|  |  | 
 
  |  |  |  |  
  |  |  |  |  
  |  |  |  |  
  |  |  |  |  
  |  | 
	
		
   
   
      | Archive::News Archive area for New's posts that were moved here after an inactivity period of 90 days. |  
	
	
		
	
	
	| 
			
			 
			
				02-20-2004, 06:09 AM
			
			
			
		 |  
	| 
		
			|  | Dragon |  | 
					Join Date: Jan 2002 
						Posts: 708
					      |  |  
	| 
				 Change your passwords. 
 Due to changes in the database all passwords will need to be updated by 2 weeks from today. 
Please choose long, strong passwords.
 
Examples of which are (do not actually use these): 
cA!hA6a@haS2 
2ubev_G8pa2u 
pruv#qastu-a
 
Please visit http://www.winguides.com/security/password.php  if you have any trouble thinking up good passwords.
			
			
			
			
			
			
			
			
			
				
			
			
			
		 |  
	
		
	
	
	| 
			
			 
			
				02-20-2004, 07:03 AM
			
			
			
		 |  
	| 
		
			
			| Dragon |  | 
					Join Date: Jan 2004 
						Posts: 860
					      |  |  
	| 
 Just a side note from more info I saw posted on a forum for one of the servers, you have to change to a different password, you can't just change your password and then change it back to the one you use now. 
			
			
			
			
			
			
			
			
			
				
			
			
			
		 |  
	
		
	
	
	| 
			
			 
			
				02-20-2004, 07:07 AM
			
			
			
		 |  
	| 
		
			|  | Dragon |  | 
					Join Date: Mar 2003 Location: #loc 
						Posts: 745
					      |  |  
	| 
 I believe someone got hold of the forum database, so they have all our passwords in hashed form.
 The idea behind changing it is so if they do manage to decrypt the hash you've changed your password anyway :P
 
			
			
			
			
			
			
			
			
			
				
			
			
			
		 |  
	
		
	
	
	| 
			
			 
			
				02-20-2004, 07:24 AM
			
			
			
		 |  
	| 
		
			
			| Dragon |  | 
					Join Date: Jan 2004 
						Posts: 860
					      |  |  
	| 
 Exactly what I wanted to say, but I wasn't sure if the forum moderators wanted us to say that since they have been very cryptic on exactly what is going on with it in their posts.  But thats the reason I said to change your password completely because the way the moderator posted the news it sounds like all you have to do is update it to anything even the old value becuase of a databse change.  So it needs to be changed to something different or else the hash will be exactly the same and some one can still log in as you. 
			
			
			
			
			
			
			
			
			
				
			
			
			
		 |  
	
		
	
	
	| 
			
			 
			
				02-20-2004, 12:10 PM
			
			
			
		 |  
	| 
		
			|  | Dragon |  | 
					Join Date: Jan 2002 
						Posts: 708
					      |  |  
	| 
 We're changing pw style in the database.  Feel free to change back to  your old password if you want.  Several md5 password hashes were gotten, but unless you're an admin, I doubt anyone would take the time to crack it.  :P 
			
			
			
			
			
			
			
			
			
				
			
			
			
		 |  
	
		
	
	
	| 
			
			 
			
				02-21-2004, 01:31 AM
			
			
			
		 |  
	| 
		
			
			| Sarnak |  | 
					Join Date: Jun 2002 
						Posts: 30
					      |  |  
	| 
 Well sprite im taking a computer forensics class and one of the tools we use is md5 and also we learn all of the algorythems to crack it. So unless we use stronger encryption which there isnt any that i know of that cant be broken we wont be safe 
			
			
			
			
			
			
			
			
			
				
			
			
			
		 |  
	
		
	
	
	| 
			
			 
			
				02-21-2004, 01:45 AM
			
			
			
		 |  
	| 
		
			
			| Hill Giant |  | 
					Join Date: Mar 2003 Location: UK 
						Posts: 242
					      |  |  
	| 
 Nobody has "cracked" MD5. There are certain known weaknesses in it which mean that it's easier to crack than it ought to be but  it still can be considered secure at the moment.
 The danger of course is that people will have used dictionary words of simple variations which can be guessed.
 
			
			
			
			
			
			
			
			
			
				
			
			
			
		 |  
	
		
	
	
	| 
			
			 
			
				02-21-2004, 01:51 AM
			
			
			
		 |  
	| 
		
			
			| Hill Giant |  | 
					Join Date: Nov 2003 
						Posts: 192
					      |  |  
	| 
 One of the issues is that everyone knows phpBB uses md5 to 'encrypt' the passwords, so if you can get someones password by an sql injection exploit, you know how to brute force it (using mdcrack for example).
 If the admins alter the php code to change the encryption algorithm, then a would be hacker would have a lot harder time trying to crack it.
 
