Go to page 1, 2  Next  [ 29 posts ]  Reply to topicPost new topic 
Author Message
 [us]
 Post subject: Regarding weak passwords
PostPosted: Mon Dec 31, 2012 8:37 pm 
User avatar
Goodbye.
Member
[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
This is being posted in regards to a recent vandalism attempt on a user. They were spotted in the User Control Panel, caught via the online user list. Thankfully there was a moderator online to stop this before any damage could be done, but the situation could have easily been worse. The troublemaker was able to easily get in because he made a valid guess at the user's password, which was a very weak one.

If you value your account, you should do the following:

1. Use a strong password consisting of numbers, lowercase and capital letters, and symbols.
Here is a password generator that may help. http://www.passwordcard.org/en (thanks Mason!)

2. Keep it as random as possible, and at least 8 characters. Write it down, and do not lose it. NEVER give your password out to anyone.

3. Try not to use the same password for multiple locations online.

These simple steps can help you avert an attack on your user accounts.

Take note that by the time a troublemaker is spotted, he could have done pretty much anything with your account. Remember that you and only you are responsible for your account! That is all.


Last edited by Miles on Thu Jan 03, 2013 11:14 am, edited 5 times in total.
Clarification: Fixed a few terms, slightly rephrased it.

_________________
When the prey has gone extinct, the hunter must seek another bounty to feed.
 
Top
Offline 
 User page at mfgg.net
 
 [us]
 Post subject: Re: Regarding weak passwords
PostPosted: Mon Dec 31, 2012 10:33 pm 
User avatar
Always have a Shy-Guy in your avatar
Administrator
[A]
[S]
[W]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

Moving this to News so more people will see it. Please read and heed this message - it's important.

_________________
Course clear! You got a card.

Image
 
Top
Offline 
 User page at mfgg.net
 
 [ca]
 Post subject: Re: Regarding weak passwords
PostPosted: Mon Dec 31, 2012 11:18 pm 
User avatar
следующая игра скоро будет
Dairy
[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
Out of curiosity, who was hacked? I understand if you feel if it would violate their privacy (even though I don't necessarily agree with that choice in this particular case), but I have to wonder regardless.

 
Top
Offline 
 User page at mfgg.net
 
 [jp]
 Post subject: Re: Regarding weak passwords
PostPosted: Mon Dec 31, 2012 11:26 pm 
User avatar
Yeah, I don't Even...
Member
[*]
[*]
[*]
[*]
[*]

[*]
^Same

_________________
Spoiler:
 
Top
Offline 
 User page at mfgg.net
 
 [us]
 Post subject: Re: Regarding weak passwords
PostPosted: Tue Jan 01, 2013 4:21 am 
Member
[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
The user in question wishes to remain anonymous. I see no good reason to break this wish.

_________________
"talk about dang ol' this ain't scientific rockets, man"
Spoiler:
Bibby Team - Nice little place. Give it a try.
 
Top
Offline 
 User page at mfgg.net
 
 [au]
 Post subject: Re: Regarding weak passwords
PostPosted: Tue Jan 01, 2013 5:43 am 
User avatar
Metal Mario's Rejected Brother
Member
[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
Who was the hacker?

_________________
Here, have a goomba:

Image Image
 
Top
Offline 
 User page at mfgg.net
 
 [us]
 Post subject: Re: Regarding weak passwords
PostPosted: Tue Jan 01, 2013 11:40 am 
User avatar
Goodbye.
Member
[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
CopperMario wrote:
Who was the hacker?

The hacker was hiding behind a Proxy, unfortunately, we actually don't know who exactly it was.
the proxy was common among spam bots, and has been banned from accessing these forums to prevent future attacks from said individual.

Fact of the matter is however:
This happened, and precautions should be taken to prevent such from happening in the future.

Rystar wrote:
Out of curiosity, who was hacked? I understand if you feel if it would violate their privacy (even though I don't necessarily agree with that choice in this particular case), but I have to wonder regardless.


Shadow Kami wrote:
^Same


for this, i quote what miles said.
Miles wrote:
The user in question wishes to remain anonymous. I see no good reason to break this wish.


Also, revealing their name may attract future attack attempts on their account.
Im sorry. That is a security risk we simply do not need.

