Home | Community | Message Board

Magic-Mushrooms-Shop.com
This site includes paid links. Please support our sponsors.


Welcome to the Shroomery Message Board! You are experiencing a small sample of what the site has to offer. Please login or register to post messages and view our exclusive members-only content. You'll gain access to additional forums, file attachments, board customizations, encrypted private messages, and much more!

Jump to first unread post Pages: 1
Security breach?
    #18328047 -

Is this for real?





I copied this from here.... http://www.reddit.com/r/Drugs/comments/154hix/attention_anyone_with_an_account_on_the_shroomery

Attention anyone with an account on the Shroomery! We had a security breach. :frown: (self.Drugs)
submitted 5 months ago by Ythan
TL;DR - you're probably fine, but if you have an account on the Shroomery, please make sure to visit the BB and change your password, and also update it on any other sites where it was re-used.
Hey guys, I'm Ythan, admin at the Shroomery. Recently, someone named 0xidium approached me, and reported that it was possible to retrieve a copy of our database. Although our site itself is believed to be secure, I have an account on a different site which is vulnerable. This allowed people to retrieve the list of users and passwords in plaintext. To my embarassment, I disregarded basic security practices, and re-used my password on certain sensitive parts of the Shroomery and Growery. This problem has existed at least since August, and possibly much longer.
We are extremely lucky to have been alerted to this problem when we were. Unfortunately, due to our limited retention of log files for privacy purposes, there is no way to determine who might have discovered and exploited this issue in the past. It is with great contrition and embarassment that we wish to inform any members of the Shroomery and Growery that the following information could possibly have been leaked to untrusted third parties:
E-mail addresses associated with your account
Unencrypted private messages
Posts in restricted or private forums and journals
IP addresses associated with your posts
Image uploads, including those which were not made public
The SHA-256 hash of your password
The last item is especially important. Although an SHA-256 hash is believed to be one-way (meaning you cannot deduce the actual password from the hash), this is not always the case in practice. If someone has a large dictionary and a fast computer, they can try millions of passwords every second, and eventually find a hash that matches. If your password is a common word, or combination of words and numbers, or a geometric pattern on the keyboard, or leetspeak, it can potentially be retrieved with a dictionary-based attack by someone who has our database. If you use the same password on other sites, especially e-mail, banking, or social networking, please make sure to change it on those sites immediately!
I wish to be clear that, except for the individual who alerted us to this problem, there is no indication anyone has actually made use of this exploit. I am simply offering full disclosure and recommending an abundance of caution.
Going forward, we are implementing new security policies to prevent the re-use of passwords, and require multiple types of authentication for sensitive admin scripts. We have switched to bcrypt hashing with per-user salts for passwords, which will help prevent dictionary-based attacks in the future. The site is more secure now than it ever has been, and we will continue to work to protect our members to the best of our ability. We hope you will forgive us for this recent failure.
If you have any questions, you can post here, or there's also a thread on the site


--------------------
My Trade List!!

Extras: Filter Print Post Top
Re: Security breach? [Re: mudbutt]
    #18328066 -

That sounds familiar but I don't know why it would be announced on there. Do you remember having to change your password here a while back?

Extras: Filter Print Post Top
Re: Security breach? [Re: psi]
    #18328103 -

I tried to find " 0xidium" on the user list....he doesnt exist!!  :cop:


--------------------
My Trade List!!

Extras: Filter Print Post Top
Re: Security breach? [Re: mudbutt]
    #18328126 -

Yeah, I remember searching for that user name too. Maybe they spoke by email and he went by that pseudonym?


Anyway here is the original link:
http://www.shroomery.org/forums/showflat.php/Number/17416556

Extras: Filter Print Post Top
Re: Security breach? [Re: psi]
    #18328156 -

There was some sort of security issue with the site about a half a year back, I remember an announcement about it on the shroomery.

I don't remember the details, but that looks familiar.


It doesn't matter if you aren't posting incriminating evidence about yourself.


--------------------

Extras: Filter Print Post Top
Re: Security breach? [Re: ganjfather]
    #18334898 -

ganjfather said:
There was some sort of security issue with the site about a half a year back, I remember an announcement about it on the shroomery.

I don't remember the details, but that looks familiar.


It doesn't matter if you aren't posting incriminating evidence about yourself.



OH!!!  BUT I AM!!


--------------------
My Trade List!!

Extras: Filter Print Post Top
Re: Security breach? [Re: mudbutt]
    #18334979 -

Mudbutt aint no sin


--------------------
Tickle my bassline.

Extras: Filter Print Post Top
Re: Security breach? [Re: mudbutt]
    #18335127 -

Yeah, I had to change my password. :shrug:

It's a forum. Not everyone on here is a drug user!

Some of us shall remain safe!


--------------------
To find yourself alone, is to find yourself with your greatest friend, and your worst enemy.

Extras: Filter Print Post Top
Re: Security breach? [Re: DarkElf]
    #18335256 -

It was around Christmas....  Feel lucky we have administration truthful enough to tell us the low down and not sweep it under the rug.

Extras: Filter Print Post Top
Re: Security breach? [Re: shLong]
    #18335341 -

Yeah didn't everyone get a PM about it and saying to change your passwords?


--------------------

Extras: Filter Print Post Top
Re: Security breach? [Re: VivaLaMushie]
    #18335372 -

It forced me to change mine. It said i could change it back but it wasnt recommended

Extras: Filter Print Post Top
Jump to top Pages: 1


Similar ThreadsPosterViewsRepliesLast post
* Serious Security Flaw In IE 5 and 8 MHbound 545 9 12/17/08 01:21 AM
by magikgrl
* Rar File Password....anyone know how to crack?
( 1 2 all )
DeadPhan 1,995 21 04/25/09 11:34 PM
by canid
* Dictionary corner LuciferSam 1,065 8 02/06/06 03:08 PM
by wrestler_az
* I think an ex hacked my email password...
( 1 2 all )
DrCamacho89 3,852 23 05/16/07 02:22 PM
by Iron_Hymen
* Password? bigrenn 741 6 12/01/05 11:52 AM
by HELLA_TIGHT
* I love security questions. NewbieS 634 5 01/19/09 01:42 PM
by upinthetrees
* secure privet messges? Simisu 312 0 11/07/05 06:12 PM
by Simisu
* Got an email from the shroomery about my password?!?!? HUBSonDUBS 1,344 5 03/23/07 03:35 PM
by Konnrade

Extra information
You cannot start new topics / You cannot reply to topics
HTML is disabled / BBCode is enabled
Moderator: Entire Staff
472 topic views. 4 members, 271 guests and 99 web crawlers are browsing this forum.
[ Show Images Only | Sort by Score | Print Topic ]
Search this thread:

Copyright 1997-2026 Mind Media. Some rights reserved.

Generated in 0.024 seconds spending 0.006 seconds on 16 queries.