All times are UTC - 6 hours




Post new topic Reply to topic   Page 1 of 3
 [ 44 posts ] 
Go to page: 1, 2, 3  Next »  Page:
Author Message

 Post subject: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 12:14 am 
Priest of Saradomin
Priest of Saradomin
User avatar

Joined: December 19th, 2002, 2:36 pm
Posts: 1,672
Gender: Female
Status: Offline

Donor: Princess (2010)
Friend of Hiker
Myself and several other users have received emails from Jagex:

Image

As you can see I have recieved two myself, I'm curious as to exactly how many other users have been affected.

__________________
ImageRunevillage member #46

Image


Top
 Profile YIM 
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 12:25 am 
the 'teflon' coated
Clan Chat Moderator
Clan Chat Moderator
User avatar

Joined: October 2nd, 2004, 11:52 pm
Posts: 6,777
Location: Sydney
Gender: Male
Status: Offline

Donor: Guardian (2010)
I got one too, as did Twobit. Unsure what is happening, but as long as they don't get in, I'm happy.

__________________
[align=center][img]http://img178.imageshack.us/img178/2707/muse1.jpg[/img]
[img]http://img821.imageshack.us/img821/738/lollolololol.jpg[/img]
[img]http://img835.imageshack.us/img835/1424/rvsig.png[/img][/align]


Top
 Profile
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 1:07 am 
Rob.
Prince
Prince

Joined: September 9th, 2009, 2:26 am
Posts: 610
Gender: Male
Status: Offline

Donor: Guardian (2013)
*sets recoveries and email*

__________________
Image


Top
 Profile
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 1:07 am 
Hello Ladies.
Village Staff
Village Staff
User avatar

Joined: October 14th, 2009, 3:38 pm
Posts: 3,025
Gender: Male
Status: Offline
I just checked i got one too, good job the MSN password is unique to any other password i have. Or is it.

__________________
Image Image Image Image
Image

There are 10 types of people in the world, the ones that understand binary, and the ones that don't.

Thanks Lou for the help with the avatar.


Top
 Profile
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 2:05 am 
the 'teflon' coated
Clan Chat Moderator
Clan Chat Moderator
User avatar

Joined: October 2nd, 2004, 11:52 pm
Posts: 6,777
Location: Sydney
Gender: Male
Status: Offline

Donor: Guardian (2010)
Muse wrote:
*sets recoveries and email*


Too late, stolen your account already. <3

__________________
[align=center][img]http://img178.imageshack.us/img178/2707/muse1.jpg[/img]
[img]http://img821.imageshack.us/img821/738/lollolololol.jpg[/img]
[img]http://img835.imageshack.us/img835/1424/rvsig.png[/img][/align]


Top
 Profile
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 2:35 am 
Queen of Runevillage
Sorceror of Saradomin
Sorceror of Saradomin
User avatar

Joined: September 1st, 2005, 2:13 pm
Posts: 3,459
Location: On an Island
Gender: Male
Status: Offline
It's no coincidence that a noob posted here the other day wondering why he couldn't access user profiles.

__________________
Image
Struggle is Nature's way of strengthening it.


Top
 Profile
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 3:49 am 
The Mutts Nuts
Champion of Saradomin
Champion of Saradomin

Joined: April 22nd, 2005, 1:22 am
Posts: 5,157
Location: England
Gender: Male
Status: Offline
I keep getting logged out of RV when I try to open the page despite having it set to log me in automatically. And then I have to do the stupid captcha thing every time. So yeah, something is going on. I havn't had that E-mail.


Top
 Profile
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 6:43 am 
Sorceror of Saradomin
Sorceror of Saradomin

Joined: June 9th, 2005, 5:04 pm
Posts: 4,086
Location: M-Town (Memphis)
Status: Offline

Donor: Guardian (2009)
Someone captured the username option on account profiles it seems like and is running a cracker on the list, so yea nothing we can do now to stop it, just hope you dont have a dictionary or other easy pass and change it now.

__________________
Image
Priest of Saradomin as of Thu Feb 16, 2006 8:46 am
I'm the 465th person to get 1000th posts!


Top
 Profile
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 6:45 am 
/jəˈʁun/
Village Legend
Village Legend
User avatar

Joined: September 18th, 2004, 12:20 pm
Posts: 6,358
Location: Holland
Gender: Male
Status: Offline

Donor: Knight (2013)
Yeah, I got one as well

__________________
Image


Top
 Profile
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 7:32 am 
Sorceror of Saradomin
Sorceror of Saradomin

Joined: November 19th, 2004, 10:13 pm
Posts: 2,229
Gender: Male
Status: Offline
Loner wrote:
Someone captured the username option on account profiles it seems like and is running a cracker on the list, so yea nothing we can do now to stop it, just hope you dont have a dictionary or other easy pass and change it now.


