Forum Settings
Forums

[Update Dec 29] Do not type your credentials into login pop ups

New
Pages (3) « 1 [2] 3 »
Dec 25, 2014 1:33 AM

Offline
Jan 2008
4217
This is terrible.
Dec 25, 2014 1:39 AM

Offline
Jun 2014
12856
Interesting. Hopefully the problem is revolved.
All credit goes to Sacred.
Dec 25, 2014 1:55 AM
Offline
Jul 2018
564612
Emnay said:
ssj is back
who?

WHAT THE **** JUST HAPPEN?
removed-userDec 25, 2014 2:01 AM
Dec 25, 2014 3:32 AM

Offline
Jun 2013
1771
ReaperCreeper said:
Well I'm staying off the forums until this is resolved. I don't need to see gore images any time soon.

Wrong answer

I suggest to install adblock and greassmonkey in your browser
Dec 25, 2014 4:50 AM

Offline
Oct 2014
989
ThisNameSucks said:
your credentials into login pop ups


I lol'd
Dec 25, 2014 6:31 AM

Offline
Jul 2012
397
Hidayat246 said:
ReaperCreeper said:
Well I'm staying off the forums until this is resolved. I don't need to see gore images any time soon.

Wrong answer

I suggest to install adblock and greassmonkey in your browser

I still don't get why people still don't install adblock as soon they get a browser.
Few minutes and you are 90% safe from most scams.

Still didn't know about greassmonkey,hmmm for Mozzila.

I painted my teary face with a disguised smile[COLOR=#ff3333] and pretended it was a cry out of joy.[/COLOR]

Dec 25, 2014 7:04 AM
Dec 25, 2014 7:05 AM

Offline
Oct 2012
700
In a club a similar pop-up appeared, I just ignore them but some people don't... I hope they're able fix this soon.
I'm learning English so maybe I make mistakes :)
Dec 25, 2014 8:45 AM
Offline
Feb 2013
760
He strikes again...
Dec 25, 2014 8:50 AM

Offline
Jan 2008
18116
Saw some pics yesterday. Was quite surprised since didn't he attack the site a few months ago? That's twice in a year? That's new, it's usually just once a year.
Dec 25, 2014 9:12 AM

Offline
Feb 2013
6827
Paul said:
Saw some pics yesterday. Was quite surprised since didn't he attack the site a few months ago? That's twice in a year? That's new, it's usually just once a year.
'Tis the season.
Dec 25, 2014 9:22 AM

Offline
Mar 2009
12423
Let's hope they don't steal another admin account and change anime info, though I doubt any admins or mods would fall for it.

Lulu ❤ | My MALoween Candy
Dec 25, 2014 9:27 AM
Offline
Oct 2013
2207
One of the best thing to do is to install "AdBlock" plugin for your browser. Blocks most of the popups and scripts on the user's end.

Ssj is a different matter though.
Dec 25, 2014 9:42 AM

Offline
Mar 2013
5831
grave_robber said:
Let's hope they don't steal another admin account and change anime info, though I doubt any admins or mods would fall for it.

An admin's account has never been hijacked since I've been on this website. When the anime database information have been massively changed, Jackson_H's (anime DB mod) account got compromised. At that time, the user supposedly got phished. This is pretty much alike, just being internal. Take extra caution. :)
Dec 25, 2014 9:50 AM

Offline
Mar 2014
21290
SSJ strikes again
Nico- said:
@Comic_Sans oh no y arnt ppl dieing i need more ppl dieing rly gud plot avansement jus liek tokyo ghoul if erbudy dies amirite
Conversations with people pinging/quoting me to argue about some old post I wrote years ago will not be entertained
Dec 25, 2014 10:11 AM

Offline
Feb 2010
2298
Thanks for the warning.
Dec 25, 2014 10:11 AM

Offline
Apr 2013
11408
Emnay said:
ssj is back
ALL HAIL

What a wonderful Christmas Present
Dec 25, 2014 10:25 AM
Offline
Aug 2013
1136
Hope this gets figured out
Dec 25, 2014 10:45 AM

Offline
Mar 2009
12423
Subpyro said:
grave_robber said:
Let's hope they don't steal another admin account and change anime info, though I doubt any admins or mods would fall for it.

