VOGONS

Common searches


DOSBox.com user database compromised

Topic actions

First post, by Qbix

User metadata
Rank DOSBox Author
Rank
DOSBox Author

Hello,

Hackers have gained access to the user database on dosbox.com.
You should consider your password for dosbox.com compromised.
So if you use it on other sites, update it.

Peter.

Water flows down the stream
How to ask questions the smart way!

Reply 4 of 24, by The_Mega_ZZTer

User metadata
Rank Newbie
Rank
Newbie

Passwords weren't encrypted... why? Seriously, PHP has several functions for hashing, MySQL has one, you can easily add a salt for near-uncrackable hashes with very little effort, there's really no excuse.

Or were passwords encrypted and you're just being cautious? It would really be nice to know if someone has IMMEDIATE access to all our passwords or if it's unlikely they'll want to go through the trouble of brute forcing all the hashes but we should know anyway.

http://www.mzzt.net/

Reply 5 of 24, by Qbix

User metadata
Rank DOSBox Author
Rank
DOSBox Author

they were hashed. but that doesn't mean you can assume that they aren't crackable

Water flows down the stream
How to ask questions the smart way!

Reply 7 of 24, by temptingthelure

User metadata
Rank Member
Rank
Member

So why does this occur? Why dosbox.com in particular? Do these hackers have some sort of beef with dosbox or the team behind it, or is it just a random thing, and dosbox site was just convenient?

Reply 10 of 24, by Qbix

User metadata
Rank DOSBox Author
Rank
DOSBox Author

I don't want to make it sound that bad.
They found a security hole in dosbox.com, but they chose a non-standard way of reporting it.
They have no problems with us nor with dosbox itself as far as a I know.

Water flows down the stream
How to ask questions the smart way!

Reply 16 of 24, by temptingthelure

User metadata
Rank Member
Rank
Member

So does anyone in the dosbox team have any contact info on these hackers, so that they can tell on them with the fbi, or something?

Rise of the Triad modding site!
http://rott.s4.bizhat.com