Select Forum Color
Forums
+ Sixandfourum » Fourum Headquarters » sixandfourum Info Center
 Re: Attempted Password Hacking



Username:
Password:
Share this topic on FacebookShare this topic on MySpaceShare this topic on Twitter
Pages: [1] Go Down
Topic: Re: Attempted Password Hacking  (Read 461 times) More Search
0 Members and 2 Guests are viewing this topic.
Author Topic: Re: Attempted Password Hacking (Read 461 times)
profilsixandfour
The other white meat
Administrator
Pro
*****

The triumphant return of Claymation Six!
Offline Offline

Posts: 3570
Topics: 432


View Profile
« on: February 16, 2011, 04:13:27 AM »

Over the last 5 days, an unknown entity (or entities) has made repeated attempts to log in using existing accounts, mostly those of the more active members here.  So far AFAIK they have been unsuccessful in over 700 tries.  Two thirds of the total incorrect password errors at sixandfourum have been generated since last Friday.  These attempts have come from literally hundreds of IP addresses, most of which are untraceable.  Most of them are coming from Europe and particularly London and Sweden.  I do have a couple of leads as to how I can find the culprit and will be sending out some emails to ISPs that host these addresses, as well as contacting a particular London-based WoW patch site owner in regards to his involvement, as he has been directly targeted as a culprit and there are several ISPs serving London involved. 

I don't expect this to be a problem for any of you, and I do not know the purpose of these attempted password hacks.  If you do have a problem, feel free to email me privately at sixandfour@hotmail.com.
Logged


Check out our Calendar for our regular games

Author Topic: Re: Attempted Password Hacking (Read 461 times)
profilsixandfour
The other white meat
Administrator
Pro
*****

The triumphant return of Claymation Six!
Offline Offline

Posts: 3570
Topics: 432


View Profile
« Reply #1 on: February 17, 2011, 12:57:03 PM »

I have learned a few things via communications with several ISPs.  I have determined that all the attack login attempts are originating from the Tor Network, a network of 800+ IPs that all voluntarily provide a tunnel of sorts in which people can anonymously and indirectly connect to other addresses.  This has beneficial uses for certain entities it was intended for, but can and is misused by some as in this case.   I have obtained a full list of all the IPs used by the Tor network, and can if necessary block them all from access.  But first I am awaiting response from about a half dozen ISPs and IP customers to see if they can stop the offending party themselves.  Either way, they seem to be wasting their time, as they have proven wholly unsuccessful in over 1000 attempts of anything but using up more of our unlimited bandwidth.

I have to talk to the real brains of this outfit (Fletch, sfov) about this yet as well, but in any case I think we have the situation under control.  I just hope I don't have to manually enter 800+ IP blocks individually into the system.
Logged


Check out our Calendar for our regular games
Author Topic: Re: Attempted Password Hacking (Read 461 times)
profilJBaker
14/f/yourlap
Administrator
Shark
*****

1st Ever TTYL Champion
Offline Offline

Posts: 2166
Topics: 121


View Profile
« Reply #2 on: February 17, 2011, 01:09:10 PM »

I just hope I don't have to manually enter 800+ IP blocks individually into the system.

That's what mods are for. 
Logged

40% Rakeback - U.S. Players welcome!

Prodigy ... not so keen on the U.S. players
Author Topic: Re: Attempted Password Hacking (Read 461 times)
profilsixandfour
The other white meat
Administrator
Pro
*****

The triumphant return of Claymation Six!
Offline Offline

Posts: 3570
Topics: 432


View Profile
« Reply #3 on: February 17, 2011, 01:27:34 PM »

That's what mods are for. 

I wish.
Logged


Check out our Calendar for our regular games
Author Topic: Re: Attempted Password Hacking (Read 461 times)
« Reply #4 on: February 17, 2011, 02:37:12 PM »

if you give me your credit card # and exp date, I can probably check your security for you
Logged

Author Topic: Re: Attempted Password Hacking (Read 461 times)
profilJBaker
14/f/yourlap
Administrator
Shark
*****

1st Ever TTYL Champion
Offline Offline

Posts: 2166
Topics: 121


View Profile
« Reply #5 on: February 17, 2011, 03:01:33 PM »

if you give me your credit card # and exp date, I can probably check your security for you

Don't forget the 3-digit CSC code!
Logged

40% Rakeback - U.S. Players welcome!

