IMPORTANT, URGENT, AND FOR ATTENTION ALL.
As of perhaps two hours ago, I believe that some, possibly all, user accounts on THN Games have been compromised. This may have been isolated to administrators and junior administrators only but I think it is very unwise to assume this.
As of this moment, please assume that the following details have been compromised:
username
password
email
Passwords are handled by vBulletin's mechanism and appear to be salted and the salt doesn't initially appear to have been compromised. However, the salts are quite simple so assume that with a bit of horsepower it'd be pretty easy to break your passwords.
Hence, assume that any email/username and password combination that matches THN is now breached and should be changed immediately.
FYI, the attack looks like a SQL injection attack directly against the shoutbox.
Sorry all. This sucks.
Further information as it's available.
As of perhaps two hours ago, I believe that some, possibly all, user accounts on THN Games have been compromised. This may have been isolated to administrators and junior administrators only but I think it is very unwise to assume this.
As of this moment, please assume that the following details have been compromised:
username
password
Passwords are handled by vBulletin's mechanism and appear to be salted and the salt doesn't initially appear to have been compromised. However, the salts are quite simple so assume that with a bit of horsepower it'd be pretty easy to break your passwords.
Hence, assume that any email/username and password combination that matches THN is now breached and should be changed immediately.
FYI, the attack looks like a SQL injection attack directly against the shoutbox.
Sorry all. This sucks.
Further information as it's available.