PMBD

The Pirate Ship => ARR! => Topic started by: Witchboy on 2010 January 25, 03:13:38



Title: Sunhair Hacked
Post by: Witchboy on 2010 January 25, 03:13:38
Sunhair's e-mail, rapidshare & pay pal accounts have been hacked.

Quote from Sunhair on BPS
Quote
Well I am a bit ticked off well ticked off is an understatement I am really irate. As I woke up today to discover I had been hacked my email address, my rapidshare, and they even went as far as to try to hack my paypal.

My email address is unrecoverable they made it so gmail couldn't do an account retrieval they changed everything. Coincidentally this was the same email that was on the petition that I signed the one that was hacked a few months ago.

This had to of occurred when I was sleeping somewhere between 2 a.m-8 a.m as I was able to access my email account before that.

Sorry for ranting but, This has me really Angry and I need to vent



Title: Re: Sunhair Hacked
Post by: ShanOw on 2010 January 25, 03:39:39
This seems almost too coincidental: No TSR undercover operative would be this stupid.

I don't see a motive, so I have to go with copycat, at least until a little more info comes out.


Title: Re: Sunhair Hacked
Post by: Witchboy on 2010 January 25, 03:49:22
This seems almost too coincidental: No TSR undercover operative would be this stupid.

I don't see a motive, so I have to go with copycat, at least until a little more info comes out.

This is TSR were talking about :D *cough~ATWA~cough*

Is it coincidence that Jill's e-mail that was hacked is the very same e-mail she used to sign the Soups petition that was hacked & culled for info?


Title: Re: Sunhair Hacked
Post by: ShanOw on 2010 January 25, 04:01:45
We know TSR have two sources for passwords: the petition and their database.

Quote
Is it coincidence that Jill's e-mail that was hacked is the very same e-mail she used to sign the Soups petition that was hacked & culled for info?
In fairness, most people only have one or two email addresses. If sunhair only has one email addy then the chance of it matching the one used in the petition is 100% - hardly a coincidence.

Also, you can't haxxor someones email without a password, unless of course that password matches either the TSR-DB or Soup-Petition password used. In that event, its highly likely that the attack came from an organization or individual who resents the free community. Do we know anyone who fits this? :P


Title: Re: Sunhair Hacked
Post by: Pescado on 2010 January 25, 04:03:20
Petitions don't have passwords and compromising the petition would not have gained access to anything other than dox. I'm not seeing a link. If a hack was attempted on a Paypal, this could constitute an actual crime and evidence may have been collected. However, the apparent profit motive may suggest an outside agent rather than one connected to the community.


Title: Re: Sunhair Hacked
Post by: Witchboy on 2010 January 25, 04:18:21
I'm waiting to hear from Jill & hope to talk to her on MSN. I'm waiting for her to sign in. Jill if your reading this i'm on MSN but in invisi mode. Message me & i'll answer.

Ok i'm chatting with Jill. Info will be forth coming. She's afraid her forum might be next. BTW i am also a creator & mod on Sunhair as well.


Title: Re: Sunhair Hacked
Post by: ShanOw on 2010 January 25, 04:44:40
If she's afraid for her forum, make sure all staff passwords are changed (quite obvious really), MySQL & PhpMyAdmin (if she has access) also get new passwords and that the forum software is up to data.


Title: Re: Sunhair Hacked
Post by: Witchboy on 2010 January 25, 05:25:43
She's done all that :)

Ok info so far is her gmail password was the same as her TSR account but she changed that. Her pay pal account password was the same as the one on TSR & is also the same pay pal account she used to subscribe to TSR. Her rapidshare account password was not the same. How that was gotten she's not sure.

She's waiting to hear from google about her gmail account, hubby is talking to rapidshare & pay pal she needs to call back tomorrow as she can not change her password & can not assign her new email as the primary account holder of her pay pal account.



Title: Re: Sunhair Hacked
Post by: ShanOw on 2010 January 25, 06:20:07
If they had email access they could have used a "forgotten my password" the have it reset and sent somewhere they can get access.


Title: Re: Sunhair Hacked
Post by: Pescado on 2010 January 25, 07:00:12
Pretty much. So the crapidshare thing indicates that the attacker is clearly learning from the conversations on MATY. IF this isn't simply a random incident. I mean, we're talking crapidshare and gmail. Not even a Sims site.


Title: Re: Sunhair Hacked
Post by: Witchboy on 2010 January 25, 07:24:30
I'm not going to say what Jill had in her crapidshare account and available for download but i'll let you take a guess ;)

As for Jill's gmail account, it seems it has been completely deleted now. Earlier she just couldn't sign into it because the sign in info was changed by the hacker.

Quote
Quote from Jill on BPS
well it is official the Jerk Hacker deleted my gmail account I just tested it using a bogus dummy email and it bounced back.

In deleting Jill's gmail account, could it have been deleted so that the IP info from the hacker could not be retrieved? Is that even a possibility?  

Could Jill's Pay Pal/TSR info being the same be a connection to other known hackings of the same type?


Title: Re: Sunhair Hacked
Post by: Pescado on 2010 January 25, 08:07:52
Well, it does mean she can get it BACK. But yeah, the information is probably unretrievable. While Google never deletes anything, they're not gonna help you retrieve it, either.


Title: Re: Sunhair Hacked
Post by: ShanOw on 2010 January 25, 08:09:21
Big companies like Google and Photobucket will only give out information to authorities. Its generally written in there privacy statement.


Title: Re: Sunhair Hacked
Post by: Pescado on 2010 January 25, 08:11:09
This is why I like to webbug my own critical accounts. I put, in them, a hotlinked object that is never linked from anywhere else, so when someone starts snooping through my inbox, their IP is immediately captured when they see the object and an alarm is sounded on my computer. I also preemptively hack my own computer. :P


Title: Re: Sunhair Hacked
Post by: ShanOw on 2010 January 25, 08:13:20
This is why I like to webbug my own critical accounts. I put, in them, a hotlinked object that is never linked from anywhere else, so when someone starts snooping through my inbox, their IP is immediately captured when they see the object and an alarm is sounded on my computer. I also preemptively hack my own computer. :P

What could you have in your accounts that needs so much protecting?

:::Actually, wait: On second thoughts its probably better for my defence lawyers if I don't know :P


Title: Re: Sunhair Hacked
Post by: Pescado on 2010 January 25, 08:36:32
What could you have in your accounts that needs so much protecting?
Absolutely nothing, but everyone needs a hobby, and mine happens to be paranoia.


Title: Re: Sunhair Hacked
Post by: Paden on 2010 January 25, 17:33:28
I thought it was stomping around and burninating peasants, ala Trogdor? :P


Title: Re: Sunhair Hacked
Post by: dstar on 2010 January 25, 17:49:53
Or barbecuing babies. Paranoia is a good hobby to have though , you can never be to cautious.


Title: Re: Sunhair Hacked
Post by: Pescado on 2010 January 25, 18:15:11
I thought it was stomping around and burninating peasants, ala Trogdor? :P
It's a subset of paranoia: Doing unto others before they do unto you.


Title: Re: Sunhair Hacked
Post by: Paden on 2010 January 25, 18:29:50
Well, yeah. Or at least have yourself so well armed that if they dare try to come at you in numbers or alone, you can incinerate them before they get more than a few steps off of the starting block.