Author |
Message |
Eagle
Site Owner
Joined: Wed Sep 15, 2004 1:09 pm Posts: 14631 Location: Pittsburgh
|
 Brute Force Attack -- Please Read
All,
I believe your accounts have, for the most part, been unsuccessfully attacked by a malicious party attempting to brute-force account login credentials.
The board includes several features to prevent these types of attacks, and I have since added additional restrictions to help prevent the attacks. In the interim, it would be helpful if all users would change their password. This can be done via the User Control Panel -> Profile -> Edit Account Settings.
If you believe your account has been compromised, please contact me via email and we will confirm your identity and help you reset your account.
Thanks,
Karl
_________________
|
Tue Feb 22, 2011 9:29 am |
|
 |
Eagle
Site Owner
Joined: Wed Sep 15, 2004 1:09 pm Posts: 14631 Location: Pittsburgh
|
 Re: Brute Force Attack -- Please Read
After more research, it appears the attacks are coming from a russian server, it also appears WoKJ is not alone in being attacked.
_________________
|
Tue Feb 22, 2011 9:42 am |
|
 |
Argos
Z
Joined: Sat May 13, 2006 2:20 pm Posts: 7952 Location: Wherever he went, including here, it was against his better judgment.
|
 Re: Brute Force Attack -- Please Read
If you make me an administrator, I might be able to stop it.
_________________ "Der Lebenslauf des Menschen besteht darin, dass er, von der Hoffnung genarrt, dem Tod in die Arme tanzt." - Arthur Schopenhauer
|
Tue Feb 22, 2011 9:56 am |
|
 |
Eagle
Site Owner
Joined: Wed Sep 15, 2004 1:09 pm Posts: 14631 Location: Pittsburgh
|
 Re: Brute Force Attack -- Please Read
If you have valid suggestions, please feel free to post them.
_________________
|
Tue Feb 22, 2011 10:01 am |
|
 |
Price
Gamaur's sex slave
Joined: Tue Dec 20, 2005 7:15 pm Posts: 8889 Location: Los Pollos Hermanos
|
 Re: Brute Force Attack -- Please Read
OK! Who pissed off Mr. R?
_________________
|
Tue Feb 22, 2011 11:34 am |
|
 |
Korrgan
problem?
Joined: Tue Oct 19, 2004 6:52 am Posts: 15515 Location: Bait Shop
|
 Re: Brute Force Attack -- Please Read
Anything worthy of a ban I've done recently was this Russian bitch hacking my account.
Yu hear that, Lecter?
_________________
|
Tue Feb 22, 2011 3:39 pm |
|
 |
Proud Ryu
Deshi Basara
Joined: Thu Sep 27, 2007 3:36 pm Posts: 5322 Location: The Interstice
|
 Re: Brute Force Attack -- Please Read
Maybe it's the guy at the bottom of this thread viewtopic.php?f=12&t=61114&p=1662701#p1662701
|
Tue Feb 22, 2011 4:05 pm |
|
 |
Eagle
Site Owner
Joined: Wed Sep 15, 2004 1:09 pm Posts: 14631 Location: Pittsburgh
|
 Re: Brute Force Attack -- Please Read
I don't think so, it doesn't seem to be WoKJ specific, rather phpbb specific.
_________________
|
Tue Feb 22, 2011 5:07 pm |
|
 |
Jmart
Superman: The Movie
Joined: Fri Oct 22, 2004 8:47 am Posts: 21230 Location: Massachusetts
|
 Re: Brute Force Attack -- Please Read
How can we recognize if our account has been compromised?
_________________My DVD Collection Marty McGee (1989-2005)
If I’m not here, I’m on Letterboxd.
|
Tue Feb 22, 2011 5:42 pm |
|
 |
Eagle
Site Owner
Joined: Wed Sep 15, 2004 1:09 pm Posts: 14631 Location: Pittsburgh
|
 Re: Brute Force Attack -- Please Read
If you can still login, it's safe to assume it hasn't been. Still a good idea to make sure your password has at a minimum letters and numbers, and ideally a symbol.
A password with letters, numbers, symbols and no actual words is almost impossible to brute force attack.
_________________
|
Tue Feb 22, 2011 6:11 pm |
|
 |
i.hope
Defeats all expectations
Joined: Fri May 26, 2006 5:04 pm Posts: 6665
|
 Re: Brute Force Attack -- Please Read
I'm scared.
|
Tue Feb 22, 2011 9:17 pm |
|
 |
Price
Gamaur's sex slave
Joined: Tue Dec 20, 2005 7:15 pm Posts: 8889 Location: Los Pollos Hermanos
|
 Re: Brute Force Attack -- Please Read
I changed my password just in case,but it still asks me for that CAPTCHA 'enter words' thingy. Is that normal?
_________________
|
Tue Feb 22, 2011 9:19 pm |
|
 |
Eagle
Site Owner
Joined: Wed Sep 15, 2004 1:09 pm Posts: 14631 Location: Pittsburgh
|
 Re: Brute Force Attack -- Please Read
It will ask if you've had more than 2 failed attempts recently. A lot of people will experience it because the brute force attack basically means they went through the member list and tried to guess the password. Only on a very small handful of accounts did they try more than 3 times, typically once they hit the captcha they move on to the next account.
