Jacob Posts
artcellrox wrote...
Mibuchiha has informed me of a bug with some of the PMs, specifically with this case.https://www.fakku.net/users/pervy_girl
https://www.fakku.net/users/pervy+girl
As seen, they're technically different, as one uses an underscore, and another doesn't. However, sending a PM to either sends the PM to pervy girl only, preventing pervy_girl from getting any PMs. This is a serious problem that needs to be addressed soon.
Nice job finding this bug, it was a quick fix. Should be working now.
Not sure what the issue is, may be related to the internet provider you are using. What country are you in? And just for kicks, did you try a different browser?
I'm investigating this, it's unrelated to the event on the front page. Looks like a malicious ad from the ad company.
My post here is my response to everything from the event three years ago. In this instance it was not my account that was compromised and no user data was lost, they messed around with an admins account which they previously had access to. Their actions were limited to front paging a post and vandalizing some manga.
The event three years ago happened when I recruited Tranquility (a FAKKU moderator at the time) to help me with some code on Sanshee before it went live. Specifically he was working on PayPal integration. When I took him on I changed the password on the database to "fakku123" because I didn't want him to see the password I had been using up until then. Unfortunately that particular server was using CPanel, so when I changed the database password it automatically changed the SSH password as well. Shortly after Sanshee went live, Tranquility shared that password with Hibia (the disgruntled ex admin I mentioned), and he immediately went into the database and reversed the encryption on my Sanshee account (which was the same password used on my main FAKKU account and my email) and stole a bunch of data off the server. That's where any notion that what they did was somehow not malicious, they broke the law and stole data.
The users that had created accounts on Sanshee at the time (three years ago) had sensitive information exposed. The hackers chose to focus entirely on me. To quote my post in the other topic... " they broke into all of my email accounts, my Skype account, my Facebook, and spent the day masquerading as me while I frantically tried to recover everything. He went as far as pulling up emails between myself and my ex-girlfriend and tried to use them against me. They downloaded all of the email I had sent in the past three years and tried to blackmail me using every random thing they found. And to top it all off after I got everything back they tried to ask me for a job."
I am all for having flaws pointed out so that they can be fixed, this was not the way to do it. At the time I chose not to pursue any legal action because Hibia lives in another country and Tranquility (though now a black hat) was someone I once respected. Plus I was a lot younger and didn't really understand the options I had.
The funny thing is I had already gone and fixed everything in the post linked above (you can now view controversial and popular manga from the past month) If they had just sent me an email with their complains a much more mature dialogue could have started, and progress would have been made.
The event three years ago happened when I recruited Tranquility (a FAKKU moderator at the time) to help me with some code on Sanshee before it went live. Specifically he was working on PayPal integration. When I took him on I changed the password on the database to "fakku123" because I didn't want him to see the password I had been using up until then. Unfortunately that particular server was using CPanel, so when I changed the database password it automatically changed the SSH password as well. Shortly after Sanshee went live, Tranquility shared that password with Hibia (the disgruntled ex admin I mentioned), and he immediately went into the database and reversed the encryption on my Sanshee account (which was the same password used on my main FAKKU account and my email) and stole a bunch of data off the server. That's where any notion that what they did was somehow not malicious, they broke the law and stole data.
The users that had created accounts on Sanshee at the time (three years ago) had sensitive information exposed. The hackers chose to focus entirely on me. To quote my post in the other topic... " they broke into all of my email accounts, my Skype account, my Facebook, and spent the day masquerading as me while I frantically tried to recover everything. He went as far as pulling up emails between myself and my ex-girlfriend and tried to use them against me. They downloaded all of the email I had sent in the past three years and tried to blackmail me using every random thing they found. And to top it all off after I got everything back they tried to ask me for a job."
I am all for having flaws pointed out so that they can be fixed, this was not the way to do it. At the time I chose not to pursue any legal action because Hibia lives in another country and Tranquility (though now a black hat) was someone I once respected. Plus I was a lot younger and didn't really understand the options I had.
