Discussion in 'Bukkit Discussion' started by Firestar, Jan 8, 2012.

    I'm not going to have an argument. The information that you may have is 7 months old and does not reflect the current workings of the mcbans system.
    so much drama.
    As you wish. I was simply replying to your (extremely incorrect) statement, as it was brought to my attention.
    As true as this might be, after each attack on an organization's security (both successful or unsuccessful) normally preludes to an improvement in the security of said organization. From the information present to everyone, it seems that the entire McBans system was literally "trusted" to one individual (who helped with said security) as proved by his ability to lock out people who are actually McBans staff. This is also compacted by fears of well known griefers (which McBans is mostly used to block) such as, example, Doridian not only assisting with McBans but possibly having access to the system itself (which he or others could use to attack servers that put their trust in McBans).

    This is worrying, not only to me but any other user out there that is using, or may use in the future, McBans. What improvements can we see come from this? How will you protect your users in the future? How can you guarantee an incident like these never occurs again? I think this are questions on everyone's mind.
    Vhab likes this.
    The system is not trusted to any one person, and the user in question is no longer involved with mcbans or its equipment. And he would not have done anything he had threatened because he did not have access to those services.
    As TkTech has stated, he is in no way affiliated with MCBouncer (or any other ban systems that I know of). He hasn't even logged into the Reddit servers, so not connected in that way either. Please don't make unfounded accusations.
    The information is question was from 7 months ago from an older version of mcbans, and does in no way reflect the operations of the current mcbans.
  9. Offline


    You should come on HF sometime, Crashdoom is a active griefer and a active MCbans staff member. While there may appear to be a conflict of interest there, it's not true, it's about the same as me being both a server admin and a griefer, and countless others like me or Crashdoom. Being a griefer doesn't mean that you don't care about stopping them, I highly doubt anyone on the current MCbans stafflist is going to abuse their powers.
    Crashdoom is NOT a griefer.
    rakiru likes this.
    @Firestar @battlekid @forty_two @TkTech

    I should note that this thread has gotten significantly off topic. I would suggest taking such a conversation about a reddit post to a more appropriate forum (Offtopic), not to mention the quick argument this thread has become.

    If this thread continues to break Bukkit rules and remains as it is now I will lock it. Please do not make me do that.

    I'm amazed that people still don't do background checks when they hire others and are going to give them any kind of access or control over critical services (directed at nobody in particular). I actually read about Z. coding for Terraria a week ago and couldn't believe it. People do NOT change, as long as what they do is successful.

    MCBans has a very poor history of whom they employ or trust with their project, which (at least that's how it got explained to me once) is the result of people knowing each other or considering each other friends. I really hope these events also change the employment process for the sake of those that rely on the service. Or the other way around, cause server operators to distrust services like McBans by default.
    We have changed the way we approach hiring new team members.
    rakiru likes this.
    You seem a little out of touch :p.

    I may be wrong, but from what he's said, he appears to be a active griefer. I've seen many things confirming this.
    This is off-topic, and is incorrect.
    Yes, it's a little offtopic. No, it's not untrue.

    Go take a look through his posts on HF, I've seen several confirming what I said.

    Anyways, I'm not going to continue taking this offtopic, if you don't believe be then go look for yourself, let's keep this ontopic now.

    Edit: Just wanted to add in that he also helped sell a grief client at one point in time on HF, and yet you claim he never griefs?
    If you could provide me proof through a pm that would be helpful. Otherwise, even based on his posts what I see, he did not even mention himself griefing.
    I really want to know this.

    Is the salt leaked?
    it was in the database as well, that is why we are telling people to change their password.
    Excuse my language but.

  21. Offline


  22. Offline


    It is good that MCBans came out with a public statement like this.

    That being said, they could have been more transparent to their users, like saying that the salt was in the compromised DB. I'm not going to judge you for having the salt in the same DB as the passwords, but that should have been said in the first post.

    Also, I noticed that you don't use SSL on the MCBans login page, as far as I can see. Interesting.
    SMF as well as other PHP scripts all have their salts in the DB. was not hacked it was the old server, which we have changed hosts.
    Well, thanks for clarifying that at least.

    I know that itself was not hacked.

    I would like a clarification on something else. In your original post you say:
    Now in your reply to me, you said that the server was the one hacked, implying it was those forums hacked. But in your OP, you said it was a backup of So I am guessing it was the latter, but this is conflicting information.

    Also, can I ask why it took a week to make a statement anyways?

    In a separate note: I'm becoming weary of who to trust these days. RSA, MCBans, who is next, Google?
    So, to clarify, if I created an account in December 2011, am I at risk?
    I already got the email, but I'm just wondering about the password.

    Also, have you been able to locate the specific people/person responsible?
    AFAIK there were SQL dumps on that machine.

    Why? there can be several reasons for that, with one it being a cheap option to use as off-site backup.
    this is actually answered in the OP
    @Firestar: learn from how they handled communications be upfront!

    I also have a question, what hashing algorithm was used for mcbans?

    You're forgetting the biggest of them all, SONY leaking credit card data of 10% of the world.
    they are 2 separate servers, so server was not hacked, the server was, which housed the site pre-april 15th

    "Contacted all ISPs/hosts used to facilitate this attack. Most if not, all ISP’s/hosts have complied with our requests, and we will continue to ask for take-downs until we see fit."
    Nathan C

    Google has already been hacked I believe.
    This basically means that if they find the person who did it, he get's booted from the internet.
