Author Topic: FA admin account compromised (yet again)  (Read 1856 times)

Jim Demintia

  • Flammuar
  • ***
  • Posts: 198
  • E-points: +5/-3
  • Deflator Mouse
    • View Profile
Re: FA admin account compromised (yet again)
« Reply #40 on: December 17, 2010, 06:40:06 pm »
God damn Adam Wan is far more nasty than I ever imagined. Jesus christ he really is this close to being a sex offender.
Fuck you, I'm a debt and deficit dragon.

Pi

  • INTERNET SYSOP
  • Löwenanführer
  • Kriegslöwe
  • ****
  • Posts: 280
  • E-points: +19/-10
  • banned from FA for at least 3 years
    • View Profile
    • Clan Spum userpage
Re: FA admin account compromised (yet again)
« Reply #41 on: December 17, 2010, 07:55:46 pm »


"if you talk about this, you risk your reputation".

It's like Dragoneer only cares about appearances!
"we did farts.  now we do sperm.  we are cutting edge." -- Theo DeRaadt

MazelTovCocktail

  • Elektrohyäne
  • **
  • Posts: 76
  • E-points: +3/-0
  • You smell somethin', Rabbit?
    • View Profile
Re: FA admin account compromised (yet again)
« Reply #42 on: December 17, 2010, 09:33:52 pm »
My God.

The amount of hypocrisy on Dragoneer's part is absolutely mind-blowing.
How ironic!  Everything I ever wanted DOES come in a rocket can!

Pi

  • INTERNET SYSOP
  • Löwenanführer
  • Kriegslöwe
  • ****
  • Posts: 280
  • E-points: +19/-10
  • banned from FA for at least 3 years
    • View Profile
    • Clan Spum userpage
Re: FA admin account compromised (yet again)
« Reply #43 on: December 17, 2010, 10:46:13 pm »
Yet another piece of general "wat":
Quote from: witchiebunny
As an fyi on the Private Notes thing, all admins can see any private note they are directly linked to...we can't  go crawling through people's inboxes or anything like that.

yes, hello

if you know anything about how computers work

you can turn this into "any person on who has access to an administrator account can see any private note (ps this person is not necessarily an admin)"
"we did farts.  now we do sperm.  we are cutting edge." -- Theo DeRaadt

Conan

  • Elektrohyäne
  • **
  • Posts: 84
  • E-points: +6/-1
  • ¯\(°_o)/¯
    • View Profile
Re: FA admin account compromised (yet again)
« Reply #44 on: December 17, 2010, 11:34:55 pm »
I'm getting curious as to why they haven't rolled back the database. I mean, they have an entire server dedicated to backups, but have yet to use it. I thought for sure we'd see a rollback today because a lot of galleries were wiped, including Adam Wan's, who FA bent the rules for just so he could keep his precious comments and +favs when he blanked his gallery.


Pi

  • INTERNET SYSOP
  • Löwenanführer
  • Kriegslöwe
  • ****
  • Posts: 280
  • E-points: +19/-10
  • banned from FA for at least 3 years
    • View Profile
    • Clan Spum userpage
Re: FA admin account compromised (yet again)
« Reply #45 on: December 17, 2010, 11:44:44 pm »
Well, they can't go read only (because it doesn't work). They can't go admin only (doesn't work). They don't know how to fix it yet because it took them a while to narrow down which problem it actually was.

They're dead in the water until they think they've got their duct tape in the right place. And this is assuming they can restore.
"we did farts.  now we do sperm.  we are cutting edge." -- Theo DeRaadt

AshleyAshes

  • Elektrohyäne
  • **
  • Posts: 65
  • E-points: +2/-10
    • View Profile
Re: FA admin account compromised (yet again)
« Reply #46 on: December 18, 2010, 12:01:15 am »
yes, hello

if you know anything about how computers work

you can turn this into "any person on who has access to an administrator account can see any private note (ps this person is not necessarily an admin)"

Maybe what she said is technicly true.  Maybe the admin system doesn't allow for admins to crack open anyone's list of notes and read them, the site is poorly put together so that feature could be absent and I think this is likely.  That said, Witchiebunny doesn't account for 'Any admin could change the password on your account, take it over and just read your notes by logging in as you'.

Pi

  • INTERNET SYSOP
  • Löwenanführer
  • Kriegslöwe
  • ****
  • Posts: 280
  • E-points: +19/-10
  • banned from FA for at least 3 years
    • View Profile
    • Clan Spum userpage
Re: FA admin account compromised (yet again)
« Reply #47 on: December 18, 2010, 11:10:27 am »
you can turn this into "any person on who has access to an administrator account can see any private note (ps this person is not necessarily an admin)"
Maybe what she said is technicly true.  Maybe the admin system doesn't allow for admins to crack open anyone's list of notes and read them
Instead of coming up with a longwinded rebuttal, including a few lines about how stupid you are, i'm just going to post a link to a note: http://www.furaffinity.net/viewmessage/972564/
"we did farts.  now we do sperm.  we are cutting edge." -- Theo DeRaadt

AshleyAshes

  • Elektrohyäne
  • **
  • Posts: 65
  • E-points: +2/-10
    • View Profile
Re: FA admin account compromised (yet again)
« Reply #48 on: December 18, 2010, 11:16:31 am »
Instead of coming up with a longwinded rebuttal, including a few lines about how stupid you are, i'm just going to post a link to a note: http://www.furaffinity.net/viewmessage/972564/

Was that link supposed to work?