The funny thing is I had already gone and fixed everything in the post linked above (you can now view controversial and popular manga from the past month) If they had just sent me an email with their complains a much more mature dialogue could have started, and progress would have been made.
Red Vodka wrote...
Jacob wrote...
Red Vodka wrote...
Jacob wrote...
Red Vodka wrote...
Also, what do you mean by "The administrator's account was broken into because they were using the same password for FAKKU that they were using elsewhere."As in, you use your personal e-mail's password for Fakku or something? Wasn't that exactly how the shit hit the fan that one time you let developer/programmer get access to your site?
It wasn't my account that was broken into, but yeah it's the same idea.
Eh, I hope you and whoever is in charge of this website learn your lesson this time, and don't repeat the same mistake then.
I don't really want to rub salt into your wounds, but this isn't a hobby anymore like it was when you first started the site as a teenager. I'm clueless when it comes to computers and shit, but what if this guy accessed our information (our passwords) instead of just vandalizing a few manga tags and making a rant on the front page? What if he was really malicious and did something worse?
You have our personal information now, and you have a responsibility to make sure it's safe.
You're absolutely right, and even moreso with the store launching.
Oh yeah, forgot about that...
BTW, didn't get a reply to the e-mail I sent you, but what exactly is the source of your goods? Did you literally go to Japan yourself and buy as much stuff as possible? Are you ordering them online?
Little bit of column A, little but of column B (plus some pretty cool stuff on the side). I'll reply to that email as soon as I get the chance, there were a bunch of different things I wanted to cover so it's taking some time.
Also your old avatar inspired me to check out Breaking Bad, great show.
Red Vodka wrote...
Jacob wrote...
Red Vodka wrote...
Also, what do you mean by "The administrator's account was broken into because they were using the same password for FAKKU that they were using elsewhere."As in, you use your personal e-mail's password for Fakku or something? Wasn't that exactly how the shit hit the fan that one time you let developer/programmer get access to your site?
It wasn't my account that was broken into, but yeah it's the same idea.
Eh, I hope you and whoever is in charge of this website learn your lesson this time, and don't repeat the same mistake then.
I don't really want to rub salt into your wounds, but this isn't a hobby anymore like it was when you first started the site as a teenager. I'm clueless when it comes to computers and shit, but what if this guy accessed our information (our passwords) instead of just vandalizing a few manga tags and making a rant on the front page? What if he was really malicious and did something worse?
You have our personal information now, and you have a responsibility to make sure it's safe.
You're absolutely right, and even moreso with the store launching. This change will ensure that even if someone breaks into the site, they are unable to access user accounts. It's a good change that was recommended by Hibia/Tranquility a long time ago that I should have implemented sooner.
Red Vodka wrote...
Also, what do you mean by "The administrator's account was broken into because they were using the same password for FAKKU that they were using elsewhere."As in, you use your personal e-mail's password for Fakku or something? Wasn't that exactly how the shit hit the fan that one time you let developer/programmer get access to your site?
It wasn't my account that was broken into, but yeah it's the same idea.
Earlier tonight one of our administrators accounts was broken into and used maliciously. Around 500 manga were re-tagged and had most of their information vandalized. But outside of the one administrator account and the manga corruption, no private information was lost. A post was made on the front page by the perpetrators outlining their reasons for doing so, which revolved entirely around me. They made some good points. I could be a better administrator and I still have a lot to learn, but I have and will continue to do my best to keep FAKKU online and mostly stable.
The administrator's account was broken into because they were using the same password for FAKKU that they were using elsewhere. When a website stores your password it encrypts it inside of the database, most often using md5 encryption. The problem with md5 is that it's widely used and once the encrypted form of the password is known you can easily look up the reverse and figure out common passwords. This is why websites prompt you to choose passwords with numbers, special characters, and uppercase letters.