Prodigy ... not so keen on the U.S. players
Author Topic: Re: Attempted Password Hacking (Read 461 times)
« Reply #6 on: February 18, 2011, 10:47:25 AM »

if you give me your credit card # and exp date, I can probably check your security for you

Don't forget the 3-digit CSC code!

 ..... and for your security, provide D.O.B., SS# and mothers maiden name
Logged

"....in general, loyalty is paramount over all at Tilt." ~Wicked Chops Entity on 8.7.2011~
Author Topic: Re: Attempted Password Hacking (Read 461 times)
« Reply #7 on: February 21, 2011, 04:51:10 AM »

WtF, Why wouldn't they just join the forum. You haven't banned that many people yet have ya?. Keep us posted thats crazy. Freerollbird
Logged
Author Topic: Re: Attempted Password Hacking (Read 461 times)
profilsixandfour
The other white meat
Administrator
Pro
*****

The triumphant return of Claymation Six!
Offline Offline

Posts: 3570
Topics: 432


View Profile
« Reply #8 on: February 21, 2011, 10:00:31 AM »

WtF, Why wouldn't they just join the forum. You haven't banned that many people yet have ya?. Keep us posted thats crazy. Freerollbird

My guess would be that they're hoping to access a popular account in hopes that it has added privileges, so that they can insert some adware code into the forum itself.  I have just learned that a email authentification popup has been installed on Starling Money's profile page for a site called designegg.com.  I'll have to have Fletch kill that bit of code, and see how that came about if we can.

In other news, having no success with a mod that will autoblock these Tor addresses, I'm currently banning the entire Tor Network by IP address.  There's actually over 1200 IPs, and I'm about halfway through so far (of course you have to post them one at a time, bastages).  I've already seen a marked reduction in attempts, and once I finish the list, they should cease entirely.  Interestingly, in my communications with an ISP provider for one of them that has been very helpful, I believe we have found the source IP, and I will be contacting them regarding restitution for the trouble they have caused.  It's a longshot, but maybe they'll throw us a little bribe to avoid any action on our part.
Logged


Check out our Calendar for our regular games
Author Topic: Re: Attempted Password Hacking (Read 461 times)
profilJBaker
14/f/yourlap
Administrator
Shark
*****

1st Ever TTYL Champion
Offline Offline

Posts: 2166
Topics: 121


View Profile
« Reply #9 on: February 21, 2011, 11:09:13 AM »

I'm in class right now but if you email me some of the IPs I can get to them tonight and tomorrow.
Logged

40% Rakeback - U.S. Players welcome!

Prodigy ... not so keen on the U.S. players
Author Topic: Re: Attempted Password Hacking (Read 461 times)
profilribbybruno
Global Moderator
Shark
*****

Swing Flip Land!!
Offline Offline

Posts: 1289
Topics: 191


View Profile
« Reply #10 on: February 21, 2011, 08:38:34 PM »

Not sure what exactly you need done six. Moderating is new to me. 
Logged

Author Topic: Re: Attempted Password Hacking (Read 461 times)
profilsixandfour
The other white meat
Administrator
Pro
*****

The triumphant return of Claymation Six!
Offline Offline

Posts: 3570
Topics: 432


View Profile
« Reply #11 on: February 22, 2011, 10:04:27 AM »

Thanks JB, but I'd rather not give you the busy work and have you regretting the offer.  You guys don't need to do anything on the mod end either, aside from the usual keeping an eye out for anything fishy. 

