• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 17:25
CEST 23:25
KST 06:25
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
[ASL21] Ro24 Preview Pt2: News Flash10[ASL21] Ro24 Preview Pt1: New Chaos0Team Liquid Map Contest #22 - Presented by Monster Energy19ByuL: The Forgotten Master of ZvT30Behind the Blue - Team Liquid History Book20
Community News
$5,000 WardiTV TLMC tournament - Presented by Monster Energy3GSL CK: More events planned pending crowdfunding6Weekly Cups (May 30-Apr 5): herO, Clem, SHIN win0[BSL22] RO32 Group Stage5Weekly Cups (March 23-29): herO takes triple6
StarCraft 2
General
JD's Ro24 review Team Liquid Map Contest #22 - Presented by Monster Energy Quebec Clan still alive ? BGE Stara Zagora 2026 cancelled Blizzard Classic Cup @ BlizzCon 2026 - $100k prize pool
Tourneys
$5,000 WardiTV TLMC tournament - Presented by Monster Energy GSL CK: More events planned pending crowdfunding Sea Duckling Open (Global, Bronze-Diamond) Sparkling Tuna Cup - Weekly Open Tournament RSL Season 4 announced for March-April
Strategy
Custom Maps
[D]RTS in all its shapes and glory <3 [A] Nemrods 1/4 players [M] (2) Frigid Storage
External Content
The PondCast: SC2 News & Results Mutation # 520 Moving Fees Mutation # 519 Inner Power Mutation # 518 Radiation Zone
Brood War
General
JD's Ro24 review ASL21 General Discussion [BSL22] RO32 Group Stage BW General Discussion so ive been playing broodwar for a week straight.
Tourneys
[Megathread] Daily Proleagues Escore Tournament StarCraft Season 2 [ASL21] Ro24 Group F [BSL22] RO32 Group B - Sunday 21:00 CEST
Strategy
Fighting Spirit mining rates Muta micro map competition What's the deal with APM & what's its true value Simple Questions, Simple Answers
Other Games
General Games
Battle Aces/David Kim RTS Megathread Stormgate/Frost Giant Megathread General RTS Discussion Thread Starcraft Tabletop Miniature Game Nintendo Switch Thread
Dota 2
The Story of Wings Gaming Official 'what is Dota anymore' discussion
League of Legends
G2 just beat GenG in First stand
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
Vanilla Mini Mafia Mafia Game Mode Feedback/Ideas TL Mafia Community Thread Five o'clock TL Mafia
Community
General
US Politics Mega-thread Russo-Ukrainian War Thread The China Politics Thread European Politico-economics QA Mega-thread Trading/Investing Thread
Fan Clubs
The IdrA Fan Club
Media & Entertainment
[Manga] One Piece [Req][Books] Good Fantasy/SciFi books Movie Discussion!
Sports
2024 - 2026 Football Thread Formula 1 Discussion Cricket [SPORT] Tokyo Olympics 2021 Thread
World Cup 2022
Tech Support
[G] How to Block Livestream Ads
TL Community
The Automated Ban List
Blogs
How Streamers Inspire Gamers…
TrAiDoS
Broowar part 2
qwaykee
Funny Nicknames
LUCKY_NOOB
Iranian anarchists: organize…
XenOsky
ASL S21 English Commentary…
namkraft
StarCraft improvement
iopq
Electronics
mantequilla
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1735 users

GOMTV.net compromised - Page 16

Forum Index > SC2 General
Post a Reply
Prev 1 14 15 16 17 18 44 Next All
Roggay
Profile Joined April 2010
Switzerland6320 Posts
August 12 2011 21:06 GMT
#301
I use the same password for nearly everything EXCEPT my Bnet account, so I don't really care, the rest is not really important (I don't know what they would do with my other accounts).
Kentor *
Profile Blog Joined December 2007
United States5784 Posts
Last Edited: 2011-08-12 21:07:21
August 12 2011 21:06 GMT
#302
On August 13 2011 05:56 Integra wrote:
Show nested quote +
On August 13 2011 03:14 R1CH wrote:
There's a post on reddit that suggests that GOMTV has been compromised. I have independently verified that at least some usernames, passwords and email addresses have been compromised.

