News:

Forum changes: Editing of posts has been turned off until further notice.

Main Menu

password security

Started by Paul Czege, March 10, 2005, 08:51:55 PM

Previous topic - Next topic

Paul Czege

Hey Clinton,

The hack could have included a download of user information, right? Are user passwords insecure as a result (i.e. we should change them)?

Paul
My Life with Master knows codependence.
And if you're doing anything with your Acts of Evil ashcan license, of course I'm curious and would love to hear about your plans

Clinton R. Nixon

Quote from: Paul CzegeHey Clinton,

The hack could have included a download of user information, right? Are user passwords insecure as a result (i.e. we should change them)?

Paul

Officially, yes.

The logs, however, do not show any downloading of info. That doesn't mean it didn't happen, and you should change your password if you are security-conscious.
Clinton R. Nixon
CRN Games

Marco

Are passwords stored plain-text by PPBB?

-Marco
---------------------------------------------
JAGS (Just Another Gaming System)
a free, high-quality, universal system at:
http://www.jagsrpg.org
Just Released: JAGS Wonderland

Clinton R. Nixon

Quote from: MarcoAre passwords stored plain-text by PPBB?

-Marco

Nope - they are hashes, which changes everything. I wasn't even thinking of that. In other words, your passwords are pretty safe, unless they are a dictionary word or small variation thereof (shipmate45, for example).

- Clinton
Clinton R. Nixon
CRN Games

Victor Gijsbers

Clinton, which version of phpBB were you running?

Clinton R. Nixon

phpBB 2.0.11. A vital security patch was released on Feb. 28th. I saw someone on RPG.net castigate me for not applying the patch when it was released, and I thought, "What the hell does this kid do with his life? Seven days after release, I haven't upgraded a piece of software - that's not so bad. In fact, I generally have about seven straight days worth of work laid out at any given time."

By the way, it's totally likely that I'll be changing the software from phpBB to something else. If I do, nothing will break - I can rewrite links and whatnot. I've done it before.
Clinton R. Nixon
CRN Games

Domhnall

Just curious-- was there a "disgruntled poster" who you suspect, or did this look just like random malevolence?  Is there a way for you (someone) to trace his IPA?
--Daniel

Clinton R. Nixon

Quote from: DomhnallJust curious-- was there a "disgruntled poster" who you suspect, or did this look just like random malevolence?  Is there a way for you (someone) to trace his IPA?

It was random malevolence. I have the IP address, but am not going to try and figure out who did it.
Clinton R. Nixon
CRN Games