So.. Has Anandtech Been Hacked?

Page 5 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Crusty

Lifer
Sep 30, 2001
12,684
2
81
Wow. Alrighty then.

You are right about the MD5 being done client side, and that's absolutely retarded.

You do realize that is NOT the standard way of doing authentication right?

If you want to secure your data in transmission you use SSL, not hashing data using client side code.

edit: disabling javascript still lets you login and you pass your password in plaintext.

vb_login_username=crusty&vb_login_password=##########&s=&securitytoken=guest&do=login&vb_login_md5password=&vb_login_md5password_utf=

instead of

vb_login_username=crusty&vb_login_password=&s=&securitytoken=guest&do=login&vb_login_md5password=#####################################&vb_login_md5password_utf=


Honestly, neither one is good for one reason or the other. If SSL was being used we wouldn't even be having this discussion as there would be absolutely no reason to hash passwords client side.
 
Last edited:

yllus

Elite Member & Lifer
Aug 20, 2000
20,577
432
126
Wrong. How does that data get hashed without being on the webserver? You can not rely on javascript to do any user side processing.

Actually he's right, if this install of vBulletin is a typical one.

If we accept that our accounts here aren't important enough to use SSL when the password information is passed from our computers to the forum server, the vBulletin method is, when you hit submit after filling out your username and password in the login form what actually happens is a JavaScript call to hash your password with MD5 and submit that, not your password. In this way you add a little bit more security in that your password is never transmitted in the clear (except when it's submitted the first time).

I should add that all of our passwords should be quite safe. Our e-mail addresses may not be so lucky.
 

Crusty

Lifer
Sep 30, 2001
12,684
2
81
Actually he's right, if this install of vBulletin is a typical one.

If we accept that our accounts here aren't important enough to use SSL when the password information is passed from our computers to the forum server, the vBulletin method is, when you hit submit after filling out your username and password in the login form what actually happens is a JavaScript call to hash your password with MD5 and submit that, not your password. In this way you add a little bit more security in that your password is never transmitted in the clear (except when it's submitted the first time).

I should add that all of our passwords should be quite safe. Our e-mail addresses may not be so lucky.

Read my post above, clarified some things and it looks like we both agree that the real solution is to use SSL. I was completely surprised to see javascript hashing my password as the only added benefit to having the hash done client side would be that if someone were to get a hold of it they could only use it to login to this site only.

However that's kind of a moot point IMO as if someone is in a position where they are capturing my network traffic my AT forum's password is the least of my worries. I'd be more concerned with MITM attacks against my banking sites.
 

Terabyte

Diamond Member
Dec 19, 1999
3,876
0
71
Has anyone else been getting spam emails about a Citi Sears credit card? I've been getting them recently :twisted:
 

BuckMaster

Diamond Member
Oct 9, 1999
3,260
0
0
So much for my only account that didnt get spam e-mails everyday till today! . Thanks Anandtech!
 

lxskllr

No Lifer
Nov 30, 2004
57,662
7,894
126
You have quite the imagination. Do you mind interpreting one more time for the answer in this thread about the broken search engine: http://forums.anandtech.com/showthread.php?t=2029178 which only leads to a thread about more people bitching about the broken search engine?

That was a mostly non-informative answer, but Gillbot was pointing out other people with the same problem which would indicate that it isn't immediately fixable, and there's nothing wrong with cesthree's setup :^)
 

Triumph

Lifer
Oct 9, 1999
15,031
13
81
I noticed something odd about the way that the email from the forum admins was worded. It reminded me of the mannerisms of a certain regular poster here. Here is the text of the email I received:

Draglift.com

Is a site that lets you Watch Movies and TV Shows online for Free.

No clutterness, no lag,

Watch over 27 movies,

and lots of TV Shows.

Notice any similarities between that writing and style and that, of our very own.....Sandorski!?!?!

http://forums.anandtech.com/showthread.php?t=312128

Go out and do that Job and Live there without Air Con then. Don't come mumbling to me when you get Heat Stroke.

They are not performing cushy Office Jobs all day, but spending most of their time out in the sun. They probably use those Homes for recouping during breaks even(possibly). Plus they are for whole families, likely far from any facility with AirCon, Rivers or Bodies of water, and other opportunities to cool down.

Much of California's Agricultural areas are Desert or near Desert. People didn't perform those Activities in those locations for 250, 000 years. It is not a Luxury, it is a necessity.
 

Gillbot

Lifer
Jan 11, 2001
28,830
17
81
That was a mostly non-informative answer, but Gillbot was pointing out other people with the same problem which would indicate that it isn't immediately fixable, and there's nothing wrong with cesthree's setup :^)

in the manually populated FS/FT field, you can manually enter the REMOVE portion as it's a simple text field. See my profile for an example.

Your profile email however doesn't seem to be as safe as my account was compromised. Sadly, I was NOT smart enough to use a different password until now. Lesson learned I guess. Luckily, here and that email were the only shared ones that really matter to me.
 

guyver01

Lifer
Sep 25, 2000
22,151
5
61
I noticed something odd about the way that the email from the forum admins was worded. It reminded me of the mannerisms of a certain regular poster here. Here is the text of the email I received:



Notice any similarities between that writing and style and that, of our very own.....Sandorski!?!?!

So.. you're saying either one of the following:
(1) Sandorski hacked Anandtech
(2) Sandorski writes like a chinese gold farmer (WoW reference)


i'm gonna vote... #2
 

Fear No Evil

Diamond Member
Nov 14, 2008
5,922
0
0
It does seem pretty unprofessional at the top of the forum like that. Keep the wit to the posts themselves..
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |