Today my sleep was interrupted by a Text Message from KaylaLovee at 9:05am say my account was being hacked. Soon to see it was true. Someone was hacking my account and banned multiple users. The person even answered my mail saying he was hacking my account.
Ok HTMLperson isnt the case anymore. Someone by the name Strike2 has hacked DSIPlace and have found my password which was the same as my Dsipaint Account. There is no evidence that HTMLperson is associated with Strike2. He some how got my password from whichever source.
We thought it was a security breach with yahoo using my email address located on my profile. But now we know the real issue. . To everyone I'm sorry this has happened, I would never do anything to harm the users or the site. For all who's accounts were banned or Perma'd by the hacker, Hull has restored most accounts. This is all the information I have on the situation. I will keep everyone updated. I have also recieved all my Admin Rights. I hope this incident won't change the way people act torwards me before.
Thanks for Reading.
Wow...I had no clue what was going on. I had some random mail as I was getting off saying 'Astra, JABINATOR is unfairly banning people in chat' I just replied saying 'If he's banning people, there is a reason.' lol, I was so failing at that incident..
At first, I thought it was really you playing a joke, then was going to unban us, but then when the hacker said in the reply to mial you had been hacked, I was shocked, then he perma'd me for asking.
But, We're all back, and everythings fixed. :D
Darmani - You can check if your password is strong or not by requesting a lost password then copying the jumble or letters and numbers after the "password" part of the link. Next, search for "SHA1 reverse lookup" on any search engine, and go to one of the matches. Finally, paste what you copied into the field to see if it can find a match. A good password will not have any matches.
To add to Jab's information, this all happened because the owner of DSiPlace gave out his email account password, which allowed indirect access to the database on the website. Unfortunately, no passwords were encrypted in the database. Any Web developers out there, if you do not encrypt passwords... why? One-way encryption is a must for security. SHA1 is the best that MySQL currently supports. Yet, even with one-way encryption, members need to be sure they have strong passwords because reverse-lookup tools do exist and can easily verify weak passwords.
I have added IP logging to the banlist to track down when admins' accounts have been compromised. Yet, that will only help on this end of the issue. The added security to this website should help alleviate any doubt should such a problem arise in the future.
I have removed DSiPlace from the affiliate links until this security hole on that website has been resolved.