Maidens of the Kaleidoscope

~Bunbunmaru News~ => Front Page Headlines => Topic started by: helvetica on February 17, 2011, 04:53:21 AM

Title: ATTENTION: Attempted security attack discovered!
Post by: helvetica on February 17, 2011, 04:53:21 AM
In the past couple of days some of you may have been randomly logged out of your accounts.  This turns out to have been caused by an ongoing attack trying to bruteforce people's logins.  There have been no signs of any successful breach but just to be safe we are asking everyone to change their passwords at this time.

The people targetted have their username set to match their display name.  If at all possible please try to keep them separate.  We are looking at a long term solution, most likely login via email or some other type of hidden info.  For now profile viewing and member list viewing has been blocked for people with less than 10 posts (guests could never view).  If  you would like to have your username changed please get in contact with me or another admin and we will gladly do so.

As a result of the security precautions, TOR is blocked from accessing the site.  We apologize for any inconvenience and we respectfully ask you disable TOR or any other anonymizing proxy if your situation allows.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Tengukami on February 17, 2011, 05:04:01 AM
Thanks for the heads up, changing password now.

So, where is this attack coming from?
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Edible on February 17, 2011, 05:11:34 AM
Very small but persistent attack from TOR.

We disabled TOR access to the site for the time being.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Schezo on February 17, 2011, 05:17:00 AM
Ah, so that would be why.  It was unusually frequent for like the past 5 or so days.  Running to change password now.  (Although not the name yet because of Mafia)
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: nintendonut888 on February 17, 2011, 05:18:34 AM
My name.

It has been butchered in the name of safety.

;_;
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Kerigis on February 17, 2011, 05:27:13 AM
Ouch, thanks for the heads up.
Pass changed.
No, I will not tell you.

*Goes back to curling up*
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: HakureiSM on February 17, 2011, 05:35:30 AM
I believe this doesn't have anything to do with the big truck in my sig 2 days ago? :derp:

Just to be sure.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: theshirn on February 17, 2011, 05:38:59 AM
Hmmm...I'll change it for now.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Zengar Zombolt on February 17, 2011, 05:39:44 AM
Shenanigans have me safe! Still, gonna get a hand on that pass.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Unassuming Squid on February 17, 2011, 05:42:07 AM
Been logged out a couple of times, so I changed my name and password. Thanks for the heads-up.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: WHMZakeri on February 17, 2011, 05:45:21 AM
I'll probably end up changing my name to back after the mafia game.
Thank you for the warning.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Dragoshi on February 17, 2011, 05:49:26 AM
Name changed.

Thanks for tellin' us.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Drake on February 17, 2011, 05:58:34 AM
i'm just a dork
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Vibri on February 17, 2011, 06:03:39 AM
sweet now I have an excuse to change all my shit and confuse everyone
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Edible on February 17, 2011, 06:08:53 AM
sweet now I have an excuse to change all my shit and confuse everyone

;_; I loved you, and your glorious music-based platformy gameplay.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Janitor Morgan on February 17, 2011, 06:10:16 AM
I was just logged out, even with my display name being different from my username.

Might be a sign that they're stepping it up a bit.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Byaaakuren on February 17, 2011, 06:11:39 AM
Changed. Thanks for the warning
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Dormio Ergo Sum on February 17, 2011, 06:16:12 AM
So that's what that was.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Kips McKipzerson on February 17, 2011, 06:18:21 AM
Ah god damn, I gotta change my password, eh?
Also, I'm getting a lot of 403, aka "Forbidden" errors. Would that be part of this attack or no?
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: NekoInc Likes Birds on February 17, 2011, 06:23:18 AM
Thank you very much for the professional, reasonably detailed report as to what was happening, and what the fixing measure are.

I would like to suggest, next time you're working on the SMF files, that somehow, a notification that your login and visible names should be different should be provided at registration. Forgetting how the registration works on SMF, I'm betting that there's a line for visible name during registration - simply adding a boldfaced "For security reasons, do not make this the same as your login name" should be a reasonable warning.

It won't stop idiots, but this might be a case where, if we can get a majority of accounts to avoid this, then this hack becomes ill-worthwhile - the machine effort put in becoming more useful to put to attack other forums. Essentially, the same principle as herd immunity in disease-research fields.

(I also changed my secret question and answer to "WHY ARE YOU ASKING THIS WHEN YOU HAVE YOUR PASSWORD STORAGE PROGRAM?!", and then made sure the secret answer would be ridiculously hard to get by any means ever.)
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Jana on February 17, 2011, 06:25:27 AM
Also, I'm getting a lot of 403, aka "Forbidden" errors. Would that be part of this attack or no?

This has to do more with forum traffic. I suggest clearing your cache.

Thanks for remaining ever-vigilant! o7
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Suikama on February 17, 2011, 06:27:52 AM
clearing your cache.
:V
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Fluffy Rocket Tails on February 17, 2011, 06:28:05 AM
Fortunately I accidentally spelled my name wrong when I joined.  :V
So when I realized, I changed the display name to the way I'd meant to spell it (Skyrocket) so I don't have to change anything here.

I'll change the password right away, as soon as I think of a good one, which shouldn't take long at all.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Bias Bus on February 17, 2011, 06:57:41 AM
Changed whatever was changeable in profile. Thanks for the heads up, although...
I was just logged out, even with my display name being different from my username.
Yeah, this for me too.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: HakureiSM on February 17, 2011, 07:03:04 AM
Came here to say the same Erebus and Rdj did.
Just got logged off. Reset my password again.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Kips McKipzerson on February 17, 2011, 07:06:11 AM
So, Why exactly are we getting attacked? Are they just jelly or wut?
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Zengar Zombolt on February 17, 2011, 07:17:50 AM
:V
it was sage all along
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: theshirn on February 17, 2011, 07:18:31 AM
Oddly enough, I haven't gotten it again...
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Dormio Ergo Sum on February 17, 2011, 07:19:27 AM
It happened again just now for me.
Guess I'll be changing my display name then.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Sophilia on February 17, 2011, 07:25:10 AM
Just got me, and I hadn't had any problems before I changed my stuff.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Captain Infinity on February 17, 2011, 07:29:54 AM
Was wondering what that was, it happened to me every day of this week.

Changed details.

/me loads a rifle and sets up claymore mines around him.

Must defend myself better.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Dizzy H. "Muffin" Muffin on February 17, 2011, 07:32:40 AM
Nyan~

Been needing an excuse to change my passwords to something more rainbowtable-safe ...
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: VIVItheFujoshi on February 17, 2011, 07:33:31 AM
i changed my password (is the same of one of my da accoounts with a plus) now must prove it...
edit: ah, little problems, but used my secret ask,changed the password, and enter again and all work fine. :)
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Kips McKipzerson on February 17, 2011, 07:34:01 AM
i changed my password (is the same of one of my da accoounts with a plus) now must prove it...
Just logged on and did the same as you. Well, at least I'm content to know Im a bit safer.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Esifex on February 17, 2011, 07:39:53 AM
Is it bad that I can't remember which of the ten~fifteen different passwords I have I originally used to register with? I just checked the 'keep me logged in' tab and told FireFox to remember my password and never looked back. :ohdear:
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Captain Infinity on February 17, 2011, 07:43:05 AM
Is it bad that I can't remember which of the ten~fifteen different passwords I have I originally used to register with? I just checked the 'keep me logged in' tab and told FireFox to remember my password and never looked back. :ohdear:

Of course not, you're a brilliant example of internet safety.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: beaver1231 on February 17, 2011, 07:46:29 AM
Done~

Damn its a bitch trying to log back in after being forced out for no reason...

EDIT: I sent 2 messages about a problem with firefox that just keeps showing this error. (http://img502.imageshack.us/img502/4117/croppercapture86.jpg)
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: VIVItheFujoshi on February 17, 2011, 07:48:06 AM
Is it bad that I can't remember which of the ten~fifteen different passwords I have I originally used to register with? I just checked the 'keep me logged in' tab and told FireFox to remember my password and never looked back. :ohdear:
don?t worry, my brother do the same (with long numbers and all!). i tend to use few passwords,but no use to much social theads and never open or admit nothing unknown.
this thing explain why i can?t read my old posts days ago (i was searching a certain image) and take me time log again and that.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Dead Princess Sakana on February 17, 2011, 07:48:55 AM
I just checked the 'keep me logged in' tab and told FireFox to remember my password and never looked back. :ohdear:
You can look up all the saved passwords within Firefox, you know? Extras -> Settings -> Security and go from there.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: E-Nazrin on February 17, 2011, 07:52:33 AM
Huh. This is sort of unexpected.

Thanks for the heads-up, TSO.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: HakureiSM on February 17, 2011, 08:02:12 AM
Just got logged off once more. At this rate I'll run out of ideas for passwords :derp:
Whoever's doing this needs a girlfriend.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Pesco on February 17, 2011, 08:09:12 AM
The people playing mafia should still change their names. It's a forumwide issue so it takes priority over the game's rules. Make it what we call you in-game and keep your avatar/sig unchanged for the time. Anyone that uses this to try gain an advantage in the game will be Lynched. So don't be a retard.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Dead Princess Sakana on February 17, 2011, 08:14:42 AM
I hadn't gotten it before, got logged off just now, after already changing the password.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: An Odd Sea Slug on February 17, 2011, 08:16:36 AM
I got logged out, even after changing display name and password. Daaaaaayuuuum.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: axman36 on February 17, 2011, 08:20:19 AM
They figured out my ingenious disguise of axman37! Though maybe as a result of not changing my password. Quite the oddity either way.

By the way, small question, if an account does by chance get deleted, is there a means to recover it or will the user have to make a new one?
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Smok, destroyer of thoughts on February 17, 2011, 08:22:14 AM
Changed.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: ultramage on February 17, 2011, 08:37:28 AM
Heh, just a day after receiving a security notice from winamp forums. But a little paranoia can't hurt.
Now that I'm using a password manager, this is a good excuse to go change the password to something long and machine-generated..
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Bias Bus on February 17, 2011, 08:40:41 AM
Logged off again. Luckily, thinking up new shit to plug in doesn't take long. Whoever's behind this needs to eat a dick, though.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: DarkOverord on February 17, 2011, 08:44:27 AM
I'll risk it myself thanks. :V I've not been logged out, on the other hand. I forget which one of my absurdly long passwords I use here. Hope it all blows over for you guys soon! :V
i changed my password (is the same of one of my da accoounts with a plus) now must prove it...
Can I just say, you should honestly never let dA share passwords with anything? They've had a few security issues lately...

*Goes back to lurking and only posting once a blue moon*
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Captain Infinity on February 17, 2011, 08:45:50 AM
Logged off once again.

Whoever's doing this, is asking to get gunned down.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Garlyle on February 17, 2011, 08:47:19 AM
oh man, my glorious username ;-; tarnished by the seeking of security.

(I know admins have the ability to send an announcement to everyone on the forum via e-mail - maybe this is the kind of thing that warrants such an alert?)
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Stuffman on February 17, 2011, 08:53:22 AM
Looks like Edible gave me more of an upgrade than he thought!

I'm gonna go change my passwords on some other places too. A lot of people tend to use the same password for every site they visit, so in many cases if you manage to break one account you can take that password and get into their e-mail, etc, and other shenanigans from there.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Momiji on February 17, 2011, 09:33:21 AM
I used a random password for my login here.  They'll never get me!  Bwahahaa!
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Ryuu on February 17, 2011, 09:38:52 AM
change password


get logged out


like a bawss
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Momiji on February 17, 2011, 10:13:11 AM
Changing your password isn't going to stop them from trying, it's just going to make it that much harder to brute-force.   Changing your username/displayed name so one is different from the other means they have to also try figuring out your username as well as your password.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Furienify on February 17, 2011, 10:24:57 AM
Welp, this isn't exactly what I wanted to wake up to. Thanks for finding out!
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Ryuu on February 17, 2011, 10:26:58 AM
Changing your password isn't going to stop them from trying, it's just going to make it that much harder to brute-force.   Changing your username/displayed name so one is different from the other means they have to also try figuring out your username as well as your password.

well yeah

I just think it's amusing that I didn't experience this until after changing my password

hee hee
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Momiji on February 17, 2011, 10:32:27 AM
well yeah

I just think it's amusing that I didn't experience this until after changing my password

hee hee
This just in:  Ryuu is (ry

Also, it's left-paren not right, iirc.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Ryuu on February 17, 2011, 10:36:42 AM
This just in:  Ryuu is (ry

Also, it's left-paren not right, iirc.

I've seen it both ways

urbandictionary says (ry though so I guess I'll fix it
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Rin Kagamine on February 17, 2011, 10:50:53 AM
I'm alright  BV
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Zengeku on February 17, 2011, 10:51:19 AM
name and password changed.Thanks for the warning.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: HolmCross on February 17, 2011, 11:10:56 AM
Haven't been logged out yet, but changing details/password just to be on the safe side, thanks for keeping us informed.
We're going to have a mass identity crisis at this rate  :V
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: WGH on February 17, 2011, 11:36:22 AM
That was insidious plan to make not talkative ones post a bit more.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: ?q on February 17, 2011, 11:41:44 AM
(I know admins have the ability to send an announcement to everyone on the forum via e-mail - maybe this is the kind of thing that warrants such an alert?)
I check my e-mail once every whenever someone tells me I have an e-mail, and I don't think I'm the only one...

I no longer have my ? filter, so I guess I don't need to go back to my original name anyway :(

Quote
That was insidious plan to make not talkative ones post a bit more.
HA!  I would NEVER fall for that!
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Mimachiro on February 17, 2011, 11:42:41 AM
That explains why I was being logged out. Oh well, first time I've had a different display name for anything in about ten years, give or take, so whatever. I think me and Flan should 'kyuu' the culprits.  :D
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Ryuu on February 17, 2011, 11:45:53 AM
oh hey I got logged out after I changed my name too


OH MAN I'M UNSECURE
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Marokuu on February 17, 2011, 11:49:13 AM
Huh. *flies of to change name and password*

Now it's time to burninate someone.

And right as I do that I get logged out :/
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Momiji on February 17, 2011, 12:10:01 PM
oh hey I got logged out after I changed my name too


OH MAN I'M UNSECURE
I think you made a friend.  Else they had already extracted all the usernames from here beforehand.

That was insidious plan to make not talkative ones post a bit more.
Hey, I know you!
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Conqueror on February 17, 2011, 12:13:40 PM
I feel lucky nothing has happened to me yet.

Password changed anyway to be more forgettable secure. I learned my lesson after Gawker.  :V
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: game2011 on February 17, 2011, 12:23:09 PM
Changed my username and profile as well, even though my account never randomly logged out.  Still, thanks for the warning!

Out of curiosity, what's TOR?

Thanks in advance!
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Lishy1 on February 17, 2011, 12:25:55 PM
First Winamp and now MoTK.. Great, nice paranoia fuel..
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Sapz on February 17, 2011, 12:29:04 PM
Done and done. I think I've been logged out twice now, first was a while ago, second was this morning.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Palewolf on February 17, 2011, 12:30:09 PM
Ah lol i was all convinced i did something weird to get logged out all the time.
Thanks for the warning.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Iryan on February 17, 2011, 12:35:48 PM
Name and password changed.

For the people who got logged out after changing name and password, I remember that any previous time I changed my name, I got logged out after some time, so I assume that changing your display name somehow defaults the selected option from "login forever" to "1 hour", so if you want to be sure, log out and back in after you changed your name. If you get disconnected again, then something is definitely up in the air.  :derp:
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Romantique Tp on February 17, 2011, 12:43:52 PM
I never got logged out. I guess I'm not interesting enough or they got my password right on the first try.
;_;
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Mimachiro on February 17, 2011, 12:48:44 PM
Name and password changed.

For the people who got logged out after changing name and password, I remember that any previous time I changed my name, I got logged out after some time, so I assume that changing your display name somehow defaults the selected option from "login forever" to "1 hour", so if you want to be sure, log out and back in after you changed your name. If you get disconnected again, then something is definitely up in the air.  :derp:
I hope you're right, since I just got logged out after changing my name and password. XD
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: ふねん1 on February 17, 2011, 01:44:50 PM
I have no idea what this TOR thing is, and I've yet to experience random logouts. I'm changing my password anyway to be safe.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: helvetica on February 17, 2011, 02:19:22 PM
Changing your display name ONLY works if you haven't been attacked yet.  I will be sending out another PM to the people we've caught login attempts on so we can discuss changing your username as well.  Changing usernames is a function only admins can do.

Ah god damn, I gotta change my password, eh?
Also, I'm getting a lot of 403, aka "Forbidden" errors. Would that be part of this attack or no?
No, that's just forum load issues.  Try clearing your cache and stuff.

Thank you very much for the professional, reasonably detailed report as to what was happening, and what the fixing measure are.

