Staredit Network

Staredit Network -> Staff Lounge -> Security "breach"
Report, edit, etc...Posted by IsolatedPurity on 2006-04-15 at 11:19:57
So, somehow, someone got into Moogle's account. I have no idea who it was because he was rather smart about it. I don't even know the method used. I'm guessing Moogle's password was weak. I know I shouldn't have to remind you of this, but your existance of staff on SEN means you need to secure your account more than if you were just a member. So if you don't have a good password, get a new one now. 10+ characters with numbers, letters, and puncuation is the best. Mine is 29 random characters.
Also, use a different password then your other passwords. That way, if one password is broken at one site, all the other sites stay safe.

You might as well as start getting into good password protection schemes for later on in life. You don't want people hacking into your paypal account because your password at random.site.x was crackable.

Moogle's powers has been suspended indefinitely, but not his account. If anyone knows Moogle personally, get in contact with him on an im and let him know he needs to change his password.


Edit: And oh, Moose, you asked a very good question:
QUOTE
On that subject, I'm curious as to who ratted it out.

The hacker on Moogle's account did.

Picture of the staff forum: http://img74.imageshack.us/img74/2563/ir0x9yf.jpg
Report, edit, etc...Posted by CaptainWill on 2006-04-15 at 11:29:41
Hmm, I don't really want to change my password - it's 9 random letters, which I hope is good enough.
Report, edit, etc...Posted by IsolatedPurity on 2006-04-15 at 12:13:27
9 random letters is pretty good.
Report, edit, etc...Posted by BeeR_KeG on 2006-04-15 at 13:28:28
Hell, I don't even know my password. Everytime I clear my cache, I need to use the "I forgot my password" function to get in.

I would guess that it's about 15~20 characters with letters, numbers and symbols.
Report, edit, etc...Posted by Mini Moose 2707 on 2006-04-15 at 13:47:08
All staff should be changing their passwords every few months anyway. I'll tell Moogle when I see him on MSN, assuming he has a different password there. I also wouldn't go "my password is this or that", this forum isn't completely unreadable.
Report, edit, etc...Posted by BeeR_KeG on 2006-04-15 at 14:06:56
I had a link, which I've tried to get but can't get it, that was a chart with different password combinations and number of characters and on the other side it displayed the time to crack that password. There were different charts for different computers, ranging from a 75Mhz computer to a whole network of Supercomputers. Some combinations were instant, others took millions of years.
I'm still trying to find that link.
Report, edit, etc...Posted by Voyager7456(MM) on 2006-04-15 at 14:20:53
Was it the one from Latova? I think the topic was deleted. sad.gif
Report, edit, etc...Posted by BeeR_KeG on 2006-04-15 at 14:22:20
Ya, that's the one.
Report, edit, etc...Posted by DT_Battlekruser on 2006-04-15 at 14:50:50
100:1 says Kellimus is the hacker. Why the hell was he ever let back here?
Report, edit, etc...Posted by Voyager7456(MM) on 2006-04-15 at 17:16:49
Well apparently he has at least some connection to the hacker.

http://www.staredit.net/index.php?showtopic=29019
Report, edit, etc...Posted by DT_Battlekruser on 2006-04-15 at 17:51:13
QUOTE(Kellimus @ Apr 15 2006, 03:01 AM)
LIARS.  The internet is full of them.  How do you know when you find one?  Easily.  Look around.  It's not hard.  Look at where you are.  It's quiet simple smile.gif

What do you think?  I think everyone here are liars.  Do you?  What is your opinion on this?

(I post this thread because of knowledge gained by my intelligence agents that I now claim.  They have enlightened me to some members TRUE selves.  Enjoy ^_^)
[right][snapback]465769[/snapback][/right]


Quoted for refenerence over editing.
Report, edit, etc...Posted by CaptainWill on 2006-04-15 at 19:24:59
He's probably found out that I'm not really on his side. =/
Report, edit, etc...Posted by DT_Battlekruser on 2006-04-15 at 21:46:14
Drat, there goes the DIA.
Report, edit, etc...Posted by Voyager7456(MM) on 2006-04-15 at 21:47:12
Talked to Moogle and explained what happened. He's changed his password now.
Report, edit, etc...Posted by LegacyWeapon on 2006-04-15 at 21:50:53
I'm pretty sure he was connected to King too because I was in Clan Oo and there were some people there laughing at how bad SEN's security is.
Report, edit, etc...Posted by Mini Moose 2707 on 2006-04-15 at 21:53:28
I guess this is a good time to post up the e-mail Zombie sent me. I bolded the important parts and took out my e-mail addy.

QUOTE
From: Alien Drone <aliendrone2006@yahoo.com> Signed-By: yahoo.com | Mailed-By: yahoo.com
To: Staredit Network <--->
Date: Apr 12, 2006 5:45 PM
Subject: Re: Zombie Banned ( From Staredit Network )
So?  I don't really care, oh btw I'm back smile.gif. Good luck trying to find me. Proxie FTW!


You are nubs. Dumb asses to be exact. Sen's will fail btw. Now that I'm banned I can actuall do a few things to the site. For one.

Bruteforce a few accounts and have fun.

Good day fark head.
Report, edit, etc...Posted by Voyager7456(MM) on 2006-04-15 at 21:55:08
Oh boy, do we get to send a letter to his ISP too? ermm.gif
Report, edit, etc...Posted by CheeZe on 2006-04-15 at 21:55:37
I'll email the ISP if someone already hasn't.