_________________
When the prey has gone extinct, the hunter must seek another bounty to feed.
 
Top
Offline 
 User page at mfgg.net
 
 [jp]
 Post subject: Re: Regarding weak passwords
PostPosted: Tue Jan 01, 2013 12:50 pm 
User avatar
Yeah, I don't Even...
Member
[*]
[*]
[*]
[*]
[*]

[*]
That's Understandable.

_________________
Spoiler:
 
Top
Offline 
 User page at mfgg.net
 
 [us]
 Post subject: Re: Regarding weak passwords
PostPosted: Tue Jan 01, 2013 11:47 pm 
User avatar
Mario Females Supporter... full force!
Member
[*]
[*]
Just saw this and I can not believe what I'm hearing. At least it tells us to take action now to keep our respective accounts secure from any more hacking attempts (heaven forbid that we get any more hacking attempts at all).

_________________
M. C. - Dedicated supporter of the Mario females full force!
---------------------------------------------------------------
Specializing in doing fangame projects featuring the Mario females in lead role territory as well!
---------------------------------------------------------------
Projects In Development - Super Princess Peach: Operation - Toad Rescue (Images coming soon, and more ideas in the concept stages!)
 
Top
Offline 
 User page at mfgg.net
 
 [us]
 Post subject: Re: Regarding weak passwords
PostPosted: Wed Jan 02, 2013 12:18 am 
User avatar
Goodbye.
Member
[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
Mason wrote:
Here's a random password generator thingy that might be of interest: http://www.passwordcard.org/en

(literally just found out about it a few days ago, thanks Xgoff)

Nite Shadow wrote:
Use a strong password consisting of numbers, lowercase and capital letters, and symbols.

2c@nz4Lyf3


Excelent!
Ive added this to the top post. Thanks mason!

lol, toucans for life.

Merit Celaire wrote:
Just saw this and I can not believe what I'm hearing. At least it tells us to take action now to keep our respective accounts secure from any more hacking attempts (heaven forbid that we get any more hacking attempts at all).


Hopfully people heed this post, and take precautions.

_________________
When the prey has gone extinct, the hunter must seek another bounty to feed.
 
Top
Offline 
 User page at mfgg.net
 
 [ca]
 Post subject: Re: Regarding weak passwords
PostPosted: Wed Jan 02, 2013 7:54 pm 
User avatar
следующая игра скоро будет
Dairy
[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
Miles wrote:
The user in question wishes to remain anonymous. I see no good reason to break this wish.

Nite Shadow wrote:
Also, revealing their name may attract future attack attempts on their account.
Im sorry. That is a security risk we simply do not need.


Understood. Sorry for the trouble ^^

 
Top
Offline 
 User page at mfgg.net
 
 [us]
 Post subject: Re: Regarding weak passwords
PostPosted: Wed Jan 02, 2013 9:12 pm 
User avatar
Goodbye.
Member
[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
Rystar wrote:
Understood. Sorry for the trouble ^^


No harm done,

Are their any more questions?

_________________
When the prey has gone extinct, the hunter must seek another bounty to feed.
 
Top
Offline 
 User page at mfgg.net
 
 [us]
 Post subject: Re: Regarding weak passwords
PostPosted: Thu Jan 03, 2013 9:34 am 
User avatar
I'll be your 1-Up boy.
Social Media Manager
[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
Just want to clarify that password guessing or informed password guessing (as in the user fell for a phishing attempt or gave their password to someone) shouldn't really be labeled hacking. If someone is able to hack into your account or computer, the password isn't going to stop them from doing so. By misusing the word hack in this situation, you're giving people false comfort that may lead them to believe other standard protections against hacking aren't necessary (such as regular virus/spyware/adware scans or not clicking links in suspicious emails).

I think the specific method in which the intruder gained anonymous' password is important information and that you should include it.

_________________
also known as SonicProject
 
Top
Offline 
 User page at mfgg.net
 
 [us]
 Post subject: Re: Regarding weak passwords
PostPosted: Thu Jan 03, 2013 11:35 am 
User avatar
Goodbye.
Member
[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
Pedigree wrote:
Just want to clarify that password guessing or informed password guessing (as in the user fell for a phishing attempt or gave their password to someone) shouldn't really be labeled hacking. If someone is able to hack into your account or computer, the password isn't going to stop them from doing so. By misusing the word hack in this situation, you're giving people false comfort that may lead them to believe other standard protections against hacking aren't necessary (such as regular virus/spyware/adware scans or not clicking links in suspicious emails).

