WARNING: QB sites hijacked! forums under attack!

General discussion for topics related to the FreeBASIC project or its community.
Post Reply
angros47
Posts: 2323
Joined: Jun 21, 2005 19:04

WARNING: QB sites hijacked! forums under attack!

Post by angros47 »

http://forum.qbasicnews.com/index.php?P ... ic=13264.0

http://qbasicstation.com/index.php?c=f_ ... ageid=3938

http://www.petesqbsite.com/forum/viewtopic.php?t=2779

The historical QB forum on Network54 has been hacked: yesterday all post have been deleted (although now they've been restored) and forum name has been changed to Zip's forum.

Zip has also attacked qbasicstation, and maybe petesqbsite.

Please, if you have an account on a QB forum, change your password (and don't use the same password here).
notthecheatr
Posts: 1759
Joined: May 23, 2007 21:52
Location: Cut Bank, MT
Contact:

Post by notthecheatr »

Wow. That has to be one of the saddest things I've ever read. Hope Zip gets his just desserts.
cha0s
Site Admin
Posts: 5319
Joined: May 27, 2005 6:42
Location: USA
Contact:

Post by cha0s »

I just want to point out that if the site was run by anyone with a misdge of security knowledge, the passwords will be virtually uncrackable. A one-way hash is generally used (usually with salt which raises the possibility of brute-forcing it to almost nil), so they can't simply be reversed into plaintext.
vdecampo
Posts: 2992
Joined: Aug 07, 2007 23:20
Location: Maryland, USA
Contact:

Post by vdecampo »

cha0s wrote:I just want to point out that if the site was run by anyone with a misdge of security knowledge, the passwords will be virtually uncrackable. A one-way hash is generally used (usually with salt which raises the possibility of brute-forcing it to almost nil), so they can't simply be reversed into plaintext.
That would still not legitimize hacking a site.

-Vince
Hexadecimal Dude!
Posts: 360
Joined: Jun 07, 2005 20:59
Location: england, somewhere around the middle
Contact:

Post by Hexadecimal Dude! »

I don't think cha0s' point was that that made it legitimate to crack the site, just that visitors to most other sites shouldn't be too worried of encountering the same problems.
notthecheatr
Posts: 1759
Joined: May 23, 2007 21:52
Location: Cut Bank, MT
Contact:

Post by notthecheatr »

Right. The point is that people's passwords are safe, even if their accounts aren't. So he can steal their accounts and post stuff as if it's from them, but he can't figure out what their passwords are to use them (in case they use the same password elsewhere... not that that's a particularly wise idea, but most of us are too lazy to think up new passwords for everything).
rolliebollocks
Posts: 2655
Joined: Aug 28, 2008 10:54
Location: new york

Post by rolliebollocks »

Odd world.

Somebody with a repressed hatred of QuickBasic, go figure.
Post Reply