An admin's account has never been hijacked since I've been on this website. When the anime database information have been massively changed, Jackson_H's (anime DB mod) account got compromised. At that time, the user supposedly got phished. This is pretty much alike, just being internal. Take extra caution. :)

phishing can include stealing someone's account(by stealing their credentials). I should have picked my words carefully, I didn't mean site admin, I meant DB users with admin-like powers so they can do CRUD operations (create, read, update & delete) on the records. A DB mod would have such a DB user account.

Anyhoo, I hope MAL staff will get things sorted out with the least amount of discomfort for all, especially them. It's really annoying to have to deal with this during the holidays.

Good luck and thank you for all your hard work MAL staff!

Lulu ❤ | My MALoween Candy
Dec 25, 2014 1:24 PM

Offline
Mar 2013
5831
Phishing is not a possibility of hijacking someone's account, but is in fact an action of hijacking someone's account through the means of posing a fake lure. When I've said no admin's account got compromised, I meant all the admins, DB and Site alike. As said, it was the moderator that has been attacked, and they do have the access power to change database entry information.
Dec 25, 2014 1:35 PM
Offline
Dec 2014
1
Firstly, im sorry for chatting in this thread.
Im new here, so i wasn't aware this site had such problems recurring.
I guess i will be extra careful around here.
For that matter, i recieved 3 Activation-Mails, but with the same (unclickable) link, you might want to check that.
Merry Christmas :)
Dec 25, 2014 2:08 PM

Offline
Jan 2014
39
Thanks for this.
Dec 25, 2014 2:52 PM

Offline
Aug 2014
159
Happy Holidays & Thanks for the warning
Dec 25, 2014 3:14 PM

Offline
Sep 2014
1003
Thank you for the info!
Dec 25, 2014 11:14 PM

Offline
Dec 2013
1589
You basically don't have to worry about anything if you have even a basic ad blocking plugin in your browser.
Step Into My Mind - ##&&##&&##&&
Dec 26, 2014 1:28 AM

Offline
Mar 2013
5831
Cakedog said:
You basically don't have to worry about anything if you have even a basic ad blocking plugin in your browser.

The malicious script appears to be blocked when using any blocker, yes. Still, even if you're using it, don't act too fast if you see any pop-ups whatsoever. That is for the example shared in the OP. Everything else can reach you even if you are using script blockers, but for that read earlier replies on the thread.
Dec 26, 2014 2:30 AM

Offline
Mar 2014
4596
I've never had this problem, but sometimes when I go on MAL it logs me out.
Dec 26, 2014 8:40 AM

Offline
Jan 2009
14190
Subpyro said:
Still, even if you're using it, don't act too fast if you see any pop-ups whatsoever.

Those Examples mentioned in the OP differ extremely, though. One has to be really stupid inattentive to not notice the Difference between the two Pop-ups. I mean, the squared instead of round Window, the "Authentication required" Title, the missing "Register" Button and the strange URL should raise red Flags to anyone.

To be honest, even after having read this News, I haven't paid too much Attention to the actual Login-URL. In most Cases, I open MAL with a Bookmark to the main page, else over Google or another Search Engine, but when I open it from there, I normally don't log-in anyway.
I've got Firefox-based browsers, which I'm primarily using, set up to always display the full URL like this:
and the important Part (myanimelist.net) stays highlighted, so I can easily see when I'm on the wrong Page.
I think it was the Value browser.urlbar.trimURLs which should be toggled to "false" in the about:config.

Since I've blocked Third-Party Scripts and all kind of Ads anyway, normally, there shouldn't be any Issues for me when clicking on the Login Button at the Top of the Main Page unless the Site itself would be compromised. But considering the Fact that MAL doesn't use a secured TLS Connection with "https:", it would be probably much easier to start a Man-in-the-middle-Attack than to compromise the Site itself. Or the bad People just outsource even that and simply use a Third Party Script like they're already doing, so as long as it stays like that, it's very easy to protect oneself, but when the Main Page Scripts are compromised and/or the unsecured connection is intercepted, you're screwed, anyway.

