The Cathedral of Attnam

Iter Vehemens ad Necem (IVAN)
Login
Username
Password


 Valid CSS  Valid HTML 4.01 Strict

Security Update

The Cathedral of Attnam  >  Website News
Print

View profile
Send messageSend email
Find posts Find topics
 
Jul 11, 2011 at 4:27 am #1  !
capristo's Avatar
capristo
The Imperialist


Joined: Dec 2, 2007
Location: New Attnam
Interests: bananas
Posts: 1227
Groups:
Security Update
As I explained briefly earlier, the reason the hacker was able to retrieve some people's passwords was that they were encrypted using MD5 (because phpBB, the old forum software, also used it), which is susceptible to rainbow table attacks.

We're now using a much stronger encryption algorithm (SHA1 + a unique salt, looped multiple times).

I can now 99.9999999% guarantee that even if somebody were to get access to both the encrypted passwords and our unique salt, there is no way they could convert them into the unencrypted original values.

So, go change your password, esp. if you were on the list of people targeted earlier. After you change it you'll have to log in again.

The forum isn't safe yet, but I promise your passwords are.
 
 
View profile
Send message
Find posts Find topics
 
Jul 11, 2011 at 8:10 am #2  !
Somagu's Avatar
Somagu
He Who Scars


Joined: Dec 4, 2007
Occupation: Magical Pâtissier
Location: Lost Worlds
Interests: クッキングですの!
Posts: 824
Groups:
Well, thanks Cap.
 
image
Proudly bringing disaster and mental scarring to Attnam since '05!
 
View profile
Send message
Find posts Find topics
 
Jul 11, 2011 at 1:29 pm #3  !
chaostrom
Mage Prophet


Joined: Dec 3, 2007
Occupation: Standing between all life and death.
Posts: 2094
Groups:
Indeed. Much appreciated.
 
image HEADBUTT
 
View profile
Send message
Find posts Find topics
 
Jul 11, 2011 at 7:15 pm #4  !
Eagle V's Avatar
Eagle V
archangel


Joined: Nov 22, 2008
Interests: IVAN
Posts: 839
Groups:
Thanks!
 
Beware! 'tis EagleV, Hardcore Weaver of Baskets!
 
View profile
Send message
Find posts Find topics
 
Jul 11, 2011 at 7:32 pm #5  !
BDR-bugged
hedgehog


Joined: Jul 6, 2011
Posts: 7
Thanks very much for the update and for fixing it!
 
 
View profile
Send messageSend email
Find posts Find topics
 
Jul 19, 2011 at 1:27 pm #6  !
capristo's Avatar
capristo
The Imperialist


Joined: Dec 2, 2007
Location: New Attnam
Interests: bananas
Posts: 1227
Groups:
Another update - some of you might have noticed we had another white-hat hacker. The problem was that some of my code allowed for SQL injection, which is a really simple problem to fix, but something I hadn't taken the time to clean up yet. Again, this is the result of having years-old code, and I knew the problem was there but I figured with custom code we'd be safe until I finished rewriting the entire site. Stupid mistake.

Well, unlike the other one, this guy was actually helpful since he created an account and I was able to email him. He double checked the loophole he had found earlier and said it was fixed. Of course I won't feel completely comfortable until I'm done rewriting the code, but for now, at least the easy ways in are closed.

And now we just have to figure out why everything always seems to break with BDR...
 
 
View profile
Send message
Find posts Find topics
 
Jul 20, 2011 at 4:41 am #7  !
chaostrom
Mage Prophet


Joined: Dec 3, 2007
Occupation: Standing between all life and death.
Posts: 2094
Groups:
Break Down Risk
 
image HEADBUTT
 
View profile
Send message
Find posts Find topics
 
Jul 28, 2011 at 4:35 am #8  !
Somagu's Avatar
Somagu
He Who Scars


Joined: Dec 4, 2007
Occupation: Magical Pâtissier
Location: Lost Worlds
Interests: クッキングですの!
Posts: 824
Groups:
Ahem...
 
image
Proudly bringing disaster and mental scarring to Attnam since '05!
 
 Print


The Cathedral of Attnam  >  Website News  >  Security Update

Jump to