Forum

> > Unreal Software > Report - USGN hacker (stolen account)
Forums overviewUnreal Software overviewLog in to reply

English Report - USGN hacker (stolen account)

50 replies
Page
To the start Previous 1 2 3 Next To the start

old Re: Report - USGN hacker (stolen account)

GeoB99
Moderator Off Offline

Quote
So, the scenario regarding CY's situation was actually true. user Sparty sent me the PM (as you can check in his first post above in the spoiler) however I thought the U.S.G.N. ID was actually faked and not necessarily stolen. It's time to sharp my eyes for once and check the accounts - the situation seems not quiet well.

• Edit: Few accounts were stolen by the same IP, I permanently banned them to avoid suspicious activities.
edited 1×, last 19.07.16 09:35:09 am

old Re: Report - USGN hacker (stolen account)

DC
Admin Off Offline

Quote
Unfortunately I don't know how he managed to get control over these accounts. If anyone knows it please let me know.

Everyone should please keep in mind that secure passwords are crucial because they are the only thing protecting your accounts. Choose long passwords with many different characters.

Also never use the same passwords anywhere else. Especially not for the connected e-mail address. Using the same password for multiple sites/services makes you extremely vulnerable.

old Re: Report - USGN hacker (stolen account)

MikuAuahDark
User Off Offline

Quote
@user DC: Maybe it's related to recent ImageMagick vulnerabilities where the attacker uses specially crafted MVG files (renamed as PNG or JPG to bypass extension detection) to create reverse shell, but I doubt that. I tried to use that vulnerabilities (for testing) in avatar page but it doesn't work and the server expects JPG/PNG. Maybe it does in file archive?

It's just my speculation, so I doubt this is related.

old Re: Report - USGN hacker (stolen account)

Rainoth
Moderator Off Offline

Quote
us.de --> your monthly source of drama

Jokes aside, saying my brother did this and that is no valid excuse. I tried it too at some point (The casual "my brother cheated" excuse) and it didn't work out. Sucks but that's the way the world works, kiddo - you do illegal stuff, you get punished.

P.S. user Starkkz I kinda feel ashamed about thinking only of reviewer stuff and not thinking about user CY's files themselves. Glad you sorted it out.

old Re: Report - USGN hacker (stolen account)

Yates
Reviewer Off Offline

Quote
My brother actually registered an account and started to spam to get me banned (was a long time ago). I asked Leiche to ban him, never happened again √

Remember kids, if your brother/cousin/friend using your computer actually registers an account here - get it over with and get him banned

@user CY: By the way - check your files to see if you edited any recently and thoroughly check the content.

old Re: Report - USGN hacker (stolen account)

CY
Reviewer Off Offline

Quote
@user SmD:

IMG:https://i.imgur.com/POxFokf.jpg


Turns out there's more to it. Here are the links to the files reviewed by the hijacker. He probably did them as an attempt to stay under the radar or just trying out the new functionality as a Reviewer.

file File does not exist (12464)
file File does not exist (13547)
file File does not exist (13394)
file cs2d Admin Skin
file cs2d Infinite Menus - OG
file File does not exist (2793)
file cs2d Battle Support V 1.0
file cs2d Extra CS2D Musics Loops (.ogg) v0.1


EDIT: He have a thing with old files.

old Re: Report - USGN hacker (stolen account)

Yates
Reviewer Off Offline

Quote
I lol'd - he actually declined some files worthy of being declined yet used a reason totally unrelated to the actual reason they should be declined for.

Top notch, seems just like you (jk)

old Re: Report - USGN hacker (stolen account)

Baloon
GAME BANNED Off Offline

Quote
Simple, just log out before you leave this site, hackers are able to check logs. He hijack user CY because he want to try how to review? Omg then. That's why I don't want being important person because people will try any way to hijack and steal your account and act like an idiot.

old Re: Report - USGN hacker (stolen account)

Yates
Reviewer Off Offline

Quote
@user Baloon: uh no

@user Mami Tomoe: The length does not matter. If I use the password omgiamsocoolandfullofmyself it will still be cracked faster than DASxAHeB (and now I have to change my password ).

Just make sure your password doesn't contain any easy human recognizable text or number sequences. So don't use your birthday and don't use any names or words. In fact, don't use anything that is recognizable to you, make up a random sequence of numbers and letters (heck go crazy and use special characters!) - eventually you will know your password by heart but by that time it's also recommended you change it to a new one

old Re: Report - USGN hacker (stolen account)

Ahmad
User Off Offline

Quote
@user Yates: I keep forgetting my email password because its complicated, and since I have a multi language keyboard i decided to set the language to english and type in arabic, the result was something like this ";glmhglv,v," i typed in 'password' in arabic √

old Re: Report - USGN hacker (stolen account)

rzvthePsycho
User Off Offline

Quote
user Starkkz has written
@user Rainoth: It would probably be wise to change his password & recovery mail, I talked to him on Skype but he appears to be always offline.

Edit: I'm surprised that we don't have the ability to change users passwords.

Edit 2: Whoever currently holds user CY's account is able to delete all his files, it's better to keep his account banned until we're able to contact user DC regarding this situation.


A moderator changed my password once. You must have the ability to chanve passwords.

old Re: Report - USGN hacker (stolen account)

Yates
Reviewer Off Offline

Quote
@user rzvthePsycho: There is but one method for moderators: Editing the user to change the e-mail, sending a recovery link to that e-mail and changing the password. Then simply change the e-mail back to what it was and send the user the new password.

old Re: Report - USGN hacker (stolen account)

GeoB99
Moderator Off Offline

Quote
user Baloon has written
Simple, just log out before you leave this site, hackers are able to check logs. He hijack user CY because he want to try how to review? Omg then. That's why I don't want being important person because people will try any way to hijack and steal your account and act like an idiot.

The account logs out by itself after a certain time if website actions weren't been taken so this is not the case. In this junction, we can only judge three causes of this effect which led few accounts, including user CY's one to be hijacked:

• Brute Force / Guessing passwords;
• Weak, broken E-mail or its security;
• Website vulnerabilities (this is one is pretty much rare)

Speaking for user CY's case, the cause of this dilemma was the second reason since his password was enough strong and immune already to brute forces or guesses. Here's the quoted part of the response which I have got from him.
Quote
I really din't see this one coming at all. I guess my account was easy to hijack due to my email being lost forever in the abyss of hotmail. I can't recover the email no matter how many bloody infos I added in the required things.
To the start Previous 1 2 3 Next To the start
Log in to replyUnreal Software overviewForums overview