Important: Many forums are being hacked, so update your password regularly

Started by BigMike, November 04, 2013, 12:30:01 PM

0 Members and 1 Guest are viewing this topic.

BigMike

First and foremost we have not been hacked nor have we ever been hacked. This isn't to say that it won't happen someday, but that we've never had to deal with the issue.

What is this about?
The reason for this thread is that it just came to my attention that there are a group of Hackers targeting forums by using log in information obtained from insecure resources.

What is happening?
1) Some random low-security/vulnerable website is hacked sometime in the past.
2) Hundreds of usernames and passwords are obtained.
3) A program uses these usernames and passwords to randomly attempt to log into other unrelated websites.
4) Once the program stumbles upon a random website where a username/password combination happens to work, it attempts to access the administration section.
5) If the account is found to be an admin account, then the database log-in info is now exposed and the program downloads the entire user table of the database obtaining more hundreds/thousands of username and password combinations.
6) Repeat step 3.

How did I find out about it?
This was brought to my attention from a different forum that I am a member of. They have multiple admin accounts and one of these accounts was accessed and their entire database was downloaded. Thus someone in the world now knows my password on that site since I am a member there.

Reassurance for our community
The good news for us is that...
A) I use different passwords for different sites -- Therefore my password on the compromised site is different than my password here.
and
B) I update my passwords a few times per year.

How secure are we?
As for us, we only have 1 admin account and that is me. There are two other "admin" users however I have prevented their access to our database settings. Additionally, our forum and store run on different databases that use different passwords. Moreover, these passwords are all different than the root password of our server, and yes they are also updated a few times per year (obviously I don't want to take any chances with your log-in OR my log-in info; ie. It is my duty to be the most paranoid user here).

Also you might ask how this is possible since all passwords are encrypted before they are stored in our database (meaning even I can't view anyone's password / this is standard forum security and practice / admins never have access to log-in info and do not by design). But there are advanced hackers who can decrypt encryption and it appears this is the trend we are seeing -- or there is some pretty crappy forum software being used at large.

So why am I posting this?
Because many username and password combos have been discovered, the only way to foil their plans is to make the info they have obsolete.

In closing, do the following
1) Regularly update your password. Even if it's just adding a different number or letter somewhere to your existing password. No humans are actually handling the bulk of "stolen" passwords - it is just a program looping through a large amount of data. So even adding a number to the end of your password is enough to keep you protected from this. However for maximum protection I strongly urge you to use a different password all together.
and
2) Never use the same password for other sites. I guess there are exceptions to this rule but if you have any site that is sensitive to you, such as your online banking or your PayPal account, then absolutely use entirely different passwords and don't forget to update them regularly!!

If you keep your log in details different and change them regularly then the chance of anyone logging into your account by chance is minimized. Who knows, maybe someone got your info from some obscure website you registered with five years ago, and the next thing we see is your account suddenly posting spam all over our forum! :smack:

Thank you for your time in reading this and in helping not just our community but the online community as a whole to be more safe and secure! :beerchug:

Regards,
BigMike
Check out our new Rock Crawling Videos!
2016 56-speed 580:1 Tacoma Rock Crawler   
1981 36-speed 511:1 3RZ-FE Rock Crawler
1987 6-speed Supercharged 4A-GZE MR2
Instagram: @SlowestTacoma
Things are only impossible until they are not.
"The worst of both worlds, the best of neither." -abnormaltoy
"An informed question. But difficult to answer. I am what you see." -Nanaki

Cheesemaker

Good info Mike.  I know I forget to change my passwords. 

And they say to not use a notebook to keep your log-in info in, but once you add up a couple dozen websites, I have a hell of time remembering my passwords. 
Miss ya Dean (4THEWKN) & Kyle (KYOTA)!!

4THEWKN~9/17/2006  If it wasn't for you, I'd be driving something other than a Toyota!

