So.. Has Anandtech Been Hacked?

Page 4 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

aigomorla

CPU, Cases&Cooling Mod PC Gaming Mod Elite Member
Super Moderator
Sep 28, 2005
20,882
3,230
126
Supporting piracy to pay for the forums... way to go AT!

LOL i hear its a VB exploit.

They found it, and i think there snuffing it out.

What im waiting for is how some of our admins are gonna lay down a cap of whoop ass on.

Harvey for one is not someone i would like to mess around with on the interweb.
 

Sea Moose

Diamond Member
May 12, 2009
6,936
7
76
all i know is the ForumsAdmin account was taken over by an unauthorized person about 10:30 pm central time last night
Perknose has disabled or otherwise neutered that account as of a couple hours ago

'they' (senior moderators/forum directors) are still figuring it all out and haven't told us lesser moderators much about what is going on

Hold your head up there big guy, in our eyes you arent a "lesser" moderator.

Cheers for letting us know some details



oh, and Fobot.


Chin up son.
 

Train

Lifer
Jun 22, 2000
13,863
68
91
www.bing.com
What im waiting for is how some of our admins are gonna lay down a cap of whoop ass on.

Harvey for one is not someone i would like to mess around with on the interweb.

oooh

What are they gonna do? Send a strongly worded email to a nigerian email account?
 

Number1

Diamond Member
Feb 24, 2006
7,881
549
126
at any rate, people should've know better than to use the same password twice for anything. (remember when 4chan "hacked" facebook by just using a password list from another site?)

if you want something easy to remember, try this. for example, my favorite food is ..let's say corndog, add a number, say... my favorite year... 76

at www.gmail.com my password would be gcorndog76l
at anandtech my password would be acorndog76h
at amazon my passowrd would be acorndog76n
etc easy

I use Keypass and as long as I dont forget the main pasword I am OK. Here is what my AT pasword might look like: eTQVC3hFGzVWK02NiuKN
I never use the same password twice.
 

Kalmah

Diamond Member
Oct 2, 2003
3,692
1
76
It's funny that all of these hacker spoof threads have been going on during the time AT get's hacked. (whats your mothers maiden name, highschool, social security number.. etc)

Is there a connection?
 

Drakkon

Diamond Member
Aug 14, 2001
8,401
1
0
Folks, and folkettes (both of you) we were the victims of a serious forum breach early this morning, possibly from aliens, we're not sure.
Our field hospitals are littered with the horribly wounded and the merely annoyed, their blood curdling complaints chilling us all.
We will fight on the beaches, and in the hills and sub-forums, so that our valor or at least our sheer stubbornness will be long cherished and dearly remembered.
For as long as the English language is misused men will say, "This was their finest hour ... sort of."​
Its nice to know when there is a "serious forum breach" the admins take the time to seriously inform us of what happened
 

Kev

Lifer
Dec 17, 2001
16,367
4
81
Posting in this thread, hoping for an explanation of what happened.

Oh and I agree with the poster in this thread who thought the "funny" forum notices are just lame now. When it's a new one every 3 days they cease to be funny.
 

Kadarin

Lifer
Nov 23, 2001
44,303
15
81
Agreed, please stop with the cutesy notices and just tell us in straightforward fashion.
 

rockyct

Diamond Member
Jun 23, 2001
6,656
32
91
Posting in this thread, hoping for an explanation of what happened.

Oh and I agree with the poster in this thread who thought the "funny" forum notices are just lame now. When it's a new one every 3 days they cease to be funny.

I like the funny notices, but I wish they were accompanied by a real explanation of what's going on. AT has a history of lack of transparency issues.
 

lxskllr

No Lifer
Nov 30, 2004
57,686
7,912
126
I like the funny notices, but I wish they were accompanied by a real explanation of what's going on. AT has a history of lack of transparency issues.

I imagine they didn't(still don't?) know exactly how it happened. Assuming that, a basic understanding of English(this is an English based forum) will tell you what's up, and what they know. For the slow amongst us, I'll help out. This time the service is free, next time I'll require Paypal donations ;^)...

Hi lxskllr, This is me, your name will be here

Folks, and folkettes (both of you) we were the victims of a serious forum breach early this morning, possibly from aliens, we're not sure. We got haxxored/somebody did naughty things with resources they weren't authorized to use

Our field hospitals are littered with the horribly wounded and the merely annoyed, their blood curdling complaints chilling us all. It's a pain in the ass, but we have a bunch of people working on it

We will fight on the beaches, and in the hills and sub-forums, so that our valor or at least our sheer stubbornness will be long cherished and dearly remembered. we'll keep at until we find out how it happened, and it will be fixed

For as long as the English language is misused men will say, "This was their finest hour ... sort of." Most of you ingrates will appreciate the work once everything's working securely and smoothly

See? It really isn't that difficult
 

SunnyD

Belgian Waffler
Jan 2, 2001
32,674
145
106
www.neftastic.com
Encrypted, yes. One way hashed, no. Brute force at that point, especially if the hashing is something better than, say, md5.

There's nothing to brute force. If you pull a hashed pw out of the database, you use the hash to log in with. The boards themselves should never even see a clear text pw when logging in.
 

Platypus

Lifer
Apr 26, 2001
31,053
321
136
I imagine they didn't(still don't?) know exactly how it happened. Assuming that, a basic understanding of English(this is an English based forum) will tell you what's up, and what they know. For the slow amongst us, I'll help out. This time the service is free, next time I'll require Paypal donations ;^)...

Hi lxskllr, This is me, your name will be here

Folks, and folkettes (both of you) we were the victims of a serious forum breach early this morning, possibly from aliens, we're not sure. We got haxxored/somebody did naughty things with resources they weren't authorized to use

Our field hospitals are littered with the horribly wounded and the merely annoyed, their blood curdling complaints chilling us all. It's a pain in the ass, but we have a bunch of people working on it

We will fight on the beaches, and in the hills and sub-forums, so that our valor or at least our sheer stubbornness will be long cherished and dearly remembered. we'll keep at until we find out how it happened, and it will be fixed

For as long as the English language is misused men will say, "This was their finest hour ... sort of." Most of you ingrates will appreciate the work once everything's working securely and smoothly

See? It really isn't that difficult

I'd sure love some of that kool-aid you've been drinking.
 

CRXican

Diamond Member
Jun 9, 2004
9,062
1
0
I don't think I got an email from them but I changed my email password anyway.

Didn't change my AT password though
 

l0cke

Diamond Member
Dec 12, 2005
3,790
0
0
Good thing I never changed my password from whatever it was when I switched my account.
 

Crusty

Lifer
Sep 30, 2001
12,684
2
81
There's nothing to brute force. If you pull a hashed pw out of the database, you use the hash to log in with. The boards themselves should never even see a clear text pw when logging in.

Wrong. How does that data get hashed without being on the webserver? You can not rely on javascript to do any user side processing.
 

thepd7

Diamond Member
Jan 2, 2005
9,429
0
0
to be fair, I watched a whole season of big bang theory on that website last night and it was great quality. So if anything I might have found something useful
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |