Блог пользователя lsmll

Автор lsmll, история, 8 лет назад, По-английски

Hello, Codeforces.

Today, my friend and teammate jiangshibiao was going to register for the round, but discovered that his Codeforces account was hacked and the avatar as well as the password has been changed. The email could be changed too, but he is unsure right now. I looked at the avatar and immediately noticed it was the same as [user:[user:im0qianqian],2018-08-27]'s avatar, who made a blog post about his account being hacked too.

I think probably the same hacker did it, and there may be more victims. So I would like to invite MikeMirzayanov to look into the issue and possibly help my friend get his account back. Also, I would advise users who have weak passwords to change the password immediately.

Also, jiangshibiao and me are onsite at Petrozavodsk Camp right now, so maybe someone can meet him in person if needed to verify his identify.

UPD Aug. 29:

The hacker sent me a message in Chinese with the account of im0qianqian claiming that he changed the password and the email back. Then im0qianqian sent me another message saying that he got his account back and the previous message wasn't sent by him. Unfortunately, my friend jiangshibiao tried the original password but it still does not work, and he forgot what email address was used when registering his account. Therefore he is still locked out of his account. Any help from Codeforces administration is still greatly appreciated.

UPD2: Apparently the hacker did not really change the password and email back, as the "last visit" of jiangshibiao is two days ago.

English translation of the message

UPD Aug. 31:

The hacker changed the email back and my friend got back his account. Thanks everyone who replied in the post.

  • Проголосовать: нравится
  • +125
  • Проголосовать: не нравится

»
8 лет назад, скрыть # |
Rev. 5  
Проголосовать: нравится +10 Проголосовать: не нравится

Is it someone who discovered a vulnerability in Codeforces? Or is your friend's password too simple?

Not only do we need to use strong passwords, but it's also a good idea to enable https in the settings.

Anyway, I hope we can take back our account.

»
8 лет назад, скрыть # |
Rev. 2  
Проголосовать: нравится +139 Проголосовать: не нравится

first benefit to be grey, don't give a damn about your account

»
8 лет назад, скрыть # |
 
Проголосовать: нравится 0 Проголосовать: не нравится

The chances of successfully guessing an 8-character truly random password are one in 500 trillion.No one can bruteforce attack this many times as the website will consider it as DDOS.Many a times shoulder surfing is also the reason for attack.

if there is some vulnerability then why only these 2 accounts. want to know how exactly you people came to know your accounts were hacked i.e some random comments,submissions,name change,location change etc because one doesn't have a random dream that let's try changing email and password.

  • »
    »
    8 лет назад, скрыть # ^ |
    Rev. 4  
    Проголосовать: нравится +13 Проголосовать: не нравится

    My friend found it simply because he couldn't login today to register for the round (he hasn't visited Codeforces for some time). Also the number of victims could be higher, there may be more hacked accounts that haven't been discovered yet. Shoulder surfing is unlikely, because the users of the two hacked accounts don't live the in same place.

    The two hacked accounts are both from China, so one possibility is that they used the same password here and on some Chinese websites, and that Chinese website leaked the password. But that doesn't explain why im0qianqian was not logged out if the password is changed using standard means.

»
8 лет назад, скрыть # |
 
Проголосовать: нравится +5 Проголосовать: не нравится

I don't know if this is related, but I woke up today and noticed that one of my talks was gone. Someone had sent a message to me and I replied. The original message he sent was deleted.

I see no obvious button that would allow you to delete talks. Maybe this also has something to do with the security of codeforces.

»
8 лет назад, скрыть # |
 
Проголосовать: нравится +127 Проголосовать: не нравится

The reason why MikeMirzayanov isn't responding is because his account might've also been hacked. It's going to be the end of CF. Let's enjoy it while it lasts.

»
8 лет назад, скрыть # |
Rev. 4  
Проголосовать: нравится +29 Проголосовать: не нравится

My account has the backing of the CIA, FBI, WAIFU, and the Navy Seals. There is no way the hacker can penetrate the defenses of AMERICA, the finest country in the world. To the coward who's been going around hacking, you have made yourself an enemy of POLICE of the WORLD and the HARBINGER of JUSTICE, AMERICA. I will personally draw you out from Codeforces like poison is drawn from a wound.

»
8 лет назад, скрыть # |
Rev. 2  
Проголосовать: нравится +11 Проголосовать: не нравится

Your approach is wrong. 'jiangshibiao and me are onsite at Petrozavodsk Camp right now' implies that they were 'hacked' using MITM, since they used CF via HTTP instead of HTTPS. Your 'hacker' is probably onsite at Petrozavodsk Camp right now, hidden, waiting for more accounts.. So as long as you use https://mirror.codeforces.com/, or a trusted network, you should be safe.

  • »
    »
    8 лет назад, скрыть # ^ |
    Rev. 2  
    Проголосовать: нравится +5 Проголосовать: не нравится

    No, we are the only Chinese team there, and the hacker used Chinese to send message to me (see the update). Also, another student from my university said he saw the avatar changed before we went to Petrozavodsk.

»
8 лет назад, скрыть # |
 
Проголосовать: нравится 0 Проголосовать: не нравится

Auto comment: topic has been updated by lsmll (previous revision, new revision, compare).

»
8 лет назад, скрыть # |
 
Проголосовать: нравится 0 Проголосовать: не нравится

Is this guy also hacked? Profile pic is the same thing

http://mirror.codeforces.com/profile/hashlib

»
8 лет назад, скрыть # |
 
Проголосовать: нравится 0 Проголосовать: не нравится

Use LastPass (or something similar), people. It's never too late to get secure.

»
8 лет назад, скрыть # |
 
Проголосовать: нравится +8 Проголосовать: не нравится

Tell me what jiangshibiao's mailbox is, then I can change it back.