• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EST 17:59
CET 23:59
KST 07:59
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
RSL Season 3 - RO16 Groups C & D Preview0RSL Season 3 - RO16 Groups A & B Preview2TL.net Map Contest #21: Winners12Intel X Team Liquid Seoul event: Showmatches and Meet the Pros10[ASL20] Finals Preview: Arrival13
Community News
Weekly Cups (Nov 10-16): Reynor, Solar lead Zerg surge1[TLMC] Fall/Winter 2025 Ladder Map Rotation13Weekly Cups (Nov 3-9): Clem Conquers in Canada4SC: Evo Complete - Ranked Ladder OPEN ALPHA8StarCraft, SC2, HotS, WC3, Returning to Blizzcon!45
StarCraft 2
General
RotterdaM "Serral is the GOAT, and it's not close" Weekly Cups (Nov 10-16): Reynor, Solar lead Zerg surge [TLMC] Fall/Winter 2025 Ladder Map Rotation Mech is the composition that needs teleportation t RSL Season 3 - RO16 Groups C & D Preview
Tourneys
2025 RSL Offline Finals Dates + Ticket Sales! $5,000+ WardiTV 2025 Championship RSL Revival: Season 3 Sparkling Tuna Cup - Weekly Open Tournament Constellation Cup - Main Event - Stellar Fest
Strategy
Custom Maps
Map Editor closed ?
External Content
Mutation # 500 Fright night Mutation # 499 Chilling Adaptation Mutation # 498 Wheel of Misfortune|Cradle of Death Mutation # 497 Battle Haredened
Brood War
General
FlaSh on: Biggest Problem With SnOw's Playstyle What happened to TvZ on Retro? BGH Auto Balance -> http://bghmmr.eu/ SnOw's ASL S20 Finals Review BW General Discussion
Tourneys
[BSL21] GosuLeague T1 Ro16 - Tue & Thu 22:00 CET [Megathread] Daily Proleagues Small VOD Thread 2.0 [BSL21] RO32 Group D - Sunday 21:00 CET
Strategy
Current Meta How to stay on top of macro? PvZ map balance Simple Questions, Simple Answers
Other Games
General Games
Clair Obscur - Expedition 33 Stormgate/Frost Giant Megathread Should offensive tower rushing be viable in RTS games? Path of Exile Nintendo Switch Thread
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread SPIRED by.ASL Mafia {211640}
Community
General
Russo-Ukrainian War Thread US Politics Mega-thread The Games Industry And ATVI Things Aren’t Peaceful in Palestine About SC2SEA.COM
Fan Clubs
White-Ra Fan Club The herO Fan Club!
Media & Entertainment
Movie Discussion! [Manga] One Piece Anime Discussion Thread Korean Music Discussion Series you have seen recently...
Sports
2024 - 2026 Football Thread Formula 1 Discussion NBA General Discussion MLB/Baseball 2023 TeamLiquid Health and Fitness Initiative For 2023
World Cup 2022
Tech Support
SC2 Client Relocalization [Change SC2 Language] Linksys AE2500 USB WIFI keeps disconnecting Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List
Blogs
Dyadica Gospel – a Pulp No…
Hildegard
Coffee x Performance in Espo…
TrAiDoS
Saturation point
Uldridge
DnB/metal remix FFO Mick Go…
ImbaTosS
Reality "theory" prov…
perfectspheres
Customize Sidebar...

Website Feedback

Closed Threads



Active: 2067 users

GOMTV.net compromised - Page 15

Forum Index > SC2 General
Post a Reply
Prev 1 13 14 15 16 17 44 Next All
Voltaire
Profile Joined September 2010
United States1485 Posts
Last Edited: 2011-08-12 20:50:41
August 12 2011 20:50 GMT
#281
Yikes. I hope there won't be a repeat occurrence.
As long as people believe in absurdities they will continue to commit atrocities.
nonsence
Profile Joined July 2010
United States57 Posts
August 12 2011 20:51 GMT
#282
On August 13 2011 05:17 R1CH wrote:
Show nested quote +
On August 13 2011 05:15 ravemir wrote:
On August 13 2011 04:57 R1CH wrote:
On August 13 2011 04:55 Glowbox wrote:
Ideally you want to use something like bcrypt: http://codahale.com/how-to-safely-store-a-password/

For those curious, this is how TL passwords are stored.

Really? Isn't that supposedly too expensive on the login operation?

Not if you balance the iterations properly. A few hundred ms extra on the login isn't noticeable by most people and is plenty enough to defeat brute force attacks.