Pi

  • INTERNET SYSOP
  • Löwenanführer
  • Kriegslöwe
  • ****
  • Posts: 280
  • E-points: +19/-10
  • banned from FA for at least 3 years
    • View Profile
    • Clan Spum userpage
Re: FA admin account compromised (yet again)
« Reply #49 on: December 18, 2010, 03:00:53 pm »
Quote from: IRC
14:59 < yak[away]> I wanted the status update to be 'yes we we hacked. yes we have everything under cntrol. we are currently  figuring out the extent of the damage. so far we know that 41 people including admins had their notes leaked and  some people had their galleries deleted; the latter we can restore. I will post more updated as we have them'
"we did farts.  now we do sperm.  we are cutting edge." -- Theo DeRaadt

pmart

  • Elektrohyäne
  • **
  • Posts: 8
  • E-points: +1/-0
  • BAWWWWW
    • View Profile
Re: FA admin account compromised (yet again)
« Reply #50 on: December 18, 2010, 04:50:46 pm »
I downloaded the Gawker database and ran every FA admin's username, and if they listed it, email address through it. I got two results other than Pinkuh.

A possible match for Irreverent. They list no email address on their FA page, and the email doesn't seem to support a match.
Then there's Rhainor,  or Gawker user zachcoggin. Email addresses match. The irony here is his FA page says "Greetings. My name, as you can see, is Rhainor. No, it's not my Real name; I'm not about to give my Real name across an unsecured web site.", yet it seems he used his real name for his Gawker username.

Did you account for every FA admin's alternate username(s)?  Running "Preyfar" through the aforementioned Slate widget gives you: Your password was released, and it's been decrypted. You should change it ASAP.  Hmm...

Conan

  • Elektrohyäne
  • **
  • Posts: 84
  • E-points: +6/-1
  • ¯\(°_o)/¯
    • View Profile
Re: FA admin account compromised (yet again)
« Reply #51 on: December 18, 2010, 06:27:10 pm »
Did you account for every FA admin's alternate username(s)?  Running "Preyfar" through the aforementioned Slate widget gives you: Your password was released, and it's been decrypted. You should change it ASAP.  Hmm...



gg Sean. What a secure password.

Pi

  • INTERNET SYSOP
  • Löwenanführer
  • Kriegslöwe
  • ****
  • Posts: 280
  • E-points: +19/-10
  • banned from FA for at least 3 years
    • View Profile
    • Clan Spum userpage
Re: FA admin account compromised (yet again)
« Reply #52 on: December 18, 2010, 06:37:47 pm »
But it isn't Princess Piche's fault. He's only human after all.
"we did farts.  now we do sperm.  we are cutting edge." -- Theo DeRaadt

MazelTovCocktail

  • Elektrohyäne
  • **
  • Posts: 76
  • E-points: +3/-0
  • You smell somethin', Rabbit?
    • View Profile
Re: FA admin account compromised (yet again)
« Reply #53 on: December 18, 2010, 08:58:53 pm »
But it isn't Princess Piche's fault. He's only human after all.

He's still way out of his league.
How ironic!  Everything I ever wanted DOES come in a rocket can!

Conan

  • Elektrohyäne
  • **
  • Posts: 84
  • E-points: +6/-1
  • ¯\(°_o)/¯
    • View Profile
Re: FA admin account compromised (yet again)
« Reply #54 on: December 19, 2010, 12:52:48 am »
IT'S HAPPENING AGAIN.


Pi

  • INTERNET SYSOP
  • Löwenanführer
  • Kriegslöwe
  • ****
  • Posts: 280
  • E-points: +19/-10
  • banned from FA for at least 3 years
    • View Profile
    • Clan Spum userpage
Re: FA admin account compromised (yet again)
« Reply #55 on: December 19, 2010, 12:58:38 am »
They sure do have some important things to talk about in the admin treehouseforums.
"we did farts.  now we do sperm.  we are cutting edge." -- Theo DeRaadt

Conan

  • Elektrohyäne
  • **
  • Posts: 84
  • E-points: +6/-1
  • ¯\(°_o)/¯
    • View Profile
Re: FA admin account compromised (yet again)
« Reply #56 on: December 19, 2010, 07:53:15 pm »

Fiz

  • Elektrohyäne
  • **
  • Posts: 26
  • E-points: +4/-0
  • no stop
    • View Profile
Re: FA admin account compromised (yet again)
« Reply #57 on: December 19, 2010, 08:47:33 pm »
Yes it really stopped the attack. That's why the site is working fine right now.

Oh, wait.  ::) No it's not.
"I don't think there's a problem with jacking off dogs. I don't see anything morally wrong with it. Sorry." - Chase "V" Rocket

Conan

  • Elektrohyäne
  • **
  • Posts: 84
  • E-points: +6/-1
  • ¯\(°_o)/¯
    • View Profile
Re: FA admin account compromised (yet again)
« Reply #58 on: December 19, 2010, 08:51:32 pm »
Yes it really stopped the attack. That's why the site is working fine right now.

Oh, wait.  ::) No it's not.

Supposedly part of the problem is someone on Lulz reminded everyone of http://www.furaffinity.net/browse/999.

Gee their inefficient coding is now being used for a DDoS attack who would have thought.

Ben

  • Rohmaterial
  • *
  • Posts: 2
  • E-points: +0/-0
    • View Profile
Re: FA admin account compromised (yet again)
« Reply #59 on: December 19, 2010, 09:15:51 pm »
They sure do have some important things to talk about in the admin treehouseforums.

Haha, oh wow. Do you have the other pages of the thread about me? This is just precious. Oh god.