Page 9 of 10 FirstFirst ... 678910 LastLast
Results 81 to 90 of 97

Thread: RTS hacked

  1. #81
    BANNED BT Rep: +15BT Rep +15BT Rep +15
    Join Date
    Jun 2007
    Posts
    302
    Quote Originally Posted by Melvinmeow View Post
    Earleir today RTS was hacked by a hacker who was a former user. This poopooface hacked into our database and found out we were really storing users passwords in non-encrypted form and thus was MAJORLY PISSED OFF and decided to nuke our site. (Please continue seeding your files until we can recover from this catastrophic loss of all your account information included passwords.) I mean loss of data.. Remember RTS staff will never ask you for your password because we can already see them anyways. Thanks RTS Staff
    ^^^ Found the above mentioned on another forum elsewhere. ^^^
    Perhaps thats the reason they were hacked?

    If you guys need any help with finding out who did it feel free to pm me. I can help you go through the logs to figure out how they got in.
    They can already see your password? Is this true for all torrent sites? I thought everything is supposed to be encrypted, and passwords couldn't be seen.

  2. BitTorrent   -   #82
    Something Else's Avatar sex a wolf in a bag BT Rep: +70BT Rep +70BT Rep +70BT Rep +70BT Rep +70BT Rep +70BT Rep +70BT Rep +70BT Rep +70BT Rep +70BT Rep +70BT Rep +70BT Rep +70BT Rep +70
    Join Date
    Mar 2007
    Location
    Addicted to placebos
    Posts
    11,863
    All torrent sites encrypt your password by default if they are using TBDEV. The option has to be manually removed as it was in this case from what I've read.
    Now go away.

  3. BitTorrent   -   #83
    Poster BT Rep: +25BT Rep +25BT Rep +25BT Rep +25BT Rep +25
    Join Date
    Oct 2006
    Posts
    331
    Quote Originally Posted by Rugmuncher View Post
    My second post;

    If indeed the passwords were kept in plainform text for the first 2 days that the site was created, whats the problem? It was only two days that it was not encrypted. As far as i can see the DB table is now encrypted, and is working fine... Really i don't see any security risks at all, and even if the passwords were in plaintext you wouldn't be able to access them directly without root axx because of the permissions on the log.php of the time.

    there is so much wrong with this that i dont even know where to start. Why in hell would you edit source code to even take out the hash to even store this in plain text.

    if it is fixed now i would not put it past them that files were changed so that it stores then in plain text and in hash/md5.. Just shows again not to trust this site.

    Also you dont need log.php to see this info, all you would have to do is set up a section in userdeatils.php and set it to sysop class or what ever class and you can see passwords if in plain text, you could also have a search script where all you have to do is search a users name and it tells you password. So again such a bad idea and proves site cant be trusted.



    Quote Originally Posted by mforcex View Post
    Quote Originally Posted by Melvinmeow View Post
    ^^^ Found the above mentioned on another forum elsewhere. ^^^
    Perhaps thats the reason they were hacked?

    If you guys need any help with finding out who did it feel free to pm me. I can help you go through the logs to figure out how they got in.
    They can already see your password? Is this true for all torrent sites? I thought everything is supposed to be encrypted, and passwords couldn't be seen.


    No this is not true. All trusted sites would never do this. As of right now i only know 1 site that has ever done this or tried this and it is RTS.



    wild
    Last edited by wildbytes; 06-26-2007 at 01:22 AM. Reason: Automerged Doublepost

  4. BitTorrent   -   #84
    BANNED BT Rep: +15BT Rep +15BT Rep +15
    Join Date
    Jun 2007
    Posts
    302
    Quote Originally Posted by benchez View Post
    All torrent sites encrypt your password by default if they are using TBDEV. The option has to be manually removed as it was in this case from what I've read.
    You have got to be kidding me... so at any time, an admin can turn off the encrypt feature and check out your password?

    This can't be... I mean... I thought ALL websites encrypted passwords, torrent site or not.

    EDIT:
    Do you guys use a unique password for every website, a few passwords, or one password?
    Last edited by mforcex; 06-26-2007 at 01:25 AM.

