×
  • remind me tomorrow
  • remind me next week
  • never remind me
Subscribe to the ANN Newsletter • Wake up every Sunday to a curated list of ANN's most interesting posts of the week. read more

Forum - View topic
Update: What's Going On with Anime News Network?


Goto page Previous    Next

Note: this is the discussion thread for this article

Anime News Network Forum Index -> Site-related -> Talkback
View previous topic :: View next topic  
Author Message
Emma Iveli



Joined: 19 Jun 2005
Posts: 679
Location: Hobo with internet
PostPosted: Tue Aug 08, 2017 12:47 pm Reply with quote
Man this is crazy. I even had to tell my mom who used to work for Viz Media. I mean come on, this is really, really crazy.
Back to top
View user's profile Send private message Send e-mail
Samet Chan



Joined: 08 Aug 2017
Posts: 10
PostPosted: Tue Aug 08, 2017 12:50 pm Reply with quote
@invalidname, Are you an owner right?

phpBB is an older version in 2005. I saw that copyright software. Why you didn't update to version new phpBB software or something import to new XenForo software strongly a security.

phpBB may be hacked. If I am wrong. Because of public RCE Exploit.
Back to top
View user's profile Send private message Visit poster's website
Velshtein



Joined: 27 Oct 2015
Posts: 72
PostPosted: Tue Aug 08, 2017 1:18 pm Reply with quote
The question now is: Why was ANN attacked?

If I had to venture a guess, I would wager that it has something to do with the forum community here, and in particular, the way moderators run the place.
Back to top
View user's profile Send private message
Zin5ki



Joined: 06 Jan 2008
Posts: 6680
Location: London, UK
PostPosted: Tue Aug 08, 2017 1:27 pm Reply with quote
Sorry to hear that this happened. Rogues and ne'er-do-wells seem limitless in their capacity at times. At least we got a backup domain within the course of a few hours!
Back to top
View user's profile Send private message Send e-mail Visit poster's website My Anime My Manga
xstylus



Joined: 04 Feb 2004
Posts: 263
PostPosted: Tue Aug 08, 2017 1:28 pm Reply with quote
CatSword wrote:
I'm curious as to how exactly a hacker completely stole control of the domain though, to the point of having his information replaced in the WHOIS. I didn't know you could just steal someone's URL like that.


It's sadly easier than one would think, if one isn't careful.

Let's say there's an admin or superuser of a company or website. Let's also say this person is also a user of one of the many other sites that recently suffered a data breach. (And, in fact, according to haveibeenpwned.com, there are indeed @AnimeNewsNetwork.com email address holders whose info has been compromised through no fault of their own.)

Let's also say that one of those admins may have the bad habit of re-using a single password at multiple sites, and has not changed it in a long time. All a hacker has to do (and it doesn't even need to be a GOOD hacker) is to snoop around for one of the publicly released breaches and see if any of the passwords are still any good -- and voila, he's in.

Once they got in, they apparently found enough information to be able to log into the domain registrar and initiate a transfer, and/or to intercept the registrar transfer emails. That's plausible because some companies share an "in-case-of-emergency" list that contains important passwords (such as twitter logins, site host logins, registrar logins, secondary email accounts, and other credentials), which is shared with important company individuals. Dunno if ANN does this, but I've previously worked with companies who do.

Anyway... again, not saying that what I described above is what actually happened, but that's one of many ways (and often the most common way) that things like this happen.

Moral of the story: Change your passwords often, use two-factor authentication, and don't use re-use the same password everywhere.


Last edited by xstylus on Tue Aug 08, 2017 1:37 pm; edited 4 times in total
Back to top
View user's profile Send private message
Emerje



Joined: 10 Aug 2002
Posts: 7336
Location: Maine
PostPosted: Tue Aug 08, 2017 1:29 pm Reply with quote
leafy sea dragon wrote:
Or it could be part of something larger, like the cyberattacks on Ukraine, which knocked out a lot of unrelated businesses and government institutions all over the world.

Since they were also going after personal Twitter accounts related to ANN it's hard to see this as anything other than a targeted attack rather than collateral damage.

Samet Chan wrote:
@invalidname, Are you an owner right?

phpBB is an older version in 2005. I saw that copyright software. Why you didn't update to version new phpBB software or something import to new XenForo software strongly a security.

phpBB may be hacked. If I am wrong. Because of public RCE Exploit.

The forums (and much of the site) here are heavily modified and customized to meet ANN's needs, upgrading to a new version would be a rather large undertaking.

