally Posted by Wolfbane5001 (Post 282235)
Of all fandoms to be attacked... why Pokémon? There are far worse.... of which I shall not name as to not offend >.>

I think the reason for this is because the common moderators/members that were hacked are from Pokemon forums. I don't think Rootinabox targeted Pokemon because it's bad. She just saw a link between accounts on those websites.

Aquablast July 9, 2013 04:55:26 AM

Smogon is back now, yay!

Maogi July 9, 2013 07:43:47 AM

What i wonder is: Why the heck would someone hack a Pokémon site? Rage? Because i don't think you would really win something outta this. :P

Wolfbane5001 July 9, 2013 02:41:33 PM

Quote:

Originally Posted by Maogi (Post 282325)
What i wonder is: Why the heck would someone hack a Pokémon site? Rage? Because i don't think you would really win something outta this. :P

Maybe the hacker is a brony trying to make MLP the top fandom! D:

(I don't hate bronies, I just like to joke at them a lot)


All times are GMT -8.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
Victory Road ©2006 - 2024, Scott Cat333Pokémon Cheney