Rage3d has been compromised

Spyhawk

Newcomer
Just in case anyone else was wondering why they werent able to connect to Rage3d today well heres why...


Rage3D.com is currently down for evaluation

On the evening of Thurs. March 11, Rage3D.com was compromised by an outside attacker. The intruder was
able to access the website and the forums for a period of up to a few hours though it may have functionally been less.

We were able to shut down the intruder’s access and minimize the damage to the site. However we
will remain offline while we restore the site to a state that we are certain is free of any malicious content.

We tentatively hope to be back online sometime this weekend

*** As A Precaution ***

We recommend those of you registered in the Rage3D Forums change the password
for the email address that you used to register in the Rage3D Forum.

If you use the same password anywhere else in your online life,
you should change it there as well.

*** ***

We’ll have more information for you as we return the site to normal working order.

Thank you for your understanding.

The Rage3D Staff
 
DAMN JOO!!!!

Do you have any idea how long it'll take me to change my default forum password at all the forums I'm registered at? Well do you?!?! :oops:
 
Digi, just keep the same password, but pre/append "rage(3d)" to it... That way it will be unique again. :p
 
With Rage3D down I have no way of knowing what email addy I used to register there...you know, like TEN years ago! Sheesh.

Of course, wouldn't any compromise only be realistic if I were to register for sites with the same passwords I would use for email accounts?
Does someone actually DO that?
 
Better safe than sorry. I don't think the attacker harvested the user db but its possible.
The DB shouldn't be a problem unless you use weak passwords (should only be a hash in the DB) the problem is that they could have simply slipped in some code to record the passwords as they were entered during log in.
 
Better safe than sorry. I don't think the attacker harvested the user db but its possible.
Yeah, I know..I do appreciate the heads up and all Jeff it's just I HATE having to go change my password everywhere. :(

G'luck though mate, hope it gets better soon. :)

(PS- Yeah, I know it's Jim...but I'm sticking with Jeff forever to keep the joke going. ;) )
 
Why would I need to change the password for my email address? Don't you mean change your Rage3D password?
 
The DB shouldn't be a problem unless you use weak passwords (should only be a hash in the DB) the problem is that they could have simply slipped in some code to record the passwords as they were entered during log in.

That is one of the concerns, yes. The advisory is because we strongly suspect some members use the same login for r3d as the email they used to register there, leaving that email account vulnerable.

Yeah, I know..I do appreciate the heads up and all Jeff it's just I HATE having to go change my password everywhere. :(

G'luck though mate, hope it gets better soon. :)

(PS- Yeah, I know it's Jim...but I'm sticking with Jeff forever to keep the joke going. ;) )

Yah yah, digi.... found yer pants yet? :LOL:

Why would I need to change the password for my email address? Don't you mean change your Rage3D password?

See above, but that as well.
 
I may have been one of the foolish ones whenever I registered there, but have long since changed things. Did you beat the intruder with a large stick?
 
Back
Top