Someone hacking your account and posting under your name

Page 1 of 2 [ 21 posts ]  Go to page 1, 2  Next

MemberSix
Veteran
Veteran

User avatar

Joined: 9 Dec 2007
Age: 40
Gender: Male
Posts: 606

29 Aug 2008, 2:55 am

Anyone had this before ?

I logged on today to find someone had posted a pretty nasty racist post under my nick.

Does that mean it'll have been a mod or something ?

Or is it more likely to be someone with the tools to do it ?



vt420
Yellow-bellied Woodpecker
Yellow-bellied Woodpecker

User avatar

Joined: 23 Aug 2008
Age: 43
Gender: Male
Posts: 53
Location: Portage, MI, USA

29 Aug 2008, 2:59 am

this seems more like an issue to take up directly with a mod/admin rather than posting publicly


Jeff



MemberSix
Veteran
Veteran

User avatar

Joined: 9 Dec 2007
Age: 40
Gender: Male
Posts: 606

29 Aug 2008, 3:02 am

vt420 wrote:
this seems more like an issue to take up directly with a mod/admin rather than posting publicly


Jeff

What if it was a mod ?



tomamil
Veteran
Veteran

User avatar

Joined: 13 May 2007
Age: 46
Gender: Male
Posts: 1,015
Location: Jeddah, Saudi Arabia

29 Aug 2008, 3:22 am

MemberSix wrote:
vt420 wrote:
this seems more like an issue to take up directly with a mod/admin rather than posting publicly

Jeff

What if it was a mod ?

or it was you under the medication :D just kidding,

it could be someone who knows you and your password, though. try to change it.


_________________
Timeo hominem unius libri, I fear the man of one book, St. Thomas Aquinas.


Last edited by tomamil on 29 Aug 2008, 3:34 am, edited 1 time in total.

MemberSix
Veteran
Veteran

User avatar

Joined: 9 Dec 2007
Age: 40
Gender: Male
Posts: 606

29 Aug 2008, 3:34 am

tomamil wrote:
MemberSix wrote:
vt420 wrote:
this seems more like an issue to take up directly with a mod/admin rather than posting publicly

Jeff

What if it was a mod ?

or it was you under the medication :D just kidding,

it could be someone who knows you and your pasword, though. try to change it.

Well, the only meds I take are fish-oil capsules which to my knowledge, have no known hallucenogenic properties.

I've changed my password to a very random one of 255 characters.

I've not searched for another MemberSix - but I can't imagine the site would allow that.

Could be a mod subtly trying to 'encourage' me to eff off.



tomamil
Veteran
Veteran

User avatar

Joined: 13 May 2007
Age: 46
Gender: Male
Posts: 1,015
Location: Jeddah, Saudi Arabia

29 Aug 2008, 3:38 am

MemberSix wrote:
I've changed my password to a very random one of 255 characters.

what? how do you remember that? are you savant?

MemberSix wrote:
Could be a mod subtly trying to 'encourage' me to eff off.

ok, so he is under the medication.

did you delete/edit the racist post? did you have the rights to do that?


_________________
Timeo hominem unius libri, I fear the man of one book, St. Thomas Aquinas.


MemberSix
Veteran
Veteran

User avatar

Joined: 9 Dec 2007
Age: 40
Gender: Male
Posts: 606

29 Aug 2008, 3:50 am

tomamil wrote:
MemberSix wrote:
I've changed my password to a very random one of 255 characters.

what? how do you remember that? are you savant?

No, it's a little more prosaic than that.
I saved it in a text file. :D

MemberSix wrote:
Could be a mod subtly trying to 'encourage' me to eff off.

tomamil wrote:
[ok, so he is under the medication.

did you delete/edit the racist post? did you have the rights to do that?

Yes.
My old password was only 8 characters - and all letters.
Don't know if changing it will make things any tougher for the perpetrator - but he's obviously pretty angry.

It happened after I posted against a racist thread-starter (thread quite old, now).
So I think it's someone who shares his racist sentiments.

But who knows ?

I guess it wouldn't be hard to hack someone's password with the right tool.



MemberSix
Veteran
Veteran

User avatar

Joined: 9 Dec 2007
Age: 40
Gender: Male
Posts: 606

29 Aug 2008, 3:57 am

MemberSix wrote:
I guess it wouldn't be hard to hack someone's password with the right tool.

Actually, it would be very easy with the right tool, as there is no limit to the number of unsuccessful log-in attempts !

Time the forum upgraded to a more modern VBulletin package ?

Maybe it hasn't been upgraded for just that reason ?

