|
#1
| |||
| |||
| My e-mail hacked by a MacOSX Member
I have just discovered that my mobileme email had been set to forward to a gmail account that shared the same login name as a member here. I believe them to be linked because I used the same password for my e-mail address as I did for my membership here, which leads me to believe they got my password from here. Could a moderator please contact me for the username of the member who may have hacked me?
|
|
#2
| ||||
| ||||
|
You can directly PM the Admin and individual Mods. --J.D.
__________________ MacBook 2.4 GHz Intel Core 2 Duo, 6 Gig RAM, 10.6.1 Fear Me! FEAR ME! His secrets are not sold cheaply. It is perilous to waste his time. |
|
#3
| ||||
| ||||
|
Contact Cheryl, Scottw or one of the mods (like me) with the details. If you are able to still access your .mac emails, change the password to something that uses a different logic. Also if you use the same password (or logic for passwords) for any other site, change them as well. Sometimes the people that might know/guess your password are more closely related to you, e.g. once my ex called me because I had changed my email password and he couldn't access it... It might be also worth to check with http://www.apple.com/support/mobileme/ if anyone other than yourself has accessed it, e.g. from which IP address the forwards were done from.
__________________ MacBook Pro | Dell Mini Inspiron 9 | Mac Mini | Newton 2000 | iPhone | @Work : Dell D620 & 2x20" + a lot of Macs | Workstation, VC & Fusion Twenty years from now you will be more disappointed by the things that you didn't do than by the ones you did do. ~ Samuel Clemens | Rants | Photos |
|
#4
| ||||
| ||||
|
For future reference, it's an extremely bad idea to use the same password for multiple places. I'd be willing to bet a small amount of money that you use the same password for a banking site, or some site that holds more personal and/or important information than here and your email. Bad, bad idea. If you have trouble remembering passwords, there are utilities and programs out there that specifically address that problem, like 1Password: http://agilewebsolutions.com/products/1Password Also, "hacked" entails that someone used some method of bypassing your password to illegally gain access to your accounts -- which doesn't sound like the case here. It sounds like someone simply guessed your password (was it a strong password, or something easy like a word, phrase, pet's name or birthday?), then tried the same password at another site. This is NOT hacking -- it's simply the result of choosing an easy-to-guess password. Think of it as leaving your front door to your house wide-open, then someone comes while you're away and steals all your stuff... you'd have a hard time convincing anyone that they "broke in" to your house, since they didn't "break in" at all -- rather, they waltzed right through the gaping hole you left open for them. This may or may not be the situation here; I'm just putting out a fair warning that people need to choose stronger passwords going forward, and no password should ever be used more than once. Wanting to remember easy passwords and avoid forgetting them, or using the same password more than once so you only have to remember a single password is no excuse -- I'd like to just leave my car wide open so I don't have to go through the hassle of putting the key in the lock (it would be much easier!), but that would just be plain stupid and I stand more to lose than I do to gain. Just information to think about in the future.
__________________ Mac mini 2.0GHz 10.6.1 4GB 320GB Superdrive 4 x 1TB USB 2.0 LED Cinema Display MacBook 2.0GHz Core 2 Duo - White 10.6.1 4GB 250GB CD-RW/DVD-ROM iPhone 3G 8GB iPod Touch 8GB iPod Photo 60GB iPod nano 1GB AT&T U-Verse 18Mb/2Mb http://www.jeffhoppe.com |
|
#5
| |||
| |||
| Quote:
Quote:
|
|
#6
| ||||
| ||||
|
I also doubt that it was acquired from the site, vBulletin encodes your passwords when it stores, so that pretty much only the creators could decode your password. Also only the administrator has access to the file that contains the password, since it is stored in the MySQL database. I doubt ScottW would ever do such a thing, or even spend a bunch of time to steal one member's password. So it would seem that you might have used your password on a not so safe site.
__________________ Be sure to thank the person that helps you! MacBook 2.1 GHz , 250 GB, 2 GB, OS 10.6.1 PowerMac G5 Dual 2.3 GHz, 750 GB, 1 GB, OS 10.5.8 Server PowerMac G4 Dual 1.25 GHz, 120 GB, 100 GB RAID, 1.5 GB, OS 10.5.8 Server iPod Classic Black 120 GB Favorite Bands: Anberlin, Five Iron Frenzy My Site |
|
#7
| ||||
| ||||
| Quote:
That's exactly what happens when you log in to any site that stores encrypted passwords -- whatever password you enter in the password box is encrypted using the same method as the original password was encrypted in, the two encrypted strings are compared, and if they match -- voila -- you just logged in. Otherwise, "Invalid password." Sites who email your password to you (and do not do the "smarter" thing, which is either email you a new, randomly-generated password or require you to visit a form to reset your password and enter a new one) do not store the passwords in an encrypted manner. There are some encryption techniques that are "two-way," meaning that you can both encrypt and decrypt, enabling one to reverse the encryption of a password if they have the "secret key" or the unencryption method available to them. A lot of these types of encryption techniques are no more effective than just storing the password in plaintext. Of course, pretty much all encryption techniques can be "cracked," but I would be pleasantly surprised if any member or moderator of this forum has the computing power or the resources and knowledge to do such a thing to a one-way (hash) encryption. If they did, their country's government would probably be paying them six figures or more. I would hope this forum uses a one-way hash encryption for password storage, but then again, not much havok could be wreaked if a password was stolen, other than posting a bunch of lewd comments or something.
__________________ Mac mini 2.0GHz 10.6.1 4GB 320GB Superdrive 4 x 1TB USB 2.0 LED Cinema Display MacBook 2.0GHz Core 2 Duo - White 10.6.1 4GB 250GB CD-RW/DVD-ROM iPhone 3G 8GB iPod Touch 8GB iPod Photo 60GB iPod nano 1GB AT&T U-Verse 18Mb/2Mb http://www.jeffhoppe.com |
|
#8
| ||||
| ||||
|
Why not just change your password and lock that hacker out? Of course this user needs to be questioned and dealt with if guilty.
__________________ http://thesalon.blogspot.com |
![]() |
| Bookmarks |
| Thread Tools | |
|
|