Home
Twitter
RSS
Newsletter
Gawker accounts hacked, change your passwords
Goto page 1, 2 Next
This forum is locked you cannot post, reply to or edit topics   This topic is locked you cannot edit posts or make replies    PAL Gaming Network Forum Index
   -> General Forums, Archive
View previous topic :: View next topic  
Author Message
el_rezzo




Status: Offline
Joined: 26 May 2007
Posts: 677
$poons: 35.40
Location: Geelong, VIC
australia.gif

PostPosted: Mon Dec 13, 2010 6:04 pm    Post subject: Gawker accounts hacked, change your passwords Reply with quote

Score:
4

Vote:
SONY
Jarrod
theory
Crank
http://pastebin.com/9rRmf6W5

http://www.neogaf.com/forum/showthread.php?t=415704

1.3 million accounts compromised apparently. Check to see if your password at Gawker wasn't enough to stop them getting your info. Then change any passwords that could be gleamed or are just the same as any of your Gawker details (and email address used with that account). Wish there was an option to delete the damn account, haven't been to Kotaku in ages. icon_sad.gif
_________________
Back to top
Trade $poons with user View users profile Send private message
Crank




Status: Offline
Joined: 05 Jul 2008
Posts: 1860
$poons: 838.60

blank.gif

PostPosted: Mon Dec 13, 2010 6:09 pm    Post subject: Reply with quote

Score:
3

Vote:
kaerlis
SONY
el_rezzo
From the FAQ relating to this:

5) How can I delete my account?
We understand how important trust is on the web, and some of you may wish to delete your Gawker Media account. Currently account deletion is not available. We will, however, give you this option as soon as possible.

So check back soon and deletion may well be possible.
Back to top
Trade $poons with user View users profile Send private message
chickenplucka




Status: Offline
Joined: 15 Oct 2008
Posts: 746
$poons: 4.60
Location: Adelaide
kazakhstan.gif

PostPosted: Mon Dec 13, 2010 6:16 pm    Post subject: Reply with quote

Score:
1

Vote:
SONY
no point in deleting the account now as the passwords and usernames have been compiled and torrented already.
mind you, people that don't reguarly change passwords or have easy to crack passwords are kinda asking for this to happen...
_________________
Back to top
Trade $poons with user View users profile Send private message MSN Messenger
Benza




Status: Offline
Joined: 11 Mar 2008
Posts: 14586
$poons: 119.20

blank.gif

PostPosted: Mon Dec 13, 2010 6:47 pm    Post subject: Reply with quote

Score:
1

Vote:
SONY
well glad I post everything under 'guest' then.
_________________
Back to top
Trade $poons with user View users profile Send private message
grim-one




Status: Offline
Joined: 07 Dec 2007
Posts: 6646
$poons: 1567.30
Location: Perth
australia.gif

PostPosted: Mon Dec 13, 2010 6:47 pm    Post subject: Reply with quote

Score:
1

Vote:
SONY
I don't get where Kotaku / LH / Gawker actually uses accounts. Looking on Kotaku, there's no log in function and the comments only ask for a name and password?

Edit - also there's a description in the article about how to check if your email address / password for an account was captured. Apparently I have one and it was
_________________

Steam:grim_one | PSN/Live:najakh | Flickr


Last edited by grim-one on Mon Dec 13, 2010 6:58 pm, edited 1 time in total
Back to top
Trade $poons with user View users profile Send private message
el_rezzo




Status: Offline
Joined: 26 May 2007
Posts: 677
$poons: 35.40
Location: Geelong, VIC
australia.gif

PostPosted: Mon Dec 13, 2010 6:48 pm    Post subject: Reply with quote

Score:
1

Vote:
SONY
Crank wrote:


So check back soon and deletion may well be possible.


I'm sure the backlash from this will get them moving on making it possible (and commonly known information) pretty damn soon.
_________________
Back to top
Trade $poons with user View users profile Send private message
DKP




Status: Offline
Joined: 07 Sep 2009
Posts: 534
$poons: 256.40
Location: Melbourne
australia.gif

PostPosted: Mon Dec 13, 2010 6:49 pm    Post subject: Reply with quote

Score:
3

Vote:
SONY
admeister
el_rezzo
What gets me is the sheer amount of people that use 'password' as their password. icon_rolleyes.gif
Back to top
Trade $poons with user View users profile Send private message
chickenplucka




Status: Offline
Joined: 15 Oct 2008
Posts: 746
$poons: 4.60
Location: Adelaide
kazakhstan.gif

PostPosted: Mon Dec 13, 2010 6:50 pm    Post subject: Reply with quote

Score:
1

Vote:
SONY
grim-one wrote:
I don't get where Kotaku / LH / Gawker actually uses accounts. Looking on Kotaku, there's no log in function and the comments only ask for a name and password?
that's the aussie site, if you want the full content
use this link for kotaku.
And this for the Australian news
_________________


