image
image

Go Back   macosx.com > Site Forums > Site Discussion

Reply
 
LinkBack Thread Tools
  #1  
Old November 11th, 2008, 11:25 AM
Registered User
 
Join Date: Oct 2001
Location: Warroad, MN
Posts: 12
Thanks: 0
Thanked 0 Times in 0 Posts
Cory Bauer is on a distinguished road
My e-mail hacked by a MacOSX Member

I have just discovered that my mobileme email had been set to forward to a gmail account that shared the same login name as a member here. I believe them to be linked because I used the same password for my e-mail address as I did for my membership here, which leads me to believe they got my password from here. Could a moderator please contact me for the username of the member who may have hacked me?
Reply With Quote
  #2  
Old November 11th, 2008, 05:17 PM
Doctor X's Avatar
Registered User
 
Join Date: Nov 2007
Posts: 901
Thanks: 67
Thanked 61 Times in 59 Posts
Doctor X will become famous soon enough
You can directly PM the Admin and individual Mods.

--J.D.
__________________
MacBook 2.4 GHz Intel Core 2 Duo, 6 Gig RAM, 10.6.1
Fear Me! FEAR ME!

His secrets are not sold cheaply.
It is perilous to waste his time.
Reply With Quote
  #3  
Old November 11th, 2008, 05:50 PM
Giaguara's Avatar
Chmod 760
 
Join Date: Nov 2002
Location: ~
Posts: 8,593
Thanks: 7
Thanked 98 Times in 97 Posts
Giaguara is a jewel in the roughGiaguara is a jewel in the roughGiaguara is a jewel in the rough
Contact Cheryl, Scottw or one of the mods (like me) with the details.

If you are able to still access your .mac emails, change the password to something that uses a different logic. Also if you use the same password (or logic for passwords) for any other site, change them as well. Sometimes the people that might know/guess your password are more closely related to you, e.g. once my ex called me because I had changed my email password and he couldn't access it...

It might be also worth to check with http://www.apple.com/support/mobileme/ if anyone other than yourself has accessed it, e.g. from which IP address the forwards were done from.
__________________
MacBook Pro | Dell Mini Inspiron 9 | Mac Mini | Newton 2000 | iPhone | @Work : Dell D620 & 2x20" + a lot of Macs | Workstation, VC & Fusion
Twenty years from now you will be more disappointed by the things that you didn't do than by the ones you did do.
~ Samuel Clemens | Rants | Photos
Reply With Quote
  #4  
Old November 11th, 2008, 08:04 PM
ElDiabloConCaca's Avatar
Registered User
 
Join Date: Aug 2001
Location: San Antonio, Texas
Posts: 12,602
Thanks: 7
Thanked 370 Times in 352 Posts
ElDiabloConCaca is a glorious beacon of lightElDiabloConCaca is a glorious beacon of lightElDiabloConCaca is a glorious beacon of lightElDiabloConCaca is a glorious beacon of lightElDiabloConCaca is a glorious beacon of lightElDiabloConCaca is a glorious beacon of light
For future reference, it's an extremely bad idea to use the same password for multiple places. I'd be willing to bet a small amount of money that you use the same password for a banking site, or some site that holds more personal and/or important information than here and your email. Bad, bad idea.

If you have trouble remembering passwords, there are utilities and programs out there that specifically address that problem, like 1Password:

http://agilewebsolutions.com/products/1Password

Also, "hacked" entails that someone used some method of bypassing your password to illegally gain access to your accounts -- which doesn't sound like the case here. It sounds like someone simply guessed your password (was it a strong password, or something easy like a word, phrase, pet's name or birthday?), then tried the same password at another site. This is NOT hacking -- it's simply the result of choosing an easy-to-guess password. Think of it as leaving your front door to your house wide-open, then someone comes while you're away and steals all your stuff... you'd have a hard time convincing anyone that they "broke in" to your house, since they didn't "break in" at all -- rather, they waltzed right through the gaping hole you left open for them.

This may or may not be the situation here; I'm just putting out a fair warning that people need to choose stronger passwords going forward, and no password should ever be used more than once. Wanting to remember easy passwords and avoid forgetting them, or using the same password more than once so you only have to remember a single password is no excuse -- I'd like to just leave my car wide open so I don't have to go through the hassle of putting the key in the lock (it would be much easier!), but that would just be plain stupid and I stand more to lose than I do to gain.

Just information to think about in the future.
__________________
Mac mini 2.0GHz 10.6.1 • 4GB • 320GB • Superdrive • 4 x 1TB USB 2.0 • LED Cinema Display
MacBook 2.0GHz Core 2 Duo - White 10.6.1 • 4GB • 250GB • CD-RW/DVD-ROM
iPhone 3G 8GB • iPod Touch 8GB • iPod Photo 60GB • iPod nano 1GB • AT&T U-Verse 18Mb/2Mb
http://www.jeffhoppe.com
Reply With Quote
  #5  
Old November 11th, 2008, 08:48 PM
Registered User
 
Join Date: Oct 2001
Location: Warroad, MN
Posts: 12
Thanks: 0
Thanked 0 Times in 0 Posts
Cory Bauer is on a distinguished road
Quote:
Originally Posted by ElDiabloConCaca View Post
For future reference, it's an extremely bad idea to use the same password for multiple places. I'd be willing to bet a small amount of money that you use the same password for a banking site, or some site that holds more personal and/or important information than here and your email. Bad, bad idea.
Duly noted, and no longer the case.

Quote:
Originally Posted by ElDiabloConCaca View Post
Also, "hacked" entails that someone used some method of bypassing your password to illegally gain access to your accounts -- which doesn't sound like the case here. It sounds like someone simply guessed your password (was it a strong password, or something easy like a word, phrase, pet's name or birthday?), then tried the same password at another site. This is NOT hacking -- it's simply the result of choosing an easy-to-guess password.
Trust me, they did not guess my password; it was a string of numbers that mean nothing to anyone. Much as I hate to throw around the "hacked" claim because I think it's clichι and overused, I do believe I was in fact hacked. The member whom my email had been set to forward to is also a member of Nulledscriptz (a webmaster resource forum), a second webmaster forum, and has posts on several forums where he is trying to sell rapidshare accounts, adword vouchers, legalsounds accounts, skype accounts, and vbulletin licenses.
Reply With Quote
  #6  
Old November 11th, 2008, 09:17 PM
icemanjc's Avatar
I'm Cool, I have a Mac.
 
Join Date: Jan 2007
Location: Ft. Lauderdale, FL
Posts: 1,029
Thanks: 2
Thanked 27 Times in 25 Posts
icemanjc has a spectacular aura abouticemanjc has a spectacular aura about
I also doubt that it was acquired from the site, vBulletin encodes your passwords when it stores, so that pretty much only the creators could decode your password. Also only the administrator has access to the file that contains the password, since it is stored in the MySQL database. I doubt ScottW would ever do such a thing, or even spend a bunch of time to steal one member's password. So it would seem that you might have used your password on a not so safe site.
__________________
Be sure to thank the person that helps you!
MacBook 2.1 GHz , 250 GB, 2 GB, OS 10.6.1
PowerMac G5 Dual 2.3 GHz, 750 GB, 1 GB, OS 10.5.8 Server
PowerMac G4 Dual 1.25 GHz, 120 GB, 100 GB RAID, 1.5 GB, OS 10.5.8 Server
iPod Classic Black 120 GB

Favorite Bands: Anberlin, Five Iron Frenzy
My Site
Reply With Quote
  #7  
Old November 11th, 2008, 10:30 PM
ElDiabloConCaca's Avatar
Registered User
 
Join Date: Aug 2001
Location: San Antonio, Texas
Posts: 12,602
Thanks: 7
Thanked 370 Times in 352 Posts
ElDiabloConCaca is a glorious beacon of lightElDiabloConCaca is a glorious beacon of lightElDiabloConCaca is a glorious beacon of lightElDiabloConCaca is a glorious beacon of lightElDiabloConCaca is a glorious beacon of lightElDiabloConCaca is a glorious beacon of light
Quote:
Originally Posted by icemanjc View Post
I also doubt that it was acquired from the site, vBulletin encodes your passwords when it stores, so that pretty much only the creators could decode your password.
Actually, no one can decode a one-way (hash) encrypted password. The only thing you can do is think of a password, encrypt it, then compare the encrypted password to the one stored in the database. If they don't match, try again. It's called "brute force" cracking.

That's exactly what happens when you log in to any site that stores encrypted passwords -- whatever password you enter in the password box is encrypted using the same method as the original password was encrypted in, the two encrypted strings are compared, and if they match -- voila -- you just logged in. Otherwise, "Invalid password."

Sites who email your password to you (and do not do the "smarter" thing, which is either email you a new, randomly-generated password or require you to visit a form to reset your password and enter a new one) do not store the passwords in an encrypted manner.

There are some encryption techniques that are "two-way," meaning that you can both encrypt and decrypt, enabling one to reverse the encryption of a password if they have the "secret key" or the unencryption method available to them. A lot of these types of encryption techniques are no more effective than just storing the password in plaintext.

Of course, pretty much all encryption techniques can be "cracked," but I would be pleasantly surprised if any member or moderator of this forum has the computing power or the resources and knowledge to do such a thing to a one-way (hash) encryption. If they did, their country's government would probably be paying them six figures or more.

I would hope this forum uses a one-way hash encryption for password storage, but then again, not much havok could be wreaked if a password was stolen, other than posting a bunch of lewd comments or something.
__________________
Mac mini 2.0GHz 10.6.1 • 4GB • 320GB • Superdrive • 4 x 1TB USB 2.0 • LED Cinema Display
MacBook 2.0GHz Core 2 Duo - White 10.6.1 • 4GB • 250GB • CD-RW/DVD-ROM
iPhone 3G 8GB • iPod Touch 8GB • iPod Photo 60GB • iPod nano 1GB • AT&T U-Verse 18Mb/2Mb
http://www.jeffhoppe.com
Reply With Quote
  #8  
Old November 11th, 2008, 11:32 PM
Natobasso's Avatar
Tech-Bot 5000
 
Join Date: Jul 2002
Location: Auckland, New Zealand
Posts: 3,267
Thanks: 1
Thanked 16 Times in 16 Posts
Natobasso is on a distinguished road
Why not just change your password and lock that hacker out?

Of course this user needs to be questioned and dealt with if guilty.
__________________
http://thesalon.blogspot.com
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Forum Jump


All times are GMT -5. The time now is 12:14 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.0 RC1
Copyright 2000-2010 DigitalCrowd, Inc.