Login
Sign Up


You are using the mobile version of the forum, some features have been disabled to have it responsive.
Limelight Reunion 2024 - v4b1Limelight Discord
Ares Defence Services Discord
Limelight Reunion 2024 - v4b1Limelight DiscordAres Defence Services Discord

receiptDevelopment Blog:

Development Contributor Workflow

receiptHR Blog:

What *are* they doing over there?

receiptTeacher Blog:

Insight into the Teacher Team

receiptDevelopment Blog:

Infrastructure Upgrade 11/2019

receiptDevelopment Blog:

how suggestions???

receiptDevelopment Blog:

Planning for the future.


This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

Security alert
George radio_button_checked
Actively inactive
Veteran Member
Posts: 1,261
Threads: 28
Likes Given: 716
Likes Recieved: 1433 in 530 posts
Joined: Aug 2015
Reputation: 20
#16
Aug 8, 2015, 06:36 PM
Just so everyone knows, all LimeLight staff have had all their previous staff access rights revoked and even informed FL of any access we did have.

This is certainly an issue at their end.
[Image: olA44b8.png]
evilmat360 radio_button_checked
That inactive fuck
Membership
Posts: 540
Threads: 27
Likes Given: 252
Likes Recieved: 164 in 110 posts
Joined: Aug 2015
Reputation: 3
#17
Aug 8, 2015, 07:18 PM
My pass has been changed too.
If you are already logged in, your pass may have changed without your knowledge and but you're still able to remain logged in
Log out and attempt to log in, and you'll find if it's changed.
[Image: bkZ74Ui.png]
Enzyme radio_button_checked
Supervising Administrator - HR
Veteran Member
Posts: 2,443
Threads: 115
Likes Given: 1110
Likes Recieved: 2721 in 820 posts
Joined: Aug 2015
Reputation: 45
#18
Aug 8, 2015, 07:32 PM
(Aug 8, 2015, 07:18 PM)evilmat360 link Wrote: My pass has been changed too.
If you are already logged in, your pass may have changed without your knowledge and but you're still able to remain logged in
Log out and attempt to log in, and you'll find if it's changed.
^
That's what happened to me.

I don't even receive an email when I try to recover my password.
I know that this is an issue that Soul is trying to keep silent, and that his staff isn't really informed about the situation.

I'd advise people to be careful drawing hasty conclusions. It's not proven that Soul or any of his staff-members are behind this, so let's give them the benefit of doubt.

I don't think that Soul would be THAT stupid to purposely attack any LimeLight-members and staff, as that'd cause un-needed drama and further conflict.

Glad to report that our security is still up and in great condition, thanks to our lovely developers and nerds.
Sincerely, Enzyme
[Image: WWBN6ow.gif]
Killjoy radio_button_checked
Member
Membership
Posts: 11
Threads: 3
Likes Given: 0
Likes Recieved: 1 in 1 posts
Joined: Aug 2015
Reputation: 0
#19
Aug 8, 2015, 07:35 PM
What I don't understand is why Wood reporting the issue was censored.
[Image: KJSIG.png]
evilmat360 radio_button_checked
That inactive fuck
Membership
Posts: 540
Threads: 27
Likes Given: 252
Likes Recieved: 164 in 110 posts
Joined: Aug 2015
Reputation: 3
#20
Aug 8, 2015, 07:40 PM
I'm just hoping that it's down to some of the MyBB updates that soul did and nothing else.
[Image: bkZ74Ui.png]
Adman radio_button_checked
User
Registered User
Posts: 1
Threads: 0
Likes Given: 0
Likes Recieved: 0 in 0 posts
Joined: Aug 2015
Reputation: 0
#21
Aug 8, 2015, 07:41 PM
Happened to me and I'm not really part of LimeLight so idk if that's the target. Silencing Wood is dumb as shit though
bimkx radio_button_checked
Developer
Developer
Posts: 809
Threads: 50
Likes Given: 851
Likes Recieved: 719 in 296 posts
Joined: Aug 2015
Reputation: 11
#22
Aug 8, 2015, 07:44 PM
well this is fucking annoying :>

edit: just checked not changed here
(This post was last modified: Aug 8, 2015, 07:46 PM by bimkx.)
Faustie radio_button_checked
Veteran
Veteran Member
Posts: 3,039
Threads: 305
Likes Given: 1050
Likes Recieved: 2419 in 844 posts
Joined: Aug 2015
Reputation: 25
#23
Aug 8, 2015, 07:48 PM
I kept a very close watch of security at FL back when I was SA, as my specific role was Head of Security. As such, I can see several possibilities as to what could've caused this.

When I was an SA and had full access to the forum control panel, I set it so that only Soul, Temar, and myself could do many widespread changes; though it was possible for other SAs to modify forums and individual user accounts, I or Temar would almost certainly notice in the logs. However, in order to strip all of my access, it's likely that group permissions were changed and from experience I know that Soul rarely every reviews security logs, and now any SA could get away with changing passwords. If the group settings were changed enough, it's even possible that an admin could do this, but that would be serious negligence on Soul's part. If it is an inside source, those with the access would be Soul, Grub, and likely Mavis.

Of course, it's possible that someone else gained access. Unlike the dedicated server Burnett and I secured, Soul never set any form of IP checks on the adminCP, so if a password was stolen then accessing it would be simple. The forum back-end was also not particularly secure, and there were multiple permissions bugs for months that Soul did not fix despite me mentioning it to him a dozen times. With this in mind, it's possible that this is the end result of permissions bugs being unchecked for months or someone breaking in, as Soul was very negligent in fixing them and had not done so for months despite me notifying him on numerous occasions.

However, that said, I find it most likely that it's someone with authorized access doing this, especially considering certain posts have been wiped in recent days (Wood's post here and another regarding FL content), no announcement has been made warning users to change their passwords manually and guard their data, and Soul has yet to respond to anyone asking about this, yet he was able to speak to me 30 minutes ago about a different issue on Steam.

If this is not someone with authorization but rather a security breach, I think that it is extremely negligent of Soul not to post an immediate announcement, ensure that user's data/IPs are safe, and use the force password-change utility, which would require users to change their passwords on sign-in in case the old ones were stolen somehow. At the very least, Soul should change his own passwords and that of Mavis (if he has access) and Grub (who certainly does) and post an announcement. Without an announcement we can only assume that the e-mail and IP - and perhaps even the password - of every user there is at risk. As such, I would not be surprised if this was intentional by someone high up at FL, but those targeted seems strange.

Of course, it's possible that what's happening is none of the above, and without evidence it is pointless to pin the blame on someone. However, if it isn't a case of someone abusing his power, then I almost certainly think it may be related to security negligence - the lack of an announcement is negligence in itself.

I recommend to all users that, if this issue continues, you should change your e-mail on the FL forums if you don't want it potentially leaked. Better safe than sorry.

<p><br></p>
(This post was last modified: Aug 8, 2015, 07:52 PM by Faustie.)
GRiiM radio_button_checked
Member
Membership
Posts: 521
Threads: 37
Likes Given: 281
Likes Recieved: 439 in 216 posts
Joined: Aug 2015
Reputation: 5
#24
Aug 8, 2015, 07:49 PM
(Aug 8, 2015, 07:18 PM)evilmat360 link Wrote: My pass has been changed too.
If you are already logged in, your pass may have changed without your knowledge and but you're still able to remain logged in
Log out and attempt to log in, and you'll find if it's changed.