Up until now FAKKU was using md5 encryption (which was left over from phpbb, the CMS FAKKU was originally built on). But from now on we will be using a form of salting along with bcrypt to secure all user accounts so that their passwords (if they are ever compromised) cannot be figured out using a reverse md5 lookup. All you have to do is login to your account and change your password, and you should take this opportunity to make sure it's something secure (fakku123 is not a good a password to use).
The administrator's account was broken into because they were using the same password for FAKKU that they were using elsewhere. When a website stores your password it encrypts it inside of the database, most often using md5 encryption. The problem with md5 is that it's widely used and once the encrypted form of the password is known you can easily look up the reverse and figure out common passwords. This is why websites prompt you to choose passwords with numbers, special characters, and uppercase letters.
Up until now FAKKU was using md5 encryption (which was left over from phpbb, the CMS FAKKU was originally built on). But from now on we will be using a form of salting along with bcrypt to secure all user accounts so that their passwords (if they are ever compromised) cannot be figured out using a reverse md5 lookup. All you have to do is login to your account and change your password, and you should take this opportunity to make sure it's something secure (fakku123 is not a good a password to use).
Alright there is no war or anything, I'm gonna lock this topic. The users who were mass downvoting have been dealt with, and I am free to use my own account to upvote any comments I like (including ones that had been downvoted).
I took a look at this and there was some mass downvoting going on. I will be rolling back the downvotes on the affected comments and upvoting them.
I will do my best to update this topic with the new features I am currently working on or plan to work on.
General
Forums
Profiles
Update
General
- Read Later for Manga
- Better support for manga volumes
- Improved translator/group pages
Forums
- Page jump drop-down within topic/forum
Profiles
- Email options for notifications
Update
- About Page
- Contact Page
Sorry but the last time I gave a person access to code in order to alleviate my load it went poorly. I trusted that person because I believed in their principles and what they spoke for (and I even considered them a friend).
But my trust was misplaced.
Once given access he shared it with a disgruntled ex administrator who went and broke into all of my email accounts, my Skype account, my Facebook, and spent the day masquerading as me while I frantically tried to recover everything. He went as far as pulling up emails between myself and my ex-girlfriend and tried to use them against me. They downloaded all of the email I had sent in the past three years and tried to blackmail me using every random thing they found. And to top it all off after I got everything back they tried to ask me for a job!
That said, the fault was my own. I used a similar password in the code to access the database as the one I used for my email account. And once you have access to someones email account you can basically get anything, and that's exactly what they did.
Since then I have trust issues, especially with random people who makes posts on the forums calling me out for my inadequacies. But I will go through and fix the bugs pointed out in this topic.
I now value the people I talk to every day that much more, and there are plenty of them. Hopefully they all understand that I am horrible at time management and often reach for the stars when I should be a bit more grounded in reality. I hope one day my life becomes tranquil and I have more time to work on FAKKU, but after spending all of the ad money on hookers and blow I really don't see the appeal.
But my trust was misplaced.
Once given access he shared it with a disgruntled ex administrator who went and broke into all of my email accounts, my Skype account, my Facebook, and spent the day masquerading as me while I frantically tried to recover everything. He went as far as pulling up emails between myself and my ex-girlfriend and tried to use them against me. They downloaded all of the email I had sent in the past three years and tried to blackmail me using every random thing they found. And to top it all off after I got everything back they tried to ask me for a job!
That said, the fault was my own. I used a similar password in the code to access the database as the one I used for my email account. And once you have access to someones email account you can basically get anything, and that's exactly what they did.
Since then I have trust issues, especially with random people who makes posts on the forums calling me out for my inadequacies. But I will go through and fix the bugs pointed out in this topic.
I now value the people I talk to every day that much more, and there are plenty of them. Hopefully they all understand that I am horrible at time management and often reach for the stars when I should be a bit more grounded in reality. I hope one day my life becomes tranquil and I have more time to work on FAKKU, but after spending all of the ad money on hookers and blow I really don't see the appeal.
