|
Your donations keep RPGWatch running!
RPGWatch Forums » General Forums » RPGWatch » Security Breach

Default Security Breach

January 12th, 2019, 18:53
In case you missed the announcement that is on the top of every forum page (for the next 4 weeks), here is the same text:
Because of a security breach, you will have to provide a new password for accessing the forums.
If, for whatever reason, you are not told to change your password when you try to login to the forums, please initiate this action yourself. Note that changing your password will only work, if you also provide a valid email address as you are send a mail with a verification link after changing your password. Make sure to check your spam folder as well if you don't receive the mail in your mailbox.

For the record, this is the link: https://www.rpgwatch.com/forums/prof…o=editpassword

If you are unable to change your password, contact us, so we can assist you.
--
In the beginning the Universe was created. This has made a lot of people very angry and been widely regarded as a bad move. Douglas Adams
There are no facts, only interpretations. Nietzsche
Some cause happiness wherever they go; others whenever they go. Oscar Wilde
Last edited by Myrthos; January 12th, 2019 at 19:20.
Myrthos is offline

Myrthos

Myrthos's Avatar
Cave Canem
Administrator
RPGWatch Team

#1

Join Date: Aug 2006
Location: Netherlands
Posts: 10,613
Mentioned: 202 Post(s)

Default 

January 12th, 2019, 19:06
Can you elaborate? Were old passwords stolen?
lilmagi is offline

lilmagi

Watcher

#2

Join Date: Nov 2007
Posts: 68
Mentioned: 0 Post(s)

Default 

January 12th, 2019, 19:10
The issue was that a security issue resulted in someone to upload a PHP script. From that script it would potentially be possible to access configuration files and even access the RPGWatch database. As non-failing PHP actions are not logged, I cannot be sure if this did or did not happen, so I assume the worst and just want everyone to change their password.
--
In the beginning the Universe was created. This has made a lot of people very angry and been widely regarded as a bad move. Douglas Adams
There are no facts, only interpretations. Nietzsche
Some cause happiness wherever they go; others whenever they go. Oscar Wilde
Myrthos is offline

Myrthos

Myrthos's Avatar
Cave Canem
Administrator
RPGWatch Team

#3

Join Date: Aug 2006
Location: Netherlands
Posts: 10,613
Mentioned: 202 Post(s)

Default 

January 12th, 2019, 19:33
This is a post in case anyone else faces the same problem I did. The change password link did not work for me after the login, and the page continually reloaded. You can just click on the login screen that you forgot your password and it will automatically be reset. You will get an email with a link and a new working password that you probably will want to change. This is more involved than being able to change your password directly through the link, but it worked for me.
forgottenlor is offline

forgottenlor

forgottenlor's Avatar
Font of Useless Knowledge
RPGWatch Team

#4

Join Date: Jan 2014
Location: Vienna, Austria
Posts: 2,590
Mentioned: 60 Post(s)

Default 

January 12th, 2019, 19:41
The link doesn't work if you accessed it from the home page of RPGWatch. If you accessed it from the forums page it should work.
--
In the beginning the Universe was created. This has made a lot of people very angry and been widely regarded as a bad move. Douglas Adams
There are no facts, only interpretations. Nietzsche
Some cause happiness wherever they go; others whenever they go. Oscar Wilde
Myrthos is offline

Myrthos

Myrthos's Avatar
Cave Canem
Administrator
RPGWatch Team

#5

Join Date: Aug 2006
Location: Netherlands
Posts: 10,613
Mentioned: 202 Post(s)
HiddenX is offline

HiddenX

HiddenX's Avatar
The Elder Spy
RPGWatch Team
Original Sin 1 & 2 Donor

#6

Join Date: Oct 2006
Location: NRW/Germany
Posts: 15,147
Mentioned: 124 Post(s)

Default 

January 12th, 2019, 20:21
Originally Posted by HiddenX View Post
This link doesn't work:
https://www.rpgwatch.com/profile.php?do=editpassword

This one does:
https://www.rpgwatch.com/forums/prof…o=editpassword
Thanks HiddenX - that second link worked for me.

It's good to have the Watch back up and running.
Pongo is offline

Pongo

Pongo's Avatar
SasqWatch
Original Sin 1 & 2 Donor

#7

Join Date: Apr 2012
Location: UK
Posts: 1,901
Mentioned: 23 Post(s)

Default 

January 12th, 2019, 20:32
One odd thing is when rpgwatch came up i received this email:

From:
DragonByte Security has detected that your account has been the subject of a breach on another site. We recommend you change your password and enable two-factor authentication to stop your account from being a target of further breaches.

Astropid (astropid.com) happened on December 19th, 2013, added to the system on 05:49, 6th Jul 2014
Battlefield Heroes (battlefieldheroes.com) happened on June 26th, 2011, added to the system on 15:10, 23rd Jan 2014
Forbes (forbes.com) happened on February 15th, 2014, added to the system on 13:24, 15th Feb 2014
Gawker (gawker.com) happened on December 11th, 2010, added to the system on 02:00, 4th Dec 2013
hackforums.net (hackforums.net) happened on June 25th, 2011, added to the system on 12:30, 11th May 2014
hemmelig.com (hemmelig.com) happened on December 21st, 2011, added to the system on 09:23, 25th Mar 2014
Lounge Board (loungeboard.net) happened on August 1st, 2013, added to the system on 12:22, 6th Jul 2014
Win7Vista Forum (win7vista.com) happened on September 3rd, 2013, added to the system on 12:01, 1st Jun 2014
--
the odd thing is i never had accounts on any of those websites….
Last edited by Eye; January 13th, 2019 at 14:25. Reason: Removed e-mail address
you is offline

you

Lazy_dog
RPGWatch Donor
Original Sin 2 Donor

#8

Join Date: Oct 2006
Location: usa - no longer boston
Posts: 7,758
Mentioned: 63 Post(s)

Default 

January 12th, 2019, 20:49
I thought I disabled that, but apparently not.

Anyway, I believe it searches some known databases for user names and email addresses. Perhaps someone else has used the name 'you' on those sites.
--
In the beginning the Universe was created. This has made a lot of people very angry and been widely regarded as a bad move. Douglas Adams
There are no facts, only interpretations. Nietzsche
Some cause happiness wherever they go; others whenever they go. Oscar Wilde
Myrthos is offline

Myrthos

Myrthos's Avatar
Cave Canem
Administrator
RPGWatch Team

#9

Join Date: Aug 2006
Location: Netherlands
Posts: 10,613
Mentioned: 202 Post(s)

Default 

January 12th, 2019, 21:03
Ok thanks that must be it since the email address is only a few months old.
you is offline

you

Lazy_dog
RPGWatch Donor
Original Sin 2 Donor

#10

Join Date: Oct 2006
Location: usa - no longer boston
Posts: 7,758
Mentioned: 63 Post(s)

Default 

January 12th, 2019, 22:09
Welcome back!

I got a mail like that… with different site, I don t have accounts on those except for one, but with a different password…
Strafe is offline

Strafe

Strafe's Avatar
Sentinel
Original Sin 2 Donor

#11

Join Date: Aug 2008
Posts: 331
Mentioned: 1 Post(s)

Default 

January 12th, 2019, 22:46
Did my duty. Changed my password. Thanks for the warning. Even though I almost never log in anymore. Don't have anything to contribute I'm afraid. But I still check the site for news - even if my backlog is HUGE.

Glad to see the Watch is up and running again. Even though that banner you see when RpgWatch is down is kinda cute. ;-)
Grolav is offline

Grolav

Watcher

#12

Join Date: Dec 2006
Posts: 22
Mentioned: 0 Post(s)

Default 

January 12th, 2019, 22:51
IT'S ALIVE!!

--
Proud leader of the Shit Games Liberation Front
All your shit games are belong to us

FIRST KNIGHT OF THE ORDER OF THE BLOB
Shagnak is offline

Shagnak

Shagnak's Avatar
SGLF Founder

#13

Join Date: Oct 2006
Location: New Zealand
Posts: 1,453
Mentioned: 12 Post(s)

Default 

January 12th, 2019, 22:54
I see a few days are missing from the forums. I think I know what happened here…

--
_______________
Love old text based RPGs? MUDs? Try Shadows of Kalendale:
https://www.rpgwatch.com/forums/showthread.php?t=14727
Caddy is offline

Caddy

Caddy's Avatar
Broken Screwdriver
Original Sin Donor

#14

Join Date: Feb 2009
Location: Calgary, Alberta
Posts: 2,243
Mentioned: 21 Post(s)
+1:

Default 

January 12th, 2019, 23:11
Took me quite a few tries to get back in, but all seems good now.
Carnifex is offline

Carnifex

SasqWatch

#15

Join Date: Oct 2011
Location: Holly Hill, FL.
Posts: 15,222
Mentioned: 66 Post(s)

Default 

January 12th, 2019, 23:24
Originally Posted by HiddenX View Post
This link doesn't work:
https://www.rpgwatch.com/profile.php?do=editpassword

This one does:
https://www.rpgwatch.com/forums/prof…o=editpassword
I also want to send this! The link it tries to recommend, after logging in is broken. And once you login you can't reach the forums either, as it keeps trying to tell you to go to the profile page. But the link is broken.

I found the correct link in the email I received with the new temp password. This could be very annoying for people, I think.
danutz_plusplus is offline

danutz_plusplus

danutz_plusplus's Avatar
SasqWatch

#16

Join Date: Jul 2007
Posts: 3,683
Mentioned: 30 Post(s)

Default 

January 12th, 2019, 23:50
When I accessed the site via Chrome, it popped up the change password message but then it got into a loop and I wasn't able to update it. I had to come in via Internet Explorer. Not sure why that would happen, but I got in now. I hope they didn't leave any back doors to capture our password changes.

Glad you folks are still in operation.
rjshae is offline

rjshae

rjshae's Avatar
Periapt vs Paronomasia
RPGWatch Donor

#17

Join Date: Mar 2012
Location: Seattle
Posts: 5,325
Mentioned: 20 Post(s)

Default 

January 12th, 2019, 23:56
Originally Posted by you View Post
One odd thing is when rpgwatch came up i received this email:

From:
DragonByte Security has detected that your account has been the subject of a breach on another site. We recommend you change your password and enable two-factor authentication to stop your account from being a target of further breaches.

Astropid (astropid.com) happened on December 19th, 2013, added to the system on 05:49, 6th Jul 2014
Battlefield Heroes (battlefieldheroes.com) happened on June 26th, 2011, added to the system on 15:10, 23rd Jan 2014
Forbes (forbes.com) happened on February 15th, 2014, added to the system on 13:24, 15th Feb 2014
Gawker (gawker.com) happened on December 11th, 2010, added to the system on 02:00, 4th Dec 2013
hackforums.net (hackforums.net) happened on June 25th, 2011, added to the system on 12:30, 11th May 2014
hemmelig.com (hemmelig.com) happened on December 21st, 2011, added to the system on 09:23, 25th Mar 2014
Lounge Board (loungeboard.net) happened on August 1st, 2013, added to the system on 12:22, 6th Jul 2014
Win7Vista Forum (win7vista.com) happened on September 3rd, 2013, added to the system on 12:01, 1st Jun 2014
--
the odd thing is i never had accounts on any of those websites….
I got one too, in my spam folder…but I had accounts on all the thing listed. :/
--
It's developer is owned by Sony which means it'll remain a hostage of inferior hardware. ~ joxer
Last edited by Myrthos; January 13th, 2019 at 01:11. Reason: Removed mail address
azarhal is offline

azarhal

SasqWatch
Original Sin Donor

#18

Join Date: Oct 2007
Posts: 7,313
Mentioned: 25 Post(s)

Default 

January 13th, 2019, 01:37
You forced me to hang out at that cesspool for a few days, and now I feel dirty.
JDR13 is offline

JDR13

JDR13's Avatar
SasqWatch
Original Sin Donor

#19

Join Date: Oct 2006
Location: Florida, US
Posts: 32,638
Mentioned: 135 Post(s)
+1:

Default 

January 13th, 2019, 01:38
To prevent the problem with the incorrect link, I hardwired the link in the message that is send. It should now send everyone to the correct page, regardless if they are entering from rpgwatch.com or rpgwatch.com/forums.
--
In the beginning the Universe was created. This has made a lot of people very angry and been widely regarded as a bad move. Douglas Adams
There are no facts, only interpretations. Nietzsche
Some cause happiness wherever they go; others whenever they go. Oscar Wilde
Myrthos is offline

Myrthos

Myrthos's Avatar
Cave Canem
Administrator
RPGWatch Team

#20

Join Date: Aug 2006
Location: Netherlands
Posts: 10,613
Mentioned: 202 Post(s)
RPGWatch Forums » General Forums » RPGWatch » Security Breach

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

All times are GMT +2. The time now is 09:31.
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2022, vBulletin Solutions Inc.
vBulletin Security provided by DragonByte Security (Pro) - vBulletin Mods & Addons Copyright © 2022 DragonByte Technologies Ltd.
User Alert System provided by Advanced User Tagging (Lite) - vBulletin Mods & Addons Copyright © 2022 DragonByte Technologies Ltd.
Copyright by RPGWatch