My build up ~ project Kilchis! http://board.marlincrawler.com/index.php?topic=32961.0
Zak's truck build ~ http://board.marlincrawler.com/index.php?topic=64319.0;topicseen

Rocksurfer

The most important thing is that Admins change them constantly and not use the same password on non Admin sites.
The Ghost-Rider/Ghost Runner

No matter how far you fall, the ground will always catch you

BigMike

Here is a good read containing tips on creating and using passwords:
http://www.pcworld.com/article/227023/how_to_build_a_better_password.html

Specifically useful is the last section on that page titled "One Password to Rule Them All", which explains how to use an easy to remember mnemonic trick that applies to just one password you'll ever need for the rest of your life :thumbs:

BigMike
Check out our new Rock Crawling Videos!
2016 56-speed 580:1 Tacoma Rock Crawler   
1981 36-speed 511:1 3RZ-FE Rock Crawler
1987 6-speed Supercharged 4A-GZE MR2
Instagram: @SlowestTacoma
Things are only impossible until they are not.
"The worst of both worlds, the best of neither." -abnormaltoy
"An informed question. But difficult to answer. I am what you see." -Nanaki

BigMike

More resources...

Explains various processes that hackers use to access your account (very interesting if you are in to this stuff):
http://www.fidian.com/programming/passwordsecurity

Password Strength Calculator:
http://rumkin.com/tools/password/passchk.php
Check out our new Rock Crawling Videos!
2016 56-speed 580:1 Tacoma Rock Crawler   
1981 36-speed 511:1 3RZ-FE Rock Crawler
1987 6-speed Supercharged 4A-GZE MR2
Instagram: @SlowestTacoma
Things are only impossible until they are not.
"The worst of both worlds, the best of neither." -abnormaltoy
"An informed question. But difficult to answer. I am what you see." -Nanaki

Cheesemaker

At work they make us get new passwords every month.  And you have to have Capitals, lowercase, numbers, and a minimum of 12 characters.  And you can't reuse passwords.  So, everyone has to be a new one.  And they won't let you use similar ones.  IE:  Marlin2013, Marlin2014, Marlin2015.  Which we were allowed to do in years past, but now with the new system. 
Miss ya Dean (4THEWKN) & Kyle (KYOTA)!!

4THEWKN~9/17/2006  If it wasn't for you, I'd be driving something other than a Toyota!

My build up ~ project Kilchis! http://board.marlincrawler.com/index.php?topic=32961.0
Zak's truck build ~ http://board.marlincrawler.com/index.php?topic=64319.0;topicseen

BigMike

Found some very interesting stats!

Click here to view this image in a new window, or right click to save...

Check out our new Rock Crawling Videos!
2016 56-speed 580:1 Tacoma Rock Crawler   
1981 36-speed 511:1 3RZ-FE Rock Crawler
1987 6-speed Supercharged 4A-GZE MR2
Instagram: @SlowestTacoma
Things are only impossible until they are not.
"The worst of both worlds, the best of neither." -abnormaltoy
"An informed question. But difficult to answer. I am what you see." -Nanaki

BigMike

Found a list of sites involved in recent stolen-database hacks


  • Apple Developer website
  • NASDAQ forums
  • Ubuntu forums
  • Club Nintendo
  • Morningstar Document Research
  • Ubisoft website
  • OVH Systems' forum
  • Yii PHP Framework's website
  • Drupal's website
  • Simple Machines Forum's website
  • SMF Hack's website (how I found out about it)     

  • Stanford University's website
  • Harvard University's website
  • MIT University's website
  • Rutger University's website
  • NASA's website
  • Mazda's website
  • Suzuki's website
  • Isuzu's website
  • Mopar's website
  • Bose's Chinese branch
I'm sure there are many more. This shows how important it is to have different passwords for different sites because if your password is discovered from one site, then it would work on them all.
I am not a hacker by any stretch of the imagination but this is what I've learned:

Websites store encrypted versions of user passwords in their database. There are a few different common types of encryption methods, in order of strength: Md5 (weaker -- what Pirate's/IH8MUD/YotaTech/TTORA/etc use), Sha1 (what our forum uses), and bcrypt (stronger). The first two methods are the most common while bcrypt is stronger but it places a larger load on the server. Nowadays it seems a lot of of software is migrating to the more powerful bcrypt and I believe the next version of our forum software (hopefully will be out before next Spring) will use bcrypt.

