What's up with being Hacked?

General discussion for players of Oolite.

Moderators: winston, another_commander

User avatar
Thargoid
Thargoid
Thargoid
Posts: 5528
Joined: Thu Jun 12, 2008 6:55 pm

Re: What's up with being Hacked?

Post by Thargoid »

CheeseRedux wrote:
(Except for the link in new tab thing. I still prefer that.)
On that one I completely agree with you (I hadn't noticed it until now).
User avatar
JensAyton
Grand Admiral Emeritus
Grand Admiral Emeritus
Posts: 6657
Joined: Sat Apr 02, 2005 2:43 pm
Location: Sweden
Contact:

Re: What's up with being Hacked?

Post by JensAyton »

Forcibly opening links in new tabs is a horrible, horrible habit, and I’m certainly not going to go out of my way to make it happen.
User avatar
Commander McLane
---- E L I T E ----
---- E L I T E ----
Posts: 9520
Joined: Thu Dec 14, 2006 9:08 am
Location: a Hacker Outpost in a moderately remote area
Contact:

Re: What's up with being Hacked?

Post by Commander McLane »

Actually it wasn't tabs, but links used to be opened in a new window.

At least for external links I find that sensible. If I for instance follow a link to some find on the web from some Outworld thread (like e.g. the one with the moon monolith), I prefer to get a new window. I can read it, possibly follow other links (which invariably happens if the external link was to tvtropes :oops: ), finally close the whole window and find myself back where it all began in the original window. I don't want to use the "page back" button umpty times in order to get back to the boards.

The same goes for links to the Elite Wiki. I like them to open in a separate window as an independent resource which I can consult alongside the thread, rather than having to go back and forward to and from the thread.
User avatar
Cody
Sharp Shooter Spam Assassin
Sharp Shooter Spam Assassin
Posts: 16081
Joined: Sat Jul 04, 2009 9:31 pm
Location: The Lizard's Claw
Contact:

Re: What's up with being Hacked?

Post by Cody »

Commander McLane wrote:
Actually it wasn't tabs, but links used to be opened in a new window.
That's what I thought CR meant, new window... this was very useful.
The 'open new windows in new tabs' thing is a browser preference.
I would advise stilts for the quagmires, and camels for the snowy hills
And any survivors, their debts I will certainly pay. There's always a way!
User avatar
JensAyton
Grand Admiral Emeritus
Grand Admiral Emeritus
Posts: 6657
Joined: Sat Apr 02, 2005 2:43 pm
Location: Sweden
Contact:

Re: What's up with being Hacked?

Post by JensAyton »

Commander McLane wrote:
At least for external links I find that sensible. If I for instance follow a link to some find on the web from some Outworld thread (like e.g. the one with the moon monolith), I prefer to get a new window. I can read it, possibly follow other links (which invariably happens if the external link was to tvtropes :oops: )
No-one’s saying you can’t have a new tab/window. Every browser has commands and shortcuts to do it with any link. What most lack is an “open this right here” command for links which override normal behaviour.
User avatar
CheeseRedux
---- E L I T E ----
---- E L I T E ----
Posts: 827
Joined: Fri Oct 02, 2009 6:50 pm

Re: What's up with being Hacked?

Post by CheeseRedux »

Commander McLane wrote:
Actually it wasn't tabs, but links used to be opened in a new window.
This must be browser and/or OS related then, because for me (Opera/WinXP), links invariably opened in a fresh tab.

Other than that, your reasonings (including, I'm afraid, the tvtropes bit) are in perfect accord with mine.
"Actually this is a common misconception... I do *not* in fact have a lot of time on my hands at all! I just have a very very very very bad sense of priorities."
--Dean C Engelhardt
User avatar
Mauiby de Fug
---- E L I T E ----
---- E L I T E ----
Posts: 847
Joined: Tue Sep 07, 2010 2:23 pm

Re: What's up with being Hacked?

Post by Mauiby de Fug »

Yep, I used to get new tabs, too, using Ubuntu/Chromium. I preferred that system with external links; with others I'm quite happy for it to remain in the same tab.
User avatar
Eric Walch
Slightly Grand Rear Admiral
Slightly Grand Rear Admiral
Posts: 5536
Joined: Sat Jun 16, 2007 3:48 pm
Location: Netherlands

Re: What's up with being Hacked?