COOL, i hadn't heard of bcrypt, I just finished integrating a java version into my software Thanks TL
OMG Bear is driving! How is that possible?
DiamondTear
Profile Joined June 2010
Finland165 Posts
August 12 2011 20:51 GMT
#283
Changed GOM password, got not confirmation email (hotmail), can't log in.
slicknav
Profile Joined January 2011
1409 Posts
August 12 2011 20:51 GMT
#284
this should really be put on the front page of TL somewhere. This is kinda serious if personal information has been compromised.
blah blah blah...
Multis
Profile Joined May 2010
Finland21 Posts
August 12 2011 20:52 GMT
#285
Thanks for the heads up!
EndOfTime88
Profile Joined February 2011
Austria259 Posts
August 12 2011 20:53 GMT
#286
On August 13 2011 05:51 DiamondTear wrote:
Changed GOM password, got not confirmation email (hotmail), can't log in.


I'm having the same problem right now.
"Time is what we want most,but what we use worst."-William Penn
FallDownMarigold
Profile Blog Joined December 2010
United States3710 Posts
August 12 2011 20:53 GMT
#287
On August 13 2011 05:39 vyyye wrote:
Show nested quote +
On August 13 2011 05:38 FallDownMarigold wrote:
I use my real full name as my login, and social security number + credit card number as my password.


And I thought Login : Password was the dumbest login/pass combo, holy shit.


It's all good now, I just changed my account name to my home address and my password to my bank routing number.
thee telescopes
Profile Joined August 2010
321 Posts
August 12 2011 20:54 GMT
#288
On August 13 2011 05:51 slicknav wrote:
this should really be put on the front page of TL somewhere. This is kinda serious if personal information has been compromised.


Kinda annoying that there's nothing on Gom's site about this.
nooboon
Profile Blog Joined July 2011
2602 Posts
August 12 2011 20:54 GMT
#289
I don't know whats more surprising, GomTV getting hacked, or that R1CH found out who had been hack by himself.
CardG
Profile Joined March 2011
France131 Posts
August 12 2011 20:55 GMT
#290
On August 13 2011 05:53 EndOfTime88 wrote:
Show nested quote +
On August 13 2011 05:51 DiamondTear wrote:
Changed GOM password, got not confirmation email (hotmail), can't log in.


I'm having the same problem right now.

Same.
Badboyrune
Profile Blog Joined May 2010
Sweden2247 Posts
Last Edited: 2011-08-12 20:56:53
August 12 2011 20:55 GMT
#291
On August 13 2011 05:41 R1CH wrote:
Show nested quote +
On August 13 2011 05:26 ravemir wrote:
But tell me this, if you want to adjust the iterations, won't you have to re-calculate every password for each user?

Most systems store the algorithm and settings with the password hash and salt. For example, if your password hash is $2a$10$WyJ.NSYEmLixexXspQyoEOVYGK55cDjQd2cZedBN4t9.., the 2a identifies the algorithm (blowfish) and the 10 identifies the iterations (2^10). So if suddenly PCs become 100x faster I can just increase the 10 in our config and all new passwords become more secure, and old passwords are upgraded on successful logon.


I think this is the point where Hot_Bid posts:

I don’t understand the check_password function, why don’t you compare with the
stored hash in the BBDD? Something like this:
function check_password(password, nickname) {
//get user from nickname user = User.objects.get(nickname=nickname)
return user.hash_stored == hash(password)
Btw in your function check_password I suppose that in order to calculate again the
hash I’d have to do it with the cost parameter, something like this:
// this will be used to compare a password against a hash
public static function check_password($hash, $password) {
$new_hash = hash($password);
return ($hash == $new_hash);
"If yellow does start SC2, I should start handsomenerd diaper busniess and become a rich man" - John the Translator
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
August 12 2011 20:56 GMT
#292
On August 13 2011 03:14 R1CH wrote:
There's a post on reddit that suggests that GOMTV has been compromised. I have independently verified that at least some usernames, passwords and email addresses have been compromised.

There appears to be zero security on the passwords as they were stored in plain text (really GOM?). This means if you use your GomTV password anywhere else, you should change it and consider it compromised. To clarify, your GomTV.net username, email address, PayPal real name and your GomTV.net password are likely compromised. Personal information such as your address may be compromised too if it was stored. You should also change your GomTV password to prevent unauthorized account access, although the exploit through which the information was compromised may still exist.

Since payments are processed through PayPal, there is no risk of your financial information being compromised, unless you used your PayPal password when signing up for GomTV (don't do this). Users who logged in via SNS should be safe as Twitter / Facebook authentication is token based, not password based.

If you aren't already, you should really use unique passwords for each website since this happens more often than you think (ever hear someone say they were "hacked"? this is likely how it happens) and not all websites will disclose if they get compromised. Use http://keepass.info/ for password management.

