PerpHeads HACKED???!

Status
Not open for further replies.
Messages
712
Reaction score
3,409
Points
500
Updated 27/9

As many of you already know, several accounts were taken over and used maliciously on the 24th of September. We have a very clear idea as to who is responsible for this attack. I will not be giving out any names however.

One main thing to note is that our database was in no way compromised so all information you have both in game and here on the forums is completely safe. This attack was simply gaining access to a staff members account and then using it to edit others in order to gain control, modify information, or delete theirs or others accounts.

Here is the most complete overview that I can put together.

Starting around 9:10AM CEST the individual first gained access to a former Administrator who will remain nameless. However all permissions from this account had already been revoked so nothing of value was gained.

From there the individual gained access to @Xquality's account and added an offensive rating, renamed some users, banned certain IPs, gave administrative permission to 4 users, deleted accounts (including myself), etc.

To note: @Jordan was a former senior admin for those of you unfamiliar with him or his previous role so we decided upon his resignation that he will maintain all his abilities but hold no formal title. Which fortunately allowed him to help hinder some of the individual's "attack" despite their best efforts. So I would ask that everyone thank @Jordan for his efforts to help us during this, I officially thank him as well on behalf of us here at PH.

One individual that was granted administrative permissions was actively seen looking through sensitive areas of the forums, including but not limited to: Staff Complaints, Admin/Mod discussions, and PLPD related matters. Because of this, that member has received a community wide ban.

One other individual looked through some other typically restricted areas of the forums, but did not act on it and instead contacted staff about it as soon as they could regarding the matter. So to them, thank you for doing the right thing, despite looking at a couple things you should not have access to. However unlike the other user, what was accessed contained no information regarding any other user.

The other two users, we are less than concerned about as they didn't do nearly as much regarding their ill gotten power.

Around 11:30AM CEST @Fredy arrived on TS and was promptly informed of the situation and the forums were rolled back approximately 11 hours so some posts may have been lost. There were some lingering breaches that were quickly taken care of. Afterward an imgur album was created with some screenshots of the staff section and other images that should not be for the public.

Conclusion: I still would suggest everyone change their password to a password that you do not use anywhere else and make it secure. Your password would not have been stolen by this individual but if you used your password somewhere else it may have been leaked in some other places so they could potentially gain access using it. (You can check that on sites like haveibeenpwned.com) Overall it is just a minor inconvenience, while unprecedented that they would go to this much effort, it hardly effects much for us since we are good about keeping backups. We do not condone anyone that attacks our server in any form or misuses any ability they should never have unless explicitly granted by senior staff members directly.

Update:
Just to give everyone a quick update. As it turns out, it was not @Xquality 's account that initially was breached but rather @MoronPipllyd's. The initial attack occurred at Saturday around 6:15AM CEST. It actually started gathering information about well known users in the community. Some of this information includes your email address as well as your IP address. At no point they were able to access any information about your passwords (not even the hashed ones) or the raw database entries. As already mentioned I strongly recommend changing your passwords if you can find it on https://www.haveibeenpwned.com but may be worth doing regardless.

If you are always reusing your password and it gets leaked it only takes one search for your email to find information like this:
2c796bd70b.png

This is why I strongly recommend using a password manager such as KeePass, LastPass or Enpass so you can easily use an entirely different and strong password for each website. If one of your passwords does get leaked then it won't compromise your security on any other website since you only used it for that one website.
 
Last edited:
Messages
1,339
Reaction score
1,295
Points
340
Location
England, Norfolk
Thanks for the heads up I have not noticed anything out of the ordinary but I use variations so I need to consider if any of them were compromised. To tighten up security why not consider the use of authenticators even using SMS authentication can make a big difference.

Stay secure, stay safe
 
Messages
2,549
Reaction score
5,476
Points
895
Location
Germany
I was a little spooked to see that I couldn't log onto sourcebans.

Then I figured @Fredy must have reset everyones account as a precaution.

Thank you to @Jordan for always helping the community out whenever possible. And for getting his club penguin password leaked. Who knew that the hacker wanted to play so bad.

I would also like to thank the owners for not being retards and having backups of everything.

Also a big thanks to @John Daymon for helping me with security.

A big thanks to @Spadille who in the past told me that my old password was compromised and poked me on teamspeak to prove it. This forced me around 6 month back to change all of my passwords to a good one.

As a precaution I have took Daymons advice and changed my passwords again to be on the safe side. As well as changing my email on steam etc.

Hacker 0
Perpheads anti hack team 1
 
Messages
352
Reaction score
416
Points
505
Lads just going to come out and say.
I was one of the users given administrative powers. I had no affiliation with the person who provided me with the powers and to be quite frank I was freaking out. I would like to say. USE TWO FACTOR AUTHENTICATION ITS SO SIMPLE.
 

amr

Messages
259
Reaction score
284
Points
470
Location
Middle East
It was quite obvious it's a hack when a hacker breached your account saying really random stuff then calling me a nig*er, then all started getting worse.

I am still really ashamed of the people that got staff instead of acting mature and wise they abused and took advantage asking for it and did not try to control the situation within but making it worse.

Nevertheless, that is behind now and is fine by me. Thanks to @Jordan actually being the only person on early to control and try to repell this and then @Creepis later on and many more. I think all the people that helped stop this must be thanked for what they did.

LxX6nN2.jpg

Thanks to all the people in this picture for their help!
@StephenPuffs @Xquality @Fredy @Bolli @Creepis @Archibald @Chris @John Daymon @LEWIS 088
 
Messages
3,607
Reaction score
2,930
Points
1,325
Absolute nutters, they leaked staff complaints on me. Also thanks @Fredy and @John Daymon for actually telling me my password was like completely public. I also strongly advise to everybody that you change your passwords after I had realised how easily they got hold of them, check if it has been leaked through haveibeenpwned.com as said in the post.
It was quite obvious it's a hack when a hacker breached your account saying really random stuff then calling me a nig*er, then all started getting worse.

I am still really ashamed of the people that got staff instead of acting mature and wise they abused and took advantage asking for it and did not try to control the situation within but making it worse.

Nevertheless, that is behind now and is fine by me. Thanks to @Jordan actually being the only person on early to control and try to repell this and then @Creepis later on and many more. I think all the people that helped stop this must be thanked for what they did.

LxX6nN2.jpg

Thanks to all the people in this picture for their help!
@StephenPuffs @Xquality @Fredy @Bolli @Creepis @Archibald @Chris @John Daymon @LEWIS 088
Don't forget the vigilante staff team @Eviction Notice, @Hazza56, @Sam, @Allen Kennedy
 
Messages
2,413
Reaction score
4,960
Points
815
Location
Nigeria
One other individual looked through some other typically restricted areas of the forums, but did not act on it and instead contacted staff about it as soon as they could regarding the matter. So to them, thank you for doing the right thing, despite looking at a couple things you should not have access to. However unlike the other user, what was accessed contained no information regarding any other user.

Thanks for thanking me Xd

I meant to go on AR thread btw. Was not trying to access complaints u know
c6bab14da33a14b69d7dfd5792dc7cb2.png



And my favorite one,
accc8bd0b563e2ef79ddef035dfbb11a.png
 
Messages
22
Reaction score
25
Points
190
Location
Birmingham, United Kingdom
Very professional response @StephenPuffs thank god you and Mr @Fredy keep regular database backups! Pheeeew!!! Also I highly recommend that Fredy buys who.is protection for the website because I have seen cases with Linus Tech Tips where hackers maliciously called up the phone provider and had all the calls and SMS redirected. Just saying this incase someone tries anything funny and somehow gains access to Fredy's emails or OVH ccount etc.
 
Messages
2,682
Reaction score
7,411
Points
935
portrait-old-man-showing-thumb-up-7139105.jpg


Glad to help! It was great to see this handled very professionally, big thank you to the Senior Administration inc. @StephenPuffs and @Fredy. This certainly is a great lesson to many members of the community, hopefully this will prevent individuals being in situations like this again.

 
Status
Not open for further replies.
Top