CheckEmoji Community · the emoji forum
🏠 Home 🆕 What's new ❓ Unanswered 🔥 Popular 📡 RSS Members 👥 0 online log in · register
Home › Miscellaneous › Forum Help! › Has there been a security breach on the forum?

Has there been a security breach on the forum?

Started by Megan Thomas5 · · 👁 8 views · 49 replies

📡 Subscribe to replies

Participants Megan Thomas5Alexander Diaz4coppersailor28Jessica Morris6Casey BennettGeorge Cook31Jack Cook7wearybison63Bradley White73urbanheron4Jose Miller3mistybisoncrimsonhound80silentviper8Matthew Jackson2
mistybison mistybison Regular
495 messages
joined Aug 2008
#41 ·
crimsonhound80 said:It’s nearly impossible to break into someone else's profile if they use a password like 4r%Zi9$"Gr..
The rest is just fairy tales.
The only way is if someone gets hold of the email you used to register on this forum... then maybe a Trojan or some other nonsense could reveal all your passwords...

Don't worry, colleague... @mistybison/">@@mistybison 😉

The email address on my current profile was deleted long ago; even I can't access it, let alone anyone else. 😁

I am intentionally not updating it to a valid one because I love the ability to change my password to something I won't remember, effectively locking myself out. It's self-banning. 🙂 😁

On social media, it's always best to use secondary email addresses specifically created for those purposes rather than your primary ones.

I opened a backup profile so that if anything happens, I can contact Nice. I can't use the ban corner because the main subforum is one of the areas where I requested a partial ban. 🤣

Then again, if something does happen, perhaps it's just a message from the universe: "Don't come back to the forum!" 😁
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#42 ·
mistybison said:All my passwords look like some massive snake made of twenty random numbers and mixed-up letters, and I can't remember a single one of them. 😁

So why don't you just write it on your monitor? 🤔

Just kidding. Don't actually do that. 🤣

Maybe I'll throw in some special characters next time I update my passwords. 🤔 😁

Man, people just use lyrics from their favorite song that they've got memorized.

By the way, the forum keeps logging me out whenever I try to post a comment. 😁

Been dealing with this for 14 years now, every single day. It’s probably a web server timeout issue.
If you check that "remember me" box during login, the web server or front end caches your password locally. Then it basically tries to auto-retry every time you interact with anything external—it acts like an agent for you without any actual verification, which is honestly pretty sketchy. If you log out, make sure you clear your cache too (at least, that's what I think you should do).

And don't get any bright ideas about security here—the whole HTTP communication with this site is just straight-up plain HTTP. That means your precious password is being sent over as raw ASCII text. In other words, any script kiddie sitting on a device between your PC and the web server could sniff out your super complex password. Like, even that cheap router your ISP gave you, which everyone knows still uses the default password. 🙂
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#43 ·
silentviper8 said:SQL injection... man, that’s some old-school hacking right there. It’s like a classic move that just refuses to die. Honestly, it still works like a charm on those clunky, outdated web apps out there. I know because, uh, yeah... I've definitely pulled it off myself before. ☕

Yeah, but... let's not get too carried away here.

Man, mobile apps are the new frontier for hackers. It’s wild. They just drop some "free" version of a popular app out there—you know, the kind everyone rushes to download because they want the premium features for zero dollars—and boom, you've got a keylogger running right in your pocket. Or they just find a massive hole in a super famous app that everyone uses daily and use it as a backdoor to scrape all your private data. It's getting crazy out there.

Whatever, man. There are tons of ways to pull it off.

Look, hashes aren't impossible to crack. It’s not like they're some unbreakable magic spell. You just gotta give it enough time. Slow and steady wins the race, right? 🙂

Look, MD4 was cracked ages ago, and MD5? Yeah, that's toast too. It’s just a bit more of a grind to find a collision, but still totally doable. As for SHA1, that one's officially busted as well—you just need some serious hardware to pull off a specific attack. We're talking like, a few thousand processors running at once. Honestly, it’s basically the exact same deal as mining crypto. 🤔
mistybison mistybison Regular
495 messages
joined Aug 2008
#44 ·
Jack Cook7 said:Well, why don't you just write it on your monitor then? 🤔

A practical detail from experience.🤣

I keep my passwords saved in documents and across several different locations, but more importantly, I have them memorized and synced to my main Gmail account (specifically via my Google profile for Chrome). I don't do that for this forum, though, because one way to spend less time here is to make access difficult. This forum is actually on my blocked sites list, so first I have to unblock the site, then find the password for the profile, and then copy it... It isn't much, but it prevents you from wasting too much time here. 😁

You have to check the "remember me" box during login; then the web server/front end caches the password locally, which performs an auto-retry during every external interaction—essentially acting as an agent on your behalf without verification, which isn't ideal. Once you log out, make sure to clear the cache (at least, I believe that's how it works).

