As many of you are aware, an anonymous party recently took advantage of a security hole in order to gain control of the site and prove a point. Now that we've sealed those leaks and reclaimed control, I'd like to be here to clarify a few questions and concerns you very likely have.
What was the extent of the damage?
At this point, we have no evidence to suggest that this was anything other than a skilled hacker making a point. He did not at any point ask us for money or information, and he quite willingly described both his methods and why they worked. I have since verified them with Aya042 (our resident server guy and code monkey) and sealed up the security holes, along with taking care of any other potential security concerns as well (for example, we have changed all of our server passwords, just to be safe). We have looked (and continue to look) and there is no evidence that any data, raw or encrypted, was downloaded, transferred, or otherwise accessed.
What about my passwords and other personally identifying information?
vBulletin 4 salts and md5 hashes all of its passwords. Even if the hacker downloaded the database containing the protected information (we have no reason to believe so), it would be next to impossible for him to retrieve and view one password - let alone all of them.
Even considering all of that, there is no evidence that the hacking was fueled by malicious intent. The hacker was happy to help point out the flaws in our system, and we have double-checked for any back doors or other potential loose ends (of which we have found none).
THAT SAID, because there is a (very) slight chance that your old password could be unsafe, we must recommend that you change your password here AND ON ANY OTHER SITES THAT SHARE IT. We doubt that your information was viewed or taken, but we cannot ignore the possibility, however small.
I'm a Donor. Is my payment information in danger?
Donors are safe. Even if the hacker managed to acquire our Paypal password (which we, again, have no evidence of), it's simply impossible to view a Donor's payment information through Paypal due to their (quite fantastic) security measures. Even by us. So you're safe.
I appreciate your help and openness, but I just don't trust LBPCentral with my information anymore.
We understand. So, for those looking to remove information from our servers, we are offering two services that you can take advantage of:
For Donors: if you have a subscription, PM us and we'll cancel it for you (even though all payment information is stored on Paypal's servers, not ours). If you're a one-time Donor, check your Paypal password and make sure it's not the same as your LBPCentral password. Aside from that, you'll be safe.
For everyone else: If you'd like us to remove your information from LBPCentral's servers and delete your account, send us a PM and we'll take care of it. Keep in mind: if you ask us to delete your account, that is exactly what we will do. Your account, including posts and other information tied to it, will be gone for good. Nothing has changed, we are still offering this service - we just want you to be fully aware of what it is you're asking us to do.
----------
If you have any other questions, feel free to post them here or PM them to me and I'll do my best to answer as promptly as I can. Thank you all for your patience.

- Forum
- Site Stuff
- Site Updates
- Security Issues
Results 1 to 15 of 34
Thread: Security Issues
-
01-16-2012 #1LBPKarting Community Dude
- PSN
- ConfusedCartman
- Join Date
- Jul 2008
- Location
- San Diego
- Posts
- 4,505
- Blog Entries
- 1
Security Issues
Last edited by ConfusedCartman; 01-16-2012 at 12:36 AM.
Twitter: @michaelbuffaloe
MSN: confusedkartman@live.com
AIM: confusedkartman
I'm the Community Coordinator for LittleBigPlanet Karting, so feel free to direct any Karting related questions to me :) If you need assistance with something LBPCentral-related, shoot a PM to Taffey, LBPCentral's current head honcho and overall awesome dude!
-
Thanks!
aceofthorns, anoken,
Antikris , bdT96000, biorogue, Brixx101, CardboardBoxMan, comishguy67, ConverseFox,coyote_blue , Darkcloudrepeat, DaSackBoy, DaSpoony,Dortr , Fang, Fenderjt,fireblitz95 , Fishrock123, flyinhawaiian, FocusRSdude, gamerguy5432,goranilic , Green Dino Bone, HappyGreenCactus, Holguin86, Iamgoofball, Jaymes_Keller, Jedi_1993, JspOt, Lady_Luck__777, lark98-2, MajorAce626, Malamo999,moonwire , Morgana25,Mr_Fusion ,n00bsack , nysudyrgh,Outlaw-Jack , Plasmavore, Pulparindo15, Puttatittut, Random, Ricky-III, Roneranger, runand_tell_that, sascha_winter, Schark94, SebasSBM, SenneChuChi, ShamgarBlade,shropshirelass , SkaterOllie795, Smurfetta5683, Spazz,Speedynutty68 , tanrockstan34, The InventingKing, TheMatrix,theswweet , tom230889, VelcroJonze, VenemoX, WoodburyRaider, xero, zzmorg82
-
01-16-2012 #2
Geez...and I thought anonymous was the only group to worry about...
Good to see nothing "very, very VERY" bad happened.
Music is Awesome!
Youtube: www.youtube.com/ResonantParadox
SoundCloud: www.soundcloud.com/ResonantParadox
LBP Schtuff: www.youtube.com/Ps3plAyAr67
Twitter: www.twitter.com/ResonantParadox
I'm a mostly a musician, but someday...I'll be a Superhero...someday...
-
01-16-2012 #3ALL YOUR BASE
- PSN
- JspOt-Kid
- Join Date
- Nov 2009
- Location
- Why do you want to know? O_O
- Posts
- 1,735
- Blog Entries
- 9
Wow, nice hacker.