There appears to be zero security on the passwords as they were stored in plain text (really GOM?). This means if you use your GomTV password anywhere else, you should change it and consider it compromised. To clarify, your GomTV.net username, email address, PayPal real name and your GomTV.net password are likely compromised. Personal information such as your address may be compromised too if it was stored. You should also change your GomTV password to prevent unauthorized account access, although the exploit through which the information was compromised may still exist.

Since payments are processed through PayPal, there is no risk of your financial information being compromised, unless you used your PayPal password when signing up for GomTV (don't do this). Users who logged in via SNS should be safe as Twitter / Facebook authentication is token based, not password based.

If you aren't already, you should really use unique passwords for each website since this happens more often than you think (ever hear someone say they were "hacked"? this is likely how it happens) and not all websites will disclose if they get compromised. Use http://keepass.info/ for password management.

R1CH, from what I can deduct they simply used a SQL Injection to list all the data, if it's that simple then why does it matter if we change the password, they will still get it, you could change it a million times.

Change it to something that you don't use anywhere else.
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
August 12 2011 21:08 GMT
#303
what, they used plain text to store the password....... WTF, encryption is a build in feature in PHP and there existst thousands of professionally made salt functions out there. WHY are people so dammn retarded when it comes to security!
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
ravemir
Profile Joined April 2011
Portugal595 Posts
August 12 2011 21:10 GMT
#304
On August 13 2011 05:41 R1CH wrote:
Show nested quote +
On August 13 2011 05:26 ravemir wrote:
But tell me this, if you want to adjust the iterations, won't you have to re-calculate every password for each user?

Most systems store the algorithm and settings with the password hash and salt. For example, if your password hash is $2a$10$WyJ.NSYEmLixexXspQyoEOVYGK55cDjQd2cZedBN4t9.., the 2a identifies the algorithm (blowfish) and the 10 identifies the iterations (2^10). So if suddenly PCs become 100x faster I can just increase the 10 in our config and all new passwords become more secure, and old passwords are upgraded on successful logon.


Good point! The password will have matching smaller value until a valid login after you make the system wide change.
"more gg, more skill"
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
August 12 2011 21:11 GMT
#305
On August 13 2011 06:06 Kentor wrote:
Show nested quote +
On August 13 2011 05:56 Integra wrote:
On August 13 2011 03:14 R1CH wrote:
There's a post on reddit that suggests that GOMTV has been compromised. I have independently verified that at least some usernames, passwords and email addresses have been compromised.

There appears to be zero security on the passwords as they were stored in plain text (really GOM?). This means if you use your GomTV password anywhere else, you should change it and consider it compromised. To clarify, your GomTV.net username, email address, PayPal real name and your GomTV.net password are likely compromised. Personal information such as your address may be compromised too if it was stored. You should also change your GomTV password to prevent unauthorized account access, although the exploit through which the information was compromised may still exist.

Since payments are processed through PayPal, there is no risk of your financial information being compromised, unless you used your PayPal password when signing up for GomTV (don't do this). Users who logged in via SNS should be safe as Twitter / Facebook authentication is token based, not password based.

If you aren't already, you should really use unique passwords for each website since this happens more often than you think (ever hear someone say they were "hacked"? this is likely how it happens) and not all websites will disclose if they get compromised. Use http://keepass.info/ for password management.

R1CH, from what I can deduct they simply used a SQL Injection to list all the data, if it's that simple then why does it matter if we change the password, they will still get it, you could change it a million times.

Change it to something that you don't use anywhere else.


