+ Reply to Thread
Results 1 to 8 of 8

Thread: Waffles database hacked?

  1. #1

    Join Date
    02.09.08
    Location
    127.0.0.1
    Posts
    89
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssssss89

    Question Waffles database hacked?

    Just got this security notice today.

    We believe our database may have been potentially compromised. Although the passwords are strongly encrypted, to be on the safe side, we still suggest all users change their passwords.

    Edit: Just a heads up, we plugged the hole that allowed this to happen.

    Edit 2: It is advisable to change your passkeys - you can now do this yourselves (for a limited time) in your profile.
    Reply With QuoteReply With Quote
    Thanks

  2. #2

    Join Date
    13.03.09
    Location
    United States of America
    P2P Client
    vuze extreme mod
    Posts
    336
    Activity Longevity
    0/20 18/20
    Today Posts
    0/5 ssssss336
    I read that too and it makes me very curious. They recommended that you change your passkeys, but not your passwords, therefore someone has been sniffing/hacker the tracker. But, if this true, how did they find out ? ...and even more crazy ...how long did it take them to do so ? I don't actually expect answers to these questions. lol But if makes me very curious !
    Reply With QuoteReply With Quote
    Thanks

  3. #3
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,458
    Activity Longevity
    9/20 19/20
    Today Posts
    1/5 ssss39458
    Quote Originally Posted by anonftw View Post
    They recommended that you change your passkeys, but not your passwords
    They did advise you to do so:
    we still suggest all users change their passwords.
    They may have noticed they have been hacked when they saw an IP that wasn't any of the admins' accessing the database or administration panel in the site logs...
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  4. Who Said Thanks:

    anonftw (08.04.09)

  5. #4

    Join Date
    12.12.08
    P2P Client
    azu
    Posts
    346
    Activity Longevity
    0/20 18/20
    Today Posts
    0/5 ssssss346
    its shocking that sites like waffles ws a victim for hacking really unusual considering that they are damn strict about their database access so i surely think it may be someone from inside
    Reply With QuoteReply With Quote
    Thanks

  6. #5

    Join Date
    13.03.09
    Location
    United States of America
    P2P Client
    vuze extreme mod
    Posts
    336
    Activity Longevity
    0/20 18/20
    Today Posts
    0/5 ssssss336
    I have been following their forums, and although Admins have responded numerous times helping users change information, they have stated that no additional details about the "breach" will be given out except for the generalized statement.
    Reply With QuoteReply With Quote
    Thanks

  7. #6
    Waffles NEWS:
    Important Security Notice posted by Mr. J on Apr-08-09
    We were not hacked. We were betrayed by a former administrator. One of his duties was maintaining backups of the database, and transferring the backups to our offsite system, in case of emergency. He misused that duty and privilege.

    Because of his indiscretions, we felt it better to err on the side of caution, and have you all change your passwords and passkeys. We sincerely regret that this has happened, and assure you we have tightened the reigns on staff requirements.

    If you're one of the people that use the same password everywhere, you may have to change the password for your email account. We only use IPs for site security, and do not link them with snatches, seeding, or the like.

    Passwords are hashed, but since most people cock their head sideways when you say it's hashed, we called it encrypted. To the general public, it means all the same. Some passwords were salted, and some older ones were not. All new passwords are salted.

    It is advisable to change your passkeys - you can now do this yourselves (for a limited time) in your profile
    Reply With QuoteReply With Quote
    Thanks

  8. Who Said Thanks:

    KalPenn (11.04.09)

  9. #7
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,458
    Activity Longevity
    9/20 19/20
    Today Posts
    1/5 ssss39458
    Quote Originally Posted by supercheater View Post
    Waffles NEWS:
    Please put quotes between QUOTE tags. I have done it for you.

    A backstabbing admin, who would have thought it... most likely that's why they originally didn't want to give more info.
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  10. #8
    Elite
    DarkSaibot v.1.3.10's Avatar
    Join Date
    15.11.08
    Location
    Black Flag
    P2P Client
    Anonymous
    Posts
    1,758
    Activity Longevity
    2/20 18/20
    Today Posts
    0/5 sssss1758
    look's like the former admin it was a " bad cookie " ))
    Reply With QuoteReply With Quote
    Thanks

+ Reply to Thread

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •