Few years back we had the same type of attack and you had us remove our email now you say we need to use it again?
Also with the current issues now more than once, please consider authenticators.
Was it the same offender that did this to us last time?
Meh...
sigh
Please troll else where if you have nothing to add to the conversation
Is this why my account got hacked and I lost everything I had built up ?
I think you guys are reading into the downtime too much. It was to fix something, Ched wasnt sitting there infront of lines of Matrix fighting off attackers.
Peace
1]
Status: Admin
Level: 50
Thread created on 17:42:55 - 09/11/15 (2 hours ago)
Hello everyone,
Today we detected an intrusion by means of XSS exploitation. This allowed someone to remotely control accounts who visited specific URL's or viewed some forum signatures, allowing it to perform simple tasks (like sending messages).
Although we do not store unencrypted passwords anywhere on the site, we did notice a flaw with user sessions. We believe there is a chance that the attacker may have been able to acquire the passwords of a small amount of users - although username and email address remains secure. We don't have any reason to believe that the leak is widespread but if you are at all concerned, we recommend you change your password, especially if you use the same one across other websites.
The following changes have been made (in the last few hours) in light of this situation:
- As a precaution, we now require an email address and password to login (instead of username). This was a feature we were planning on anyway to improve security, so it made sense to expedite this.
- CityWatch also now requires an email address (even though it still states 'username').
- Sessions are using authentication tokens now. And we'll be working on ensuring that any attacker who takes control of a session is immediately kicked off.
- Forum signatures no longer accept iframes (a big oversight on our part).
- XSS vulnerabilities have been resolved in the areas we discovered (and were used). We're also investigating for other potential areas for windows of exploitation.
We're very sorry for our lapse in security, we're fortunate it was brought to light in such a minor way by someone who does not appear to be overly malicious. We do have the attacker's personal details and will be seeking advice from our legal counsel on next steps to pursue action.
We will update this announcement with any further information that comes to light.
Thanks.
I'm with you on this. They need to add authentication to this like 2FactorAuth, SMS Verification, Security Pin Code, Historic Security Codes (like one every 1month), Emergency Codes. Any 2 of them would be good tbh.
According to Global and the Announcement they sent messages from the players account. You should probably check your sent mailbox and see if there is a mail you did not send there.
+ Emergency Backup Mail and Pin Code to change account details.
an authenticator would of had zilch to affect what happened today
It would stop them from being able to use your password though. Although yeah an XSS attack would still allow them to control your account but it'd at least mitigate the effects a bit.
There is no excuse not to increase security standard. Only when its too late it will be improved.
Security 2.0
This same type of attacked happened June 2013 and it was then they had us remove the emails for the exact same reason they quoted today. It would be nice if a staff would explain it. The post is from Dave June 2013 in the old forums.
Davzz
Thread created on Sun Jun 02, 2013 13:49:28
Last replied to on Sun Jun 02, 2013 14:49:28
** TORN Downtime over the last few days **EDIT - a note on SecurityGood news:* TORN does not, ever, store anything about your payment details. We use three providers (PayPal, Zong and Google Checkout) and they handle everything. All we store is the email provided by this service, the amount you donate, and the transaction ID. Even this information was not revealed, because it is stored on a physically isolated database server from the one that was compromised. We can say with concrete assurance that your credit card information, and similar, is totally safe - and would remain so regardless of what happened to torn. * Your password is protected properly (we salt and hash each password, with a per-user salt). Your password is safe. [It is still a good idea to use a different password for each web service, for the record]* Your email, username and playername are potentially at risk because they are stored in the DB server that was injected. Logs however show that the goal of this attacher was not to reveal this data, and we do not believe that this data was extracted (we log to syslog each query executed, and these logs were certainly not compromised). Therefore, I can say with good confidence that even this data is safe.The goal of this attacker was basically to cheat in the game, by being able to update random rows of data.--TORN has been very unreliable for the last few days for many users. We have now figured out why: attackers were exploiting a SQL injection in profiles.php (this is now fixed). We tried various other options but in the end we have decided to restore the site back to Wednesday morning TC time (0400), which is the last time before the first of these SQL injections came in. This is the most fair way to handle what has happened.Some important notes: your passwords are safe (we salt and hash passwords) but these attackers did have a good look at approximately 20% of the overall data (about a third of the data that we store in MySQL). This includes email addresses, usernames, profile names and so on.We will in the next few hours apply all donations, so you do not need to report missing donations.Please report other bugs as usual.Once again, apologies for the inconvenience. We will do everything we can to detect and prevent this sort of attack, but the nature of the TORN code base makes it impossible for me to guarantee that we are immune from these attacks.Davz, and the other admins(many of us have not slept much for the last 3 days!!)
Now its going to take me a year to type in my username.
Ye this sucks! I don't want to use my email!.. My email has been hacked a few times.. And it's really long to type in...
Also so if anyone can answer this for me... If I want to change the email on file I can do so easily right? And that would technically change my username so now we can change our username and passwords right?.
no clue, try it and let me know if you can
Why would changing your email change your username? They are not linked. They weren't before, so why would they be now...?
Actually, I tried changing my email a while back and it took hours for the confirmation to come through ... and until it did and I clicked the link, I could not login to Torn. Hopefully they've streamlined that process, but I sure won't be the one to find out.