 |
|

04-24-2012, 09:15 AM
|
|
Newcomer
|
|
Join Date: Apr 2012
Posts: 1
|
|
Re: Update regarding the recent hackings
Iknow this from a trusted source of HF and heres the story a microsoft application was compromised leading to some hotmails / live emails getting hacked those were the only two kind of emails that were able to get hacked anybody else who claims they have been hacked lies. well not everyone but the hacker only took hotmails and lives since the application didnt have nothing to do with yahoo / gmail etc. well i can confirm that your database hasnt been leaked and that this were simple microsofts fault and that the source told me that this has been fixed and therefor there shouldnt be anymore hacked accounts again. alittle reminder dont post your msn in your signature / in posts that was prob how he got your emails. as said above dont feel like getting hacked? = dont use hotmail! simple as that  hotmail sucks in everyway gmail or yahoo should keep u safe
i cant say how exactly this was done. but it had something to do with microsoft forgot to secure a certain breakpoint in the application so all u had to do was write "command" <-- thats not the command but a certain command to the person after youve added them on msn u write a command to them they cant see it but it sends a string / hash or so to the "sender" = sending them your actual password when he then got your password as a hash all he had to do was decrypt it so yeah microsoft fails again.
Last edited by trustedornot : 04-24-2012 at 09:26 AM.
|

04-24-2012, 09:34 AM
|
|
Hero
|
|
Join Date: May 2005
Location: Netherlands
Posts: 5,347
|
|
Re: Update regarding the recent hackings
Quote:
Originally Posted by trustedornot
Iknow this from a trusted source of HF and heres the story a microsoft application was compromised leading to some hotmails / live emails getting hacked those were the only two kind of emails that were able to get hacked anybody else who claims they have been hacked lies. well not everyone but the hacker only took hotmails and lives since the application didnt have nothing to do with yahoo / gmail etc. well i can confirm that your database hasnt been leaked and that this were simple microsofts fault and that the source told me that this has been fixed and therefor there shouldnt be anymore hacked accounts again. alittle reminder dont post your msn in your signature / in posts that was prob how he got your emails. as said above dont feel like getting hacked? = dont use hotmail! simple as that  hotmail sucks in everyway gmail or yahoo should keep u safe
i cant say how exactly this was done. but it had something to do with microsoft forgot to secure a certain breakpoint in the application so all u had to do was write "command" <-- thats not the command but a certain command to the person after youve added them on msn u write a command to them they cant see it but it sends a string / hash or so to the "sender" = sending them your actual password when he then got your password as a hash all he had to do was decrypt it so yeah microsoft fails again.
|
The method intercepted the password reset link that is supposed to be sent to your alternate e-mail account, they never got your actual password.
|

04-24-2012, 03:18 PM
|
 |
Calm as a Hindu cow
|
|
Join Date: Aug 2007
Location: earth
Posts: 5,180
|
|
Re: Update regarding the recent hackings
Quote:
Originally Posted by T R 1 B A L
Chances are it was just the old database leak that's still circulating around the internet - that could be used as an elaborate hoax maybe?
|
Regardless, if there was a database leaked with Kevin's information in there then it's one we didn't know about.
__________________
I have a crush on Govind and his big brown rod

|

04-24-2012, 09:33 PM
|
|
|
|
Join Date: Jun 2007
Location: North London.
Posts: 2,699
|
|
Re: Update regarding the recent hackings
Quote:
Originally Posted by Verts
Regardless, if there was a database leaked with Kevin's information in there then it's one we didn't know about.
|
True say, forgot to check his join date, apologies.
Bearing in mind that it's encrypted with standard md5 (i'm presuming), and nobody has simple 1 word passwords (maybe an announcement about password strength would be advisable), surely there's more chance that the password was obtained via phishing, or another illicit method?
I really hope that kevin's keylogged (or was phished), rather than the Sythe database being spread around the internet - god knows how many inactive accounts still hang around in the database.
|

04-24-2012, 09:52 PM
|
|
Hero
|
|
Join Date: May 2005
Location: Netherlands
Posts: 5,347
|
|
Re: Update regarding the recent hackings
Isn't md5 pretty outdated and pretty easy to dehash now a days lol.
I hope we're not using that >.>
|

04-25-2012, 02:52 AM
|
 |
Let's Go!
|
|
Join Date: Sep 2009
Location: Australia
Posts: 5,631
|
|
Re: Update regarding the recent hackings
Quote:
Originally Posted by kevin001
I spoke to a guy at the day while i msn got compromised, he claimed sythe datebase has been hacked, and showed original info of my sythe acc, like password(not current one), email, etc, even some mod's acc info. i was shocked like "wtf!!??"
then i was wondering why my msn got hacked but my sythe account is safe? Now i know datebase leaking was a coincidence with MSN hacked issue.
thank you N4n0 to clarify this 
|
Come to think of it, are you sure your old password wasn't related to any of your MSN's? That could be where it came from.
|

04-25-2012, 03:50 PM
|
|
Member
|
|
Join Date: May 2009
Location: Netherlands
Posts: 50
|
|
Re: Update regarding the recent hackings
Brilliant, some good news 
|

04-25-2012, 09:29 PM
|
|
Forum Addict
|
|
Join Date: Apr 2012
Posts: 308
|
|
Re: Update regarding the recent hackings
it is unfortunate to see people get hacked :/
|