Tried this, my password isn't working now either.
What the fuck Fearless.
[Image: qqGXQQw.gif]
GRiiM radio_button_checked
Member
Membership
Posts: 521
Threads: 37
Likes Given: 281
Likes Recieved: 439 in 216 posts
Joined: Aug 2015
Reputation: 5
#25
Aug 8, 2015, 07:53 PM
(Aug 8, 2015, 07:40 PM)evilmat360 link Wrote: I'm just hoping that it's down to some of the MyBB updates that soul did and nothing else.

If that was the case then people from other communities would be reporting the issue, Google doesn't find anything for me though.
[Image: qqGXQQw.gif]
evilmat360 radio_button_checked
That inactive fuck
Membership
Posts: 540
Threads: 27
Likes Given: 252
Likes Recieved: 164 in 110 posts
Joined: Aug 2015
Reputation: 3
#26
Aug 8, 2015, 07:56 PM
Soul's reply on the situation.
"It's not your password that's changed, it's just broken. It happened after the MyBB 1.8.5 update. Nobody changed it. Simply press forgot password and a link will be send to your e-mail address to change it."
[Image: bkZ74Ui.png]
bimkx radio_button_checked
Developer
Developer
Posts: 809
Threads: 50
Likes Given: 851
Likes Recieved: 719 in 296 posts
Joined: Aug 2015
Reputation: 11
#27
Aug 8, 2015, 08:00 PM
posted a reply to his reply asking why he suppressed wood.
>gets supressed

hahahaha he's lying through his teeth

EDIT: Ok guys, never ever question Soulripper!
[Image: a73dabd416275669adf25b126533e9c8.png]

can somebody please reply to the post asking why i was permanently banned from posting just for asking a question? Smile

EDIT 2: Turns out he shadow banned me c':
Can't even like posts
(This post was last modified: Aug 8, 2015, 08:06 PM by bimkx.)
Faustie radio_button_checked
Veteran
Veteran Member
Posts: 3,039
Threads: 305
Likes Given: 1050
Likes Recieved: 2419 in 844 posts
Joined: Aug 2015
Reputation: 25
#28
Aug 8, 2015, 08:02 PM
There have been no other reported incidents of a 1.8.5 update causing this. The fact that several people have now had their posting rights permanently revoked (they sent me evidence of this) for questioning Soul's statement leads me to believe that all may not be as it seems. Please be very cautious with your personal information on the FL forums; I do not currently believe that it is entirely safe.

That said, there is currently no proof about what is behind this. While personally think that the site is currently unsafe, I could very well be wrong, and I will not be posting about this on the FL forums as I do not wish to cause drama there.
<p><br></p>
(This post was last modified: Aug 8, 2015, 08:04 PM by Faustie.)
Preditor radio_button_checked
Supervising Veteran :)
Veteran Member
Posts: 553
Threads: 14
Likes Given: 423
Likes Recieved: 832 in 314 posts
Joined: Aug 2015
Reputation: 12
#29
Aug 8, 2015, 08:09 PM
Aye happened to me as well. Not sure who it is but Soul seems really fishy about it.
[Image: 0bfCO3P.png]
Thx bambo gambo dambo sambo lambo jambo rambo.
Aviator radio_button_checked
User
Registered User
Posts: 50
Threads: 1
Likes Given: 23
Likes Recieved: 15 in 12 posts
Joined: Aug 2015
Reputation: 0
#30
Aug 8, 2015, 08:10 PM
This is what I was thinking Faustie.

I'd have thought and expect any security breach, even if it turns out false, to have proper precautions taken place to safeguard people's details. In fact, I'm not sure why I even have to say that, because it's just common sense.

I've never heard of such thing as "broken passwords" in my life, and browsing the MyBB support website shows no other customers experiencing that. Even if there was a problem with passwords, I would expect MyBB to fix it and issue warnings to people or not even let it get to the stable release.

I think it's better to be safe than sorry to be honest. I feel this is extremely negligent that these problems could persist multiple days without a peep.

Let's see how it pans out.
Cheers,
Aviator




Users browsing this thread: 1 Guest(s)