As of this post, I have entered over 1100 of the 1230 IPs, and after repeated hits on ban notices, evidently the culprit has given up at last.  I will enter the remainder of the IPs anyway to prevent this in the future.  But hopefully, we've seen the last of that and the only drama will be that which I create for the villain.
Logged


Check out our Calendar for our regular games
Author Topic: Re: Attempted Password Hacking (Read 461 times)
profilsixandfour
The other white meat
Administrator
Pro
*****

The triumphant return of Claymation Six!
Offline Offline

Posts: 3570
Topics: 432


View Profile
« Reply #12 on: February 22, 2011, 11:26:36 AM »

All the Tor IPs have now been banned.  I'll let you all know if anything interesting comes about regarding getting after the villain.
Logged


Check out our Calendar for our regular games
Author Topic: Re: Attempted Password Hacking (Read 461 times)
« Reply #13 on: February 22, 2011, 05:36:53 PM »

WtF, Why wouldn't they just join the forum. You haven't banned that many people yet have ya?. Keep us posted thats crazy. Freerollbird

My guess would be that they're hoping to access a popular account in hopes that it has added privileges, so that they can insert some adware code into the forum itself.  I have just learned that a email authentification popup has been installed on Starling Money's profile page for a site called designegg.com.  I'll have to have Fletch kill that bit of code, and see how that came about if we can.

In other news, having no success with a mod that will autoblock these Tor addresses, I'm currently banning the entire Tor Network by IP address.  There's actually over 1200 IPs, and I'm about halfway through so far (of course you have to post them one at a time, bastages).  I've already seen a marked reduction in attempts, and once I finish the list, they should cease entirely.  Interestingly, in my communications with an ISP provider for one of them that has been very helpful, I believe we have found the source IP, and I will be contacting them regarding restitution for the trouble they have caused.  It's a longshot, but maybe they'll throw us a little bribe to avoid any action on our part.

What exactly is an email authentification popup? they don't have access to my email address do they?
Logged

Author Topic: Re: Attempted Password Hacking (Read 461 times)
« Reply #14 on: February 22, 2011, 05:43:11 PM »

Any who, yeah, I just went to my profile, that pop-up or one similar to it has been there for a while, like for months since we had that survivor game.

So are they trying to get me to enter my password so they can have mod privileges?
Logged

Author Topic: Re: Attempted Password Hacking (Read 461 times)
« Reply #15 on: February 22, 2011, 11:00:11 PM »

Any who, yeah, I just went to my profile, that pop-up or one similar to it has been there for a while, like for months since we had that survivor game.

So are they trying to get me to enter my password so they can have mod privileges?

my guess is they saw your pic and were trying to get your e-mail addy and pw in the hopes of intercepting more revealing photos or perhaps home address  Shocked
Logged

"....in general, loyalty is paramount over all at Tilt." ~Wicked Chops Entity on 8.7.2011~
Author Topic: Re: Attempted Password Hacking (Read 461 times)
« Reply #16 on: February 22, 2011, 11:43:25 PM »

Any who, yeah, I just went to my profile, that pop-up or one similar to it has been there for a while, like for months since we had that survivor game.

So are they trying to get me to enter my password so they can have mod privileges?

my guess is they saw your pic and were trying to get your e-mail addy and pw in the hopes of intercepting more revealing photos or perhaps home address  Shocked

Naw, I highly doubt that, I am sure they can find much better photos of much younger chicks with much less efforts lol

But I do always wonder if people try to use forum info, such as passwords etc.. to try to access poker accounts....so I am super cautious.
Logged

Author Topic: Re: Attempted Password Hacking (Read 461 times)
« Reply #17 on: February 23, 2011, 02:27:22 AM »

ok, please keep us posted becuase i know nothing about ip or isp and computer stuff as such. And realy don't wanna be Hacked. Thanks Freerollbird just wanna play good solid poker with people who enjoy the game as much as i do. I'm still learning and don't need any problems.
Logged
Author Topic: Re: Attempted Password Hacking (Read 461 times)
« Reply #18 on: February 23, 2011, 08:06:29 AM »

...But I do always wonder if people try to use forum info, such as passwords etc.. to try to access poker accounts....so I am super cautious.


