Skidforums DB dumped 05-10-2011, 10:29 AM
#1
yep, HF's DB was hacked last february
here's omnis quote
if you wanna change your pass, email or help me find the dump to tell omni [though i doubt the admins want people helping him
] then ok, pm me if u find it 
EDIT: Fixed the link
here's omnis quote
Quote:What a day this is turning out to be.
Since rumors are likely to spread and I think this info will be public soon anyways I'm going to announce it to everyone.
Back in February 2011 we were shelled. Yes that's right. We were shelled. We are not impenetrable and have no golden lock on our server/website.
I became aware of the shells weeks ago while reviewing server files. It was a very alarming moment of course. Site was shut down for "maintenance" and I started reviewing logs and other forensics were done. Ultimately I found out who uploaded the shells but their English was terrible and they didn't really provide me much info.
I believe the shells were updated from a MyBB exploit just before it was patched.
http://blog.mybb.com/2011/02/22/mybb-1-6...ty-update/
All evidence points to a XSS vulnerability in modcp that is now patched.
I had previously no evidence that the shells were used maliciously or that data was stolen. The penetrators are still members here and I hold no ill will against them. They had the shells up for weeks without any real damage to the site.
However the real question remained. Did they grab the database? I wasn't sure. They weren't saying. It did not seem appropriate to alarm the member base without knowing more information. We have too many members to just change all passwords. Also all passwords in the DB are encrypted and salted. Which means any passwords harder than "password" or "pass123" won't be easy to crack. Given that we force complex passwords anyone having the DB shouldn't be easily able to grab accounts.
But there are other concerns. Like grabbing members emails and IPs. I do take member privacy and security seriously. Today is the first time I've had any evidence our data was compromised. So now you're being informed.
Today a member is boasting about having access to the DB. So someone or some group may be releasing it public. After reviewing data given I've been convinced it's valid and it's from the time period I know we were shelled.
If you'd like to change your password or email now is the time to do it. While I'm firmly convinced accounts are safe that doesn't mean you're not exposed somewhere else.
I'm really not looking forward to posting this but I believe it's the right thing to do. Let's see how it goes.
if you wanna change your pass, email or help me find the dump to tell omni [though i doubt the admins want people helping him
] then ok, pm me if u find it 
EDIT: Fixed the link




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)