(Just tell me how)
Report, edit, etc...Posted by LegacyWeapon on 2006-04-16 at 01:43:37
Location:
Twin Falls, Idaho, USA
Not a proxy

ISP:
CableONE
Acceptable Use Policy
QUOTE
CableOne.Net High Speed Internet Access Service
Acceptable Use Policy

Last modified: June 27, 2005

Important Note: Cable One, Inc. may revise this Acceptable Use Policy from time to time without notice by posting a new version of this document on the CableOne.Net Web site at http://www.cableone.net/internet/cmaup.asp. Accordingly, users of the CableOne.Net residential services should consult this document regularly to ensure that their activities conform to the most recent version. In the event of a conflict between any subscriber agreement and this policy, the terms of this policy will govern. Questions regarding this policy can be directed to legal@cableone.net. Complaints of violations of this policy by CableOne.Net users can be directed to abuse@cableone.net.


Introduction

Cable One, provides a variety of Internet services to residences and businesses (the "Services"). The CableOne.Net residential service allows subscribers to connect to the Company's high-speed Internet connection. The Services use resources that are shared with many other customers. Moreover, the Services provide access to the Internet, which is used by millions of other users. Each user benefits by being able to share resources and communicate almost effortlessly with other members of the user community. However, as with any community, the benefits and privileges available from the Services, and the Internet in general, must be balanced with duties and responsibilities so that other users can also have a productive experience. Use of the Services is subject to the following rules and guidelines. Each customer of CableOne.Net is responsible for ensuring that the use of all Services provided to such customer complies with this Acceptable Use Policy (the "Policy"). ANY USER WHO DOES NOT AGREE TO BE BOUND BY THESE TERMS SHOULD IMMEDIATELY STOP USE OF THE SERVICES AND NOTIFY THE CABLE ONE CUSTOMER SERVICE DEPARTMENT SO THAT THE USER'S ACCOUNT MAY BE CLOSED.


Illegal Activity

The use of the Services for any activity that violates any local, state, federal or international law, order or regulation is a violation of this Policy. Prohibited activities include, but are not limited to:

    * Posting or disseminating material which is unlawful (such as child pornography or obscene material).
    * Disseminating material which violates the copyright or other intellectual property rights of others. You assume all risks regarding the determination of whether material is in the public domain.
    * Pyramid or other illegal soliciting schemes.
    * Any fraudulent activities, including impersonating any person or entity or forging anyone else's digital or manual signature.



Security

You are responsible for any misuse of the Services that you have contracted for, even if the inappropriate activity was committed by a friend, family member, guest, employee or customer with access to your account. Therefore, you must take steps to ensure that others do not gain unauthorized access to the Services. The Services may not be used to breach the security of another user or to attempt to gain access to any other person's computer, software or data, without the knowledge and consent of such person. They also may not be used in any attempt to circumvent the user authentication or security of any host, network, or account. This includes, but is not limited to, accessing data not intended for you, logging into or making use of a server or account you are not expressly authorized to access, or probing the security of other networks. Use or distribution of tools designed for compromising security, such as password guessing programs, cracking tools, port scanners, packet sniffers or network probing tools, is prohibited. You may not disrupt the Services. The Services also may not be used to interfere with computer networking or telecommunications services to any user, host or network, including, without limitation, denial of service attacks, flooding of a network, overloading a service, improper seizing and abuse of operator privileges and attempts to "crash" a host. The transmission or dissemination of any information or software which contains a virus, worm or other harmful feature also is prohibited. You are solely responsible for the security of any device you choose to connect to the Services, including any data stored on that device. In particular, Cable One, Inc. recommends against enabling file or printer sharing of any sort. Cable One, Inc. recommends that any files or services you do choose to make available for remote access be protected with a strong password, personal firewall or as otherwise appropriate.
I don't know any other rules that Zombie broke but that's the part about bruteforcing.
Report, edit, etc...Posted by Revelade on 2006-04-16 at 02:33:58
Do you have any proof that it IS in fact, Kell or Zombie? Just to prevent a pointingfest, let's make 100% who really is the hacker.

Sigh, I don't see why everyone's acting so worked up these days. The bannage of Slyence still shocks me to this day.
Report, edit, etc...Posted by IsolatedPurity on 2006-04-16 at 07:27:08
It's not kelly...
Report, edit, etc...Posted by BeeR_KeG on 2006-04-16 at 10:17:17
Not Kellimus, as far as I know, I can't talk to myself on messenger.

Proxies won't do much. His ISP is still the same and eventually, his IP Addresses will start to match.

I've also checked Zombie's posts and IPAddreses, and he's under no such proxie that he 's stating about. He's been using the same IP Address since Mar 10 2006, 04:18 PM under 69.92.189.215.
Report, edit, etc...Posted by IsolatedPurity on 2006-04-17 at 21:45:43
It was zombie. Confirmed...
Report, edit, etc...Posted by CheeZe on 2006-04-17 at 21:51:47
Umm... have we done something against him yet (ISP, etc)?
Report, edit, etc...Posted by IsolatedPurity on 2006-04-18 at 08:35:33
What would that exactly do? Couldn't his family just get a new isp if they deny service to them anymore? And that would just mean he'd have a new ip. His ip is relatively stable enough to block him with htaccess... ... ...
So I dunno. I'm going to try contacting them to see if they can filter staredit.net from their account to deny him of even using proxies... That doesn't stop him from accessing SEN from school or friends houses though.

I have to wonder if Zombie is the reason why Google is now disallowing staredit.net from participating in AdSense (if you notice the lack of ads... that's why).
Next Page (1)