What the encryption does is it takes the password and changes it into a unique, arbitrary string. For example, the password "marlin" would become "0fe74481e67876a75541e5341659839104a44b11" (depending on the method used). This is known as the password's "hash" and this is what is actually stored in a database. When you log into our website, our system doesn't check to see if you've entered your actual correct password, rather it checks if you've entered a password that generates the same hash that is stored in the database that was created when you originally set your password (ie. your actual password is not stored anywhere!). When an unauthorized user acquires the database, he only sees the hash associated with the password (and not the password). This would be the necessary "hacking" -- the act of wrongfully entering the system and obtaining the hash data.

Once the hacker has a database, he can look through it and find your username, email, and your hash. He never has your actual password, which as mentioned was never stored anywhere in the first place. Depending on the length and variability of the password you use and that the website generated your unique hash from, your actual password can be found in a reverse manner by generating hashes from randomly created passwords until suddenly a matching hash is found. This would be the successful "crack", or cracking the hash by finding what actual password generated your unique hash value. It isn't until then that the hacker actually discovers your actual password.

From what I've read, generally no hacker is after one specific user, rather he or she is after vulnerable users - specifically those with weak passwords that use common words and are child's play to crack. So they apply a large list of generated hashes against the hundreds of "collected" (ie. stolen) hashes. So maybe out of a few thousands of users a dozen or so passwords are found using this reverse method (depending on how "smart" those user's passwords are). Then they can sell these lists of email/password combos on the black market or try to log into profitable sites such as banks or universities. I'm no hacker, but this is how I believe the general process goes.

The good news is that encrypting by design is extremely efficient, or should I say random. Even by changing just one letter, you can have an entirely different hash.
Compare the following:
"My name is BigMike" = 78b0506db7964eaabd5e79bbd50dcabae3b622ef
"My name Is BigMike" = 917db56dc1b95bdf7cb621ba1e90d8655224cb98
All I changed was the capitalization of one letter and the hash is entirely different.

From what I've learned there are two ways to crack each hash.
1) Loop through a dictionary of common words to generate a bunch of hashes, and then see if any of these generated hashes matches the original hash. If so, then you cracked it. This is known as a dictionary attack and also similarly a brute-force attack where you just compare a bazillion combinations until you find one that produces the same hash.
2) Hash collision. This is an extremely rare scenario where a hash happens to match but was not generated from the original password used.

For case (1), the odds of your hash being cracked depends on the length of your password and it's character set size (how many characters are possible for every character used). This is explained in a few of the links I've posted above, but to quickly cover it, if I have a 2-character password that only uses lower case alphabet letters, for example "ab", then the "strength" (measured in bits) would be Length * Logarithm, base 2 * (possible characters) = 2 * log2(26 lowercase characters in the alphabet) = 9.4 bits. If I change the "a" to an "A", now we have doubled the character set size and the resulting strength becomes 11.4 bits, or 20% stronger (26 lower case letters + 26 upper case letters = 52 total possible letters that might have to be looped through until you reach my password). See this link to determine how many bits / how strong your password is:
  • Less than 28 bits is considered very weak
  • 28-35 bits is considered weak
  • 35-59 is considered reasonable (this is what most of my personal passwords score)
  • 60-127 bits is considered strong (this is what my strongest passwords score)
  • and anything over 128 is pretty much overkill
After learning about all this stuff, I've now started replacing all my reasonable passwords with stronger versions (yet keeping them all different).
The important thing to know is that password strength increases exponentially as you make it longer and add in a mixture of different types of characters such as numbers and special characters. More on this later.

Additionally, the encryption that most online sites are using nowadays -- including our forum and our website -- use an added security measure known as "salts" to generate their hashes. Salts are any sort of arbitrary text added to the password before the hash is generated and stored in the database. What this means is that every hash was generated in a different way. This prevents a group of hackers from building a huge "master list" of common hashes, known as a Rainbow Table, requiring them to start cracking from scratch for every user hash encountered. In other words, even though someone's password might be "monkeyballs", it's hash was created using "monkeyballs" plus some other random bit of data. So a hacker can't use a default guide where she has already generated the hash for "monkeyballs" because this instance of "monkeyballs" has been deemed unique through the addition of a salt. This provides more randomness to everyone's hash making it that much harder for someone to find the proper match.