IF people used the same password that they used on GOM they better dammn be changing those passwords on all the other sites as well. I mean you don't know what kind of databasetype that is being used, what if the hacker thinks up the bright idea to rollback the Server image to revert the changes of the password you did, then he will get the passwords anyway.
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
Penecks
Profile Joined August 2010
United States600 Posts
August 12 2011 21:19 GMT
#306
Sooo is there any point changing the password you used on the GOM site or is there still shit happening that would cause that new password to be compromised?
straight poppin
TaKemE
Profile Joined April 2010
Denmark1045 Posts
August 12 2011 21:21 GMT
#307
I dont know anything about this but is the only proof of this happening that one screenshot? couldnt someone who knows about that stuff easy make a "fake" screenshot?
Jibba
Profile Blog Joined October 2007
United States22883 Posts
August 12 2011 21:22 GMT
#308
On August 13 2011 06:08 Integra wrote:
what, they used plain text to store the password....... WTF, encryption is a build in feature in PHP and there existst thousands of professionally made salt functions out there. WHY are people so dammn retarded when it comes to security!

After this kind of stupidity, I just stop purchasing/supporting people. ;o Same goes for Sony.
ModeratorNow I'm distant, dark in this anthrobeat
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
August 12 2011 21:23 GMT
#309
On August 13 2011 06:21 TaKemE wrote:
I dont know anything about this but is the only proof of this happening that one screenshot? couldnt someone who knows about that stuff easy make a "fake" screenshot?

It's been verified.
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
forgottendreams
Profile Joined August 2010
United States1771 Posts
August 12 2011 21:25 GMT
#310
There's still no email notification or news on GOMTV.net yet....I feel sorry for all the people who don't know because they don't frequent TeamLiquid.net or PlayXP.
thee telescopes
Profile Joined August 2010
321 Posts
August 12 2011 21:27 GMT
#311
On August 13 2011 06:25 forgottendreams wrote:
There's still no email notification or news on GOMTV.net yet....I feel sorry for all the people who don't know because they don't frequent TeamLiquid.net or PlayXP.


This is really irresponsible.
pog0
Profile Joined June 2010
United States30 Posts
August 12 2011 21:28 GMT
#312
Sucks as that is my password for many things but different accounts and variations. Le sigh.
tuho12345
Profile Blog Joined July 2011
4482 Posts
August 12 2011 21:29 GMT
#313
what about my facebook account? I use that to sign in
RogueStatus
Profile Joined August 2010
266 Posts
August 12 2011 21:33 GMT
#314
On August 13 2011 06:29 tuho12345 wrote:
what about my facebook account? I use that to sign in

Facebook is going down by the 5th of November anyways. lol
sixfour
Profile Blog Joined December 2009
England11061 Posts
August 12 2011 21:38 GMT
#315
wow, i'm sure glad i don't have a gomtv account
p: stats, horang2, free, jangbi z: soulkey, zero, shine, hydra t: leta, hiya, sea
L3g3nd_
Profile Joined July 2010
New Zealand10461 Posts
August 12 2011 21:41 GMT
#316
probably about time i change my pass words. good job gom, good job.
https://twitter.com/#!/IrisAnother
grobo
Profile Blog Joined February 2007
Japan6199 Posts
August 12 2011 21:41 GMT
#317
Thanks GOM, i appreciate you treating my information like shit.

Forget about me paying a single cent to you in the future
We make signature, then defense it.
betaV1.25
Profile Joined April 2010
425 Posts
August 12 2011 21:43 GMT
#318
Amateur night at gom.tv.

-plain text pswrds
-no communication
-no taking down and fixing the site

At the very least dissapointing
Infenwe
Profile Joined September 2009
Denmark170 Posts
Last Edited: 2011-08-12 21:50:54
August 12 2011 21:48 GMT
#319
Instantly deleted account over this. If they are so fucking incompetent that they store password in plaintext and they don't even have the common decency to communicate about it, then they're not to be trusted with anything any more.

Bye, GOM.