 Even with MD5, if you choose a password >9 characters with a mix of upper/lower case, numbers and non-alpha characters, brute forcing it using a PC would be extremely time consuming.
 
			
			
			
			
			
			
			
			
			
				
			
			
			
		 |  
	
		
	
	
	| 
			
			 
			
				02-21-2004, 06:27 PM
			
			
			
		 |  
	| 
		
			
			| Fire Beetle |  | 
					Join Date: Feb 2003 
						Posts: 12
					      |  |  
	| 
 You spell things out in hash? Sweet glory, hook a brotha up.   
			
			
			
			
			
			
			
			
			
				
			
			
			
		 |  
	
		
	
	
	| 
			
			 
			
				02-22-2004, 12:22 AM
			
			
			
		 |  
	| 
		
			
			| Sarnak |  | 
					Join Date: Jun 2002 
						Posts: 30
					      |  |  
	| 
 All im saying is that any good hacker uses a mathmematical forula to crack then encryption you dont need a program to do it like md5 as long as you figure out the math forula they use for that type of encryption you can hack anything you want 
			
			
			
			
			
			
			
			
			
				
			
			
			
		 |  
	
		
	
	
	| 
			
			 
			
				02-22-2004, 12:39 PM
			
			
			
		 |  
	| 
		
			
			| Fire Beetle |  | 
					Join Date: Jan 2003 
						Posts: 16
					      |  |  
	| 
				 only one problem chief 
 hey all
 the only problem with me is tht i have had to go back to the free e-mail sites and the one i am using now isnt supported by your system... now what do i do??? i dont want to get locked out because i am going to post a server and all... so waht do i do????
 
				__________________The Name of the game is death, the mark of Starbob
 
			
			
			
			
			
			
			
			
			
				
			
			
			
		 |  
	
		
	
	
	| 
			
			 
			
				02-22-2004, 01:13 PM
			
			
			
		 |  
	| 
		
			|  | Demi-God |  | 
					Join Date: Aug 2003 
						Posts: 1,056
					      |  |  
	| 
 Why cant you use the email account that comes with your ISP? 
				__________________   
	Quote: 
	
		| Analysis paralysis will keep you from failing, but it will also keep you from succeeding. | 
			
			
			
			
			
			
			
			
			
				
			
			
			
		 |  
	
		
	
	
	| 
			
			 
			
				02-23-2004, 11:54 AM
			
			
			
		 |  
	| 
		
			|  | Dragon |  | 
					Join Date: Jan 2002 
						Posts: 708
					      |  |  
	| 
 If you're stupid enough to have your password be a word in the dictionary and not have any numbers, then it's your own fault.
 
 7d8c1e812e4cb5d6d64cde9cca41a349 crack away ^_^
 
			
			
			
			
			
			
			
			
			
				
			
			
			
		 |  
	
		
	
	
	| 
			
			 
			
				02-24-2004, 08:57 AM
			
			
			
		 |  
	| 
		
			
			| Fire Beetle |  | 
					Join Date: Jan 2003 
						Posts: 16
					      |  |  
	| 
 well the only thing for that is i dont use the same isp.... i use a friends high speed account and he also uses a free e-mail hosting as well... should i e-mail a admin for permission or what??? 
				__________________The Name of the game is death, the mark of Starbob
 
			
			
			
			
			
			
			
			
			
				
			
			
			
		 |  
	
		
	
	
	| 
			
			 
			
				02-24-2004, 09:05 AM
			
			
			
		 |  
	| 
		
			
			| Dragon |  | 
					Join Date: Feb 2004 Location: Everywhere you want to be 
						Posts: 582
					      |  |  
	| 
 my password is 
 superultramegagiganticpowerfultough
 
 that sounds strong to me.
 
 and it's a ridiculously long password.
 
 i mean it don't get much more stronger than "superultramegagiganticpowerfultough"
 
				__________________An obnoxiously large picture should go here with some witty saying about some cartoon character I made in EQ, but then I realized that shit is fucking annoying.
 
			
			
			
			
			
			
			
			
			
				
			
			
			
		 |  
	
		
	
	
	
	
	| 
	|  Posting Rules |  
	| 
		
		You may not post new threads You may not post replies You may not post attachments You may not edit your posts 
 HTML code is Off 
 |  |  |  All times are GMT -4. The time now is 06:25 PM.
 
 |  |  
    |  |  |  |  
    |  |  |  |  
     |  |  |  |  
 |  |