For case (2), this is very improbable but still possible depending on the encryption method used. For example our forum uses 160-bit encryption for which you'd need to guess 2-to-the-60th-power (2^60) times in order to find your first collision, or a matching hash by mistake. The hash might match, but the passwords used to generate said hash would be different. From what I've read this is extremely rare and even still they possibly would have not discovered your true password -- only one that happens to match your hash -- which will not get them into any other website where you've unfortunately used the same password.

So what is the goal?
The goal is to have a complex enough password that even if someone had your hash it will take them many, many computer cycles to find a matching password. It takes one computer cycle to run one iteration of code. For instance if we have a computer with a 2 Gigahertz processor, this means it can compare 2*10^9 power or 2-billion passwords per second to your hash. Fortunately our hashes are stored in 160-bit strings which have 2^64 total possible values. A powerful thing to know is that for every increase in exponential number, it will take a hacker 10 times longer to crack. So computing 10^10 hashes will take 10 times longer than 10^9, and 10^11 takes 100 times longer, etc. Take a look at this password checker. It shows time estimates at the bottom of the page. I played with some simple passwords and here are some figures of how long it (theoretically) takes a hacker to find the password from it's hash:
PasswordLengthCharacter Set SizeAverage PC ProcessorFast ProcessorFast Processor + Graphics ProcessorGroup of multiple fast computers working together

marlin
626 characters3 secs1 secless than a secondless than a second

marlin1
73613 mins1 min39 secsless than a second

Marlin1
76210 hrs2 hrs29 minsless than a second

Marlin1%
8942 yrs6 months1 month1 min

Marlin1%x
9942,000 yrs46 yrs9 yrs2 hrs

Marlin1%xy
1094208k yrs52k yrs10k yrs6 days

Marlin1%xyz
119420 million yrs5 million yrs977k yrs2 yrs

This is why you see sites saying to make your passwords at least 8 characters long, include at least some numbers, upper case letters, and special characters ... because it will take the average hacker much longer than he'd ever have patience for to crack (compare how the time required jumps from just 10 hours to 2 years -- all because we added a special character!). It's true that not every password is unbreakable, but if you consider the amount of time required to crack a well-made password, given an electricity power rate of ~ $0.10 per kWHr, to have many machines running for decades straight ... the associated cost could be in the millions or higher just to find 1 password match of very strong passwords. Look at this link for more on this. It's pretty crazy!

Summarize
Look how scary simple passwords are to crack ... and 'marlin' is a more rare name ... yet it only takes a basic laptop or even a smartphone only 3 seconds to crack the password. That's 3 seconds and someone just got the log-in details for your PayPal account -- if you so happen to use the same password on every site.

The solution is two fold: 1) Use a complicated enough password that it will take a skilled hacker more than 1 year to crack, and then 2) change your password once a year. If someone has obtained a database containing a hash of your password, then all the money and computing power in the world is rendered useless the moment you change your password as the hash the hackers have is no longer valid! :best:

Regards,
BigMike
Check out our new Rock Crawling Videos!
2016 56-speed 580:1 Tacoma Rock Crawler   
1981 36-speed 511:1 3RZ-FE Rock Crawler
1987 6-speed Supercharged 4A-GZE MR2
Instagram: @SlowestTacoma
Things are only impossible until they are not.
"The worst of both worlds, the best of neither." -abnormaltoy
"An informed question. But difficult to answer. I am what you see." -Nanaki

BigMike

Wow after reading my opening post to this thread I now realize I didn't know what was going on and need to update that post :P
Check out our new Rock Crawling Videos!
2016 56-speed 580:1 Tacoma Rock Crawler   
1981 36-speed 511:1 3RZ-FE Rock Crawler
1987 6-speed Supercharged 4A-GZE MR2
Instagram: @SlowestTacoma
Things are only impossible until they are not.
"The worst of both worlds, the best of neither." -abnormaltoy
"An informed question. But difficult to answer. I am what you see." -Nanaki

Stlstrs


BigMike

Check out our new Rock Crawling Videos!
2016 56-speed 580:1 Tacoma Rock Crawler   
1981 36-speed 511:1 3RZ-FE Rock Crawler
1987 6-speed Supercharged 4A-GZE MR2
Instagram: @SlowestTacoma
Things are only impossible until they are not.
"The worst of both worlds, the best of neither." -abnormaltoy
"An informed question. But difficult to answer. I am what you see." -Nanaki

Cheesemaker

What's amazing is how people still fall for the email scams.  We've been warned for at least 15 years, and people still fall for them.  They are just as serious as a website hack.  Sometimes a website hack just needs a email address.  Look at how the Target credit card numbers issue started. 
Miss ya Dean (4THEWKN) & Kyle (KYOTA)!!