"Imagination is more important than knowledge."-Albert Einstein
"One touch of nature makes the whole world kin."- William Shakespeare
Thanks to Moleynator for the Mudkip sig! And AdenRlumdan for the ShinRa sig!
"Oh, hi. How are you holding up? Because I'm a potato."-GLaDOS
"Space? SPAAAAACE!"-Core 1
-
01-16-2012 #4
Tbh I haven't noticed at all D:
I'm glad everything's okay, but how was the site affected during the hacking...?
-
Thanks!
-
01-16-2012 #5A ★ is born ♥
- PSN
- Lady_Luck__777
- Join Date
- May 2009
- Location
- Texas
- Posts
- 4,092
- Blog Entries
- 9
I would like to thank CC and Aya for such prompt attention to this.
Thank ya'll for handling this quickly and with minimal disturbance to the site and its members.
Also for keeping us informed via twitter and this post.
I think sometimes people forget you guys have real lives too.
Published LBP2 Levels:County Fun Fair
Published LBP1 Levels: Aquarium Adventure, Temple Of The Dragons, Shapes, The Goodies Store
Aquarium Adventure Video (Thx Sackboy223): http://www.youtube.com/watch?v=-Bho5KKC8w4
Life is not the way it's supposed to be. It's the way it is.
The way we cope with it is what makes the difference.
Get listed or just check who's in your area:
Member-Locations
-
Thanks!
-
01-16-2012 #6Heir to the Sackthrone
- PSN
- xtremesackboy
- Join Date
- Aug 2010
- Location
- Remote Moon 5/4
- Posts
- 195
- Blog Entries
- 5
-
-
01-16-2012 #7
Thanks, CC and crew.
Although I don't necessarily agree with the method the hacker used to make his point, it does seem like we're better off now than we were before.
-
Thanks!
-
01-16-2012 #8
If he was so willing to help, what did he want, anyways?
-
01-16-2012 #9SackgirlsruleGuest
I'd like to say pretty much what Lady Luck said, I'd like to thank yall' as well.
You did it so quick considering you do have your own things going on in real life. Good job!!
-
Thanks!
-
01-16-2012 #10
-
01-16-2012 #11
This kind of activity is not unheard of in the cyber world. There are hackers out there that exploit security flaws for the sole purpose of pointing them out to the sys admin.
-
01-16-2012 #12
yeah but it's usually for a job or for money...in this case from what we know the hacker has received none of those...so what was the purpose?
-
01-16-2012 #13Junior Sackperson
- PSN
- Tyranny68
- Join Date
- Aug 2011
- Location
- Florida, USA
- Posts
- 400
- Blog Entries
- 11
No wonder i couldnt get on the forums for days or do half the stuff i wanted to do, i thought someone had hacked the site, sad to see that and also hope they were dealt with accordingly, though it seems you guys have no idea who it was XD

~Upcoming Projects~
- Terraformer
- Sun Lander
- Chrono Chrysalis
- Tyranny68
Skype Name: MechaStorm
-
01-16-2012 #14
Last edited by n00bsack; 01-16-2012 at 08:55 AM. Reason: posted edit as separate post
-
Thanks!
-
01-16-2012 #15Junior Sackperson
- PSN
- majormel84
- Join Date
- Aug 2010
- Location
- bronx
- Posts
- 404
- Blog Entries
- 4
So like, can we do this again for april fools?
A epic rpg that will blow your mind .
with absurd comedy, of course!
http://www.lbpcentral.com/forums/sho...nd-other-stuff
-
«
Previous Thread
|
Next Thread
»
All times are GMT. The time now is 05:18 PM.
Powered by vBulletin® Version 4.1.12
Copyright © 2013 vBulletin Solutions, Inc. All rights reserved.
Extra Tabs by vBulletin Hispano
Copyright © 2013 vBulletin Solutions, Inc. All rights reserved.
Image resizer by SevenSkins
Extra Tabs by vBulletin Hispano


Reply With Quote