04-26-2012, 09:39 AM
|
|
Apprentice
|
|
Join Date: Aug 2011
Posts: 650
|
|
Re: Update regarding the recent hackings
Quote:
Originally Posted by trustedornot
Iknow this from a trusted source of HF and heres the story a microsoft application was compromised leading to some hotmails / live emails getting hacked those were the only two kind of emails that were able to get hacked anybody else who claims they have been hacked lies. well not everyone but the hacker only took hotmails and lives since the application didnt have nothing to do with yahoo / gmail etc. well i can confirm that your database hasnt been leaked and that this were simple microsofts fault and that the source told me that this has been fixed and therefor there shouldnt be anymore hacked accounts again. alittle reminder dont post your msn in your signature / in posts that was prob how he got your emails. as said above dont feel like getting hacked? = dont use hotmail! simple as that  hotmail sucks in everyway gmail or yahoo should keep u safe
i cant say how exactly this was done. but it had something to do with microsoft forgot to secure a certain breakpoint in the application so all u had to do was write "command" <-- thats not the command but a certain command to the person after youve added them on msn u write a command to them they cant see it but it sends a string / hash or so to the "sender" = sending them your actual password when he then got your password as a hash all he had to do was decrypt it so yeah microsoft fails again.
|
first post, ban evader?
|

04-26-2012, 07:44 PM
|
|
Member
|
|
Join Date: Apr 2012
Location: Pig Farts
Posts: 65
|
|
Re: Update regarding the recent hackings
Us this why the websites been cradhing alot?
|

04-26-2012, 08:28 PM
|
|
Forum Addict
|
|
Join Date: Mar 2012
Location: No where..
Posts: 311
|
|
Re: Update regarding the recent hackings
Quote:
Originally Posted by fpla
What is this?

|
says "sythe.com"
Thanks for the update.
|

04-26-2012, 10:45 PM
|
 |
Let's Go!
|
|
Join Date: Sep 2009
Location: Australia
Posts: 5,631
|
|
Re: Update regarding the recent hackings
Quote:
Originally Posted by 688
Us this why the websites been cradhing alot?
|
I don't think so. I believe the sites crashing because it's under a DDoS attack.
|

04-26-2012, 11:26 PM
|
 |
Grand Master
|
|
Join Date: Jan 2007
Location: Sythe
Posts: 3,739
|
|
Re: Update regarding the recent hackings
Quote:
Originally Posted by n4n0
As far as we are aware, this exploit has been discovered and patched by Microsoft.
|
Hope it's really patched now.
My msn got blocked after I recovered it back from the hacker due to unusual activity. I was unable to unblock it because "phone service was unavailable in my area". I gave up and made a new MSN.
I tried to log in just now to see if it's unblocked and the password was incorrect so I recovered again, it seems they hacked it again in the past 72 hours or so. Not sure when because I haven't tried to log in since 3 days ago.
Last edited by king tijn 2 : 04-26-2012 at 11:27 PM.
|

04-27-2012, 06:44 AM
|
|
Newcomer
|
|
Join Date: Apr 2012
Posts: 4
|
|
Re: Update regarding the recent hackings
The hashing function used by sythe and other vBulletin forums is md5(md5($pass).$salt)
Generally 90% of them or so are crackable, the best GPU running through hashcat about 1.1M passwords a second can be attempted
|

04-27-2012, 07:46 AM
|
 |
Let's Go!
|
|
Join Date: Sep 2009
Location: Australia
Posts: 5,631
|
|
Re: Update regarding the recent hackings
Quote:
Originally Posted by HJQscammmm
The hashing function used by sythe and other vBulletin forums is md5(md5($pass).$salt)
Generally 90% of them or so are crackable, the best GPU running through hashcat about 1.1M passwords a second can be attempted
|
You seem to know a lot about the subject.
Just wondering, is the upgrade to vB4 going to make Sythe any safer? Will it have any extra layers of security that could make it harder for hackers to take the Sythe Database in the future?
|

04-27-2012, 12:19 PM
|
|
Hero
|
|
Join Date: May 2005
Location: Netherlands
Posts: 5,347
|
|
Re: Update regarding the recent hackings
Quote:
Originally Posted by Brendan
You seem to know a lot about the subject.
Just wondering, is the upgrade to vB4 going to make Sythe any safer? Will it have any extra layers of security that could make it harder for hackers to take the Sythe Database in the future?
|
He's banned already.
And the security will pretty much be the same btw, patches are usually rolled out pretty fast if needed.
|

04-27-2012, 01:15 PM
|
|
Untired, we stand. Exhausted, we fall.
|
|
Join Date: May 2009
Posts: 2,689
|
|
Re: Update regarding the recent hackings
Quote:
Originally Posted by just un dude
He's banned already.
And the security will pretty much be the same btw, patches are usually rolled out pretty fast if needed.
|
Yeh, security should be nearly the same. The only changes will be added and improved features. 
__________________
If you need help with something, please feel free to PM me. If I haven't responded within a day or two, feel free to add my Skype.

|

04-27-2012, 03:56 PM
|
|
Member
|
|
Join Date: Apr 2012
Posts: 82
|
|
Re: Update regarding the recent hackings
Quote:
Originally Posted by Fendle
Thanks for clearing this up n4n0, it is a shame for the people who got hacked as they now have to pay back what was scammed.
|
^^^^^
|

05-02-2012, 04:22 AM
|
 |
Apprentice
|
|
Join Date: Jan 2012
Location: United States America
Posts: 738
|
|
Re: Update regarding the recent hackings
It would have to be a keylogger. But phishing would of gotten more info instead of just hacking emails.
|
 |
|
|