To publish content you need to register for a free account or login.

/ Homepage / Idle Chat /

I am astounded.

In the fullness of time, I will describe the details of the hideous fuckup I have just repaired.

In the meantime, if anyone has any problems logging in to WAN, please email me at hello [at] wereallneighbours [at] co [at] uk, and I will help you.

(In the fullness of time, that is. I ain't that idle.)

Published by Wrongfellow at 10:10pm on Fri 24th July 2015. Viewed 4,302 times.
This topic has been edited, last edit at 10:11pm on Fri 24th July 2015.

I'm in! Do I win five pounds?

Published by randomandtwisted at 11:21am on Sun 26th July 2015.

You certainly do! You can collect it whenever you like, from Bigmal.

Published by Wrongfellow at 11:38am on Sun 26th July 2015.

I think I know what you just found... was it related to logging in? At first I couldn't believe it hadn't been exploited, but then I realised that there's not really that much to exploit on WAN...

Published by Free Will at 11:41am on Sun 26th July 2015.

About 13 years ago I used to post on another forum and one day (I don't know why), someone posted their password in a thread. For the next fortnight everyone on the forum posted their usual discussion using the same account so it looked like just one person was posting everything on the board, except with wildly different writing styles and differing opinions post to post.

Published by Silent Rob at 4:50pm on Sun 26th July 2015.

Somehow that reminds me of this: http://bash.org/?244321

Anyway, it turned out that WAN wasn't checking people's passwords. All you needed to know was someone's email address, and then it didn't matter what you put in the password box; you were sure to get in.

It doesn't work that way any longer. Now you have to know the correct password to log in.

If anyone's having problems, it may be that what you thought was the password, wasn't the actual password. If this happens to you, please contact me via smoke signal email as above, and we'll sort it out.

(I seem to remember "Name and Shame" getting deleted a few years back. I wonder if this is how it happened?)

Published by Wrongfellow at 9:14pm on Mon 3rd August 2015.

This makes the achievement of wrongfellow's profile being hacked by "ashmine security team" (or whatever they were called) even less impressive.

Published by Silent Rob at 4:14pm on Tue 4th August 2015.

They didn't get anywhere near my profile. They just pulled off an SQL injection attack and got a few people's email addresses and passwords: http://www.wereallneighbours.co.uk/idlechat/message.php?sv=default&id=...

Published by Wrongfellow at 9:02pm on Tue 4th August 2015.

Post a Reply

You either need to register for a free publisher account or login to post content on this website.