As for the mentioned List, I've added all Entries to my Blocklist, although I have seen legit, non-disturbing Images from imageban.ru and I can't really make Sense of Blocking the Kid Buu Image, unless the Entry was added to make ignoring certain People more easily.
With that Setup, I haven't seen any disturbing Images at all, so you can't count on me to report anything in that Regard, when I don't see anything.

To sum it up, as long as the Perpetrator(s) doesn't/don't put more Effort, it's easy to protect oneself against the disturbing Images and the Phishing.
Dec 26, 2014 9:12 AM

Offline
Mar 2009
12423
Subpyro said:
As said, it was the moderator that has been attacked, and they do have the access power to change database entry information.

Poor moderator, hacking a site like MAL is such an evil thing to do. >_>


ziggy_Z said:
I've never had this problem, but sometimes when I go on MAL it logs me out.

It happens to me quite often (ever since I signed up in 2009), I simply re-login.

Lulu ❤ | My MALoween Candy
Dec 26, 2014 9:24 AM

Offline
Mar 2013
5831
Noboru said:
Since I've blocked Third-Party Scripts and all kind of Ads anyway, normally, there shouldn't be any Issues for me when clicking on the Login Button at the Top of the Main Page unless the Site itself would be compromised. But considering the Fact that MAL doesn't use a secured TLS Connection with "https:", it would be probably much easier to start a Man-in-the-middle-Attack than to compromise the Site itself. Or the bad People just outsource even that and simply use a Third Party Script like they're already doing, so as long as it stays like that, it's very easy to protect oneself, but when the Main Page Scripts are compromised and/or the unsecured connection is intercepted, you're screwed, anyway.

I wonder if the HTTPS would as the ending result truly benefit the website more than it hurts it. Indeed, wiretapping and man-in-the-middle attacks can be performed on user-community websites such as Mal and having a secure protocol set would be a wise move, but that is if the servers could handle it. Encrypting and decrypting data takes its toll overall, and with bandwidth issues Mal is constantly experiencing (I'm sure you've experienced the lag yourself before), the weight put-on would be just too much.

At the end of the day, there are so many bugs on Mal and such server issues that two things would simply need to be done in order to increase the functionality drastically: Re-write the code from scratch (it's not as horrible as it sounds), as well as perform a move to better servers if the processing wouldn't improve by the change in the code alone.
Dec 26, 2014 10:24 AM

Offline
Jan 2009
14190
Subpyro said:
I wonder if the HTTPS would as the ending result truly benefit the website more than it hurts it.

That is one of the Questions where you should be glad that they don't have to do it right now, meaning, there would be known Cases en mass about it, however, the Point still stands.

I agree with you that there needs to be done much Effort in the technical Background, but on the other Hand, I can somehow understand if it's still only one Person doing the Coding and new/better Server (Upgrade)s don't fall from the Sky and run with Air and Love alone and it's already kind of sad imho when you have to block Ads/Scripts just to stay safe while still having the Comfort of using Windows.
Dec 26, 2014 10:30 AM

Offline
Jan 2012
31481
I just got this A username and password are being requested by http://www.alletscheisse.de. The site says: "myanimelist.net login required"

when I entered to this guy profile http://myanimelist.net/profile/Xiniil

Dec 26, 2014 10:36 AM

Offline
Feb 2010
2171
AllenVonStein said:
I just got this A username and password are being requested by http://www.alletscheisse.de. The site says: "myanimelist.net login required"

when I entered to this guy profile http://myanimelist.net/profile/Xiniil
Same, that guy posted a picture on a club that I handle and got the pop-up. Immediately deleted his post and voila, no more pop-ups.
"Your taste is shit cause you like what I hate. Believe me I have 1000 cartoons that I rated with less than 5."


Dec 26, 2014 10:37 AM

Offline
Jan 2012
31481
Cashdax said:
AllenVonStein said:
I just got this A username and password are being requested by http://www.alletscheisse.de. The site says: "myanimelist.net login required"

when I entered to this guy profile http://myanimelist.net/profile/Xiniil
Same, that guy posted a picture on a club that I handle and got the pop-up. Immediately deleted his post and voila, no more pop-ups.


Who the fuck is him? mods please ban this guy

Dec 26, 2014 10:38 AM

Offline
Mar 2009
12423
Subpyro said:

At the end of the day, there are so many bugs on Mal and such server issues that two things would simply need to be done in order to increase the functionality drastically: Re-write the code from scratch (it's not as horrible as it sounds), as well as perform a move to better servers if the processing wouldn't improve by the change in the code alone.


Revamping the site is not as horrible as it sounds indeed, if it were ever to happen I'd recommend doing it with angularJS+bootstrap, make it a SPA (single page app) with REST web APIs/services on the server. It'll work nicely, be secure, provide a rich user experience and it'll look great too. <3

Server issues are not my area of expertise but load balancing issues (I assume they're using a server farm not a single server) can be fixed by changing the software and/or hosting process. Unless the servers are old and need to be replaced.

Lulu ❤ | My MALoween Candy
Dec 26, 2014 11:11 AM

Offline
Mar 2013
234
why the fuck would people hack fucking mal accounts hack something worth ur time
Full time redditor and fedora owner, gg
Dec 26, 2014 2:14 PM

Offline
Sep 2013
3323
AllenVonStein said:
Cashdax said:
Same, that guy posted a picture on a club that I handle and got the pop-up. Immediately deleted his post and voila, no more pop-ups.


Who the fuck is him? mods please ban this guy


There are various people who are doing this, not just Xinii. Examples: Jupkmn (Who I can accurately say started this whole fiasco) and YuroNoMajo were neutralized the day of this thread. If none of you are aware yet, and probably can assume as much, the pictures that are randomly being posted in your clubs are in fact causing the pop-up and these people should be brought to a moderator's attention. All you can do to extensively defend yourselves and others is to delete the picture, remove the user from the club, ban the user, and bring it to a moderator's attention, and just go from there.

Commenting w/ Subpyro in a club earlier today, the hacker could be stockpiling accounts for a big ol' attack and pull a Summer Wars on us. And Yes, I included this just so I could reference Summer Wars. :p
Robokiller87Dec 26, 2014 2:20 PM
Dec 26, 2014 2:32 PM

Offline
Mar 2013
5831
Robokiller87 said:
Commenting w/ Subpyro in a club earlier today, the hacker could be stockpiling accounts for a big ol' attack and pull a Summer Wars on us. And Yes, I included this just so I could reference Summer Wars. :p

More like Winter Wars at this time of the year. :p

But yes, do take the advice Robo above has given. Specific users are being "infected" and the number only grows. We could choose not to follow who and simply look at the big picture until the entire matter is taken care of, but pinpointing fresh changes is also an option. I recommend the later while taking uttermost caution.
Dec 27, 2014 9:47 AM

Offline
Sep 2010
6759
SSJ is back! I seriously think he is an MAL user cause I mean why else would he attack yearly?
"What has two arms, two legs, and is alive? Not your favorite character lol! xD"
Dec 27, 2014 10:33 AM

Offline
Jan 2012
31481
Roloko said:
SSJ is back! I seriously think he is an MAL user cause I mean why else would he attack yearly?

What's Your Evidence?

Dec 27, 2014 10:41 AM

Offline
Mar 2009
12423
Roloko said:
SSJ is back! I seriously think he is an MAL user cause I mean why else would he attack yearly?

Because he's an a**

Lulu ❤ | My MALoween Candy
Dec 27, 2014 2:31 PM

Offline
Apr 2013
104
Thanks for the info :D
Dec 27, 2014 7:20 PM

Offline
Apr 2009
69
This is why you always use adblock.
Dec 28, 2014 1:56 AM
Ceasefire NOW

Offline
Aug 2009
3699
Thanks for the warning.
Dec 28, 2014 2:34 AM

Offline
Jun 2013
1171
Thank you very much for your helpful information. Now I know what domains and images I should block.
Dec 28, 2014 7:05 AM

Offline
Nov 2009
186
I had posted the following suggestion as a countermesaure against basic access authentication injection over a year ago but it was ignored. I'll post it again, betting on the slim chance that someone reads it this time.

http://myanimelist.net/forum/?topicid=671199&show=140#msg25775993

basmimarsinan said:
As mentioned a few times before, the solution to the basic access authentication injection would be making sure the URL given to the img tag is a real image. However, doing this every time for every img tag with PHP isn't be viable for a site of huge size like this, since you have to download the image or a part of it.

I was thinking that maybe you could make clients do the pre-check rather than handling it server-side. For instance, all img tags could be parsed with a loading image as a place holder and once the page loads, a JavaScript function could first make sure that the image is valid and then embed the image. In my tests with Chrome and Safari, if you provide a username and password for the AJAX call, browser doesn't trigger the basic access authentication pop-up.

Here's an example code I have been testing things with:

https://gist.github.com/silentguardian/7005884

I'm no expert when it comes to client-side scripting, so I'm sure if this will be a huge burden to the browser. Maybe images could be embedded as the image comes in sight of the user and this may even speed up the page loads or images that can't be loaded maybe marked as broken and removed in fail method. If the behavior is the same in other browsers too, it might be something to consider.
And slowly, you come to realize... It's all as it should be...
Dec 29, 2014 12:18 AM

Offline
Jan 2009
92511
basmimarsinan said:
I had posted the following suggestion as a countermesaure against basic access authentication injection over a year ago but it was ignored. I'll post it again, betting on the slim chance that someone reads it this time.

http://myanimelist.net/forum/?topicid=671199&show=140#msg25775993

basmimarsinan said:
As mentioned a few times before, the solution to the basic access authentication injection would be making sure the URL given to the img tag is a real image. However, doing this every time for every img tag with PHP isn't be viable for a site of huge size like this, since you have to download the image or a part of it.

I was thinking that maybe you could make clients do the pre-check rather than handling it server-side. For instance, all img tags could be parsed with a loading image as a place holder and once the page loads, a JavaScript function could first make sure that the image is valid and then embed the image. In my tests with Chrome and Safari, if you provide a username and password for the AJAX call, browser doesn't trigger the basic access authentication pop-up.

Here's an example code I have been testing things with:

https://gist.github.com/silentguardian/7005884

I'm no expert when it comes to client-side scripting, so I'm sure if this will be a huge burden to the browser. Maybe images could be embedded as the image comes in sight of the user and this may even speed up the page loads or images that can't be loaded maybe marked as broken and removed in fail method. If the behavior is the same in other browsers too, it might be something to consider.


there are lots of programming/coding suggestions that was made in the past too but MAL staff keeps ignoring it, i say do not count on it, the staff like Xinil rather work on adding more advertisement banners (MAL on mobile has too much ads now) than solving the problems of the website
Dec 29, 2014 3:15 PM

Offline
Aug 2008
352
thnx
Dec 29, 2014 4:40 PM

Offline
Dec 2014
114
Thank you for the warning and the hard work to solve this. Hacking and gore images, just why... :(
Dec 30, 2014 1:11 AM

Offline
Jan 2012
16
Azphix said:
This is why you always use adblock.
Indeed


-Positive and negative energy coexist to exist-
Pages (3) « 1 [2] 3 »

More topics from this board

» Moderators Wanted! Accepting applications for all positions

Kineta - 1 hour ago

0 by Kineta »»
1 hour ago

» [Challenge] You Should Read This Manga 2024 ( 1 2 3 4 5 )

Kineta - Feb 23

208 by hawkpelt5 »»
Today, 1:49 AM

» Try MAL's New Mobile Site! ( 1 2 3 4 5 ... Last Page )

Xinil - Feb 15, 2015

423 by RED-clover12 »»
Apr 24, 10:19 AM

» Planned 5hr Maintenance, Thursday April 25 @ 1am-6am PT

Kineta - Apr 22

0 by Kineta »»
Apr 22, 8:10 PM

» New Site Update: Peak Anime 🗻 ( 1 2 3 4 5 )

Kineta - Mar 31

213 by Lancelot73 »»
Apr 21, 4:28 AM
It’s time to ditch the text file.
Keep track of your anime easily by creating your own list.
Sign Up Login