I would like to suggest, next time you're working on the SMF files, that somehow, a notification that your login and visible names should be different should be provided at registration. Forgetting how the registration works on SMF, I'm betting that there's a line for visible name during registration - simply adding a boldfaced "For security reasons, do not make this the same as your login name" should be a reasonable warning.

It won't stop idiots, but this might be a case where, if we can get a majority of accounts to avoid this, then this hack becomes ill-worthwhile - the machine effort put in becoming more useful to put to attack other forums. Essentially, the same principle as herd immunity in disease-research fields.

(I also changed my secret question and answer to "WHY ARE YOU ASKING THIS WHEN YOU HAVE YOUR PASSWORD STORAGE PROGRAM?!", and then made sure the secret answer would be ridiculously hard to get by any means ever.)
We're looking into alternate login methods, probably something involving email address.  Username is exposed in user profiles as people tend to change their display name a lot (oftentimes to things that aren't readily recognizable) and it's a nice tool to figure out who's who since they're normally unchangeable.  Email addresses, on the other hand, do not need to be exposed directly ever as the forum can email on the behalf of other users, and thus can remain totally hidden and unique per user.

But until that is in place, profile viewing has been blocked from people with less than 10 posts.  This makes the task of farming usernames much much much more difficult, far beyond any automated tool.

oh man, my glorious username ;-; tarnished by the seeking of security.

(I know admins have the ability to send an announcement to everyone on the forum via e-mail - maybe this is the kind of thing that warrants such an alert?)
Already sent it :V

I have no idea what this TOR thing is, and I've yet to experience random logouts. I'm changing my password anyway to be safe.
The Onion Router, an anonymizing proxy that works by scattering your connection across thousands of "exit nodes" so noone can reasonably track your original IP.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Zengeku on February 17, 2011, 02:34:01 PM
Yeah. Now i've been logged out once too. Quite a nuisance.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Huckebein on February 17, 2011, 02:52:06 PM
They can take my name, but they can't take my sweet av.  Thanks for the heads-up.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Alice★f on February 17, 2011, 02:52:36 PM
Changed, thanks for the notification.

I used to use TOR to tunnel through my school's firewall in the past. Awfully slow, though.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: helvetica on February 17, 2011, 02:59:52 PM
OK a new profile field has been added to replace username as a method of identification.  Under Account Settings you will see a new option named "Nickname", it will show up right under your avatar so people can recognize you even if you change your display name.  This is a PERMANENT option, so choose wisely what you wish to be there.  We are leaving the field open for editing for the next couple of days to let people use it, but after that it can only be edited by an admin.  At registration time you are forced to fill it out.

Usernames are now hidden again, only staff and the owner of the account can see the actual username.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Yadogari on February 17, 2011, 03:19:16 PM
So weird getting messages from this site. Haven't checked here for ages.

Maybe you're just getting the non-actives to post eh   :V
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Gpop on February 17, 2011, 03:29:16 PM
Hmm, I don't ever remember being logged ou- wait once but a while ago.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: The Girl with the Golden Smile on February 17, 2011, 03:34:55 PM
Changed up some stuff to protect me :)
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Unassuming Squid on February 17, 2011, 03:45:20 PM
OK a new profile field has been added to replace username as a method of identification.  Under Account Settings you will see a new option named "Nickname", it will show up right under your avatar so people can recognize you even if you change your display name.  This is a PERMANENT option, so choose wisely what you wish to be there.  We are leaving the field open for editing for the next couple of days to let people use it, but after that it can only be edited by an admin.  At registration time you are forced to fill it out.

Usernames are now hidden again, only staff and the owner of the account can see the actual username.

Question. Does the nickname have to be different from the username? 
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: HakureiSM on February 17, 2011, 03:47:40 PM
Question. Does the nickname have to be different from the username?
Your username should not match ANYTHING publicly identifiable on your account, so don't set your display name, your nickname, or any instant messaging nicks to your username.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: helvetica on February 17, 2011, 03:50:16 PM
Question. Does the nickname have to be different from the username?
Defeats the purpose of having them separate.  If you want your current username to be your nickname, you can PM one of the admins and we'll change your username so you can reuse it.  NOTHING publicly visible on your account should match your username.  Your username is only visible by staff and yourself, and is only necessary for logging in, that's it.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Yakitori on February 17, 2011, 04:01:59 PM
Okay, I just changed a few things. However, does this new nickname thing mean that I can't go with my previous username as my nickname?
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Chronojet ⚙ Dragon on February 17, 2011, 04:04:35 PM
Woah.