_________________
|
Tue Feb 22, 2011 10:07 pm |
|
 |
Price
Gamaur's sex slave
Joined: Tue Dec 20, 2005 7:15 pm Posts: 8889 Location: Los Pollos Hermanos
|
 Re: Brute Force Attack -- Please Read
It did ask me that with the old password, but it also did ask me with my first attempt with the new password, saying I had tried too many logins, while as I said in reality it was my first try.
_________________
|
Wed Feb 23, 2011 5:07 am |
|
 |
Bradley Witherberry
Extraordinary
Joined: Sat Oct 30, 2004 1:13 pm Posts: 15197 Location: Planet Xatar
|
 Re: Brute Force Attack -- Please Read
Fortunately, my account seems untampered with - - I'm still the same old Bradley Witherberry who thinks that Inception is the finest film ever made (next to TDK, of course).
|
Wed Feb 23, 2011 8:21 am |
|
 |
Eagle
Site Owner
Joined: Wed Sep 15, 2004 1:09 pm Posts: 14631 Location: Pittsburgh
|
 Re: Brute Force Attack -- Please Read
Price wrote: It did ask me that with the old password, but it also did ask me with my first attempt with the new password, saying I had tried too many logins, while as I said in reality it was my first try. It doesn't instantly reset, there are a few events that trigger resetting the number of failed logins, but i'm not sure what they are off the top of my head.
_________________
|
Wed Feb 23, 2011 9:13 am |
|
 |
Mister Ecks
New Server, Same X
Joined: Wed Oct 13, 2004 7:07 pm Posts: 28301 Location: ... siiiigh...
|
 Re: Brute Force Attack -- Please Read
Someone please hold me.
_________________ Ecks Factor: Cancelled too soon
|
Wed Feb 23, 2011 9:40 am |
|
 |
Chippy
KJ's Leading Pundit
Joined: Tue Oct 12, 2004 4:45 pm Posts: 63026 Location: Tonight... YOU!
|
 Re: Brute Force Attack -- Please Read
It was Loyal.
_________________trixster wrote: shut the fuck up zwackerm, you're out of your fucking element trixster wrote: chippy is correct
|
Wed Feb 23, 2011 3:48 pm |
|
 |
TonyMontana
Undisputed WoKJ DVD King
Joined: Thu Oct 14, 2004 8:55 am Posts: 16278 Location: Counting the 360 ways I love my Xbox
|
 Re: Brute Force Attack -- Please Read
I've changed my password to studmonkey70-1.
My question: Eagle suggested using a password with no actual words, but would studmonkey be ok? The way I see it, it is two actual words, but when combined together, it makes zero actual words.
Please let me know if this sounds secure enough, if not I'll change it again.
_________________
|
Wed Feb 23, 2011 6:33 pm |
|
 |
David
Pure Phase
Joined: Tue Feb 15, 2005 7:33 am Posts: 34865 Location: Maryland
|
 Re: Brute Force Attack -- Please Read
lol... 
_________________   1. The Lost City of Z - 2. A Cure for Wellness - 3. Phantom Thread - 4. T2 Trainspotting - 5. Detroit - 6. Good Time - 7. The Beguiled - 8. The Florida Project - 9. Logan and 10. Molly's Game
|
Wed Feb 23, 2011 6:41 pm |
|
 |
matatonio
Teh Mexican
Joined: Fri Oct 15, 2004 11:56 pm Posts: 26066 Location: In good ol' Mexico
|
 Re: Brute Force Attack -- Please Read
i dont know what the hell just happen but i believe ive been "attacked", but all is well i guess :/
|
Mon Feb 28, 2011 1:11 am |
|
 |
Price
Gamaur's sex slave
Joined: Tue Dec 20, 2005 7:15 pm Posts: 8889 Location: Los Pollos Hermanos
|
 Re: Brute Force Attack -- Please Read
matatonio wrote: i dont know what the hell just happen but i believe ive been "attacked", but all is well i guess :/ What?!?! The Kohl's guy again? 
_________________
|
Mon Feb 28, 2011 5:41 am |
|
 |
matatonio
Teh Mexican
Joined: Fri Oct 15, 2004 11:56 pm Posts: 26066 Location: In good ol' Mexico
|
 Re: Brute Force Attack -- Please Read
Price wrote: matatonio wrote: i dont know what the hell just happen but i believe ive been "attacked", but all is well i guess :/ What?!?! The Kohl's guy again?  thanks for bringing back traumatizing memories ... 
|
Mon Feb 28, 2011 8:47 pm |
|
 |
STEVE ROGERS
The Greatest Avenger EVER
Joined: Fri Oct 29, 2004 4:02 am Posts: 18501
|
 Re: Brute Force Attack -- Please Read
Chippy wrote: It was Loyal. 
_________________http://www.youtube.com/watch?v=2dmXF3CE04A This kills TDKR At the box office next summer.. Get used to this
|
Wed Apr 13, 2011 7:39 am |
|
|