Might want to change passwords

Status
Not open for further replies.

waldojnk

Member
Dec 28, 2014
53
22
8
Looks like little cow board got hacked. I have no idea how to get information on extent so don't know if account information is at risk. But if you are reusing passwords, you may want to change them. Right now the hacking team has blocked access to the site and put their own splash page up. Not sure if an admin for that board is here and can comment, but thought I should let others know.

My apologies to mods if I should not have posted info here about another board, but didn't know any other way to get the information to others.
 

matthaus_2000

New member
Jun 30, 2015
4
0
0
I can't believe this shit too. Neither one of us can defend our little farmhouse home.

It must be the NDP and Trudeau messing around with Alberta.
 

rdreamer

Banned
Feb 28, 2007
92
0
0
The little cow did not update their site ever, so it was easy pickings for hackers. There have been a few other sites hacked this week as well. Guess we are going to find out who has decent security on their sites.
 
W

Warl0ck

Looks like he work of @RealTeaMr00t. Likely the admin didn't patch or update whatever plugins he was using. Question is did they gain root access to the DB for a data dump?
 

rdreamer

Banned
Feb 28, 2007
92
0
0
They have complete control of the site and uploaded to the server, so yes they got all the information, and you should see it pop up on the underground marketplace soon. They sell membership lists and emails to spammers on underground forums.
 

waldojnk

Member
Dec 28, 2014
53
22
8
Not too big a deal for most of us I hope, but going to be a huge deal for registered SPS I would imagine.
 

Quarter Mile'r

Injected and Blown
May 17, 2005
3,597
134
63
Out of Town
What the hell is the little cow board? Never heard of it.




....................QM'r
 

hankmoody

Active member
Aug 12, 2014
979
51
28
I don't go there much but received an email from CAF saying if i was having trouble logging in to bookmark one of 3 links they sent me.
Now i'm suspicious, did the email really come from them?

I hope Fred and the boys have things up to snuff here..
 

rictor71

Member
Nov 3, 2005
40
0
6
I don't go there much but received an email from CAF saying if i was having trouble logging in to bookmark one of 3 links they sent me.
Now i'm suspicious, did the email really come from them?

I hope Fred and the boys have things up to snuff here..
Got the same e-mail. Deleted it once I saw what happened. Very easily could have been a fishing expedition.
 

gndvan

GND
May 4, 2015
316
201
43
Canada
I am not very technically savvy, but what information do members have in this or other boards that is considered private or a risk? I mean I don't think anyone even uses their real name or enter credit card information or anything to become a member, even SPs. Please educate me.
 

Bad Santa

Seeking Sexy Helpers
Feb 26, 2010
1,111
28
48
South Pole
I don't go there much but received an email from CAF saying if i was having trouble logging in to bookmark one of 3 links they sent me.
Now i'm suspicious, did the email really come from them?

I hope Fred and the boys have things up to snuff here..
I am not very technically savvy, but what information do members have in this or other boards that is considered private or a risk? I mean I don't think anyone even uses their real name or enter credit card information or anything to become a member, even SPs. Please educate me.
I haven't received one of these emails from baby cow but I agree, I wouldn't open such an email. It's too bad. I'm gonna miss that board. Hope they can get things fixed.
 

buggs312

Member
Jul 11, 2013
331
13
18
Anmore
It's done through the navigation bar above.

Select "Forum", then "Forum Actions", then "General Settings".

Once you are there, scroll down to "My Setting", and select "Edit Email and Password" under "My account"
Thank you! never would have found it
 

BS Detector

Active member
Sep 7, 2003
1,526
4
38
www.bsdetector.com
LOL, the mad dash is on to change passwords. If I use sites like that, not only is my password different from any other I use but the email address was used strictly to open that account and never used again for any other purpose so if any one hacks, info they glean is totally useless.
 
W

Warl0ck

The real risk when a forum gets hacked depends on how the administrator of the forum stores passwords. When you log into a system, the server will "hash" a password. This means to create a mathematical algorithm. Now, it is possible to easily crack a hash so that hash is often salted. Salted means to toss in random characters & data. This makes the hash almost impossible to crack. So if the hacker of the forum does a data dump of the information the email will be in view but the password will not be.

Why does this matter? Users tend to recycle passwords & email. So the email and password you use to log into this forum are probably used for other accounts. When the hacker dumps this data he does so in a place where other hackers can see it. The first thing they'll do is try other social media, email accounts, etc. In a very short time they have a great deal of your personal data & can use it to extort whatever from you. After the data dump from Ashley Madison was released people reported being sent threatening messages to pay up in bitcoin or have the public information be released and destroy you. Believe it or not, there are lots of men who are stupid enough to sign up with an account that identifies them. Lulzsec hacked Pron.com in 2011 and there were a number of government & military officials who signed up using their official email. Information is the new currency.

There is speculation that certain forums (not this one) do not encrypt their passwords at all. The result is the moderator of that forum can see your email and password in plain text. This is more common than you imagine as many web administrators have limited to zero security skills. That is why you often see data dumps which contain the password in plain text. These forums are canned products like Wordpress is. They need to be constantly updated or they're the internet version of Swiss cheese.
 

Corrado Soprano

I prefer Mr. Soprano
Nov 22, 2016
1
0
1
On my sofa
Jesus on the cross, it must be the feds.
 

Fred Zed

Administrator
May 11, 2002
784
255
63
UP ABOVE SMILING
The result is the moderator of that forum can see your email and password in plain text. This is more common than you imagine as many web administrators have limited to zero security skills. That is why you often see data dumps which contain the password in plain text.
Not here. We can see the email addresses not the passwords .....I'm pretty sure same is true of CAF, they use the same software as us.

I think the worst they can happen to users from these hacks is spam ( to the email address used on the hacked site) as hackers sell the emal address on the dark web.
 
W

Warl0ck

@FredZed

That depends. If the passwords are simply hashed, a good GPU or rainbow tables makes cracking the hash (converting it to text) easy. If the passwords are salted, it's next to impossible. There is still the matter of some people using a known personal email to log into these sites & having the database dumped by a hacker(s).

Take a look at https://ashley.cynic.al/ It allows any person to check to see if an email address had an account on Ashley Madison. One could claim they didn't sign up but...
 

rictor71

Member
Nov 3, 2005
40
0
6
I have a funny feeling shit is already starting. The e-mail account I used just got an e-mail out of the blue. This was not normal spam. It asked a simple question "Are you at home?" and had a e-mail address that looked very normal. For clarity, I used this account for JUST that and there was nothing sexual about this e-mail....no selling anything.....just a simple"Are you at home?". I deleted it but I've seen enough spam to know when something looks specific.
 
Status
Not open for further replies.
Vancouver Escorts