I'll go change my password anyways.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: helvetica on February 17, 2011, 04:06:22 PM
Okay, I just changed a few things. However, does this new nickname thing mean that I can't go with my previous username as my nickname?
Again, we can change your username to something else so you can use it as your nickname.  Just PM a staff member.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Whatthe on February 17, 2011, 04:14:24 PM
Okay, got my username changed (thanks TSO), and changed my password.

Had a couple of thoughts though:

Edit: I changed my TV Tropes password, too.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: helvetica on February 17, 2011, 04:18:45 PM
OpenID isn't working at all at the moment, and as for being logged out of here and TVTropes at the same time, that's all you :B
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Agent of the BSoD on February 17, 2011, 04:21:54 PM
Done and done.
I love my new name. Don't you agree?
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Agent of the BSoD on February 17, 2011, 05:22:17 PM
Darn it. After changing BOTH my name and password, I just got logged out. What the heck?
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: helvetica on February 17, 2011, 05:30:26 PM
I'm screwing with stuff so it's possible sessions are just being corrupted.  There hasn't been a successful attempt since I blocked TOR last night.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Whatthe on February 17, 2011, 05:33:05 PM
Darn it. After changing BOTH my name and password, I just got logged out. What the heck?
For the people who got logged out after changing name and password, I remember that any previous time I changed my name, I got logged out after some time, so I assume that changing your display name somehow defaults the selected option from "login forever" to "1 hour", so if you want to be sure, log out and back in after you changed your name. If you get disconnected again, then something is definitely up in the air.  :derp:
This 1-hour thing seems to be true. After I had my username changed and password reset, I was logged out when I finally came back here, and when I went to log back in it was set to stay logged in for 60 minutes.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: helvetica on February 17, 2011, 05:35:14 PM
All your existing cookies are invalidated once your username is changed.  So you'll have to set yourself to stay logged in again.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: helvetica on February 17, 2011, 05:37:09 PM
At this point there hasn't been a successful attempt since last night when I blocked TOR.  So for those of you continuing to be logged out, clean your cache and cookies and make sure you're setting "stay logged in forever" when you log in.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Alice★f on February 17, 2011, 06:23:39 PM
I'm sorry.

Maybe I'm a little slow, but I don't understand this at all...

I have a:
Username
Name
Nickname

But I still want to use "GreenVirus," so do I have to fill in the nickname field? I uh... honestly don't get this...

I'll have three fields with the same information...  :/
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Janitor Morgan on February 17, 2011, 06:25:12 PM
I'm sorry.

Maybe I'm a little slow, but I don't understand this at all...

I have a:
Username
Name
Nickname

But I still want to use "GreenVirus," so do I have to fill in the nickname field? I uh... honestly don't get this...

Set your nickname to GreenVirus, and then if your username is also GreenVirus, ask an admin to change that to something different. The other name (the one that shows at the top-left of your posts) can be whatever you want.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Unassuming Squid on February 17, 2011, 06:35:43 PM
I'm sorry.

Maybe I'm a little slow, but I don't understand this at all...

I have a:
Username
Name
Nickname

But I still want to use "GreenVirus," so do I have to fill in the nickname field? I uh... honestly don't get this...

I'll have three fields with the same information...  :/

Username is for the purpose of logging in only. You and the admins are the only ones that will ever be able to see it. It should be different from your nickname.
Display name is what's on the top left of your posts and can be set to anything you want.
Nickname is the little line under your avatar that shows which user you are. It fills in for having to go to the user's profile and check the username there. As stated before, it should be different from your username for safety reasons.

So, for example, you can set your username to Jim Jim Jimmy Jim Jimmy Jim Jim, then set your nickname to GreenVirus, then set your display name to GreenVirus or whatever else you want. The purpose of having a different username is to make it significantly more difficult for someone to get into your account.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Alice★f on February 17, 2011, 06:47:27 PM
Thanks guys~

I'll just do what A-F did then-
You'll see in a moment.

----------------------------

E: Even users from the forum are going to have a hard time finding out what to call me :<
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Agent of the BSoD on February 17, 2011, 07:27:19 PM
Username is for the purpose of logging in only. You and the admins are the only ones that will ever be able to see it. It should be different from your nickname.
Display name is what's on the top left of your posts and can be set to anything you want.
Nickname is the little line under your avatar that shows which user you are. It fills in for having to go to the user's profile and check the username there. As stated before, it should be different from your username for safety reasons.