Last edited by chickenplucka on Mon Dec 13, 2010 6:53 pm, edited 1 time in total
Back to top
Trade $poons with user View users profile Send private message MSN Messenger
el_rezzo




Status: Offline
Joined: 26 May 2007
Posts: 677
$poons: 35.40
Location: Geelong, VIC
australia.gif

PostPosted: Mon Dec 13, 2010 6:52 pm    Post subject: Reply with quote

Score:
1

Vote:
SONY
chickenplucka wrote:
mind you, people that don't reguarly change passwords or have easy to crack passwords are kinda asking for this to happen...


More that their encryption is pretty lazy, as Gawker tracks your username and password for that account if you use the same password for your email (luckily I don't) then you open yourself up to hackers having your emails which probably contain a few password changes or at least strong clues for them to go from. Basically as long as you change your connected email account's password as soon as possible everyone should be fine. This was more to embarrass gawker than to hurt the users.
_________________
Back to top
Trade $poons with user View users profile Send private message
chickenplucka




Status: Offline
Joined: 15 Oct 2008
Posts: 746
$poons: 4.60
Location: Adelaide
kazakhstan.gif

PostPosted: Mon Dec 13, 2010 6:55 pm    Post subject: Reply with quote

Score:
1

Vote:
SONY
el_rezzo wrote:
chickenplucka wrote:
mind you, people that don't reguarly change passwords or have easy to crack passwords are kinda asking for this to happen...


More that their encryption is pretty lazy, as Gawker tracks your username and password for that account if you use the same password for your email (luckily I don't) then you open yourself up to hackers having your emails which probably contain a few password changes or at least strong clues for them to go from. Basically as long as you change your connected email account's password as soon as possible everyone should be fine. This was more to embarrass gawker than to hurt the users.
it may have been to embarrass gawker, but the fact is there are lists of users and passwords available on torrent sites that are now open to everyone. so the chances of the community getting hurt are still pretty high.
_________________
Back to top
Trade $poons with user View users profile Send private message MSN Messenger
el_rezzo




Status: Offline
Joined: 26 May 2007
Posts: 677
$poons: 35.40
Location: Geelong, VIC
australia.gif

PostPosted: Mon Dec 13, 2010 7:19 pm    Post subject: Reply with quote

Score:
1

Vote:
SONY
chickenplucka wrote:
it may have been to embarrass gawker, but the fact is there are lists of users and passwords available on torrent sites that are now open to everyone. so the chances of the community getting hurt are still pretty high.


I agree, that's why I made this thread to warn people. I meant more that Anon are boasting about it and posting details on what was taken rather than silently going through everyones accounts and spending their money. Now that it is all on the web anyone can use the data to their advantage unfortunately. Hopefully not too many people get burned by it.
_________________
Back to top
Trade $poons with user View users profile Send private message
chickenplucka




Status: Offline
Joined: 15 Oct 2008
Posts: 746
$poons: 4.60
Location: Adelaide
kazakhstan.gif

PostPosted: Mon Dec 13, 2010 11:41 pm    Post subject: Reply with quote

Score:
3

Vote:
SONY
Island_Wolf
ObsoletE
just found this great comment in the #speakup section on Kotaku about how to check if your account has been hacked:
So, with all of the major hoopla going around surrounding the breach of passwords and accounts, you might be wondering, "Am I affected?"

Well, classy internet man, if you used the same username and password on your Gawker account for the rest of the media websites (or perhaps just orphan accounts as well), then you're probably at risk.

"Oh no! What can I do?" You might ask. Well, if you want to know if some unclassy internet guy could get into your account, and wreak havoc, posting trollish things across the internet (not really, unless you use the same password and username EVERYWHERE), you can follow these simple steps, courtesy of lastkarrde and futant462 of the Reddit community.

First, open this fusion table: http://www.google.com/fusiontables/DataSource?dsrcid=350662

Second, go to this website: http://pajhome.org.uk/crypt/md5/

Third, place your email into the "Input" line, and click MD5. Copy the corresponding string out of the "Output" field.

Fourth, in the fusion table, click "Show Options" (right underneath the Google logo), change "Domain" to "MD5," and lastly, paste the earlier string into the right-most box.

Fifth, click the apply button. If you're having a good day today, then the string will not show up, and your account has not been compromised. You might want to change your password regardless, but that's up to you.

If today is not your day, then the string will show up. Change your password, and I might suggest deleting the entire account when the option rolls around.

If you so happened to use the same username and password across the internet, your day will not get better. Hit high-risk targets first (bank accounts), move into more medium-range targets (online shopping aggregates, webhosting), and then take care of everything else. It's you against the clock.

