CPPS.me development blog

Text

Well, damn.

* Yes, this is a tumblr. :p *

If you want the low-down, here’s the TL;DR:
A test database was found, two passwords (Stanley + d0pe’s) hash’s were cracked, people fucked with it for about 5 minutes.

Full story is below.

Hax?no.

A few of CPPS.me’s machines were *supposedly* today (8th June 2012) at around 6:15PM GMT. That’s when I was informed of a breach. (If you want me to be brief, they were not. - Nothing got hacked).

I was given screenshots of my account on the CPPS.me user manager. A few seconds earlier I had been told that my “Skype” account had a password which was insecure, and the same with my CPPS.me. I changed my Skype account password and changed my CPPS.me account’s password to NULL. I expected this to be the end of the matter, it was not.

Several people went on to IM me about chatlogs with the adversary and them. I took note of what was being claimed and verified if the claims were true. The majority of them were not. Despite this, I was already in the process of shutting down all of the servers (I shut down the MySQL server first, then returned to shutdown all of the servers we control to prevent spread).

During this time, I changed all of my account passwords to ensure nothing else could happen, as a precaution. I was told a number of rumours:

  • SQLi was used in the panel for moderators
  • CPPS.me’s machines have been ‘rooted’ (gained Administrator access)
  • Current live database had been compromised

All of these were false.

It turns out that.. a lot of what was said by these adversaries was exaggeration.

A test database given to someone outside of CPPS.me (incomplete, pretty small actually, not much user data was in this) was found by another person outside of CPPS.me with a pure accident. Only Stanley + d0pe’s passwords were cracked. Nobody else’s. We’ll be enforcing security measures despite this though. We’re paranoid people. In this case, a ‘test’ database compromised of a very small portion of the actual database, enough data to be able to code without compromising security.

None of our servers were actually compromised. It turns out one of the attackers just.. really really liked to exaggerate. Didn’t stop me shutting down everything just in case, but y’know (unlike some people, we did actually react as one should in a situation like this. We killed everything to ensure *nothing* could be done to damage any further, as we were not aware of the extent at the time. — Yes, we still have all the data, yes we have backups too.)

CPPS.me will remain offline while we take precautions, however. The game will not return until we are *really* satisfied with the security, but in conclusion:

we were not hacked.

-The CPPS.me team

Posted on Friday, June 8 2012.
17
Notes
  1. holasoyunerizo reblogged this from cppsme
  2. ellirocks123 likes this
  3. penguin9869 likes this
  4. caio93 likes this
  5. themsbkg reblogged this from cppsme and added:
    You said it should be up by now but i still havent got service is it just me?
  6. rarata11 likes this
  7. christophersteven007 reblogged this from cppsme
  8. cocorex87 likes this
  9. andresito436 likes this
  10. sasuke291113 likes this
  11. mario5433 reblogged this from cppsme
  12. ivonicos reblogged this from cppsme
  13. pufflehanded likes this
  14. valeswagg08 likes this
  15. valeswagg08 reblogged this from cppsme
  16. dhaniela3 likes this
  17. alexito212 reblogged this from cppsme
  18. gmch3 likes this
  19. danny10477 reblogged this from cppsme and added:
    cppsme If you want the low-down, here’s the TL;DR: A test database was found, two passwords (Stanley + d0pe’s) hash’s...
  20. adrian3502 likes this
  21. miguel308 likes this
  22. fausther likes this
  23. bartocuatro likes this
  24. alexzhiito12 reblogged this from cppsme
  25. eliana012345 likes this
  26. zarol likes this
  27. adelina457 reblogged this from cppsme
  28. pingno4 likes this
  29. nikolasneculqueo reblogged this from cppsme
  30. pingualex10 likes this
  31. reanischweitzer reblogged this from cppsme
  32. ninjago8003 reblogged this from cppsme
  33. putumuju likes this
  34. snake694 likes this
  35. snake694 reblogged this from cppsme
  36. duke2994 reblogged this from cppsme
  37. rompni likes this
  38. andres1238 likes this
  39. adrian3502 reblogged this from cppsme
  40. andres1238 reblogged this from cppsme
  41. idontwannayourl0ve likes this
  42. smartjoshua reblogged this from cppsme
  43. alfrdo reblogged this from cppsme
  44. vickyhause reblogged this from cppsme
  45. ifoundyourlittlethings likes this
  46. marieny2 likes this
  47. mafercitha likes this
  48. kai1908 reblogged this from cppsme
  49. goergekrowns likes this
  50. goergekrowns reblogged this from cppsme
  51. Show more notesLoading...
Ask us about CPPS.me!
Previous Next