R1CH, from what I can deduct they simply used a SQL Injection to list all the data, if it's that simple then why does it matter if we change the password, they will still get it, you could change it a million times.
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
Eleaven
Profile Joined September 2010
772 Posts
August 12 2011 20:57 GMT
#293
man i was seriously worried till you get to the facebook part.. phew
SilentShout
Profile Joined March 2011
686 Posts
August 12 2011 20:57 GMT
#294
Just got done changing a lot of my passwords... Just in case. My fault for using the same pass for so many sites, but better to be safe than sorry. Or so they say
Toons
Profile Joined November 2010
Australia136 Posts
August 12 2011 20:57 GMT
#295
^ Read further down, he says this ...

Change your pass to something completely obscure until they figure it out
Probes and pylons
strexer
Profile Blog Joined September 2010
United States54 Posts
August 12 2011 20:59 GMT
#296
You have to be kidding me, of course the only place I use my email password is GOMTV, I hope I'm not too late.
TOCHMY
Profile Blog Joined June 2010
Sweden1692 Posts
August 12 2011 20:59 GMT
#297
fuck hackers ffs i cant keep track on all my passwords ( some dipshit tried to login to my facebook from japan.
Yoona <3 ¯\_(ツ)_/¯ Look! It's Totoro! ☉.☉☂
ma70
Profile Joined October 2010
253 Posts
August 12 2011 21:04 GMT
#298
Thank you for posting this. I immediately changed my GOMTV.net/Email/Paypal password to different things....
Soulish
Profile Joined April 2010
Canada1403 Posts
August 12 2011 21:05 GMT
#299
On August 13 2011 03:18 radim wrote:
Show nested quote +
On August 13 2011 03:14 R1CH wrote:
...the passwords as they were stored in plain text...

are you serious? oh my god :x

Being stored in plain text doesn't mean they arent encrypted
me all in, he drone drone drone, me win
nOondn
Profile Joined March 2011
564 Posts
August 12 2011 21:05 GMT
#300
OMG GOM .... so careless, they are not professional in business
Mid Master Terran @ kr server fighting !!!
Prev 1 13 14 15 16 17 44 Next All
Please log in or register to reply.
Live Events Refresh
Next event in 2m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
PiGStarcraft303
UpATreeSC 135
SteadfastSC 121
StarCraft: Brood War
Britney 12483
NaDa 25
yabsab 7
Other Games
Grubby5554
shahzam458
Maynarde309
C9.Mang069
ToD50
Trikslyr37
Organizations
Other Games
BasetradeTV44
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 22 non-featured ]
StarCraft 2
• kabyraGe 104
• Hupsaiya 30
• poizon28 21
• IndyKCrew
• sooper7s
• Migwel
• AfreecaTV YouTube
• LaughNgamezSOOP
• intothetv
• Kozan
StarCraft: Brood War
• blackmanpl 33
• Azhi_Dahaki20
• HerbMon 16
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• masondota2550
League of Legends
• Doublelift2198
Other Games
• imaqtpie1299
• WagamamaTV345
• Shiphtur262
• Scarra180
Upcoming Events
Replay Cast
2m
CranKy Ducklings8
ChoboTeamLeague
2h 2m
WardiTV Korean Royale
13h 2m
BSL: GosuLeague
22h 2m
PiGosaur Cup
1d 2h
The PondCast
1d 11h
Replay Cast
2 days
RSL Revival
2 days
herO vs Zoun
Classic vs Reynor
Maru vs SHIN
MaxPax vs TriGGeR
BSL: GosuLeague
2 days
RSL Revival
3 days
[ Show More ]
WardiTV Korean Royale
3 days
RSL Revival
4 days
WardiTV Korean Royale
4 days
IPSL
4 days
Julia vs Artosis
JDConan vs DragOn
RSL Revival
5 days
Wardi Open
5 days
IPSL
5 days
StRyKeR vs OldBoy
Sziky vs Tarson
Replay Cast
6 days
Liquipedia Results

Completed

Proleague 2025-11-14
Stellar Fest: Constellation Cup
Eternal Conflict S1

Ongoing

C-Race Season 1
IPSL Winter 2025-26
KCM Race Survival 2025 Season 4
SOOP Univ League 2025
YSL S2
BSL Season 21
CSCL: Masked Kings S3
SLON Tour Season 2
RSL Revival: Season 3
META Madness #9
BLAST Rivals Fall 2025
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
CS Asia Championships 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025

Upcoming

BSL 21 Non-Korean Championship
Acropolis #4
IPSL Spring 2026
HSC XXVIII
RSL Offline Finals
WardiTV 2025
IEM Kraków 2026
BLAST Bounty Winter 2026
BLAST Bounty Winter 2026: Closed Qualifier
eXTREMESLAND 2025
ESL Impact League Season 8
SL Budapest Major 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.