net-cat (thevirtualcat) wrote in furaffinity,
net-cat
thevirtualcat
furaffinity

February 26, 2009: What happened.

Oh, where to begin... So much happened. A hijacked account, an administrative mistake and an unpleasant piece of our history coming back to haunt us.

During the whole ordeal, three accounts were defaced: nek0gami, tincrash and hobbesmaxwell.

It started when tincrash's email account was compromised, as explained in this forum post. The attacker reset tincrash's password, logging in an started deleting pictures.

An administrator, who will not ever be named publicly by anyone in FA's administration, responded to the problem, banning the account and deleting the inappropriate pictures that were posted. Unfortunately, a mistake was made and there was a period of about four minutes where tincrash's account was set to administrator, rather than banned. In this time, the attacker used his newfound access to the admin panel to compromise nek0gami's account.

I really don't know why the attacker went for nek0gami and not one of the administrative accounts, but once the mistake was corrected, the danger to the site was over as the user in question no longer had administrative access. (The screen shots that were posted may have been a clue... the attacker was too stupid to think of that.)

This was confirmed after a night of furious log grepping by yak and tsawolf. Bow down before them, as they are your gods.

After hundreds of attempts to regain administrative access through both nek0gami and tincrash's accounts, the attacker gave up, instead deciding to rely on an old fall-back of people who hate furries and/or FA. And that would be the list of passwords leaked years ago... by... uh... fuck. I don't know. Nobody seems to actually know who originated it.

There are about 4800 accounts on said list and the attacker picked one and got lucky. This is how he got into hobbesmaxwell's account. (We stopped him before anything was deleted, in this case.)

On a whim, I took the leaked password database and compared it to site's current user table. I was utterly shocked... no... horrified by what I found. Over 700 accounts were still using the same password. The same password that had been leaked years earlier and is available to anyone who cared to look for it. So we purged them. When some people reset their passwords to the same thing, we started leaving shouts on their pages as themselves when we locked them out. (See more details on the forums.)

That is everything that went down yesterday. I would like to leave you with a warning, though.

The person who originally initiated this unfortunate incident really seems to have it in for furries in general. We've gotten reports of other accounts being compromised in much the same way as tincrash's was, getting defaced by the same person. (Yes, we've checked our logs. All the people in question were attacked through the password reset feature, which would require access to their email.) Naturally, people who hate furries are hardly unusual. We all know this. This is just meant as a warning to make sure your systems are patched, behind a firewall (most modern consumer routers are also firewalls) and have sufficient virus protection.
Subscribe
Only problem I see on here is that the hacker probably also watches on LJ & probably as well as the forums. :P

I changed my password tonight anyway.

I wish you luck in tracking him or her down though.

Z
Bow down before them, as they are your gods.

Could you be any more pretentious?
Why must people take things that are simply and obviously a joke as seriousness. Please go grow up.
Why must you speak for others when you've got little/nothing to do with them?

I re-state my comment of "Could you be any more pretentious?"
Could you be the one who's been screwing around with accounts?

Deleted comment

Friday was my birthday. I was out of town for the weekend.

Yes, it was totally me! You caught me!
I suppose it's a matter of whether or not you'd like your account to be compromised because someone else doesn't know best practices for security.

Having been on the other side of the fence, I can safely say that it sucks balls to pore (or grep) through what could be millions of lines of logfile-y goodness looking for that one nugget of clarity.

The least they deserve in return for your security is a little gratitude. <3
What security? I've been banned three times (two permanent).

I've lost money due to my shit getting hacked, but I re-gained it because the company I lost it through (PayPal) saw that my account was compromised and worked with my bank to have the crap removed.

I have no gratitude to a administration "team" that is led by an incompetent ass who can't even have them inpliment an E-MAIL VERIFICATION SYSTEM.

I've been signing up using the same e-mail address EVERY TIME I start up a sock/troll account. The account gets banned, I change my proxy, create another account and I'm back in the game in less than 60 seconds. But that's back when I didn't have a life and loved to troll FA. Now I don't see the fun in picking on the retarded child of the internet.
If your Paypal got "hacked" I can almost guarantee that it was due to weak password security. Enjoy your fail. :-D
The only way anyone could have got my password is through either a keylogger OR I got hit by a scanner that snagged my Paypal debit card's information when I pulled some money from it a couple weeks ago.

My passwords are by no means "weak".
If there's one (albeit unfortunate) fact I've learned as a sysadmin, it's that people will ALWAYS use weak passwords and will ALWAYS reset them to weak ones, given the opportunity.

I'm sure there's a timestamp feature of some kind, so it shouldn't be too hard to implement a rollback feature for compromised accounts. You might set up a "Hall of Shame" for people with the worst track records of account compromises too. :-P
I don't think they could afford the bandwidth to host such a list. The vast majority of FA's userbase wouldn't be considered for Valedictorian in this lifetime.
They liked it 0