Sythe.Org Forums     Register     FAQ     Members List     Calendar     Mark Forums Read    
 
Sythe.Org Forums  
   Runescape Gold

Sythe.org — A Virtual Goods Trading Hub

Make real cash! buying and selling in-game items.

We have a no-scam policy.

You can make thousands playing your favourite games here at Sythe.org.

Just sign up an account and follow the rules!


Take me to

Runescape Markets

Other Game Markets

Support Center

Register an Account

Close
Update regarding the recent hackings
Closed Thread
 
LinkBack Thread Tools Display Modes
  #61  
Old 04-24-2012, 09:15 AM
Newcomer
 
Join Date: Apr 2012
Posts: 1
Default Re: Update regarding the recent hackings

Iknow this from a trusted source of HF and heres the story a microsoft application was compromised leading to some hotmails / live emails getting hacked those were the only two kind of emails that were able to get hacked anybody else who claims they have been hacked lies. well not everyone but the hacker only took hotmails and lives since the application didnt have nothing to do with yahoo / gmail etc. well i can confirm that your database hasnt been leaked and that this were simple microsofts fault and that the source told me that this has been fixed and therefor there shouldnt be anymore hacked accounts again. alittle reminder dont post your msn in your signature / in posts that was prob how he got your emails. as said above dont feel like getting hacked? = dont use hotmail! simple as that hotmail sucks in everyway gmail or yahoo should keep u safe

i cant say how exactly this was done. but it had something to do with microsoft forgot to secure a certain breakpoint in the application so all u had to do was write "command" <-- thats not the command but a certain command to the person after youve added them on msn u write a command to them they cant see it but it sends a string / hash or so to the "sender" = sending them your actual password when he then got your password as a hash all he had to do was decrypt it so yeah microsoft fails again.

Last edited by trustedornot : 04-24-2012 at 09:26 AM.
  #62  
Old 04-24-2012, 09:34 AM
Hero
 
Join Date: May 2005
Location: Netherlands
Posts: 5,347
Send a message via MSN to just un dude Send a message via Skype™ to just un dude
Default Re: Update regarding the recent hackings

Quote:
Originally Posted by trustedornot View Post
Iknow this from a trusted source of HF and heres the story a microsoft application was compromised leading to some hotmails / live emails getting hacked those were the only two kind of emails that were able to get hacked anybody else who claims they have been hacked lies. well not everyone but the hacker only took hotmails and lives since the application didnt have nothing to do with yahoo / gmail etc. well i can confirm that your database hasnt been leaked and that this were simple microsofts fault and that the source told me that this has been fixed and therefor there shouldnt be anymore hacked accounts again. alittle reminder dont post your msn in your signature / in posts that was prob how he got your emails. as said above dont feel like getting hacked? = dont use hotmail! simple as that hotmail sucks in everyway gmail or yahoo should keep u safe

i cant say how exactly this was done. but it had something to do with microsoft forgot to secure a certain breakpoint in the application so all u had to do was write "command" <-- thats not the command but a certain command to the person after youve added them on msn u write a command to them they cant see it but it sends a string / hash or so to the "sender" = sending them your actual password when he then got your password as a hash all he had to do was decrypt it so yeah microsoft fails again.
The method intercepted the password reset link that is supposed to be sent to your alternate e-mail account, they never got your actual password.
  #63  
Old 04-24-2012, 03:18 PM
Verts's Avatar
Calm as a Hindu cow
Crabby Sythe Verified User
 
Join Date: Aug 2007
Location: earth
Posts: 5,180
Lumpy Space Princess Wait, do you not have an Archer rank?
Default Re: Update regarding the recent hackings

Quote:
Originally Posted by T R 1 B A L View Post
Chances are it was just the old database leak that's still circulating around the internet - that could be used as an elaborate hoax maybe?
Regardless, if there was a database leaked with Kevin's information in there then it's one we didn't know about.
__________________
I have a crush on Govind and his big brown rod



  #64  
Old 04-24-2012, 09:33 PM
Ex-Moderator
 
Join Date: Jun 2007
Location: North London.
Posts: 2,699
Default Re: Update regarding the recent hackings

Quote:
Originally Posted by Verts View Post
Regardless, if there was a database leaked with Kevin's information in there then it's one we didn't know about.
True say, forgot to check his join date, apologies.
Bearing in mind that it's encrypted with standard md5 (i'm presuming), and nobody has simple 1 word passwords (maybe an announcement about password strength would be advisable), surely there's more chance that the password was obtained via phishing, or another illicit method?