they absolutely do... wouldn't be surprised if this whole thing was an attempt at exactly that, hack in, in order to get peoples emails, pw's in the hopes they use same one for poker accts

 lotsa people are dumb when it comes to pw's and security ect.... using same e-mail for poker site accts as the one they use (and openly display) on forums and such.... real birthday info on forum or names of pets ect and they use some combo of such readily available info for their pw

there's a long post from a couple years back somewhere at railbirds from someone who got either pstars or FTP accts (mighta been both ?) hacked into...
the guy that got hacked was on aim or msn talking to the guy that hacked him and after a bit the hacker revealed himself to be the one that busted into his accts....went on to tell him how he found out all kinds of info about him from forums and used that info to search his address and found out what the local high schools team name was (which was his pw to his e-mail) ....

from there hacker changed pw on the guys email and then did lost pw thing w/ poker site who just sends new pw to registered email.... real acct holder was locked out of his email and poker site wouldn't deal with him communicating from diff email addy... luckily for the guy that got hacked, the hacker was just doing the whole thing for fun and didn't take any $ and gave the guy the new pw's to his email addys and poker acts

anyhoo... the takeaway message is it really doesn't matter how ingenious or complicated your poker site pw's are, and the extra security stuff like FTPs picking the cards thing is useless as well if your e-mail isn't secure.....
 
anyone gets into your email acct that's associated with poker acct and all they have to do is change your e-mail pw to lock you out of it, then they can claim lost pw to poker acct and site will send em a new one (they can also change email addy associated with poker acct so even if you regain control of your email acct you're locked out of poker acct) .... and they'll have at least a couple of days to empty your acct because it will take at least that long to jump through all the hoops before poker site will recognize your contact/requests as valid when they're coming from email addy that isn't associated with the poker acct

best policy is to have email acct(s) that are used exclusively for poker sites (and any other sensitive type accts like banking) and make the email names and pw's nothing to do with anything that is even remotely connected to you in any way .... and it's good idea to not post your real birthday or any other personal info .... with even the smallest tidbit of real info to start with, just way to easy these days to find out all kinds of details about a person ..... dont just keep pw's safe, treat the email addy itself as if it was a pw

also a good practice to change associated email addys to new ones at least semi-regularly.....especially if you've ever done a site for site funds trade where you were on receiving end at one of the sites that requires sender has the recipients email addy (think cake skins do this) ...


can safely assume that any info that could eventually lead to money, someone somewhere out there is chasing it down

« Last Edit: February 23, 2011, 08:28:21 AM by wachinpntdry » Logged

"....in general, loyalty is paramount over all at Tilt." ~Wicked Chops Entity on 8.7.2011~
Author Topic: Re: Attempted Password Hacking (Read 461 times)
profilsixandfour
The other white meat
Administrator
Pro
*****

The triumphant return of Claymation Six!
Offline Offline

Posts: 3570
Topics: 432


View Profile
« Reply #19 on: February 23, 2011, 08:52:29 AM »

Any who, yeah, I just went to my profile, that pop-up or one similar to it has been there for a while, like for months since we had that survivor game.

So are they trying to get me to enter my password so they can have mod privileges?

Doubt that, they prolly just want to gather live emails to spam, so they hid some code on your page.  I'll look at your profile page and see if it's something outward.

Edit:  Found nothing there, might be in the page code     You wouldn't happen to know what you might have done around the time that happened to make it happen? 
« Last Edit: February 23, 2011, 08:59:21 AM by sixandfour » Logged


Check out our Calendar for our regular games
Author Topic: Re: Attempted Password Hacking (Read 461 times)
« Reply #20 on: February 23, 2011, 02:50:26 PM »

Any who, yeah, I just went to my profile, that pop-up or one similar to it has been there for a while, like for months since we had that survivor game.

So are they trying to get me to enter my password so they can have mod privileges?

Doubt that, they prolly just want to gather live emails to spam, so they hid some code on your page.  I'll look at your profile page and see if it's something outward.

Edit:  Found nothing there, might be in the page code     You wouldn't happen to know what you might have done around the time that happened to make it happen? 

I tried to download Dexter once on my other computer, and I ended up with all this adware, could that have caused it? It put links everywhere, I uninstalled a couple of the programs it put on my other computer and it went away.
Logged

Pages: [1] Go Up Print 
« previous next »



Jump to: