Two Plus Two Newer Archives  

Go Back   Two Plus Two Newer Archives > Two Plus Two > MOD DISCUSSION
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #101  
Old 05-30-2006, 12:15 AM
Jim Kuhn Jim Kuhn is offline
Senior Member
 
Join Date: Nov 2002
Location: USA
Posts: 2,757
Default Re: POTENTIALLY A VERY LARGE SECURITY BREACH

[ QUOTE ]

Quote:

Quote:
I've posted an "apology", for what it's worth, for this very reason. Hopefully he will accept that the Admins are not available at this moment, and delay whatever wrath he intends to inflict upon us.



That was just pathetic.

When somebody does something like this, you don't immmediately start giving him what he wants.



I've ignored this until now but,

The apology was very stupid.

[/ QUOTE ]

What is wrong with the apology? What did it 'cost' anyone? Mike did what he felt was in the best interest of 2+2 and the forum members. He should be commended for that! I think it is very 'stupid' to question his actions.

Thank you,

Jim Kuhn
Catfish4u
[img]/images/graemlins/spade.gif[/img] [img]/images/graemlins/diamond.gif[/img] [img]/images/graemlins/club.gif[/img] [img]/images/graemlins/heart.gif[/img]
Reply With Quote
  #102  
Old 05-30-2006, 12:38 AM
Ryan Beal Ryan Beal is offline
Senior Member
 
Join Date: Sep 2004
Posts: 7,461
Default Re: POTENTIALLY A VERY LARGE SECURITY BREACH

Oh, I can't fault people for questioning much of anything. But it is clear to me that, as others have said, Mike was only thinking about what would be best for 2+2.
Reply With Quote
  #103  
Old 05-30-2006, 12:49 AM
Dynasty Dynasty is offline
Senior Member
 
Join Date: Sep 2002
Location: Las Vegas
Posts: 16,088
Default Re: POTENTIALLY A VERY LARGE SECURITY BREACH

[ QUOTE ]

What is wrong with the apology?

[/ QUOTE ]

An apology was wrong because it was giving someone who was trying to extort 2+2 exactly what he asked for. That's not the way you deal extortionists.
Reply With Quote
  #104  
Old 05-30-2006, 12:51 AM
Ed Miller Ed Miller is offline
Senior Member
 
Join Date: Sep 2002
Location: Email please... no PMs
Posts: 7,540
Default Re: POTENTIALLY A VERY LARGE SECURITY BREACH

FWIW, I was present during his entire "30 minute countdown," but I wasn't particularly concerned. If he could really root the server or whatever, then he wouldn't be screwing around with his little BS links and scripts like he did.

I was a little concerned about a Denial of Service attack, but then shutting down the forum is a DoS too, so whatever.

Also, the forum gets backed up nightly... and the backup had just completed when he started his countdown. So even if he did somehow explode everything, the only thing we'd really lose longterm would be the evidence (at least that's what I was worried about losing).

Also, when he posted about TotalBluff.com, I immediately went to their forum to find out what he did. Apparently he called technical support at their webhost and did the "I lost my password... can you reset it for me" game. Or something like that.

Chuck assured me that the 2+2 web hosts wouldn't be nearly as forthcoming to random kids asking for root access.

All-in-all, I didn't think he had another play besides his initial attack, so I just let him be. But I understand the pressure Mike Haven and Lloyd felt, since it may have seemed that the admins were all asleep. You did what you thought was best... and ultimately the only thing sacrificed was perhaps a little pride. It's all good.

I am concerned in general about the security of UBB. I don't have a lot of faith in the code. In my software updates in the coming weeks, I'm going to take a look at the forum code and look for ways to improve it.
Reply With Quote
  #105  
Old 05-30-2006, 01:02 AM
Sniper Sniper is offline
Senior Member
 
Join Date: Jun 2005
Location: Finance Forum
Posts: 12,364
Default Re: POTENTIALLY A VERY LARGE SECURITY BREACH

Probably worth noting that version 7 of the software is supposed to be released shortly.
Reply With Quote
  #106  
Old 05-30-2006, 01:13 AM
MicroBob MicroBob is offline
Senior Member
 
Join Date: Sep 2003
Location: The cat is back by popular demand.
Posts: 29,344
Default Re: POTENTIALLY A VERY LARGE SECURITY BREACH

different topic:

do we think the new poster mccaff0 might be this same guy?

He seems pretty weird in the thread in the internet-forum.

He just came to my forum-suggestions thread about it and mentioned something about microbobisajackass.com

I'm letting it go for now because I want to see where this guy is going with this stuff.
Reply With Quote
  #107  
Old 05-30-2006, 01:34 AM
rt1 rt1 is offline
Senior Member
 
Join Date: Jun 2004
Location: MN!!!!!!!!!!!!!!!
Posts: 907
Default Re: POTENTIALLY A VERY LARGE SECURITY BREACH

Also, when he posted about TotalBluff.com, I immediately went to their forum to find out what he did. Apparently he called technical support at their webhost and did the "I lost my password... can you reset it for me" game. Or something like that.


awesome!
Reply With Quote
  #108  
Old 05-30-2006, 01:58 AM
MrWookie MrWookie is offline
Senior Member
 
Join Date: Feb 2005
Location: Treating my drinking problem
Posts: 17,411
Default Re: POTENTIALLY A VERY LARGE SECURITY BREACH

[ QUOTE ]
different topic:

do we think the new poster mccaff0 might be this same guy?

He seems pretty weird in the thread in the internet-forum.

He just came to my forum-suggestions thread about it and mentioned something about microbobisajackass.com

I'm letting it go for now because I want to see where this guy is going with this stuff.

[/ QUOTE ]

I think it could well be him. He's got a new IP address, but it's of unknown location again. He's the only guy I've found to get this, but it's not like a check a whole lot

Also, as to total bluff, I'd loved to have heard the conversation...

"TotalBluff.com Techsupport. How can I help you?"

"Hi, yes, I forgot my password. I need it reset."

"OK, just a moment. We can do that for you. What was your account name?"

"Root."

"How do you spell that?"

"R-O-O-T."

"OK, I see you right here. Your new password is temp12345, and you will be asked to change it when you log in. Remember, never give your password out to anyone that asks for it. Is there anything else I can help you with?"

"!!!"

<font color="white">Yeah, I know he didn't get root, but someone elses. Let me enjoy my joke, dammit! </font>
Reply With Quote
  #109  
Old 05-30-2006, 05:05 AM
stabn stabn is offline
Senior Member
 
Join Date: Sep 2004
Location: eatin ur taco
Posts: 9,680
Default Re: POTENTIALLY A VERY LARGE SECURITY BREACH

[ QUOTE ]

But the remarks made by Jason and the title change were uncalled for.


[/ QUOTE ]

FWIW, someone, i'm not sure who, did this in the past week to another spammer (the guy who got 38 out in different forums before he was banned). They changed his title to something similar and i fixed his title back to newbie and left a note in his profile that doing something like that isn't cool even if the guy is a spammer.

However,

While that person may have been deserving of an apology if he had come to 2+2 and posted in about the forums about it once you start hacking accounts that is out the window.
Reply With Quote
  #110  
Old 05-30-2006, 05:14 AM
stabn stabn is offline
Senior Member
 
Join Date: Sep 2004
Location: eatin ur taco
Posts: 9,680
Default Re: POTENTIALLY A VERY LARGE SECURITY BREACH

[ QUOTE ]
Mike was only thinking about what would be best for 2+2.

[/ QUOTE ]

I don't think anyone questioned his intentions.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 06:34 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.