Security Risk - Change your passwords

  • 🇵🇦 Nuestro primer dominio localizado está en español en kiwifarms.pa. Our first localized domain is on Spanish on kiwifarms.pa.
  • Want to keep track of this thread?
    Accounts can bookmark posts, watch threads for updates, and jump back to where you stopped reading.
    Create account
Yeah I tried changing my password but it's not letting me. I know what it is as it is simple but for some reason it's not letting me change it.
 
I used the same password elsewhere but its one of my throwaway passwords in the same way "Datiko" is just a random name I chose.

As a security professional I can say its unlikely they have the salt so there is very little risk. Still, its better to be safe than sorry.

@Null How did they DDOS you though? I thought the KiwiForums were behind cloudflare. Did you keep the same IP after you enrolled? I'm interested in knowing more so I can ask the local cloudflare guys.
 
It's also not letting me log in with my password on my phone. Null if you can can you PM me about it? I know you're busy and all but let me know either way.
 
Considering half of my job is helping people reset passwords, it's probably high time I update all of mine. Never hurts to do so.
 
I used the same password elsewhere but its one of my throwaway passwords in the same way "Datiko" is just a random name I chose.

As a security professional I can say its unlikely they have the salt so there is very little risk. Still, its better to be safe than sorry.
Yeah, that's what I think. The salt is in the config file and no damage to the system was done.

How did they DDOS you though? I thought the KiwiForums were behind cloudflare. Did you keep the same IP after you enrolled? I'm interested in knowing more so I can ask the local cloudflare guys.
Oh, I don't keep attack mode on all the time. Lower security levels of CF protected against early DDoS attacks but their later more effective ones required a different setup that's more intrusive to users, so I keep it off until they start.

From my tests the DDoS attacks last between 1 hour and 4 hours and they do it about once a month.

Also, the botnet is a real deal and from across the world so I feel this is a paid-for attack, as was whatever hit the DB.
 
I used a shitty throwaway password for this account, and this entire username and identity is completely synthetic and has never been brought up anywhere but here and on Lolcow/Mr Enter wikis.

Think I'm good.
 
Atrás
Top Abajo