I really hope that kevin's keylogged (or was phished), rather than the Sythe database being spread around the internet - god knows how many inactive accounts still hang around in the database.
__________________
  #65  
Old 04-24-2012, 09:52 PM
Hero
 
Join Date: May 2005
Location: Netherlands
Posts: 5,347
Send a message via MSN to just un dude Send a message via Skype™ to just un dude
Default Re: Update regarding the recent hackings

Isn't md5 pretty outdated and pretty easy to dehash now a days lol.

I hope we're not using that >.>
  #66  
Old 04-25-2012, 02:52 AM
Brendan's Avatar
Let's Go!
$50 USD Donor
 
Join Date: Sep 2009
Location: Australia
Posts: 5,631
Send a message via Skype™ to Brendan
MushyMuncher
Default Re: Update regarding the recent hackings

Quote:
Originally Posted by kevin001 View Post
I spoke to a guy at the day while i msn got compromised, he claimed sythe datebase has been hacked, and showed original info of my sythe acc, like password(not current one), email, etc, even some mod's acc info. i was shocked like "wtf!!??"
then i was wondering why my msn got hacked but my sythe account is safe? Now i know datebase leaking was a coincidence with MSN hacked issue.
thank you N4n0 to clarify this
Come to think of it, are you sure your old password wasn't related to any of your MSN's? That could be where it came from.
  #67  
Old 04-25-2012, 03:50 PM
Member
 
Join Date: May 2009
Location: Netherlands
Posts: 50
Default Re: Update regarding the recent hackings

Brilliant, some good news
  #68  
Old 04-25-2012, 09:29 PM
Forum Addict
 
Join Date: Apr 2012
Posts: 308
Default Re: Update regarding the recent hackings

it is unfortunate to see people get hacked :/
  #69  
Old 04-26-2012, 09:39 AM
Apprentice
 
Join Date: Aug 2011
Posts: 650
MushyMuncher St. Patrick's Day 2013 Gohan has AIDS Homosex
Default Re: Update regarding the recent hackings

Quote:
Originally Posted by trustedornot View Post
Iknow this from a trusted source of HF and heres the story a microsoft application was compromised leading to some hotmails / live emails getting hacked those were the only two kind of emails that were able to get hacked anybody else who claims they have been hacked lies. well not everyone but the hacker only took hotmails and lives since the application didnt have nothing to do with yahoo / gmail etc. well i can confirm that your database hasnt been leaked and that this were simple microsofts fault and that the source told me that this has been fixed and therefor there shouldnt be anymore hacked accounts again. alittle reminder dont post your msn in your signature / in posts that was prob how he got your emails. as said above dont feel like getting hacked? = dont use hotmail! simple as that hotmail sucks in everyway gmail or yahoo should keep u safe

i cant say how exactly this was done. but it had something to do with microsoft forgot to secure a certain breakpoint in the application so all u had to do was write "command" <-- thats not the command but a certain command to the person after youve added them on msn u write a command to them they cant see it but it sends a string / hash or so to the "sender" = sending them your actual password when he then got your password as a hash all he had to do was decrypt it so yeah microsoft fails again.
first post, ban evader?
  #70  
Old 04-26-2012, 07:44 PM
Member
 
Join Date: Apr 2012
Location: Pig Farts
Posts: 65
Default Re: Update regarding the recent hackings

Us this why the websites been cradhing alot?
  #71  
Old 04-26-2012, 08:28 PM
Forum Addict
 
Join Date: Mar 2012
Location: No where..
Posts: 311
Default Re: Update regarding the recent hackings

Quote:
Originally Posted by fpla View Post
What is this?

says "sythe.com"

Thanks for the update.
  #72  
Old 04-26-2012, 10:45 PM
Brendan's Avatar
Let's Go!
$50 USD Donor
 
Join Date: Sep 2009
Location: Australia
Posts: 5,631
Send a message via Skype™ to Brendan
MushyMuncher
Default Re: Update regarding the recent hackings

Quote:
Originally Posted by 688 View Post
Us this why the websites been cradhing alot?
I don't think so. I believe the sites crashing because it's under a DDoS attack.
  #73  
Old 04-26-2012, 11:26 PM
king tijn 2's Avatar
Grand Master
$200 USD Donor New
 
Join Date: Jan 2007
Location: Sythe
Posts: 3,739
Send a message via MSN to king tijn 2 Send a message via Skype™ to king tijn 2
Default Re: Update regarding the recent hackings

Quote:
Originally Posted by n4n0 View Post
As far as we are aware, this exploit has been discovered and patched by Microsoft.
Hope it's really patched now.