  5. BitTorrent   -   #85
    Poster BT Rep: +25BT Rep +25BT Rep +25BT Rep +25BT Rep +25
    Join Date
    Oct 2006
    Posts
    331
    Quote Originally Posted by mforcex View Post
    Quote Originally Posted by benchez View Post
    All torrent sites encrypt your password by default if they are using TBDEV. The option has to be manually removed as it was in this case from what I've read.
    You have got to be kidding me... so at any time, an admin can turn off the encrypt feature and check out your password?

    This can't be... I mean... I thought ALL websites encrypted passwords, torrent site or not.


    No you would have to remove the the md5 hash code and change this to save as plain text. All torrent source codes use md5 hash


    I use a different password on ever site, and you should also.






    Wild
    Last edited by wildbytes; 06-26-2007 at 01:29 AM.

  6. BitTorrent   -   #86
    TheFoX's Avatar www.arsebook.com
    Join Date
    Jan 2007
    Posts
    1,567
    Quote Originally Posted by wildbytes View Post
    No this is not true. All trusted sites would never do this. As of right now i only know 1 site that has ever done this or tried this and it is RTS.

    wild

    This is actually the second time a site has stored passwords as plaintext. I cannot remember the name of the first site to do it, but I do remember that they used the plaintext passwords to access the members' accounts at another tracker, and leeched from those members' accounts.

    The information is on TPG, but since it is currently down, no one can reference it.

    The ONLY reason to store plaintext passwords is to allow the Site Operators access to similar accounts on other trackers. PERIOD...

  7. BitTorrent   -   #87
    Gish's Avatar Seeda from Hell BT Rep: +14BT Rep +14BT Rep +14
    Join Date
    May 2006
    Location
    My Underpants!!!
    Posts
    734
    its funny... I would be able to forgive rts but since RTS the member here at FST and staff at RST has not respond in defense since the first page. it is just making them look as guilty as many other members here say they are.... I will no longer be using RTS.

  8. BitTorrent   -   #88
    I think all that had to be done, was to explain from the beginning. So if the passwords where plain text for 2 days, why say they never where?
    ______________________________________________

  9. BitTorrent   -   #89
    Buggyme's Avatar Retired BT Rep: +35BT Rep +35BT Rep +35BT Rep +35BT Rep +35BT Rep +35BT Rep +35
    Join Date
    Sep 2006
    Posts
    539
    Quote Originally Posted by seppypom View Post
    I think all that had to be done, was to explain from the beginning. So if the passwords where plain text for 2 days, why say they never where?
    Well, it's just word for word.
    Melvinmeow said the passwords were in plaintext.
    RTS said the passwords were always encrypted.

    I think, like wild said, we should just use different passwords at all sites just to be 100% sure.

    I did code for RTS for a bit when the site started, and I saw nothing wrong with the user authentication system as they were using the default TBDev system (MD5 encryption). And because of this, I have to defend RTS. (BTW, IRC passwords are not encrypted, that's why there's a note saying that you should use a different password than the site password)

    I'm not sure why you guys think that the staff members are untrusted and are account 'stealers'. I've personally been in contact with them and know that they have absolutely no motive to steal others' accounts as they already have 'good' accounts in most torrent sites. Why wouldn't they? They have seedboxes, and axx too.

    I'm not even sure how, and I mean, the technical details, on how melvinmeow came to see that the passwords were not encrypted. So, if you can PM me melvinmeow, that would be great. Same goes with wild, where exactly did you hear that RTS is untrusted from? If you can explain that to me in PM, that would be nice too, because I'm seriously lost on why you guys think that RTS is untrusted.

    Quote Originally Posted by gish View Post
    its funny... I would be able to forgive rts but since RTS the member here at FST and staff at RST has not respond in defense since the first page. it is just making them look as guilty as many other members here say they are.... I will no longer be using RTS.
    Personally, I don't think RTS can do anything in response.
    As I said before, it's just word for word. Melvinmeow's against RTS'.

  10. BitTorrent   -   #90
    How about melvinmeow PM's me on how he read these logs of plaintext.

    If he can't come up with it, well ill just post and confirm that he didn't gain access to the rts box.

    IMHO; melvinmeow is creating social rubbish to put down a troubled torrent site..

    Should I post the attacking IP's?

Page 9 of 10 FirstFirst ... 678910 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •