7 Pages V < 1 2 3 4 > »   
Closed TopicStart new topic
> Login security changes, You shall not pass

 
post Feb 22 2015, 03:54
Post #21
xmagus



Big, Bad and Horny
*******
Group: Members
Posts: 1,042
Joined: 16-July 12
Level 424 (Godslayer)


QUOTE(Tresik @ Feb 22 2015, 10:39) *

Well, as always, keeping same passwords in multiple services or otherwise easy to guess password is very bad idea. Because people tend to do that it is also good idea to sometimes remind them about that.

Hence, the wonderful existence of services like LastPass and its brethren. Nothing quite like a 20-character ahphanumeric+special characters password to keep the paranoia at bay.

Although, I'm hearing interesting things about Steve Gibson's SQRL project, so probably should watch that as well...


--------------------
Come visit my shop! (Massive update 16 May 2013) Might be something that interests you there. Lowest prices guaranteed by way of matching. Low-level players are sure to get something good!

Loving my Magnificent Fiery Mace of the Battlecaster.

This Exquisite Ethereal Estoc of Slaughter is courtesy of ChosenUno. All Hail Uno, creator of the Riddle Limiter!
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 06:18
Post #22
indarain



DO IT FAGGOT!
*******
Group: Gold Star Club
Posts: 1,079
Joined: 3-January 13
Level 301 (Godslayer)


QUOTE(Tenboro @ Feb 21 2015, 19:52) *

Due to a large increase to the number of brute-force login attempts against member accounts, there have been some hardening changes made to the login mechanism to thwart this. For most of you this will never come into play, but if you fail multiple login attempts or connect from what the site considers a suspect IP, you will now also have to solve a captcha for every login attempt. Hosts that fail a large number of attempts may be shut out entirely.

Note that if you are using a weak password, one that closely resembles your login username, or one that you've reused on other sites, you may want to change it just to be safe.


uhhh wait, maybe some noob questions:

1. What is brute-force login?

QUOTE
For most of you this will never come into play, but if you fail multiple login attempts or connect from what the site considers a suspect IP, you will now also have to solve a captcha for every login attempt.


2. How long this will be, I mean the captcha? And is it depends on the IP address?

QUOTE
Hosts that fail a large number of attempts may be shut out entirely.


3. What does it means? If someone failed several times to login, s/he may get banned?


--------------------
Teach me how to be a pro PFUDOR player


Karma for bunnies

Strength, Dexterity, Endurance, Agility, Intelligence, Wisdom... I prefer LUCK


User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 08:50
Post #23
xmagus



Big, Bad and Horny
*******
Group: Members
Posts: 1,042
Joined: 16-July 12
Level 424 (Godslayer)


QUOTE(indarain @ Feb 22 2015, 14:18) *

uhhh wait, maybe some noob questions:

1. What is brute-force login?

There are various ways to crack passwords. You can use what's known as a dictionary attack (which uses a list of common passwords), or you can just start guessing from 'a' and make your way through to 'zzzzzzzzzz' and beyond. As you can see, the second method employs no subtlety; hence the term brute-force (think of it as taking a hammer to the lock to bash it open - or a gun to shoot it open - instead of using lockpicks).

QUOTE

2. How long this will be, I mean the captcha? And is it depends on the IP address?

I think this one is best fielded by TenB. But I suspect the IP thing will only proc if you normally log in from Melbourne, VIC and suddenly one day you're trying to log in from Lagos. Or Nanking. Which could be slightly problematic for anyone who normally uses a VPN and forgets one day.

QUOTE

3. What does it means? If someone failed several times to login, s/he may get banned?

I suspect the IP (range) will be blocked for a period of time.


--------------------
Come visit my shop! (Massive update 16 May 2013) Might be something that interests you there. Lowest prices guaranteed by way of matching. Low-level players are sure to get something good!

Loving my Magnificent Fiery Mace of the Battlecaster.

This Exquisite Ethereal Estoc of Slaughter is courtesy of ChosenUno. All Hail Uno, creator of the Riddle Limiter!
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 10:43
Post #24
wantek



Lurker
Group: Lurkers
Posts: 1
Joined: 2-June 09
Level 0 (Newbie)


i just changed my password today, better safe than sorry
then again, i cant access h**p://ehentaihip.com/ for some reason
this words show up:
Your IP address has been temporarily banned for excessive pageloads ... and bla bla bla
wonder if mine has already compromised o.O
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 11:58
Post #25
S BENZ



Casual Poster
***
Group: Members
Posts: 163
Joined: 15-August 10
Level 220 (Destined)


I just hope my IP holds up as the modem-system that it runs on is a floating one that was designed to be a counter to this sort of 'brute-force' entry-thing in the first place. Other than that, thanks for the heads up.
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 12:11
Post #26
Arith Undine



ElvenCon
******
Group: Catgirl Camarilla
Posts: 803
Joined: 24-August 11
Level 485 (Dovahkiin)


With thanks to the reinforcement.
What about moving the forum site to HTTPS?



QUOTE(wantek @ Feb 22 2015, 09:43) *

i just changed my password today, better safe than sorry
then again, i cant access h**p://ehentaihip.com/ for some reason
this words show up:
Your IP address has been temporarily banned for excessive pageloads ... and bla bla bla
wonder if mine has already compromised o.O


Your password not, but your IP is somewhat "compromised".

This post has been edited by penuser0: Feb 22 2015, 12:12


--------------------

Status: Vampire Survivors     Total Karma+: 595111     Karma gauge: 3.9x     Last seen on 2022-04-30
Karma Exhaustion: none               Last imbuement to the one at 2022-04-03 17:37
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 12:44
Post #27
el h



It's all about the Pentiums, baby!
*******
Group: Members
Posts: 1,326
Joined: 10-November 09
Level 390 (Ascended)


QUOTE(penuser0 @ Feb 22 2015, 11:11) *

What about moving the forum site to HTTPS?

Already works: /
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 14:25
Post #28
Tenboro

Admin




QUOTE(blue penguin @ Feb 21 2015, 23:55) *
Given that the authentication takes some time the brute force attacks must have been very directed, i.e. they must have known the password (or a likehood of the password) from another source. I cannot find a hash of my password in my cookies so there must be some salt on EH side. I do not believe that whoever got the passwords got some hash to compare against.


My theory, supported by certain access and brute forcing patterns as well as honeypot triggers, is that people were compromised by signing up at a certain para-site that starts with an N. Though there could be other sources as well, and the background login attempt fail noise is still around a hundred per minute even after adding the hardening.

QUOTE(blue penguin @ Feb 21 2015, 23:55) *
BTW Tenb, when you change your password do all your sessions are invalidated? The session time on EH is quite long (i never managed to expire it myself, i always cleaned cookies) therefore someone that managed to get hold of an account may open a session and use it for a long time.


Should be when you visit them, but the systems aren't fully integrated so it doesn't happen automatically.

QUOTE(indarain @ Feb 22 2015, 05:18) *
2. How long this will be, I mean the captcha? And is it depends on the IP address?


If it does trigger it, until the system is reasonably convinced that the IP isn't used for brute forcing attempts. Which depends on a number of factors.
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 15:52
Post #29
pencil1



Lurker
Group: Recruits
Posts: 6
Joined: 2-August 11
Level 130 (Ascended)


QUOTE(Tenboro @ Feb 22 2015, 07:25) *

My theory, supported by certain access and brute forcing patterns as well as honeypot triggers, is that people were compromised by signing up at a certain para-site that starts with an N. Though there could be other sources as well, and the background login attempt fail noise is still around a hundred per minute even after adding the hardening.
Should be when you visit them, but the systems aren't fully integrated so it doesn't happen automatically.
If it does trigger it, until the system is reasonably convinced that the IP isn't used for brute forcing attempts. Which depends on a number of factors.


Uh, hi. So I haven't really followed what has been going on because I am not very active on the forums here; however, I do a lot of file hosting for H@H because I don't have to worry about monitoring it and stuff. Yesterday I realized I couldn't access g.e-hentai because it states that my account does not exist on that site. However, I can clearly log in here and the main site. Is this an issue unique to my account or are other people having this issue as well?
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 16:03
Post #30
Tenboro

Admin




QUOTE(pencil1 @ Feb 22 2015, 14:52) *
Uh, hi. So I haven't really followed what has been going on because I am not very active on the forums here; however, I do a lot of file hosting for H@H because I don't have to worry about monitoring it and stuff. Yesterday I realized I couldn't access g.e-hentai because it states that my account does not exist on that site. However, I can clearly log in here and the main site. Is this an issue unique to my account or are other people having this issue as well?


Well, it clearly exists and still works, try clearing all the cookies and see if that fixes it.
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 16:12
Post #31
pencil1



Lurker
Group: Recruits
Posts: 6
Joined: 2-August 11
Level 130 (Ascended)


QUOTE(Tenboro @ Feb 22 2015, 09:03) *

Well, it clearly exists and still works, try clearing all the cookies and see if that fixes it.

I have tried this twice already sad.gif
I can try again I suppose.

Just cleared and still no luck. ;~; Gotta head to work i'll check back after~~

This post has been edited by pencil1: Feb 22 2015, 16:16
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 18:05
Post #32
PAMRZ



Newcomer
**
Group: Members
Posts: 82
Joined: 7-September 13
Level 246 (Godslayer)


QUOTE(Maximum_Joe @ Feb 22 2015, 02:36) *

China; they're coming for our hentai money!


The Chinese! I knew it was them. Even when it was the Nips, I knew it was them!


This whole thing is hillarious by the way.
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 18:53
Post #33
moonflow



Active Poster
*******
Group: Gold Star Club
Posts: 1,464
Joined: 17-September 06
Level 500 (Dovahkiin)


I'm surprised. I'm a little bit confused. I wonder if it is possible to steal the Bitcoins from the E-Hentai accounts. I mean, everything else is just of virtual worth.
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 19:03
Post #34
LostLogia4



Translating Miku's Yuri Nikki for the heck of it~~
********
Group: Gold Star Club
Posts: 2,716
Joined: 4-June 11
Level 361 (Godslayer)


QUOTE(moonflow @ Feb 23 2015, 00:53) *
I'm surprised. I'm a little bit confused. I wonder if it is possible to steal the Bitcoins from the E-Hentai accounts. I mean, everything else is just of virtual worth.
Not possible from member's account. Bitcoins in the e-hentai wallet can't be used for anything else apart from donations afaict.

This post has been edited by LostLogia4: Feb 22 2015, 19:04


--------------------
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 19:14
Post #35
Tenboro

Admin




QUOTE(moonflow @ Feb 22 2015, 17:53) *
I'm surprised. I'm a little bit confused. I wonder if it is possible to steal the Bitcoins from the E-Hentai accounts. I mean, everything else is just of virtual worth.


There is no way to do that. Even if you hacked the server, it's a watch-only wallet so it doesn't have the private keys needed to do so.
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 20:31
Post #36
blue penguin



in umbra, igitur, pugnabimus
***********
Group: Global Mods
Posts: 10,027
Joined: 24-March 12
Level 500 (Godslayer)


I know this is old news, but I just logged in through the main page (e-henta.org) and monitored it. It is pretty cool, it forces my browser to redirect the request with the same login fields to / .

I could figure out most of what is happening in the conversation between forum.e-hentai.org , e-hentai.org and rapidssl-ocsp.geotrust.com , yet am struggling to figure out the reason to talk (in SSL) with 179.60.192.3 . I guess that's the tweeter feed as it points to facebook ( edge-star-shv-01-cdg2.facebook.com ) but am not sure. Does the tweeter feed use SSL?

(sorry i never used the tweeter API)


--------------------
QUOTE(blue penguin @ Jun 21 2021, 17:24)
For 10 years of my life I have refused to add if-else blocks in order to support internet explorer idiocy, am not going to start doing it now in order to support google chrome's idiocy. Sorry folks. As harsh as the advice sounds my advice will be: use a browser that follows IETF standards.
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 20:31
Post #37
moonflow



Active Poster
*******
Group: Gold Star Club
Posts: 1,464
Joined: 17-September 06
Level 500 (Dovahkiin)


QUOTE(LostLogia4 @ Feb 22 2015, 18:03) *

Not possible from member's account. Bitcoins in the e-hentai wallet can't be used for anything else apart from donations afaict.


QUOTE(Tenboro @ Feb 22 2015, 18:14) *

There is no way to do that. Even if you hacked the server, it's a watch-only wallet so it doesn't have the private keys needed to do so.


Thank you for your answers to lessen my confusion.
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 21:07
Post #38
Tenboro

Admin




QUOTE(blue penguin @ Feb 22 2015, 19:31) *
I could figure out most of what is happening in the conversation between forum.e-hentai.org , e-hentai.org and rapidssl-ocsp.geotrust.com , yet am struggling to figure out the reason to talk (in SSL) with 179.60.192.3 . I guess that's the tweeter feed as it points to facebook ( edge-star-shv-01-cdg2.facebook.com ) but am not sure. Does the tweeter feed use SSL?


rapidssl-ocsp.geotrust.com is your browser checking if the certificate is revoked. But there is nothing on the site that would make you talk to Facebook, and the Twitter feed communication is all done on the backend. I'm guessing that's some kind of browser function or plugin. Could be the new Firefox share/social function, which I couldn't turn off fast enough.
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 22:25
Post #39
EsotericSatire



Look, Fat.
**********
Group: Catgirl Camarilla
Posts: 9,643
Joined: 31-July 10
Level 500 (Ponyslayer)


QUOTE(moonflow @ Feb 22 2015, 06:53) *

I mean, everything else is just of virtual worth.


1 hath is worth 3c or 0.20 yuan. A cheap meal in China costs 100 hath.


--------------------
Only My Electro Mage
Staff: Staff (0.82) Staff (0.83)
Main Mjolnir Gear: Cap Robe Gloves Pants Shoes
Forgotten Fenrir: Staff Cap Robe Gloves Pants Shoes

Send +Karma to make King Marien (lvl 2250) stronger:
Battles Won: 15869



Project Preempt and Defuse: Releasing genetically engineered viruses to prevent future SARS pandemics (Ecohealth 2018 Famous last words)
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post

 
post Feb 22 2015, 22:31
Post #40
pencil1



Lurker
Group: Recruits
Posts: 6
Joined: 2-August 11
Level 130 (Ascended)


Just a quick update to my earlier post. I tried logging back in after work and it seems to work now.
User is offlineProfile CardPM
Report PostGo to the top of the page
+Quote Post


7 Pages V < 1 2 3 4 > » 
Closed TopicStart new topic
1 User(s) are reading this topic (0 Guests and 0 Anonymous Users)
1 Members: Test8899

 


Lo-Fi Version Time is now: 15th October 2022 - 08:45