My msn got blocked after I recovered it back from the hacker due to unusual activity. I was unable to unblock it because "phone service was unavailable in my area". I gave up and made a new MSN.

I tried to log in just now to see if it's unblocked and the password was incorrect so I recovered again, it seems they hacked it again in the past 72 hours or so. Not sure when because I haven't tried to log in since 3 days ago.

Last edited by king tijn 2 : 04-26-2012 at 11:27 PM.
  #74  
Old 04-27-2012, 06:44 AM
Newcomer
 
Join Date: Apr 2012
Posts: 4
Default Re: Update regarding the recent hackings

The hashing function used by sythe and other vBulletin forums is md5(md5($pass).$salt)

Generally 90% of them or so are crackable, the best GPU running through hashcat about 1.1M passwords a second can be attempted
  #75  
Old 04-27-2012, 07:46 AM
Brendan's Avatar
Let's Go!
$50 USD Donor
 
Join Date: Sep 2009
Location: Australia
Posts: 5,631
Send a message via Skype™ to Brendan
MushyMuncher
Default Re: Update regarding the recent hackings

Quote:
Originally Posted by HJQscammmm View Post
The hashing function used by sythe and other vBulletin forums is md5(md5($pass).$salt)

Generally 90% of them or so are crackable, the best GPU running through hashcat about 1.1M passwords a second can be attempted
You seem to know a lot about the subject.

Just wondering, is the upgrade to vB4 going to make Sythe any safer? Will it have any extra layers of security that could make it harder for hackers to take the Sythe Database in the future?
  #76  
Old 04-27-2012, 12:19 PM
Hero
 
Join Date: May 2005
Location: Netherlands
Posts: 5,347
Send a message via MSN to just un dude Send a message via Skype™ to just un dude
Default Re: Update regarding the recent hackings

Quote:
Originally Posted by Brendan View Post
You seem to know a lot about the subject.

Just wondering, is the upgrade to vB4 going to make Sythe any safer? Will it have any extra layers of security that could make it harder for hackers to take the Sythe Database in the future?
He's banned already.

And the security will pretty much be the same btw, patches are usually rolled out pretty fast if needed.
  #77  
Old 04-27-2012, 01:15 PM
Untired, we stand. Exhausted, we fall.
$5 USD Donor New Ex-Moderator
 
Join Date: May 2009
Posts: 2,689
Send a message via Skype™ to Wolfdog
Default Re: Update regarding the recent hackings

Quote:
Originally Posted by just un dude View Post
He's banned already.

And the security will pretty much be the same btw, patches are usually rolled out pretty fast if needed.
Yeh, security should be nearly the same. The only changes will be added and improved features.
__________________
If you need help with something, please feel free to PM me. If I haven't responded within a day or two, feel free to add my Skype.

  #78  
Old 04-27-2012, 03:56 PM
Member
 
Join Date: Apr 2012
Posts: 82
Send a message via MSN to Stl Arr0w Send a message via Skype™ to Stl Arr0w
Default Re: Update regarding the recent hackings

Quote:
Originally Posted by Fendle View Post
Thanks for clearing this up n4n0, it is a shame for the people who got hacked as they now have to pay back what was scammed.
^^^^^
  #79  
Old 05-02-2012, 04:22 AM
ur0wnedman's Avatar
Apprentice
 
Join Date: Jan 2012
Location: United States America
Posts: 738
Send a message via MSN to ur0wnedman Send a message via Yahoo to ur0wnedman Send a message via Skype™ to ur0wnedman
Default Re: Update regarding the recent hackings

It would have to be a keylogger. But phishing would of gotten more info instead of just hacking emails.
__________________

Closed Thread



Cheap RS Gold Store  Runescape Gold

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

All times are GMT +1. The time now is 10:13 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.6.1