VOGONS


DOSBox.com user database compromised

Topic actions

First post, by Qbix

User metadata
Rank DOSBox Author
Rank
DOSBox Author

Hello,

Hackers have gained access to the user database on dosbox.com.
You should consider your password for dosbox.com compromised.
So if you use it on other sites, update it.

Peter.

Water flows down the stream
How to ask questions the smart way!

Reply 1 of 24, by lwc

User metadata
Rank Member
Rank
Member

Does tihs include the wiki?

Reply 2 of 24, by Qbix

User metadata
Rank DOSBox Author
Rank
DOSBox Author

not that I know, but I can't make promisses.

Water flows down the stream
How to ask questions the smart way!

Reply 3 of 24, by Snover

User metadata
Rank l33t++
Rank
l33t++

The only information taken was from the compatibility database, not the wiki, but if you used the same password anywhere else consider it compromised.

Yes, it’s my fault.

Reply 4 of 24, by The_Mega_ZZTer

User metadata
Rank Newbie
Rank
Newbie

Passwords weren't encrypted... why? Seriously, PHP has several functions for hashing, MySQL has one, you can easily add a salt for near-uncrackable hashes with very little effort, there's really no excuse.

Or were passwords encrypted and you're just being cautious? It would really be nice to know if someone has IMMEDIATE access to all our passwords or if it's unlikely they'll want to go through the trouble of brute forcing all the hashes but we should know anyway.

http://www.mzzt.net/

Reply 5 of 24, by Qbix

User metadata
Rank DOSBox Author
Rank
DOSBox Author

they were hashed. but that doesn't mean you can assume that they aren't crackable

Water flows down the stream
How to ask questions the smart way!

Reply 6 of 24, by leileilol

User metadata
Rank l33t++
Rank
l33t++

i'm not sure if I even registered on the compatibility list D:

apsosig.png
long live PCem

Reply 7 of 24, by temptingthelure

User metadata
Rank Member
Rank
Member

So why does this occur? Why dosbox.com in particular? Do these hackers have some sort of beef with dosbox or the team behind it, or is it just a random thing, and dosbox site was just convenient?

Reply 8 of 24, by wd

User metadata
Rank DOSBox Author
Rank
DOSBox Author

Seems like they have commercial interest in selling their "service" of securing internet sites.

Reply 9 of 24, by temptingthelure

User metadata
Rank Member
Rank
Member

Ah, so it's their way of saying , "You dont want this to occur, hire us!". Sounds like blackmail.

Reply 10 of 24, by Qbix

User metadata
Rank DOSBox Author
Rank
DOSBox Author

I don't want to make it sound that bad.
They found a security hole in dosbox.com, but they chose a non-standard way of reporting it.
They have no problems with us nor with dosbox itself as far as a I know.

Water flows down the stream
How to ask questions the smart way!

Reply 11 of 24, by temptingthelure

User metadata
Rank Member
Rank
Member

Do you have their contact info? Maybe they can find security holes in my network. 😀

Rise of the Triad modding site!
http://rott.s4.bizhat.com

Reply 12 of 24, by Kippesoep

User metadata
Rank Oldbie
Rank
Oldbie

I wonder if they can find a security hole in my fist... or maybe my fist can find a security hole in them...

Reply 13 of 24, by temptingthelure

User metadata
Rank Member
Rank
Member

Maybe your foot can find a security hole in their asses. : 😵

Reply 14 of 24, by ripa

User metadata
Rank Oldbie
Rank
Oldbie

Will access to the comments on the compability of each game be restored?

Reply 15 of 24, by Napostriouf

User metadata
Rank Newbie
Rank
Newbie

Yes i agree, i've several games that i've tested that still to be added to the database that are currently not listed! ^^

Reply 16 of 24, by temptingthelure

User metadata
Rank Member
Rank
Member

So does anyone in the dosbox team have any contact info on these hackers, so that they can tell on them with the fbi, or something?

Rise of the Triad modding site!
http://rott.s4.bizhat.com

Reply 17 of 24, by lightmaster

User metadata
Rank Oldbie
Rank
Oldbie

maybe they're the fbi or something :p

25071588525_735097840e_b.jpg

Reply 18 of 24, by Serious Callers Only

User metadata
Rank Member
Rank
Member

Just to be clear, it wasn't the forum accounts?

Reply 19 of 24, by wd

User metadata
Rank DOSBox Author
Rank
DOSBox Author

Right, the forum accounts were NOT affected.