1. Remember to check the Simple Questions/Simple Answers , Suggestions , Bug Reports and Technical Support threads before posting. If you have something that warrants extended discussion then post a thread, but when in doubt, please use an already existing thread

June 2013 attack on Pokémon Showdown

Discussion in 'Pokémon Showdown!' started by mikel, Jun 21, 2013.

Thread Status:
Not open for further replies.
  1. mikel

    mikel The Young an Wild Take Chances Together.
    is a Battle Server Admin Alumnusis a Forum Moderator Alumnus

    Joined:
    Jun 26, 2011
    Messages:
    859
  2. Soul Fly

    Soul Fly IMMA TEACH YOU WHAT SPLASHIN' MEANS
    is a Contributor to Smogon

    Joined:
    Jan 16, 2013
    Messages:
    1,341
    Fuck.

    My 15 alts parodying the showdown Staff.

    All share the same password
  3. mikel

    mikel The Young an Wild Take Chances Together.
    is a Battle Server Admin Alumnusis a Forum Moderator Alumnus

    Joined:
    Jun 26, 2011
    Messages:
    859
    that's not the issue; the issue is whether any of your accounts share a pass with any other online services (eg. email, amazon, google, etc). if they do, change them all including the other services. even if they don't, you probably should change them just to be sure.
  4. Soul Fly

    Soul Fly IMMA TEACH YOU WHAT SPLASHIN' MEANS
    is a Contributor to Smogon

    Joined:
    Jan 16, 2013
    Messages:
    1,341
    My 15 alts ALL share the same password WHICH IS shared with my SMORGEN FOREMZ ACCOUNT.

    on the hindsight changing my smogon password is much more convenient.

    Thanks for letting us know about this so quickly
  5. jumpluff

    jumpluff ghosts will come & kiss our eyes
    is a Site Staff Alumnusis a Super Moderator Alumnusis a Smogon IRC SOp Alumnusis a Researcher Alumnusis a Smogon Media Contributor Alumnusis a Contributor Alumnusis a Battle Server Moderator Alumnus

    Joined:
    Aug 22, 2008
    Messages:
    5,920
    It's not a bad idea (although I think a lot of us don't follow it) to change your passwords frequently anyway, or to switch up what you're using (using the same pass everywhere is unequivocally a terrible idea).
  6. Soul Fly

    Soul Fly IMMA TEACH YOU WHAT SPLASHIN' MEANS
    is a Contributor to Smogon

    Joined:
    Jan 16, 2013
    Messages:
    1,341
    My involvement with smogon began in a very casual manner so I used my 'default' password for signing up and making alts..
    I never realized I'd be sticking around long enough.

    oh come on... everyone has one 'default' password for casual/non-sensitive activities.

    But you're right ofc.
  7. jumpluff

    jumpluff ghosts will come & kiss our eyes
    is a Site Staff Alumnusis a Super Moderator Alumnusis a Smogon IRC SOp Alumnusis a Researcher Alumnusis a Smogon Media Contributor Alumnusis a Contributor Alumnusis a Battle Server Moderator Alumnus

    Joined:
    Aug 22, 2008
    Messages:
    5,920
    Oh, I acknowledge it's really annoying and in practice doesn't get followed.

    I more meant this kind of incident is the stuff that scares people into doing it. At least for a little while. And it is a good idea. :heart:
  8. UltiMario

    UltiMario

    Joined:
    Aug 11, 2009
    Messages:
    1,133
    1 word:

    shit
  9. Pikachuun

    Pikachuun

    Joined:
    Dec 27, 2012
    Messages:
    924
    Thank goodness my computer broke while this was happening!
  10. Soul Fly

    Soul Fly IMMA TEACH YOU WHAT SPLASHIN' MEANS
    is a Contributor to Smogon

    Joined:
    Jan 16, 2013
    Messages:
    1,341
    Your showdown account is compromised regardless. lol
  11. AJC

    AJC

    Joined:
    Jun 7, 2005
    Messages:
    2,252
    the password i use on PS is totally different from other services i use i never use the same password so even if the asshat did get it he wouldn't be able to do anything with anything else.
  12. Pikachuun

    Pikachuun

    Joined:
    Dec 27, 2012
    Messages:
    924
    I use several passwords anyways <_<
  13. HybridHammer

    HybridHammer

    Joined:
    Mar 1, 2013
    Messages:
    10
    regarding this issue... when are these "login keys" going to be changed and who has to change them? I am just wondering because creator of the pokemonperfect.psim server hasn't been online for a good few months and there is a tournament scheduled for net Saturday that many people are going to need to get on and prepare their teams for
  14. mikel

    mikel The Young an Wild Take Chances Together.
    is a Battle Server Admin Alumnusis a Forum Moderator Alumnus

    Joined:
    Jun 26, 2011
    Messages:
    859
    this is the new public key

    the old keys were just disallowed so you will need to edit your config/config.js appropriate before users will be able to connect to your server. anyone with root access to the showdown code should be able to make the change to the file required.
  15. HybridHammer

    HybridHammer

    Joined:
    Mar 1, 2013
    Messages:
    10
    Giving me that though Mikel isnt providing me with a suitable answer... well it is but it isnt. proving me with all this coding isnt gonna help because i am merely a "Driver", so unless someone wants to come onto the server fix the issue and then promote me to a rank that can actually do something... the coding is useless to me. But also like i said, Lutra (creator of the server) never comes online tbh. I am always the only staff member, on that server, online
  16. mikel

    mikel The Young an Wild Take Chances Together.
    is a Battle Server Admin Alumnusis a Forum Moderator Alumnus

    Joined:
    Jun 26, 2011
    Messages:
    859
    you need the host of the server to change config/config.js to the new public key. otherwise, you can git clone the code yourself and run the server on your computer if you desire, i suppose.
  17. HybridHammer

    HybridHammer

    Joined:
    Mar 1, 2013
    Messages:
    10
    Yeah like i say Lutra hasnt been online in months so the server is going to remain down unless someone can get him online as its his server. as for git cloning the code and running the server myself... how would i do that?
  18. mikel

    mikel The Young an Wild Take Chances Together.
    is a Battle Server Admin Alumnusis a Forum Moderator Alumnus

    Joined:
    Jun 26, 2011
    Messages:
    859
  19. Metal Sonic

    Metal Sonic Never fear the fall
    is a Tutoris a Tiering Contributoris a Contributor to Smogon

    Joined:
    Sep 14, 2012
    Messages:
    1,475
    ^

    Did anybody read the documentation provided in the OP? Its pretty informative(and always giving me second doubts about taking up Computing)
  20. Obvious

    Obvious

    Joined:
    Jun 22, 2013
    Messages:
    2
    So what is my password now since you changed it?
    The site wont let me play at all without logging in on some account.
  21. Laikue

    Laikue

    Joined:
    Aug 10, 2012
    Messages:
    10
    Great, all three of my accounts shared passwords, and now none of them are working....I wish I more regularly checked the forums. T.T

    (Thank you though for informing us, and warning everyone. I gotta go change my passwords.)
  22. juleocesar

    juleocesar

    Joined:
    Jun 22, 2013
    Messages:
    32
    I changed the ones that I think they were equal to the Showdown's account.
    Huge thanks for the advice, now I believe i'm safe.
Thread Status:
Not open for further replies.

Users Viewing Thread (Users: 0, Guests: 1)