And how exactly does one's username allow access to their password? Security doesn't work that way; if you mean trying to brute-force passwords, the server isn't going to allow very many requests before it starts requesting CAPTCHAs. The only attack vectors here are using easily guessable passwords or using the same password on a compromised site that doesn't secure its passwords. The forum software here uses per-user salting with several layers of MD5 hashing to slow down the process and make it unfeasible to brute force, if I recall.

(Not that you shouldn't change your password if it's overly simple, though.)


Top
 Profile WWW YIM 
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 7:55 am 
Sorceror of Saradomin
Sorceror of Saradomin

Joined: June 9th, 2005, 5:04 pm
Posts: 4,086
Location: M-Town (Memphis)
Status: Offline

Donor: Guardian (2009)
Fire_Adept wrote:
Loner wrote:
Someone captured the username option on account profiles it seems like and is running a cracker on the list, so yea nothing we can do now to stop it, just hope you dont have a dictionary or other easy pass and change it now.


And how exactly does one's username allow access to their password? Security doesn't work that way; if you mean trying to brute-force passwords, the server isn't going to allow very many requests before it starts requesting CAPTCHAs. The only attack vectors here are using easily guessable passwords or using the same password on a compromised site that doesn't secure its passwords. The forum software here uses per-user salting with several layers of MD5 hashing to slow down the process and make it unfeasible to brute force, if I recall.

(Not that you shouldn't change your password if it's overly simple, though.)


lurn2crack

you use https proxys, which you can easily find large lists of them online. The program works like this, it has a username list, password list, proxy list, it starts on proxy #1 and goes to username #1 with pass #1 and it then goes down list of passes, after it reaches end of the pass list it goes down to the next username, if the program encounters a captcha is switches proxy. Eventually when you run out of proxys the first one has been past the hour security thingy for logging in or however long it is and it starts over, any succesful logins are recorded.

__________________
Image
Priest of Saradomin as of Thu Feb 16, 2006 8:46 am
I'm the 465th person to get 1000th posts!


Top
 Profile
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 8:14 am 
Tweaking all the time
Staff Elder
Staff Elder
User avatar

Joined: July 5th, 2003, 7:13 am
Posts: 8,699
Location: Flanders (northern Belgium)
Gender: Male
Status: Offline

Donor: Knight (2012)
Friend of Hiker
After 2 incorrect attempts at logging in on an account on RuneVillage, the board requires the completion of a CAPTCHA indeed. To counter-act against proxies and automated bot-farms, the CAPTCHA will always need to be filled in when you try to log in, even if you weren't the one who failed to login twice.

It's annoying, but it's the only efficient way to deter password guessing.

Also, Fire_Adept is right about the MD5 hashing and salting.

We've been making it as hard as possible to harvest nicknames by making the userlist unavailable for newly registered users. But there are only so many things that you can do against it all since we don't want to break the feature itself either.

Greetings,
Glodenox

__________________
XML, SOAP, XSLT, JavaScript, SQL, Java, CSS, PHP, Scheme, JSP, C#, ASP.NET, VB.NET, PL/SQL, Visual Basic 6.0, C/AL and C (sorted well to less known).


Top
 Profile WWW 
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 8:45 am 
Captain of DOOP Starship
Village Elder
Village Elder
User avatar

Joined: January 12th, 2004, 5:37 pm
Posts: 7,020
Location: Massachusetts, US
Gender: Male
Status: Offline

Donor: Prince (2010)
Yeah last week I tried to login and it said I maxed out on login attempts...

__________________
Image

Painting by mousersix.


Top
 Profile WWW 
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 11:10 am 
Village Elder
Village Elder
User avatar

Joined: November 15th, 2003, 8:43 pm
Posts: 4,850
Location: !!!!CANADA!!!!
Gender: Male
Status: Offline
i had my rs, email, and rv accounts hacked into just a 2 days ago, everything is good now, but something fishy is going on

__________________
Image


Top
 Profile
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 12:10 pm 
Priest of Saradomin
Priest of Saradomin
User avatar

Joined: December 19th, 2002, 2:36 pm
Posts: 1,672
Gender: Female
Status: Offline

Donor: Princess (2010)
Friend of Hiker
Loner wrote:
Fire_Adept wrote:
Loner wrote:
Someone captured the username option on account profiles it seems like and is running a cracker on the list, so yea nothing we can do now to stop it, just hope you dont have a dictionary or other easy pass and change it now.


And how exactly does one's username allow access to their password? Security doesn't work that way; if you mean trying to brute-force passwords, the server isn't going to allow very many requests before it starts requesting CAPTCHAs. The only attack vectors here are using easily guessable passwords or using the same password on a compromised site that doesn't secure its passwords. The forum software here uses per-user salting with several layers of MD5 hashing to slow down the process and make it unfeasible to brute force, if I recall.

(Not that you shouldn't change your password if it's overly simple, though.)


lurn2crack

you use https proxys, which you can easily find large lists of them online. The program works like this, it has a username list, password list, proxy list, it starts on proxy #1 and goes to username #1 with pass #1 and it then goes down list of passes, after it reaches end of the pass list it goes down to the next username, if the program encounters a captcha is switches proxy. Eventually when you run out of proxys the first one has been past the hour security thingy for logging in or however long it is and it starts over, any succesful logins are recorded.