Emerje
Back to top
View user's profile Send private message Visit poster's website My Anime My Manga
Tenchi



Joined: 03 Jan 2002
Posts: 4469
Location: Ottawa... now I'm an ex-Anglo Montrealer.
PostPosted: Tue Aug 08, 2017 1:30 pm Reply with quote
NormanS wrote:
If i may ask. Are the password hashed/salted? And correct me if i am wrong but isn't ANN using a really old forum software? Couldnt that be the target as well as perhaps updating to a new one?[/img]


Did they actually hack the site itself or just change the DNS info to route to their own server rather than the one at which ANN is hosted?

I suspect it's the latter but if you're concerned about your forum password being compromised, you should probably change it.


Last edited by Tenchi on Tue Aug 08, 2017 1:32 pm; edited 1 time in total
Back to top
View user's profile Send private message Send e-mail Visit poster's website My Anime My Manga
KutovoiAnton



Joined: 03 Mar 2013
Posts: 941
Location: Vladimir, Russia
PostPosted: Tue Aug 08, 2017 1:31 pm Reply with quote
Sad to see this happening. And I've got a question: if I'll add anything to encyclopedia on back-up site, will it remain, when the main site is back, or I'd better to wait?
Back to top
View user's profile Send private message
Master Menos



Joined: 03 Jul 2015
Posts: 15
PostPosted: Tue Aug 08, 2017 1:33 pm Reply with quote
Sorry to hear this happen to you guys! D: I hope the damage wasn't too great, even though this was a huge hack attack.
Back to top
View user's profile Send private message
Zac
ANN Executive Editor


Joined: 05 Jan 2002
Posts: 7912
Location: Anime News Network Technodrome
PostPosted: Tue Aug 08, 2017 1:35 pm Reply with quote
Tenchi wrote:
NormanS wrote:
If i may ask. Are the password hashed/salted? And correct me if i am wrong but isn't ANN using a really old forum software? Couldnt that be the target as well as perhaps updating to a new one?[/img]


Did they actually hack the site itself or just change the DNS info to route to their own server rather than the one at which ANN is hosted?

I suspect it's the latter but if you're concerned about your forum password being compromised, you should probably change it.


Our servers were not compromised, but it never hurts to change your password. We set articles to publish last night that still went up today, for example.

More information to come!
Back to top
View user's profile Send private message Visit poster's website My Anime
vampireknightgal



Joined: 10 Feb 2010
Posts: 34
PostPosted: Tue Aug 08, 2017 1:41 pm Reply with quote
What they did was pretty low on their part. hope everything gets sorted out on your end.

Here's some cookies to help you through... Anime smile

Back to top
View user's profile Send private message
ChibiKangaroo



Joined: 01 Feb 2010
Posts: 2941
PostPosted: Tue Aug 08, 2017 1:48 pm Reply with quote
I assume that some of the initial result of the hack will be reversed in due time once the proper actions are taken by Twitter etc. That being said, if you guys need an IP attorney, you know where to find me...
Back to top
View user's profile Send private message
Tenchi



Joined: 03 Jan 2002
Posts: 4469
Location: Ottawa... now I'm an ex-Anglo Montrealer.
PostPosted: Tue Aug 08, 2017 1:49 pm Reply with quote
KutovoiAnton wrote:
Sad to see this happening. And I've got a question: if I'll add anything to encyclopedia on back-up site, will it remain, when the main site is back, or I'd better to wait?


It's still the same website on the same server, so anything you add to the encyclopedia should be there no matter which domain name you use to get to it.
Back to top
View user's profile Send private message Send e-mail Visit poster's website My Anime My Manga
TasteyCookie



Joined: 19 Jan 2017
Posts: 421
PostPosted: Tue Aug 08, 2017 1:53 pm Reply with quote
Man that's pretty crazy. Sorry to hear about it Sad Hopefully they didn't do anything too crazy with your twitters. Anime fans (assuming one was responsible) can be extremely petty.
Back to top
View user's profile Send private message
Kimiko_0



Joined: 31 Aug 2008
Posts: 1796
Location: Leiden, NL, EU
PostPosted: Tue Aug 08, 2017 1:55 pm Reply with quote
Did you get the 4nn.cx URL shortener/redirect back already? Earlier today it showed a "domain name for sale" placeholder.
Back to top
View user's profile Send private message My Anime My Manga
Display posts from previous:   
Reply to topic    Anime News Network Forum Index -> Site-related -> Talkback All times are GMT - 5 Hours
Goto page Previous    Next
Page 2 of 11

 


Powered by phpBB © 2001, 2005 phpBB Group