Upvote Upvoted 16 Downvote Downvoted
UGC Forums hacked?
1
#1
0 Frags +

Not sure if this belongs in here, but just wanted to post this as it seems UGCs security fears have been raised with this troll post.
http://www.ugcleague.net/forum/announcement.php?f=61&a=9

Is this true? :O

Not sure if this belongs in here, but just wanted to post this as it seems UGCs security fears have been raised with this troll post.
http://www.ugcleague.net/forum/announcement.php?f=61&a=9

Is this true? :O
2
#2
12 Frags +

Looks like the UGC Admins are aware of it now. The forums are unavailable.

Looks like the UGC Admins are aware of it now. The forums are unavailable.
3
#3
1 Frags +

ugc got ddos'd by an angry 12 yo in the past, im not surprised this happened

ugc got ddos'd by an angry 12 yo in the past, im not surprised this happened
4
#4
-5 Frags +

and nothing of value was lost

and nothing of value was lost
5
#5
1 Frags +

I got some warning on my Gmail saying that my account was tried to be accessed from Ukraine, unsure whether or not is it affected with this or the Steam fuck up with last evening. Either way I don't even use the same password in both UGC and Gmail or Steam.

I got some warning on my Gmail saying that my account was tried to be accessed from Ukraine, unsure whether or not is it affected with this or the Steam fuck up with last evening. Either way I don't even use the same password in both UGC and Gmail or Steam.
6
#6
8 Frags +

The link I provided said: UGC has been hacked, your emails, IPs and passwords were leaked, also follow some random account on twitter, so yeah probs a 12 year old fucking around.

The link I provided said: UGC has been hacked, your emails, IPs and passwords were leaked, also follow some random account on twitter, so yeah probs a 12 year old fucking around.
7
#7
34 Frags +

So we're still trying to get things sorted out. Here's what we know so far:

  • The attacker gained administrative privileges through an unused account that had administrative rights
  • The attacker had administrative access to the forums and executed control panel actions from 5:25am EST - 5:51am EST
  • The attacker created an email list of board members. It is safe to assume he retrieved it and stored the list on his local machine
  • Passwords were not compromised as there is no way to receive password hashes from the forum itself. The attacker never had access outside of the vbulletin admin panel. (Yes password are hashed and salted)
  • Other actions included altering forum permissions then deleting forums, leaving only the recruitment and general forum behind
  • There is no "quick" or "easy" way to receive IP addresses from users as an administrator must go from profile to profile and manually copy and paste last login IP addresses.

We are still investigating, however it appears that the only damage done was a leak of email addresses as well as loss of forum data. If anyone has any information that they would like to share, add me on steam and leave something on my profile so I know to accept it (too many spam bots add me so I generally ignore friend invites).

So we're still trying to get things sorted out. Here's what we know so far:
[list]
[*] The attacker gained administrative privileges through an unused account that had administrative rights
[*] The attacker had administrative access to the forums and executed control panel actions from 5:25am EST - 5:51am EST
[*] The attacker created an email list of board members. It is safe to assume he retrieved it and stored the list on his local machine
[*] Passwords were not compromised as there is no way to receive password hashes from the forum itself. The attacker never had access outside of the vbulletin admin panel. (Yes password are hashed and salted)
[*] Other actions included altering forum permissions then deleting forums, leaving only the recruitment and general forum behind
[*] There is no "quick" or "easy" way to receive IP addresses from users as an administrator must go from profile to profile and manually copy and paste last login IP addresses.
[/list]

We are still investigating, however it appears that the only damage done was a leak of email addresses as well as loss of forum data. If anyone has any information that they would like to share, add me on steam and leave something on my profile so I know to accept it (too many spam bots add me so I generally ignore friend invites).
8
#8
6 Frags +

hope you guys get things under control for the upcoming season, its a real pain when this sorta thing happens

hope you guys get things under control for the upcoming season, its a real pain when this sorta thing happens
9
#9
15 Frags +

so it wasnt because your forum runs a outdated forum script?

http://www.vbulletin.com/forum/forum/vbulletin-announcements/vbulletin-announcements_aa/4250687-security-exploit-found-in-vbulletin-4

so it wasnt because your forum runs a outdated forum script?

http://www.vbulletin.com/forum/forum/vbulletin-announcements/vbulletin-announcements_aa/4250687-security-exploit-found-in-vbulletin-4
10
#10
3 Frags +

-

-
11
#11
-12 Frags +
brihgtI will never understand why people decide to do stuff like this during Christmas, a while ago, some people hacked Super Meat Boy's online section during Christmas too, and I'm sure there are tons of other examples as well. It just seems like a dick move to do this when everyone is trying to enjoy being with their family, and instead is having to deal with shit like this.

The people that do this often have some sort of severe mental health issues. People always say "hackers have autism xd", but in reality they most likely have some sort of severe depression or social awkwardness IRL and that carries over to the internet as well.

They get some sort of twisted high by making other people miserable/ inconveniencing them, and when people react to it, it makes them feel more worthwhile and or they like the attention they get from doing it.

[quote=brihgt]I will never understand why people decide to do stuff like this during Christmas, a while ago, some people hacked Super Meat Boy's online section during Christmas too, and I'm sure there are tons of other examples as well. It just seems like a dick move to do this when everyone is trying to enjoy being with their family, and instead is having to deal with shit like this.[/quote]

The people that do this often have some sort of severe mental health issues. People always say "hackers have autism xd", but in reality they most likely have some sort of severe depression or social awkwardness IRL and that carries over to the internet as well.

They get some sort of twisted high by making other people miserable/ inconveniencing them, and when people react to it, it makes them feel more worthwhile and or they like the attention they get from doing it.
12
#12
33 Frags +

at least passwords aren't in plaintext anymore

at least passwords aren't in plaintext anymore
13
#13
23 Frags +
Tury
The people that do this often have some sort of severe mental health issues. People always say "hackers have autism xd", but in reality they most likely have some sort of severe depression or social awkwardness IRL and that carries over to the internet as well.

They get some sort of twisted high by making other people miserable/ inconveniencing them, and when people react to it, it makes them feel more worthwhile and or they like the attention they get from doing it.

ya i dont think anything u said is remotely true nor does it contribute to the conversation

ive actually never heard somebody say 'hackers have autism'

im pretty sure there was just some low level ugc player who was mad at ugc admins for something and googled a vbulletin script

a lot of gray/blackhat guys are just bored more than anything

also ive noticed the people who consistently try to pin autism/depression/mental health issues on others tend to be the most unstable/unhappy themselves

funny how that works

[quote=Tury]

The people that do this often have some sort of severe mental health issues. People always say "hackers have autism xd", but in reality they most likely have some sort of severe depression or social awkwardness IRL and that carries over to the internet as well.

They get some sort of twisted high by making other people miserable/ inconveniencing them, and when people react to it, it makes them feel more worthwhile and or they like the attention they get from doing it.[/quote]

ya i dont think anything u said is remotely true nor does it contribute to the conversation

ive actually never heard somebody say 'hackers have autism'

im pretty sure there was just some low level ugc player who was mad at ugc admins for something and googled a vbulletin script

a lot of gray/blackhat guys are just bored more than anything

also ive noticed the people who consistently try to pin autism/depression/mental health issues on others tend to be the most unstable/unhappy themselves

funny how that works
14
#14
5 Frags +

wait, so they left behind the general and recruitment forums, but deleted everything else? did they not realize that those were the only 2 public forums anyone used? lmao... hope you guys can fix this idiot's work and retrieve the lost stuff :/

wait, so they left behind the general and recruitment forums, but deleted everything else? did they not realize that those were the only 2 public forums anyone used? lmao... hope you guys can fix this idiot's work and retrieve the lost stuff :/
15
#15
-27 Frags +
Rightjustifyat least passwords aren't in plaintext anymore

I believe you're confusing UGC with ESEA

[quote=Rightjustify]at least passwords aren't in plaintext anymore[/quote]
I believe you're confusing UGC with ESEA
16
#16
16 Frags +
DoctorMiggyRightjustifyat least passwords aren't in plaintext anymoreI believe you're confusing UGC with ESEA

https://www.reddit.com/r/truetf2/comments/30d8hf/ugc_stored_passwords_in_plaintext_you_should/

:^)

[quote=DoctorMiggy][quote=Rightjustify]at least passwords aren't in plaintext anymore[/quote]
I believe you're confusing UGC with ESEA[/quote]

https://www.reddit.com/r/truetf2/comments/30d8hf/ugc_stored_passwords_in_plaintext_you_should/

:^)
17
#17
1 Frags +

Good fucking job UGC

Good fucking job UGC
18
#18
18 Frags +

And here people were saying UGC never gets coverage on TFTV!

And here people were saying UGC never gets coverage on TFTV!
19
#19
4 Frags +

It's unfortunate it happened over Christmas, thank you for taking the time away from your family to remedy the problem.

It's unfortunate it happened over Christmas, thank you for taking the time away from your family to remedy the problem.
20
#20
-4 Frags +

Well, the forums are back now. Have fun.

Well, the forums are back now. Have fun.
Please sign in through STEAM to post a comment.