That used to help for a while, but even that hasn't been effective for quite some time... However, there is a better way. 🙂 It is an excellent method for breaking a forum habit. 😍

Don't be under any illusions; all HTTP communication with the American forum site is pure HTTP, meaning your valuable password is transferred as plain ASCII text. In other words, any amateur hacker who gains access to any device sitting between your PC and the forum's web server can read your complex password—for example, that cheap router provided by your ISP that everyone uses the same default password for. 🙂

That is truly unfortunate. 😢

In that case, the safest move is to request a temporary ban. 🤔 Even if a hacker manages to get into the profile, they won't be able to do anything except look at an email address that doesn't exist. 😁

(It already logged me out for the second time...)
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#45 ·
mistybison said:I keep my passwords saved in documents and scattered across a few different spots, but more importantly, I have them memorized and synced to my main Gmail account. Not for this forum, though—that’s actually one way I try to spend less time hanging out here. This forum is actually on my blocked sites list, so first I have to unblock the site, then hunt down my profile password, and then copy it over... It’s not much, but it stops me from wasting too much time here. 😁

Heh, so you're keeping passwords for other services on Gmail, which by definition and their own "Contract Agreement" gives them the right to dig through your emails and data and hand it off to random third parties without even asking you?
Man, oh man... 🙂

It used to help for a while, but even that hasn't really worked lately... But hey, even better. 🙂 Great way to break the forum habit. 😍

Haha, some people have actually asked me to just uninstall their web browser for them. 😬

That is just so sad. 😢

In that case, the safest move is to request a temporary ban. 🤔 Even if a hacker gets into your profile, they can't do anything except read an email address that doesn't even exist. 😁

(The site already logged me out for the second time today...)

Alright, jokes aside. There are these little tools called password managers that can handle hundreds of passwords. You only need one master password to access everything, and when you click an entry, it logs you right in. I won't get into the whole security deep dive here—this won't fix the security issues with HTTP access on this forum—but it will stop you from having to keep hundreds of passwords scattered all over the place.
Essentially, it's like having your own personal offline Directory service.
mistybison mistybison Regular
495 messages
joined Aug 2008
#46 ·
Jack Cook7 said:So, you're storing passwords for other services on Gmail? According to their Contract Agreement, they basically reserve the right to scan your emails and data, potentially sharing it with third parties without your consent.
Hey there, hey there...🙂

It’s definitely going to be a hit at my place! 😂

I don't store my passwords in Gmail; instead, I let Chrome handle them through my Google profile.

Using a Google profile is incredibly practical and efficient. It syncs everything automatically, so if you ever need to factory reset your device or upgrade to a new one, the entire setup process handles itself. 😍

I realize this might seem superficial, but conformity often takes precedence over actual security. 😁 To be honest, I don't really have anything significant or private stored on my online profiles. Most of them are just used for reading or playing games.

Haha, a few people actually asked me to uninstall their web browser for them. 😬

I decided to take several screenshots of the specific threads that prompted me to jump into the discussion or simply got under my skin. 😁 If I can't contribute to the conversation, I lose interest in reading it too. I'll probably just pop in once every few weeks to see if there’s anything interesting new on the Television and Movie boards, and that's about it.

All jokes aside, you should really look into using a password manager. These programs can handle hundreds of credentials, requiring you to remember just one master password to access everything; once you select an entry, it handles the login process for you. I won't dive into the technical security implications here—that won't solve the underlying HTTP security issues for this forum—but it will definitely stop you from having to keep hundreds of passwords written down on scraps of paper.
It’s essentially a personal offline directory service.