4THEWKN~9/17/2006  If it wasn't for you, I'd be driving something other than a Toyota!

My build up ~ project Kilchis! http://board.marlincrawler.com/index.php?topic=32961.0
Zak's truck build ~ http://board.marlincrawler.com/index.php?topic=64319.0;topicseen

BigMike

Quote from: Cheesemaker on March 25, 2014, 09:37:40 PM
What's amazing is how people still fall for the email scams.

Congratulations! We've successfully completed the bank transfer of $50,000 to your account! Please open, print, sign, and fax in the attached PDF file, confirm-pdf.scr, which clearly not a PDF file, and is instead a malicious screen saver file (.scr) capable of screwing up your entire Windows operating system! :party:
Check out our new Rock Crawling Videos!
2016 56-speed 580:1 Tacoma Rock Crawler   
1981 36-speed 511:1 3RZ-FE Rock Crawler
1987 6-speed Supercharged 4A-GZE MR2
Instagram: @SlowestTacoma
Things are only impossible until they are not.
"The worst of both worlds, the best of neither." -abnormaltoy
"An informed question. But difficult to answer. I am what you see." -Nanaki

Cheesemaker

Alot of friends have been getting scammed/hacked on their cell phones lately.  Friend got a bill for $800.   All the numbers showing up are actual provider phone numbers, so it looks legit.  I've gotten these phone calls too.  But if I don't know the number, I won't answer it.  I let it go to voice mail.  If they don't leave a message, then I know it was not anybody I knew.


Miss ya Dean (4THEWKN) & Kyle (KYOTA)!!

4THEWKN~9/17/2006  If it wasn't for you, I'd be driving something other than a Toyota!

My build up ~ project Kilchis! http://board.marlincrawler.com/index.php?topic=32961.0
Zak's truck build ~ http://board.marlincrawler.com/index.php?topic=64319.0;topicseen

BigMike

Quote from: Cheesemaker on March 26, 2014, 09:47:53 PM
Alot of friends have been getting scammed/hacked on their cell phones lately.  Friend got a bill for $800.
Did you happen to ask what the bill entailed? Was it from excessive data? SMS? Voice minutes? Or app/store purchases?

Thanks
Mike
Check out our new Rock Crawling Videos!
2016 56-speed 580:1 Tacoma Rock Crawler   
1981 36-speed 511:1 3RZ-FE Rock Crawler
1987 6-speed Supercharged 4A-GZE MR2
Instagram: @SlowestTacoma
Things are only impossible until they are not.
"The worst of both worlds, the best of neither." -abnormaltoy
"An informed question. But difficult to answer. I am what you see." -Nanaki

Cheesemaker

Mostly long distance phone calls!  From the sounds of it, they are scamming your phones signal/number (not sure 100% how its done) to use it for making calls.  Kinda like hijacking your ISP#.   They said that they went online to see all the calls and texts made to figure it out, and there was dozens of calls made to one phone number.  And a couple of their family members got it too, as I just found out the other day.

Miss ya Dean (4THEWKN) & Kyle (KYOTA)!!

4THEWKN~9/17/2006  If it wasn't for you, I'd be driving something other than a Toyota!

My build up ~ project Kilchis! http://board.marlincrawler.com/index.php?topic=32961.0
Zak's truck build ~ http://board.marlincrawler.com/index.php?topic=64319.0;topicseen

BigMike

Tell your friends to stop using "Bob's Mobile" and to switch to a reputable phone company.

Regards,
BigMike
Check out our new Rock Crawling Videos!
2016 56-speed 580:1 Tacoma Rock Crawler   
1981 36-speed 511:1 3RZ-FE Rock Crawler
1987 6-speed Supercharged 4A-GZE MR2
Instagram: @SlowestTacoma
Things are only impossible until they are not.
"The worst of both worlds, the best of neither." -abnormaltoy
"An informed question. But difficult to answer. I am what you see." -Nanaki

Cheesemaker

 :rofl2:   Nah this was all on Verizon.  Which like I said, I've gotten the calls and texts, but if I don't recognize the number or who the message came from I don't answer or reply. 