Now off to fix stuff...
close the world - txen eht nepo
MicroTastiC
Profile Joined January 2011
375 Posts
Last Edited: 2011-08-12 21:50:29
August 12 2011 21:50 GMT
#320
such a shame that GOMtv would spend more time preventing their content being leaked rather than securing their clients personal information as well!
Prev 1 14 15 16 17 18 44 Next All
Please log in or register to reply.
Live Events Refresh
BSL
19:00
RO32 Group A
n0maD vs perroflaco
TerrOr vs ZZZero
MadiNho vs WolFix
DragOn vs LancerX
ZZZero.O263
LiquipediaDiscussion
PSISTORM Gaming Misc
15:55
FSL s10 code A/B Championships
Liquipedia
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
Ketroc 76
CosmosSc2 62
StarCraft: Brood War
Britney 12848
Mini 468
Shuttle 367
ZZZero.O 263
910 24
Rock 24
NaDa 11
Dota 2
ROOTCatZ23
Counter-Strike
pashabiceps3158
Heroes of the Storm
Khaldor215
Other Games
gofns14502
summit1g10398
Grubby3502
FrodaN2050
crisheroes234
Liquid`Hasu187
Organizations
Other Games
gamesdonequick691
StarCraft 2
angryscii 27
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 19 non-featured ]
StarCraft 2
• musti20045 19
• Adnapsc2 17
• HeavenSC 4
• LaughNgamezSOOP
• sooper7s
• AfreecaTV YouTube
• intothetv
• Migwel
• Kozan
• IndyKCrew
StarCraft: Brood War
• 3DClanTV 32
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• WagamamaTV1669
• masondota21144
League of Legends
• Doublelift3677
Other Games
• Shiphtur279
• tFFMrPink 14
Upcoming Events
Sparkling Tuna Cup
12h 35m
WardiTV Team League
13h 35m
OSC
15h 35m
BSL
21h 35m
Sterling vs Azhi_Dahaki
Napoleon vs Mazur
Jimin vs Nesh
spx vs Strudel
IPSL
21h 35m
Artosis vs TBD
Napoleon vs TBD
Replay Cast
1d 11h
Wardi Open
1d 12h
Afreeca Starleague
1d 12h
Soma vs YSC
Sharp vs sSak
Monday Night Weeklies
1d 18h
Afreeca Starleague
2 days
Snow vs PianO
hero vs Rain
[ Show More ]
GSL
2 days
Replay Cast
3 days
Kung Fu Cup
3 days
The PondCast
4 days
Escore
5 days
Korean StarCraft League
6 days
CranKy Ducklings
6 days
IPSL
6 days
WolFix vs nOmaD
dxtr13 vs Razz
BSL
6 days
Liquipedia Results

Completed

Escore Tournament S2: W2
RSL Revival: Season 4
NationLESS Cup

Ongoing

BSL Season 22
ASL Season 21
CSL 2026 SPRING (S20)
IPSL Spring 2026
StarCraft2 Community Team League 2026 Spring
Nations Cup 2026
PGL Bucharest 2026
Stake Ranked Episode 1
BLAST Open Spring 2026
ESL Pro League S23 Finals
ESL Pro League S23 Stage 1&2
PGL Cluj-Napoca 2026
IEM Kraków 2026

Upcoming

Escore Tournament S2: W3
Acropolis #4
BSL 22 Non-Korean Championship
CSLAN 4
Kung Fu Cup 2026 Grand Finals
HSC XXIX
uThermal 2v2 2026 Main Event
RSL Revival: Season 5
WardiTV TLMC #16
IEM Cologne Major 2026
Stake Ranked Episode 2
CS Asia Championships 2026
Asian Champions League 2026
IEM Atlanta 2026
PGL Astana 2026
BLAST Rivals Spring 2026
CCT Season 3 Global Finals
IEM Rio 2026
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2026 TLnet. All Rights Reserved.