GOMTV.net compromised - Page 16
| Forum Index > SC2 General |
|
Roggay
Switzerland6320 Posts
| ||
|
Kentor
United States5784 Posts
On August 13 2011 05:56 Integra wrote: R1CH, from what I can deduct they simply used a SQL Injection to list all the data, if it's that simple then why does it matter if we change the password, they will still get it, you could change it a million times. Change it to something that you don't use anywhere else. | ||
|
Integra
Sweden5626 Posts
| ||
|
ravemir
Portugal595 Posts
On August 13 2011 05:41 R1CH wrote: Most systems store the algorithm and settings with the password hash and salt. For example, if your password hash is $2a$10$WyJ.NSYEmLixexXspQyoEOVYGK55cDjQd2cZedBN4t9.., the 2a identifies the algorithm (blowfish) and the 10 identifies the iterations (2^10). So if suddenly PCs become 100x faster I can just increase the 10 in our config and all new passwords become more secure, and old passwords are upgraded on successful logon. Good point! The password will have matching smaller value until a valid login after you make the system wide change. | ||
|
Integra
Sweden5626 Posts
On August 13 2011 06:06 Kentor wrote: Change it to something that you don't use anywhere else. IF people used the same password that they used on GOM they better dammn be changing those passwords on all the other sites as well. I mean you don't know what kind of databasetype that is being used, what if the hacker thinks up the bright idea to rollback the Server image to revert the changes of the password you did, then he will get the passwords anyway. | ||
|
Penecks
United States600 Posts
| ||
|
TaKemE
Denmark1045 Posts
| ||
|
Jibba
United States22883 Posts
On August 13 2011 06:08 Integra wrote: what, they used plain text to store the password....... WTF, encryption is a build in feature in PHP and there existst thousands of professionally made salt functions out there. WHY are people so dammn retarded when it comes to security! After this kind of stupidity, I just stop purchasing/supporting people. ;o Same goes for Sony. | ||
|
Integra
Sweden5626 Posts
On August 13 2011 06:21 TaKemE wrote: I dont know anything about this but is the only proof of this happening that one screenshot? couldnt someone who knows about that stuff easy make a "fake" screenshot? It's been verified. | ||
|
forgottendreams
United States1771 Posts
| ||
|
thee telescopes
321 Posts
On August 13 2011 06:25 forgottendreams wrote: There's still no email notification or news on GOMTV.net yet....I feel sorry for all the people who don't know because they don't frequent TeamLiquid.net or PlayXP. This is really irresponsible. ![]() | ||
|
pog0
United States30 Posts
| ||
|
tuho12345
4482 Posts
| ||
|
RogueStatus
266 Posts
On August 13 2011 06:29 tuho12345 wrote: what about my facebook account? I use that to sign in Facebook is going down by the 5th of November anyways. lol | ||
|
sixfour
England11061 Posts
| ||
|
L3g3nd_
New Zealand10461 Posts
| ||
|
grobo
Japan6199 Posts
Forget about me paying a single cent to you in the future | ||
|
betaV1.25
425 Posts
-plain text pswrds -no communication -no taking down and fixing the site At the very least dissapointing | ||
|
Infenwe
Denmark170 Posts
Bye, GOM. Now off to fix stuff... | ||
|
MicroTastiC
375 Posts
| ||
| ||
