Malicious security breach...

Play Now

PackardBell

LOMCN Veteran
Veteran
Loyal Member
Feb 7, 2009
284
4
44
what a shame.. who ever did this spoiled completely the game.

we will never be sure of what happened so login data, dropfiles, backdoors, source leak? what could have happened? it will even be difficult to discover.

breach was based on a windows exploit? unpatched RDP? what was it? security breach based of unproper setup by user? i find it difficult that there are still hosters around with unpatched windows components.

lol @ you ...spoiled completely the game.

really? how? why?

imo who done this have nothing to win just prove his skills....this is a private server Sam can delete anything he wish

better now then later !

Keep up the **** Sam, show them who you are.
 

CraiG^

Legend
Legendary
Jun 22, 2003
3,142
34
275
Scotland
I'd also ask that if we're getting new passwords - can Copy/Paste be allowed for the login box - personally I always use a password generator and I couldn't here because we couldn't copy/paste, no doubt the passwords being sent out will be generated and since we can't change these passwords without great effort right now trying to type them in every time will be a complete ballache

+1
 

boothy

LOMCN Veteran
Veteran
Mar 23, 2007
458
12
45
Funny how, from my understanding archers have just been released on korean mir 2? Chronicles gets hacked a day later...
 

SmavidDavid

Playing Legend of Mir 5
Legendary
Jun 13, 2006
4,215
635
290
Worthing is depressing.
I hear Korean Mir II is worried that they will loose their entire player base to this server.


Or it was Russia.. lets not rule them out. Maybe Putin heard the lands of mir was ungoverned, and needed a ruler, so hes hacked it & attempted to turn it into a communist state for Oma's to thrive.
 

Vane

Dedicated Member
Dedicated Member
Feb 2, 2014
23
0
27
need to know if they have our email address as well as password
 

Vane

Dedicated Member
Dedicated Member
Feb 2, 2014
23
0
27
If you were to use the same password for your email & mir account... Sir you are a monkey. NEVER cross use passwords for sensitive access data & a game, even worse a private server.

I have used the same password and email for a couple of other unimportant websites (like this one) and if the email address and passwords have been taken together I will change them.

I would never use the password from something important on a forum or any game for that matter.

My question remains - do the hackers have both email address and password.
 

Jest

LOMCN Veteran
Veteran
Oct 29, 2005
682
8
105
My question remains - do the hackers have both email address and password.

Hi all,

Unfortunately a malicious hacker has managed to breach our server and access the Chronicles database, it is currently unknown what data has been breached, but, I would guess that they have likely got hold of passwords.

I would like to sincerely apologize for this breach and assure you I am going to be working around through out the night if I have to to ensure that one this security breach is 100% patched, and two, that all of your accounts are secure again.

Unfortunately as we are a small team communication from is will be spotty, however, rest assured we are doing all that is in our power to resolve this.

We will be resetting ALL passwords and will be sending out new passwords via the emails you registered with... For those who did not register with a legitimate email address *cries softly into hands* we will deal with on an individual basis.

Once again I sincerely apologize for this, I can't believe there are people still in the community that are this malicious.

Thanks as always for your support and interest,
Chronicles Development Team.

:(
 

Vane

Dedicated Member
Dedicated Member
Feb 2, 2014
23
0
27

How is this helpful in answering my question?

Like you I can read what Sam posted yesterday - no doubt by now the situation will be clearer?

I could guess that this information is stored together but confirmation that this is the case would be useful.
 

Adv

LOMCN Veteran
Veteran
Feb 13, 2014
1,553
34
110
Change your passwords incase????????????????????????????????????????????????????

Swear, downtown Derp City sometimes.

x
 

Tist

Dedicated Member
Dedicated Member
Loyal Member
Feb 19, 2014
87
2
34
Sam is at work. Give him a break lol
 

Blank

Dedicated Member
Dedicated Member
Jan 3, 2014
109
1
44
How is this helpful in answering my question?

Like you I can read what Sam posted yesterday - no doubt by now the situation will be clearer?

I could guess that this information is stored together but confirmation that this is the case would be useful.

It's pretty standard for a database leak to have ID, Password, Email Address & DoB fields all in one location.

So yes, if you've used the same password elsewhere you'll be wanting to change them & make note in future that even gigantic corporations have experienced these sorts of database losses/thefts & are under constant attack, so you should always use different passwords for all services when possible.... and using the same password for a private server of any kind hosted by someone you don't know that has no legal or professional obligation to keep your information secure is right up there with eating yellow snow & pissing into the wind. (This is a global rule, nothing against Sam)
 

mStation

Golden Oldie
Golden Oldie
Oct 29, 2003
2,042
69
235
♫♪♫ ♦♥♠♣ ♀♂♀
i use the same junk password for all the crap i don't really care about, even games and some websites..

for all the rest where money is and might be involved then no.. and the really important services have anyway the 2 way protection password method with password + sms on phone + additional token for bank so they can keep my password.. best shot they will get online on some private tracker site or something
 

Tashohnie

LOMCN Veteran
Veteran
Jan 13, 2009
855
4
104
Server went down so I was unable to AFK my red last night.... Fancy taking me off of red?;)
 

holly

LOMCN Veteran
Veteran
Loyal Member
Mar 26, 2003
400
4
94
Server went down so I was unable to hunt PT last night. Fancy giving me that %?
 

BoomBoom

Dedicated Member
Dedicated Member
Aug 16, 2013
108
9
44
It is most likely a inside job or a very bad choice of password.

If the database is hosted on the same server only local access should be permitted and the port should be closed.

If it's external then it should be set for only X IP to connect to it.

It's inevitable to happen when you have more than one person who access the server.

Dictatorship works with Mir :)