On a side note, I've gotten some crazy picture texts from somebody Hispanic.   And they are all about bathrooms!  And one has a fridge in it, right beside a toilet!!  :rofl2:  I saved that one!!
Miss ya Dean (4THEWKN) & Kyle (KYOTA)!!

4THEWKN~9/17/2006  If it wasn't for you, I'd be driving something other than a Toyota!

My build up ~ project Kilchis! http://board.marlincrawler.com/index.php?topic=32961.0
Zak's truck build ~ http://board.marlincrawler.com/index.php?topic=64319.0;topicseen

BigMike

Quote from: Cheesemaker on March 29, 2014, 09:26:07 AM
Mostly long distance phone calls!

Quote from: Cheesemaker on March 30, 2014, 09:55:57 PM
this was all on Verizon.

Verizon has free long distance (assuming you have remaining minutes on your billing cycle). Did they mean international calls?

Regards,
BigMike
Check out our new Rock Crawling Videos!
2016 56-speed 580:1 Tacoma Rock Crawler   
1981 36-speed 511:1 3RZ-FE Rock Crawler
1987 6-speed Supercharged 4A-GZE MR2
Instagram: @SlowestTacoma
Things are only impossible until they are not.
"The worst of both worlds, the best of neither." -abnormaltoy
"An informed question. But difficult to answer. I am what you see." -Nanaki

Cheesemaker

All their minutes got used up rather quickly.  Like in the first week of the billing cycle.  They said they rarely use up their minutes, cause their family was all on Verizon.  Calling another Verizon number is free, and you won't use your minutes. 
Miss ya Dean (4THEWKN) & Kyle (KYOTA)!!

4THEWKN~9/17/2006  If it wasn't for you, I'd be driving something other than a Toyota!

My build up ~ project Kilchis! http://board.marlincrawler.com/index.php?topic=32961.0
Zak's truck build ~ http://board.marlincrawler.com/index.php?topic=64319.0;topicseen

BigMike

Check out our new Rock Crawling Videos!
2016 56-speed 580:1 Tacoma Rock Crawler   
1981 36-speed 511:1 3RZ-FE Rock Crawler
1987 6-speed Supercharged 4A-GZE MR2
Instagram: @SlowestTacoma
Things are only impossible until they are not.
"The worst of both worlds, the best of neither." -abnormaltoy
"An informed question. But difficult to answer. I am what you see." -Nanaki

BigMike

Quote from: BigMike on November 08, 2013, 05:02:07 PM
There are a few different common types of encryption methods, in order of strength: Md5 (weaker -- what Pirate's/IH8MUD/YotaTech/TTORA/etc use), Sha1 (what our forum uses), and bcrypt (stronger). The first two methods are the most common while bcrypt is stronger but it places a larger load on the server. Nowadays it seems a lot of of software is migrating to the more powerful bcrypt and I believe the next version of our forum software (hopefully will be out before next Spring) will use bcrypt.

This just in: SMF released it's first public beta of our next forum version and announced they will be using bcrypt :booya: HA!! Take that Pirates, TTORA, and all you other SISSIES who sold out to the Canadian mega-butt-holes-taking-over-the-world VerticalScope jackasses. Damn community killers with lower grade forum software. /Rant off

More info here: http://www.simplemachines.org/community/index.php?topic=530233,
Quote"Password hashing has been improved from sha1 to bcrypt."

We'll be upgrading both our store website and forum to newer major versions this year. Store website has higher priority but should get them both done in 2015 :thumbs: New features, improved performance, stability, and most importantly security for our customers! :hattip:

Regards,
BigMike
Check out our new Rock Crawling Videos!
2016 56-speed 580:1 Tacoma Rock Crawler   
1981 36-speed 511:1 3RZ-FE Rock Crawler
1987 6-speed Supercharged 4A-GZE MR2
Instagram: @SlowestTacoma
Things are only impossible until they are not.
"The worst of both worlds, the best of neither." -abnormaltoy
"An informed question. But difficult to answer. I am what you see." -Nanaki