SQL injection vulnerability

Aduiavas Ida

Aes Sedai
Head of the White Ajah
Joined
Jun 10, 2008
Messages
20,151
Age
34
Location
Drøbak, Norway
Pronouns
  1. She - Her
The site just went down again, just for about a minute :look: It said DNS could not be reached :look: Is this the same as before?
 

Ashara Koh'inor

Aes Sedai
Joined
May 24, 2015
Messages
4,715
Location
North Carolina, US
Pronouns
  1. She - Her
Discord
Ashara#3362
Thanks for taking care of everything so quickly and being patient enough to answer all our questions. Great job!!!
 

Kelgan al'Moranwin

Aes Sedai
Moderator
Joined
Nov 8, 2009
Messages
23,806
Location
Maynard, MA
Thanks for getting things taken care of so quickly, Mendo!
 

Mendo Cath

Voidbringer
Aes Sedai
Joined
Apr 2, 2013
Messages
4,925
The site just went down again, just for about a minute :look: It said DNS could not be reached :look: Is this the same as before?

Unrelated. Our host reported "DNS Resolution Issues" around the same time.

When it rains?
 

Cassie Dainar

Darth Dainar
The Amyrlin Seat
Joined
May 10, 2010
Messages
5,681
Age
44
Location
Arkansas
Mine was clearly secure as I couldn't hack it on my own and had to reset it. :cheeseeni:

I'm going to presume that my groggy text message conversation with Mendo last night about this was successful.
 
Joined
Sep 10, 2001
Messages
9,522
Location
Perth, Australia
Pronouns
  1. He - Him
same around 1400, must be the last time we updated the forums :)
 

Defen Estrator

Mastering the Watch
Gaidin
The Illuminator
Joined
Jan 23, 2005
Messages
145
Location
rand(), USA
Pronouns
  1. He - Him
Got the update to fix this (the vulnerable part of the forums was disabled in the meantime), so there's going to be a quick emergency maintenance to apply it and re-enable things. Should be just a quick blip.

[edit]Done![/edit]
 

Caerwyn Jolan

Gaidin
Joined
Sep 24, 2007
Messages
429
Age
63
Location
Volcano, California USA
Thank you for letting us know so quickly!
Unfortunately, I've used that password on a lot of non-identification, non-financial stuff, so I've got a lot of password changing to do.

I suspect this sort of thing is common. I know i used to reuse passwords between sites until a couple years ago.

So. The way security folk that i know (computer security) do it, is similar to what I do, which is to use a password manager like Lastpass to create unique, complex passwords (the one i just set my tv.net password to is a random string of 20 digits with mixed character types, I generally use 20 characters or whatever the maximum length of the password field that is accepted is.

This lets you never worry that a compromised password on one site affects others. (it turned out my password here actually predated my doing this, but i had since changed all the other places that password was used).

Lastpass (and several other password managers) have browser plugins so its easy to actually log in with them. you dont have to type those crazy passwords.

Anyway, if you're thinking of upgrading your online security becuase of this incident, i'd recommend using a password manager rather than just picking another password and setting a bunch of sites to use it.

thanks
Caerwyn
 

Eleyan Al'Landerin

Koyn Amyrlin
Aes Sedai
Joined
May 9, 2010
Messages
499
Location
Chapel Hill, NC
1500 days..... so I... win? Er...?
Either way, it was time to change my password. :indifferent:


Caerwyn, I've been very interested in using a password manager but was afraid that I'd get confused and just end up without access. I'd love suggestions (and a little education) for current best practices.

Dear IT Team, the Internet is dark and full of terrors. Thank you for noticing the breach and working straight away to notify everyone and correct the problem as best you can.
 

Caerwyn Jolan

Gaidin
Joined
Sep 24, 2007
Messages
429
Age
63
Location
Volcano, California USA
1500 days..... so I... win? Er...?
Either way, it was time to change my password. :indifferent:


Caerwyn, I've been very interested in using a password manager but was afraid that I'd get confused and just end up without access. I'd love suggestions (and a little education) for current best practices.
.

This is a pretty good article on password managers, how they work and it mentions some of the stronger ones at the end.

A number of the screenshots are from using Lastpass but there are several other choices mentioned.
 
Top