Hot Summer Deals are Here!
Celebrate with up to 99% off on 18,000 resources
00
Days
01
Hours
57
Mins
14
Secs

Thoughts on competing forums database being breached

Status
This thread has been locked.

Sag

No, I don't want your fortnite account.
Restricted
Feedback score
17
Posts
294
Reactions
231
Resources
0
Glove I was going to make this post, I’m getting my self banned from that shit site, imagine using MD5 in 2019 ace your legit retarded
LOL NO WAY THEY WERE USING THAT
 

OG

Premium
Feedback score
31
Posts
1,274
Reactions
1,327
Resources
0
for a popular forum they're not really secure, rip anyone who wasn't using a gen'd password
 

User

i left click on lego people
Supreme
Feedback score
107
Posts
3,721
Reactions
2,538
Resources
0
ouch man, i was gonna make an account there in like a week from now but i'm glad i didn't lol
 

Sloth

Feed Me
Supreme
Feedback score
6
Posts
4,370
Reactions
2,660
Resources
0
That really sucks for people who made accounts on there.
 

jxhdvn

The Visionary
Supreme
Feedback score
30
Posts
2,480
Reactions
1,282
Resources
0
I have an account on there but I never did anything on the site but talk so ig im fine

Glove Werent you banned there at one point
 

Glove

Supreme
Feedback score
111
Posts
350
Reactions
2,697
Resources
0
I have an account on there but I never did anything on the site but talk so ig im fine

Glove Werent you banned there at one point
yurp staff member tried to extort me for 1k for unban but now me unban
 

Azmi

Im sorry if I have been toxic to you in the past
Premium
Feedback score
47
Posts
1,232
Reactions
433
Resources
0
WHelpp im still unable to join that site it says access denied[DOUBLEPOST=1558112087][/DOUBLEPOST]Rip me for using literally the same password :(
 
Last edited:

Doge

Long Dogs
Supreme
Feedback score
126
Posts
5,271
Reactions
8,930
Resources
0
I downloaded this within 2 hours of it becoming public and looked through it a lot and I showed a friend who did as well and here are all of the interesting parts I remember:

1. The important data the user table includes: Hash+Salt, Email, Date of Birth. I couldn't find any IPs in the main database file as was claimed.

2. In \Source Code\inc\functions_user.php you can see that the hashing algorithm they use is
Code:
md5(md5($salt).md5($password)
which is the default MyBB hashtype (salted md5).

3. There is a folder with a .png of every user's avatar, not surprisingly, the vast majority of them are rappers, drugs, hood stuff, anime and women

4. Private messages are included, but only seem to be from November-December and are in an odd formatting making them hard to parse.

I've also seen a lot of people getting too scared about this leak. Unless you reused this password elsewhere or used an email that contains personal info, you'll be fine. If the password is your main concern, change it everywhere and you'll be good.
 

SheepeyDarkness

shep
Supreme
Feedback score
24
Posts
883
Reactions
570
Resources
0
d680938b86713808de07cf9570a6680a.jpg
 

Doge

Long Dogs
Supreme
Feedback score
126
Posts
5,271
Reactions
8,930
Resources
0
Everyone look here: https://www.mc-market.org/account/manage-security

Check if you have people trying to log into your account LOL

I have a New York VPN IP that tried to log into my MCM and email:
http://i.doge.bz/ufGAnraqDp-234730364.png
http://i.doge.bz/LQ9B8raWp8-134051322.png

Imagine thinking that I reuse passwords facepalm

And go to the banlist: https://www.mc-market.org/members/banned

CTRL + F "Compromi" to see all compromised account bans. There are 34 bans since this leak was publicized. I can't believe this many people failed to use such basic security practices.
 
Last edited:

Glove

Supreme
Feedback score
111
Posts
350
Reactions
2,697
Resources
0
Everyone look here: https://www.mc-market.org/account/manage-security

Check if you have people trying to log into your account LOL

I have a New York VPN IP that tried to log into my MCM and email:
http://i.doge.bz/ufGAnraqDp-234730364.png
[Redacted]

Imagine thinking that I reuse passwords facepalm

And go to the banlist: https://www.mc-market.org/members/banned

CTRL + F "Compromi" to see all compromised account bans. There are 34 bans since this leak was publicized. I can't believe this many people failed to use such basic security practices.
sum1 tried logging into mine from santa clara LMFAO imagine that
 
Last edited by a moderator:

Doge

Long Dogs
Supreme
Feedback score
126
Posts
5,271
Reactions
8,930
Resources
0
sum1 tried logging into mine from santa clara LMFAO imagine that

lmfaooo, they thought Glove would reuse passwords!

also aliensushi you edited out my screenshot of someone trying to log into my email with a VPN, guess they need more privacy so they can log into everyone's mcm accounts Kappa
 

Sloth

Feed Me
Supreme
Feedback score
6
Posts
4,370
Reactions
2,660
Resources
0
Everyone look here: https://www.mc-market.org/account/manage-security

Check if you have people trying to log into your account LOL

I have a New York VPN IP that tried to log into my MCM and email:
http://i.doge.bz/ufGAnraqDp-234730364.png
http://i.doge.bz/LQ9B8raWp8-134051322.png

Imagine thinking that I reuse passwords facepalm

And go to the banlist: https://www.mc-market.org/members/banned

CTRL + F "Compromi" to see all compromised account bans. There are 34 bans since this leak was publicized. I can't believe this many people failed to use such basic security practices.
You underestimate the intelligence of children who set their passwords to be “Fortnite123” across all platforms.
 
Status
This thread has been locked.
Top