I'll look into that, thanks for the heads-up. 🙂
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#47 ·
mistybison said:Man, this is gonna be awesome for me! 😂

Having a Google profile is super handy and useful because it pulls everything along with it. If you ever have to factory reset a device or just pick up a new phone—it handles everything automatically. 😍

Let me highlight at least one way Google actually profits from getting access to your passwords.

By analyzing your passwords, they get a statistical sample of how you build them. That makes it way easier for them to crack them, even if you've sent those credentials through other channels.

And why on earth would Google do that?

For the money. Period.

Google has basically forced itself into being the main Directory service, Facebook is totally in bed with them, Apple stays separate but still swaps data. And Twitter just broke away.

What most people see as just social media sites or public services, I see as one giant, unified information-gathering machine.

All your hard work making "strong" passwords is pretty much pointless, no matter how secure your communication channel is. You’ve got random script kiddies on some shady forum running brute force attacks on passwords like "password123" or whatever. Real elite hackers right there.
mistybison mistybison Regular
495 messages
joined Aug 2008
#48 ·
Jack Cook7 said:Let me highlight at least one advantage Google gains from accessing your passwords.

By analyzing your passwords, they build a statistical profile of how you construct them, making it much easier to crack them—even if you've shared them through other channels.

And why would Google do this?

For the money.

Google has positioned itself as a primary Directory service; Facebook is in league with them, Apple operates separately but still swaps data, and Twitter has just branched off.

What most people see as individual social media platforms and public services, I view as a single, unified information-gathering system.

Any effort you spend on password quality is essentially meaningless, regardless of how secure your communication channel might be. There are plenty of low-level hackers out there using brute force attacks on simple passwords like "pump_up" or similar nonsense. They aren't exactly elite teams.

I don't believe it's truly possible to protect your privacy online, and if you only use the web for entertainment, I'm not sure how much sense it makes to stress over it too much. 🤷

(It logged me out for the third time... 😠 )
Jack Cook7 Jack Cook7 Regular
376 messages
joined Aug 2017
#49 ·
mistybison said:I don't think it’s actually possible to stay private online, and if you’re just using it for fun—I don't even know how much sense it makes to stress over it too much. 🤷

(Third time it's logged me out today... 😠 )

Look, putting privacy aside, thinking the Internet is *just* a source of entertainment is pretty naive.

It's kind of like how our distant, super cute but totally nameless ancestors used to wander around trying to entertain themselves by tossing useless bones at each other.


And lo and behold, two million years later...

And hey, don't say I didn't warn ya! 🙂
Matthew Jackson2 Matthew Jackson2 Active Member
146 messages
joined Jan 2016
#50 ·
Jack Cook7 said:Well, not exactly, because passwords aren't actually stored in the database in their original plain-text form; they're hashed using MD5 or SHA1/128/256 or whatever else.

So, even if you somehow manage to get your hands on the password database, you wouldn't be able to just log in using those strings. That’s literally what hashing is designed to prevent.

To be honest, MD5 is about as secure as a screen door on a submarine, and while the SHA algorithms are a step up depending on which version you're looking at, by today's modern standards, none of them are really adequate for actual protection.

I'm not entirely sure what specific stack this particular forum is running, but back in the day, vBulletin used to rely on double MD5—where you hash the password, add a salt, and then hash it all over again. While that does technically kill off pre-calculated attacks, it doesn't actually provide a massive leap in security compared to just using basic MD5 plus a salt. I don't know if they migrated to something more robust later on, but whenever I hear someone on a support desk claiming that double MD5 is significantly more secure than standard salted MD5, it immediately sets off red flags for me. It feels like tech-babble meant to soothe people who don't know better.

Furthermore, we have to consider that SQL injection attacks don't necessarily require someone to read a password to be successful. If an attacker can extract enough information to forge a "remember me" cookie, they can bypass the login process entirely without ever needing to touch a single password string.

In some poorly architected systems, it might even be possible to change a password through such a vulnerability, though the downside there is that the user usually realizes they've been compromised once they find themselves locked out of their own account.

There's also the issue of other potential attack vectors, like advertisements. If they aren't implemented correctly—and I've personally dealt with a few incidents on various US message boards where ads caused malicious redirects because they weren't properly sandboxed—they can end up having access to data they should never have been touching in the first place.

You must log in or register to reply here.

Log in Register

🔗 Similar threads