Learn how rs works, you can only have 6 failed login attempts before you cannot try again for 5 minutes, this is based per account, not per ip. Thats 7200 password attempts per day, there are over 250000 words in the english dictionary alone, even brute force could take days/weeks/months to guess even an easy password, which I hope no-one uses anymore.

__________________
ImageRunevillage member #46

Image


Top
 Profile YIM 
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 2:46 pm 
Hello Ladies.
Village Staff
Village Staff
User avatar

Joined: October 14th, 2009, 3:38 pm
Posts: 3,025
Gender: Male
Status: Offline
Someone tried to hack into my RV account and failed, certain problems arosse (sp?) for me, but now it is sorted.

Much Love Glodenox <3

__________________
Image Image Image Image
Image

There are 10 types of people in the world, the ones that understand binary, and the ones that don't.

Thanks Lou for the help with the avatar.


Top
 Profile
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 6:12 pm 
Sorceror of Saradomin
Sorceror of Saradomin

Joined: June 9th, 2005, 5:04 pm
Posts: 4,086
Location: M-Town (Memphis)
Status: Offline

Donor: Guardian (2009)
Flick wrote:
Loner wrote:
Fire_Adept wrote:
Loner wrote:
Someone captured the username option on account profiles it seems like and is running a cracker on the list, so yea nothing we can do now to stop it, just hope you dont have a dictionary or other easy pass and change it now.


And how exactly does one's username allow access to their password? Security doesn't work that way; if you mean trying to brute-force passwords, the server isn't going to allow very many requests before it starts requesting CAPTCHAs. The only attack vectors here are using easily guessable passwords or using the same password on a compromised site that doesn't secure its passwords. The forum software here uses per-user salting with several layers of MD5 hashing to slow down the process and make it unfeasible to brute force, if I recall.

(Not that you shouldn't change your password if it's overly simple, though.)


lurn2crack

you use https proxys, which you can easily find large lists of them online. The program works like this, it has a username list, password list, proxy list, it starts on proxy #1 and goes to username #1 with pass #1 and it then goes down list of passes, after it reaches end of the pass list it goes down to the next username, if the program encounters a captcha is switches proxy. Eventually when you run out of proxys the first one has been past the hour security thingy for logging in or however long it is and it starts over, any succesful logins are recorded.


Learn how rs works, you can only have 6 failed login attempts before you cannot try again for 5 minutes, this is based per account, not per ip. Thats 7200 password attempts per day, there are over 250000 words in the english dictionary alone, even brute force could take days/weeks/months to guess even an easy password, which I hope no-one uses anymore.


Well I apologize, in the past it was not based on account, but per IP.

__________________
Image
Priest of Saradomin as of Thu Feb 16, 2006 8:46 am
I'm the 465th person to get 1000th posts!


Top
 Profile
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 15th, 2011, 8:32 pm 
Level 0
Village Elder
Village Elder
User avatar

Joined: May 13th, 2004, 6:41 pm
Posts: 18,969
Location: The Tower of Mist
Status: Offline

Donor: Wizard (2013)
Friend of Hiker
That's creepy. I haven't gotten anything from Jagex, and nothing on my RV account either, although several months ago I had to fill in a Captcha a few days in a row, now that I think about it.

I do use the same password for a lot of trivial things, though (though my RS and RV passwords are unique to themselves.) Ever since XKCD posted this comic, I've made sure the important passwords (like banks and stuff) are unique. It's scary but true! :P

Image

__________________
Image

.
Image

.
Legendary themed months are back! Maybe.
Image
!!!!!!!!!!!!!!!!!!!!!!!!


Top
 Profile WWW 
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 16th, 2011, 1:08 am 
Hello Ladies.
Village Staff
Village Staff
User avatar

Joined: October 14th, 2009, 3:38 pm
Posts: 3,025
Gender: Male
Status: Offline
Only thing i can think that we all definately came into contact with was the RS Radio o_O. But i doubt it's that alot.

__________________
Image Image Image Image
Image

There are 10 types of people in the world, the ones that understand binary, and the ones that don't.

Thanks Lou for the help with the avatar.


Top
 Profile
 

 Post subject: Re: Rvers been targetting for hacking?
PostPosted: February 16th, 2011, 8:44 am 
Queen of Runevillage
Sorceror of Saradomin
Sorceror of Saradomin
User avatar

Joined: September 1st, 2005, 2:13 pm
Posts: 3,459
Location: On an Island
Gender: Male
Status: Offline
Never trusted those guys.

__________________
Image
Struggle is Nature's way of strengthening it.


Top
 Profile
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  Page 1 of 3
 [ 44 posts ] 
Go to page: 1, 2, 3  Next »  Page:

All times are UTC - 6 hours


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Jump to:  

Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
The Village and this web site are © 2002-2012

ThePub 2.0 - Designed by Goten & Jackstick. Coded by Glodenox & Henner.
With many thanks to the Website Team!