Maybe I'm being a bit conspiracy theorist now ?



tomamil
Veteran
Veteran

User avatar

Joined: 13 May 2007
Age: 46
Gender: Male
Posts: 1,015
Location: Jeddah, Saudi Arabia

29 Aug 2008, 4:00 am

MemberSix wrote:
I guess it wouldn't be hard to hack someone's password with the right tool.

if not well protected, it's enough to bypass the password protection. i guess that some mods do have the rights to do that officially, but I cannot imagine someone doing that. or, again, am i naive? when it happens it's usually someone who actually knows your password after you gave it to them.


_________________
Timeo hominem unius libri, I fear the man of one book, St. Thomas Aquinas.


MemberSix
Veteran
Veteran

User avatar

Joined: 9 Dec 2007
Age: 40
Gender: Male
Posts: 606

29 Aug 2008, 4:09 am

tomamil wrote:
MemberSix wrote:
I guess it wouldn't be hard to hack someone's password with the right tool.

if not well protected, it's enough to bypass the password protection. i guess that some mods do have the rights to do that officially, but I cannot imagine someone doing that. or, again, am i naive? when it happens it's usually someone who actually knows your password after you gave it to them.

I've never given anyone a password in my life.
You know - like some people give trusted ones the PIN on their credit card to go shopping and stuff ?
Me, I'd never do that - too many trust issues. ;)



tomamil
Veteran
Veteran

User avatar

Joined: 13 May 2007
Age: 46
Gender: Male
Posts: 1,015
Location: Jeddah, Saudi Arabia

29 Aug 2008, 4:20 am

if you want to learn about hacking sites, this is a great place
http://www.hackthissite.org/
start with the basic missions under the Challenges menu.
it's actually fun to go through the missions.

i didn't hack your account, honest :D


_________________
Timeo hominem unius libri, I fear the man of one book, St. Thomas Aquinas.


Quatermass
Veteran
Veteran

User avatar

Joined: 27 Apr 2006
Age: 43
Gender: Male
Posts: 18,779
Location: Right behind you...

29 Aug 2008, 4:23 am

None of the mods have this capability. We can edit posts and delete them, but we cannot post under another's name.

Is it possible that you have a mischievous sibling or friend who has just used your computer?


_________________
(No longer a mod)

On sabbatical...


MemberSix
Veteran
Veteran

User avatar

Joined: 9 Dec 2007
Age: 40
Gender: Male
Posts: 606

29 Aug 2008, 4:25 am

Quatermass wrote:
None of the mods have this capability. We can edit posts and delete them, but we cannot post under another's name.

Is it possible that you have a mischievous sibling or friend who has just used your computer?

I live alone.

Could have been a burglar with a grudge, I suppose.



ooOoOoOAnaOoOoOoo
Veteran
Veteran

Joined: 18 Jun 2008
Gender: Female
Posts: 12,265

29 Aug 2008, 5:15 am

That's funny, man. Wasn't me. Just kidding :lol:



ManErg
Veteran
Veteran

User avatar

Joined: 4 Apr 2006
Age: 64
Gender: Male
Posts: 1,090
Location: No Mans Land

29 Aug 2008, 5:56 am

MemberSix, are you sure it's just the one post? Have you checked any other threads for rogue comments?

I ask because most of your posts seem intelligent and reasonable enough, but then there's the odd one that seems downright insulting and posted just to provoke, which sounds like the racist one you've deleted. For example, there's a recent post (allegedly) by you calling dougn the "R" word based on his pic. This is blatantly out of order, maybe this is a hacked one trying to get you into trouble, too?

On this page: http://www.wrongplanet.net/postxf75555-0-15.html


_________________
Circular logic is correct because it is.


lau
Veteran
Veteran

User avatar

Joined: 17 Jun 2006
Age: 77
Gender: Male
Posts: 9,798
Location: Somerset UK

29 Aug 2008, 6:03 am

I assume the post you are talking about was the one that occurred ten minutes after your first post in the thread?

As you edited it, we don't really know what was there to start with, so you've blocked most routes of enquiry.

When you say that your password was just eight alphabetic characters, bear in mind that, even if they were all lower case, say, at the rate of a thousand attempts per second, the expected time to crack it would be just over three years.

However, if it was an eight character WORD, then you would only need about seven seconds (still at the silly 1,000 tries per second, which is quite unrealistic).

I'm not sure what you consider to be a "very random" 255 characters. This is a random eight characters: "QBuUnx6U". It comes from the "makepasswd" command, which uses /dev/random:

Quote:
The random number generator gathers environmental noise from device drivers and other sources into an entropy pool. The generator also keeps an estimate of the number of bits of noise in the entropy pool. From this entropy pool random numbers are created.
With the same 1,000 tries per second, this would take rather more than three millennia to crack.

Of course, all the password protection in the world is not going to stop someone who has a root kit on your machine and/or is piggybacking on your network, one way or another, etc... but I can see no reason why someone with that sort of access would bother to make a post on WP. The same sort of argument goes for moderators... why would we bother?


_________________
"Striking up conversations with strangers is an autistic person's version of extreme sports." Kamran Nazeer