In the age of a mass digital network, NEVER assume you are safe. Now may not be a bad time to change all of your passwords regardless of whether or not you were compromised.

Once again, I am simply using copypasta from Reddit, thank lastkarrde for the fusion table, and futant462 for the instructions. I am but a messenger.

Thank you internet, and have a great day.

#stayclassyinternet
#speakup

EDIT (OH LOOK IT'S BELOW THE HASHTAGS THIS MUST BE IMPORTANT): If you used Facebook Connect, the FAQ (in the red bar at the top) claims that your account would not be at risk. Once again, the friendlier side of the internet would like to remind you to pretty much not trust anything. Change your password (do it anyway), or delete the profile and start over. It's just social connections, people will find you, so long as you're not dead. They'll probably find you after you die, too.

I might also be suggesting the use of OpenID across the Gawker Media sites, but that's another matter entirely.
_________________
Back to top
Trade $poons with user View users profile Send private message MSN Messenger
chickenplucka




Status: Offline
Joined: 15 Oct 2008
Posts: 746
$poons: 4.60
Location: Adelaide
kazakhstan.gif

PostPosted: Tue Dec 14, 2010 12:01 am    Post subject: Reply with quote

Score:
1

Vote:
SONY
I am furious, yet glad to have found out that my account was stolen and has been freely distributed amongst torrent sites. I am relieved that I use a different password for different websites however.
If you want tips on the best ways to remember passwords for different websites check this guide:
http://lifehacker.com/184773/geek-to-live--choose-and-remember-great-passwords
_________________
Back to top
Trade $poons with user View users profile Send private message MSN Messenger
xboxdude




Status: Offline
Joined: 05 Dec 2010
Posts: 214
$poons: 260.20
Location: Somewhere in Vic
australia.gif

PostPosted: Tue Dec 14, 2010 6:52 am    Post subject: Reply with quote

Score:
1

Vote:
SONY
Too late guys,
torrents are already here
http://www.kickasstorrents.com/gawker-dbs-usernames-passwords-encrypted-and-unencrypted-t4814566.html
_________________
Back to top
Trade $poons with user View users profile Send private message
xboxdude




Status: Offline
Joined: 05 Dec 2010
Posts: 214
$poons: 260.20
Location: Somewhere in Vic
australia.gif

PostPosted: Tue Dec 14, 2010 7:09 am    Post subject: Reply with quote

Score:
1

Vote:
SONY
Got a hold of that torrent (not for bad reasons)
And went into the database searched my password. Sure enough it comes up with my password & username. I have since changed my password
_________________
Back to top
Trade $poons with user View users profile Send private message
xboxdude




Status: Offline
Joined: 05 Dec 2010
Posts: 214
$poons: 260.20
Location: Somewhere in Vic
australia.gif

PostPosted: Tue Dec 14, 2010 7:13 am    Post subject: Reply with quote

Score:
1

Vote:
SONY
3,366 pages full of passwords. How could this happen???
_________________
Back to top
Trade $poons with user View users profile Send private message
Fyuusii




Status: Offline
Joined: 13 Jan 2010
Posts: 1103
$poons: 213.80
Location: Perth, WA
blank.gif

PostPosted: Tue Dec 14, 2010 11:40 am    Post subject: Reply with quote

Score:
1

Vote:
SONY
^Quit with the spamming mate; you could've put all of that into a single post.

I got an email from DeviantART which seems to be referencing this leak. Is DA also affected?
_________________

"Now I stand, the lion before the lambs... and they do not fear.
They cannot fear..."
Back to top
Trade $poons with user View users profile Send private message
grim-one




Status: Offline
Joined: 07 Dec 2007
Posts: 6646
$poons: 1567.30
Location: Perth
australia.gif

PostPosted: Tue Dec 14, 2010 12:14 pm    Post subject: Reply with quote

Score:
1

Vote:
SONY
Fyuusii wrote:
I got an email from DeviantART which seems to be referencing this leak. Is DA also affected?

I think the dA thing was unrelated, unless the mass-email firm they use is related to Gawker somehow?

I got an email from a third-party group "hint.io" telling me my Gawker account was compromised. It was a nice idea, I just wish they hadn't filled it with links. Felt far too close to phising for me.
_________________

Steam:grim_one | PSN/Live:najakh | Flickr
Back to top
Trade $poons with user View users profile Send private message
Eyce




Status: Offline
Joined: 22 Oct 2003
Posts: 3780
$poons: 6.60
Location: Geelong, Vic.
australia.gif

PostPosted: Tue Dec 14, 2010 12:16 pm    Post subject: Reply with quote

Score:
1

Vote:
SONY
Fyuusii wrote:
^Quit with the spamming mate; you could've put all of that into a single post.