So, for example, you can set your username to Jim Jim Jimmy Jim Jimmy Jim Jim, then set your nickname to GreenVirus, then set your display name to GreenVirus or whatever else you want. The purpose of having a different username is to make it significantly more difficult for someone to get into your account.
Ok, that makes MUCH more sense. I get it now.
Well, I want to keep Agent of the BSoD as my name so I guess that'll have to be my nickname. So that means I have to change my username don't I.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: helvetica on February 17, 2011, 07:31:17 PM
Thanks guys~

I'll just do what A-F did then-
You'll see in a moment.

----------------------------

E: Even users from the forum are going to have a hard time finding out what to call me :<
Then ask to have your username changed so you can use it as your nick?  It takes me 5 seconds to do it really, just PM me what you want as a username.

Ok, that makes MUCH more sense. I get it now.
Well, I want to keep Agent of the BSoD as my name so I guess that'll have to be my nickname. So that means I have to change my username don't I.
Yup, PM me for a username change.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Whatthe on February 17, 2011, 07:45:44 PM
Anyone whose display name has ever matched their username should get their username changed, since old quotes keep their authors' old display names.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Doll.S CUBE on February 17, 2011, 10:22:39 PM
Wow, lucky I changed my display name to something different from my username the first week I'm on this site...

But now I need to come up with a nickname...hmm
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: nintendonut888 on February 17, 2011, 10:26:38 PM
It's worth noting that after changing my user name, I just got logged out again. :/
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Unassuming Squid on February 17, 2011, 10:30:09 PM
It's worth noting that after changing my user name, I just got logged out again. :/

Immediately after, or some time after?

If the former, that's supposed to happen.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: OkashiiKisei on February 18, 2011, 12:23:57 AM
I just got logged out too, and my username is still the same. What should I do now? I already sent a PM to change my username...
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: helvetica on February 18, 2011, 12:34:08 AM
There hasn't been an attempt since last night.  Just log back in.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Byaaakuren on February 18, 2011, 12:44:12 AM
Thanks for the change, TSO
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: An Odd Sea Slug on February 18, 2011, 06:04:37 PM
I cleared my cookies and cache, set the thingy to forever, yet I keep getting logged out after a certain amount of time. I'm so confused...
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Mimachiro on February 19, 2011, 08:24:00 AM
I cleared my cookies and cache, set the thingy to forever, yet I keep getting logged out after a certain amount of time. I'm so confused...
You did remember to change the login time back to forever, right? After clearing everything, it defaults back to an hour.  :D
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Iliq on February 19, 2011, 09:22:50 AM
That was insidious plan to make not talkative ones post a bit more.

This is very true.

Well, at least I finally have an excuse to use this internet name somewhere. This can only be good!
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Pepperdirt on February 19, 2011, 02:58:55 PM
Weel,  Hello everyone.
  I am quite new here so no PMin for me, hah. Sadly, I got here after these changes were set. I would have liked to suggest making the login screen 'lock out' a user for so much time after so many failed attempts at guessing username and password. I can't say I like having to remember two usernames, but for the sake of security, I will deal.
  Thanks for keeping our information safe. Peace.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Schezo on February 19, 2011, 03:02:53 PM
Well you really only have to remember your login username because your display name shown is always there when you login. :V
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: helvetica on February 19, 2011, 07:25:09 PM
Weel,  Hello everyone.
  I am quite new here so no PMin for me, hah. Sadly, I got here after these changes were set. I would have liked to suggest making the login screen 'lock out' a user for so much time after so many failed attempts at guessing username and password. I can't say I like having to remember two usernames, but for the sake of security, I will deal.
  Thanks for keeping our information safe. Peace.
Yes, allowing other people to lock you out of your own account is wise.  And you only have to remember your username.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: J.O.B on February 20, 2011, 07:05:21 AM
After changing my password I got logged out for the first time since i joined this forum.
Is it possible that they're monitoring any changes that have been made since the first attack?
People seem to be getting logged out after changing their details.
Title: Re: ATTENTION: Attempted security attack discovered!
Post by: Stuffman on February 20, 2011, 10:29:16 AM
Changing your profile crap logs you out once as a security measure. Pay attention, people.