I think the specific method in which the intruder gained anonymous' password is important information and that you should include it.


you might have a point,
some of the wording in the top post has been fixed. (Thanks Miles)

_________________
When the prey has gone extinct, the hunter must seek another bounty to feed.
 
Top
Offline 
 User page at mfgg.net
 
 [ca]
 Post subject: Re: Regarding weak passwords
PostPosted: Thu Jan 03, 2013 5:16 pm 
User avatar
The Goomba Guy
Member
[*]
[*]
[*]
Has the user been notified of the attack? From a Privite Message that was send by an administrator?


Last edited by MagikGames on Thu Jan 03, 2013 5:35 pm, edited 1 time in total.
_________________
Image
 
Top
Offline 
 User page at mfgg.net
 
 [us]
 Post subject: Re: Regarding weak passwords
PostPosted: Thu Jan 03, 2013 5:24 pm 
User avatar
Goodbye.
Member
[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
[*]
[*]

[*]
[*]
mario4513 wrote:
Has the user been notified of the attack?

Yes.

_________________
When the prey has gone extinct, the hunter must seek another bounty to feed.
 
Top
Offline 
 User page at mfgg.net
 
 [tn]
 Post subject: Re: Regarding weak passwords
PostPosted: Wed Jan 09, 2013 10:41 am 
User avatar
They Seeme Rawlin' Dey Hatein'
Member
[*]
[*]
I think i found a way to show password strength through UCP, Admins, use this Plugin.
https://www.phpbb.com/customise/db/mod/ ... _strength/

_________________

 
Top
Offline 
 User page at mfgg.net
 
 [gb]
 Post subject: Re: Regarding weak passwords
PostPosted: Sat Feb 02, 2013 8:07 am 
User avatar
Member
[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
I know this is sort of old, but I just wanted to kind of mention that if you want a strong password you should just use a sentence made up of 4 or 5 random words.

Also:
FTON wrote:
I think i found a way to show password strength through UCP, Admins, use this Plugin.
https://www.phpbb.com/customise/db/mod/ ... _strength/

This indicator won't show you password strength. 12345qwert!"£$% will show as a very strong password, which it isn't. If you want a good password strength indicator, look at Dropbox's zxcvbn. It recognises logically weak passwords (e.g. ones using keys near to each other, or common words with numbers substituted for letters).

Password strength is tricky, but the XKCD comic that I linked is a good method to follow. It's easy for you to remember, but (if you really use random words, like the "correcthorsebatterystaple" example in the comic) it's almost (and effectively) impossible to crack.

 
Top
Offline 
 User page at mfgg.net
 
 [gb]
 Post subject: Re: Regarding weak passwords
PostPosted: Sun Feb 03, 2013 4:50 am 
User avatar
Lord of the Pies
Member
[*]
I reccomend this site:
http://howsecureismypassword.net/

You type in a password, and it will tell you how secure it is and how long it would take to hack.

 
Top
Offline 
 
 
 [gb]
 Post subject: Re: Regarding weak passwords
PostPosted: Sun Feb 03, 2013 5:59 am 
User avatar
Member
[*]
[*]
[*]
[*]
[*]

[*]
[*]
[*]
That site says that qwert12345! is a strong password, so I wouldn't trust it.

EDIT: wow, okay. It also says just running through the letters on the keyboard ("qwerty...asdfgh...") is a very secure password and would take "48 quintillion years" to crack on a desktop PC (which is a useless comparison anyway, since it won't be done on a single desktop).

This is a much better password strength indicator. It's an implementation of zxcvbn that I linked just before. It shortens that 48 quintillion years estimate down to a realistic 7 hours.

 
Top
Offline 
 User page at mfgg.net
 
« Previous topic | Next topic »
Display posts from previous:  Sort by  
Go to page 1, 2  Next  [ 29 posts ]  Reply to topicPost new topic 


Who is online

Users browsing this topic: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum
Jump to:  
cron
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group