Forum

> > Unreal Software > Report - USGN hacker (stolen account)
ForenübersichtUnreal Software-ÜbersichtEinloggen, um zu antworten

Englisch Report - USGN hacker (stolen account)

50 Antworten
Seite
Zum Anfang Vorherige 1 2 3 Nächste Zum Anfang

alt Re: Report - USGN hacker (stolen account)

GeoB99
Moderator Off Offline

Zitieren
So, the scenario regarding CY's situation was actually true. user Sparty sent me the PM (as you can check in his first post above in the spoiler) however I thought the U.S.G.N. ID was actually faked and not necessarily stolen. It's time to sharp my eyes for once and check the accounts - the situation seems not quiet well.

• Edit: Few accounts were stolen by the same IP, I permanently banned them to avoid suspicious activities.
1× editiert, zuletzt 19.07.16 09:35:09

alt Re: Report - USGN hacker (stolen account)

DC
Admin Off Offline

Zitieren
Unfortunately I don't know how he managed to get control over these accounts. If anyone knows it please let me know.

Everyone should please keep in mind that secure passwords are crucial because they are the only thing protecting your accounts. Choose long passwords with many different characters.

Also never use the same passwords anywhere else. Especially not for the connected e-mail address. Using the same password for multiple sites/services makes you extremely vulnerable.

alt Re: Report - USGN hacker (stolen account)

MikuAuahDark
User Off Offline

Zitieren
@user DC: Maybe it's related to recent ImageMagick vulnerabilities where the attacker uses specially crafted MVG files (renamed as PNG or JPG to bypass extension detection) to create reverse shell, but I doubt that. I tried to use that vulnerabilities (for testing) in avatar page but it doesn't work and the server expects JPG/PNG. Maybe it does in file archive?

It's just my speculation, so I doubt this is related.

alt Re: Report - USGN hacker (stolen account)

Rainoth
Moderator Off Offline

Zitieren
us.de --> your monthly source of drama

Jokes aside, saying my brother did this and that is no valid excuse. I tried it too at some point (The casual "my brother cheated" excuse) and it didn't work out. Sucks but that's the way the world works, kiddo - you do illegal stuff, you get punished.

P.S. user Starkkz I kinda feel ashamed about thinking only of reviewer stuff and not thinking about user CY's files themselves. Glad you sorted it out.

alt Re: Report - USGN hacker (stolen account)

Yates
Reviewer Off Offline

Zitieren
My brother actually registered an account and started to spam to get me banned (was a long time ago). I asked Leiche to ban him, never happened again √

Remember kids, if your brother/cousin/friend using your computer actually registers an account here - get it over with and get him banned

@user CY: By the way - check your files to see if you edited any recently and thoroughly check the content.

alt Re: Report - USGN hacker (stolen account)

CY
Reviewer Off Offline

Zitieren
@user SmD:

IMG:https://i.imgur.com/POxFokf.jpg


Turns out there's more to it. Here are the links to the files reviewed by the hijacker. He probably did them as an attempt to stay under the radar or just trying out the new functionality as a Reviewer.

file Datei existiert nicht (12464)
file Datei existiert nicht (13547)
file Datei existiert nicht (13394)
file cs2d Admin Skin
file cs2d Infinite Menus - OG
file Datei existiert nicht (2793)
file cs2d Battle Support V 1.0
file cs2d Extra CS2D Musics Loops (.ogg) v0.1


EDIT: He have a thing with old files.

alt Re: Report - USGN hacker (stolen account)

Yates
Reviewer Off Offline

Zitieren
I lol'd - he actually declined some files worthy of being declined yet used a reason totally unrelated to the actual reason they should be declined for.

Top notch, seems just like you (jk)

alt Re: Report - USGN hacker (stolen account)

Baloon
GAME BANNED Off Offline

Zitieren
Simple, just log out before you leave this site, hackers are able to check logs. He hijack user CY because he want to try how to review? Omg then. That's why I don't want being important person because people will try any way to hijack and steal your account and act like an idiot.

alt Re: Report - USGN hacker (stolen account)

Yates
Reviewer Off Offline

Zitieren
@user Baloon: uh no

@user Mami Tomoe: The length does not matter. If I use the password omgiamsocoolandfullofmyself it will still be cracked faster than DASxAHeB (and now I have to change my password ).

Just make sure your password doesn't contain any easy human recognizable text or number sequences. So don't use your birthday and don't use any names or words. In fact, don't use anything that is recognizable to you, make up a random sequence of numbers and letters (heck go crazy and use special characters!) - eventually you will know your password by heart but by that time it's also recommended you change it to a new one

alt Re: Report - USGN hacker (stolen account)

Ahmad
User Off Offline

Zitieren
@user Yates: I keep forgetting my email password because its complicated, and since I have a multi language keyboard i decided to set the language to english and type in arabic, the result was something like this ";glmhglv,v," i typed in 'password' in arabic √

alt Re: Report - USGN hacker (stolen account)

rzvthePsycho
User Off Offline

Zitieren
user Starkkz hat geschrieben
@user Rainoth: It would probably be wise to change his password & recovery mail, I talked to him on Skype but he appears to be always offline.

Edit: I'm surprised that we don't have the ability to change users passwords.

Edit 2: Whoever currently holds user CY's account is able to delete all his files, it's better to keep his account banned until we're able to contact user DC regarding this situation.


A moderator changed my password once. You must have the ability to chanve passwords.

alt Re: Report - USGN hacker (stolen account)

Yates
Reviewer Off Offline

Zitieren
@user rzvthePsycho: There is but one method for moderators: Editing the user to change the e-mail, sending a recovery link to that e-mail and changing the password. Then simply change the e-mail back to what it was and send the user the new password.

alt Re: Report - USGN hacker (stolen account)

GeoB99
Moderator Off Offline

Zitieren
user Baloon hat geschrieben
Simple, just log out before you leave this site, hackers are able to check logs. He hijack user CY because he want to try how to review? Omg then. That's why I don't want being important person because people will try any way to hijack and steal your account and act like an idiot.

The account logs out by itself after a certain time if website actions weren't been taken so this is not the case. In this junction, we can only judge three causes of this effect which led few accounts, including user CY's one to be hijacked:

• Brute Force / Guessing passwords;
• Weak, broken E-mail or its security;
• Website vulnerabilities (this is one is pretty much rare)

Speaking for user CY's case, the cause of this dilemma was the second reason since his password was enough strong and immune already to brute forces or guesses. Here's the quoted part of the response which I have got from him.
Zitat
I really din't see this one coming at all. I guess my account was easy to hijack due to my email being lost forever in the abyss of hotmail. I can't recover the email no matter how many bloody infos I added in the required things.
Zum Anfang Vorherige 1 2 3 Nächste Zum Anfang
Einloggen, um zu antwortenUnreal Software-ÜbersichtForenübersicht