Post by Eric Walch »

CheeseRedux wrote:
Commander McLane wrote:
Actually it wasn't tabs, but links used to be opened in a new window.
This must be browser and/or OS related then, because for me (Opera/WinXP), links invariably opened in a fresh tab.

Other than that, your reasonings (including, I'm afraid, the tvtropes bit) are in perfect accord with mine.
I only know how it works with Safari. There you can set the preferences to open links in new pages or tabs.

And like Ahruman wrote, you can still open links in tabs with Safari by Cmd-clicking the link. (You can define this in preferences) I assume other browsers have similar options.
User avatar
Rxke
Retired Assassin
Retired Assassin
Posts: 1760
Joined: Thu Aug 12, 2004 4:54 pm
Location: Belgium

Re: What's up with being Hacked?

Post by Rxke »

Warning?

The e-mail account that I use for all things Oolite got hacked yesterday.

And I know I've been a bad boy: that account had the same password as here (I have oodles of passwords, so it happens rarely, but it does :( )


Sooooo.... Very probably the hackers got their hands on the passwords from this place, I have no other explanation (it was not a dictionary attack)


So it might be a good idea to change passwords?
User avatar
Zieman
---- E L I T E ----
---- E L I T E ----
Posts: 680
Joined: Tue Sep 01, 2009 11:55 pm
Location: in maZe

Re: What's up with being Hacked?

Post by Zieman »

Rxke wrote:
Warning?

...

So it might be a good idea to change passwords?
Done.

Thanks for the heads up!
...and keep it under lightspeed!

Friendliest Meteor Police that side of Riedquat

[EliteWiki] Far Arm ships
[EliteWiki] Z-ships
[EliteWiki] Baakili Far Trader
[EliteWiki] Tin of SPAM
User avatar
Phantom Hoover
Dangerous
Dangerous
Posts: 100
Joined: Mon Mar 22, 2010 9:06 pm

Re: What's up with being Hacked?

Post by Phantom Hoover »

So wait, the passwords were stored in plaintext somewhere? Surely some mistake?
User avatar
Rxke
Retired Assassin
Retired Assassin
Posts: 1760
Joined: Thu Aug 12, 2004 4:54 pm
Location: Belgium

Re: What's up with being Hacked?

Post by Rxke »

I'm not saying that, but it seems like a very creepy coincidence.

Might be just that, coincidence....
User avatar
aegidian
Master and Commander
Master and Commander
Posts: 1161
Joined: Thu May 20, 2004 10:46 pm
Location: London UK
Contact:

Re: What's up with being Hacked?

Post by aegidian »

Phantom Hoover wrote:
So wait, the passwords were stored in plaintext somewhere? Surely some mistake?
No, the passwords are stored as MD5 hashes within the phpbb database. If they were to be acquired by a black hat gaining access to the board's MySQL database they could be decrypted (cracked) but even then the process takes time.

For best security, don't use the same password everywhere, and change your passwords regularly.
"The planet Rear is scourged by well-intentioned OXZs."

Oolite models and gear? click here!
User avatar
Phantom Hoover
Dangerous
Dangerous
Posts: 100
Joined: Mon Mar 22, 2010 9:06 pm

Re: What's up with being Hacked?

Post by Phantom Hoover »

So the reported password compromises cannot have been through a brute-force attack on the database?
User avatar
aegidian
Master and Commander
Master and Commander
Posts: 1161
Joined: Thu May 20, 2004 10:46 pm
Location: London UK
Contact:

Re: What's up with being Hacked?

Post by aegidian »

As I understand it the databases are not stored on the same machine as the files that make up the site. It was the machine hosting those files that was hacked (hence the databases not being lost). A brute force attack would not work as the databases weren't directly exposed.

It is possible (although unlikely) that as a result of that hack the databases may have been made vulnerable if a cracker got to configuration files for this board and decrypted the MD5 password hash for database access (since changed, multiple times and securely), allowing that cracker to access and then to decrypt some of the MD5 password hashes.

If you use the same password for the board as you do for any other site associated with the email address you use here, then your access here and to those other sites may be at risk. Therefore we're advising you change your password here and to change any passwords that are the same as the one you use here.
"The planet Rear is scourged by well-intentioned OXZs."

Oolite models and gear? click here!
Post Reply