I got an email from DeviantART which seems to be referencing this leak. Is DA also affected?


No, it's relatively precautionary. People use the same password for many sites, so yeah.

I checked up my email address in the list and it was signed up under a random account name that wasn't mine. Password wasn't cracked either so I've got no idea what happened. Gmail has never been logged in from anywhere else icon_confused.gif
_________________
Back to top
Trade $poons with user View users profile Send private message MSN Messenger
xboxdude




Status: Offline
Joined: 05 Dec 2010
Posts: 214
$poons: 260.20
Location: Somewhere in Vic
australia.gif

PostPosted: Tue Dec 14, 2010 4:06 pm    Post subject: Reply with quote

Score:
1

Vote:
SONY
Fyuusii wrote:
^Quit with the spamming mate; you could've put all of that into a single post.

I got an email from DeviantART which seems to be referencing this leak. Is DA also affected?

Actually,
I found out that second piece of information after i posted the first.
_________________
Back to top
Trade $poons with user View users profile Send private message
subbastard




Status: Offline
Joined: 15 Oct 2008
Posts: 1306
$poons: 432.00

north_korea.gif

PostPosted: Tue Dec 14, 2010 4:15 pm    Post subject: Reply with quote

Score:
3

Vote:
SONY
Eyce
Fyuusii
That is what Edit is for champ.
_________________
I'd be apathetic, but I can't be arsed.
Back to top
Trade $poons with user View users profile Send private message
JamalH




Status: Offline
Joined: 20 Oct 2010
Posts: 283
$poons: 60.00
Location: Sydney, Australia
australia.gif

PostPosted: Wed Dec 15, 2010 11:22 am    Post subject: Reply with quote

Score:
1

Vote:
SONY
So what if i only look at Kotaku and replied with my facebook account once?

other than that ive never signed up there or have an account with any GAWKER sister site

EDIT - heres a widget you type your email in to see if it was compromised.

http://www.slate.com/id/2277768/

2) What if I logged in using Facebook Connect? Was my password compromised?
No. We never stored passwords of users who logged in using Facebook Connect. We have, however, disabled Facebook Connect logins temporarily.

3) What if I linked my Twitter account with my Gawker Media account? Was my Twitter password compromised?
No. We never stored Twitter passwords from users who linked their Twitter accounts with their Gawker Media account. However, if you used the same password for your Twitter account as you did on your Gawker Media account, you should change it immediately.

^^^ good news atleast
_________________


Now Playing: Dragon Age Origins: Ultimate Edition Awakening Expansion (PS3)
Back to top
Trade $poons with user View users profile Send private message
kaerlis




Status: Offline
Joined: 08 Jan 2008
Posts: 1170
$poons: 324.00

blank.gif

PostPosted: Thu Dec 16, 2010 12:47 pm    Post subject: Reply with quote

Score:
0

Vote:
This link explains pretty much everything that went on, and it's pretty amusing and interesting as well:

http://blogs.forbes.com/firewall/2010/12/13/the-lessons-of-gawkers-security-mess/
_________________
Back to top
Trade $poons with user View users profile Send private message Visit posters website
JamalH




Status: Offline
Joined: 20 Oct 2010
Posts: 283
$poons: 60.00
Location: Sydney, Australia
australia.gif

PostPosted: Thu Dec 16, 2010 3:14 pm    Post subject: Reply with quote

Score:
0

Vote:
After reading that suck shit to GAWKER they deserved it.

N. Hamilton basically said that the users accounts being compromised was "unimportant"
_________________


Now Playing: Dragon Age Origins: Ultimate Edition Awakening Expansion (PS3)
Back to top
Trade $poons with user View users profile Send private message
grim-one




Status: Offline
Joined: 07 Dec 2007
Posts: 6646
$poons: 1567.30
Location: Perth
australia.gif

PostPosted: Thu Dec 16, 2010 4:13 pm    Post subject: Reply with quote

Score:
0

Vote:
I don't understand why their database stores the actual passwords. I would have thought they would store a hash (MD5 or SHA1) and just perform the hash on the entered password to compare it to the stored one. The only possible reason I can think of is that it would allow recovery, but it can easily be avoided by just emailing out new random passwords upon request.
_________________

Steam:grim_one | PSN/Live:najakh | Flickr
Back to top
Trade $poons with user View users profile Send private message
Display posts from previous:   
This forum is locked you cannot post, reply to or edit topics   This topic is locked you cannot edit posts or make replies    PAL Gaming Network Forum Index
   -> General Forums, Archive
All times are GMT + 11 Hours
Goto page 1, 2 Next
Page 1 of 2

 
Jump to: 
 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum