Forum Settings
Forums

[Update May 23] Fake Ban Messages and Login Pop-Ups + Producers

New
Pages (3) « 1 2 [3]
May 20, 2015 7:13 PM

Offline
Aug 2014
2829
Susmit said:
I am beginning to doubt MAl security. The ban really freaked me out.


It's MAL security.... what do you expect lol.
May 20, 2015 7:23 PM

Offline
Jun 2014
39
We will persevere!!
May 20, 2015 7:53 PM

Offline
Dec 2012
2737
Crips said:
Susmit said:
I am beginning to doubt MAl security. The ban really freaked me out.


It's MAL security.... what do you expect lol.
It's not like the guy's doing much though, normally he just baits and spams shit only when he's lucky enough to get his hands on a mod account, then he gets to have fun.



May 21, 2015 4:04 AM

Offline
Apr 2015
732
I just recently got banned for real while this happens lol ???

banned by mal and the hacker

I think im the chosen one

Hi
May 21, 2015 6:57 AM

Offline
Dec 2012
2927
I almost had a mini heart attack. :((

May 21, 2015 2:29 PM
Offline
Jul 2018
564612
As it was said multiple times before, I too recommend getting an SSL certificate. When a website's popularity grows, you have to grow with it.

If you are serious about securing your website, you could always go with Sucuri, SiteLock or StopTheHacker security.
removed-userMay 24, 2015 8:39 AM
May 22, 2015 2:38 AM

Offline
Jan 2014
1832
GosuGian said:
I almost had a mini heart attack. :((
May 22, 2015 4:39 AM

Offline
Nov 2014
316
I'm safe. :v

To-Do List:

  • NOTHING

May 23, 2015 2:51 PM

Offline
Aug 2014
159
Everytime I'm on an anime MAL page it won't let me scroll down and it keeps centering the screen on the ad :/
Profile, Panel, & List don't have this problem.
May 23, 2015 4:26 PM

Offline
Mar 2010
13613
oh wow... this happened when im gone.
May 23, 2015 4:31 PM

Offline
Dec 2012
16302
May 23, 2015 4:35 PM

Offline
Oct 2014
3645
Xinil or the new devs stop fucking around and fix the site security already
May 23, 2015 7:56 PM

Offline
Feb 2014
8500
It's happening!
May 23, 2015 8:18 PM

Offline
Sep 2013
3323
My my I hope at the very least one of the moderators wasn't hacked to make this occur.

Because if that's the cause, hot damn yall need to pick personnel wisely... happens every 6 months.

Anywho, GL and GJ so far.
May 23, 2015 10:35 PM

Offline
Sep 2014
12
Welp, good thing I have Adblock. Good luck MAL staff, I hope you follow everyone's advice and do what is necessary to stop this.
May 23, 2015 10:47 PM

Offline
Feb 2015
102
The Producers info is compromised now, what's going on lol.
From what i read this is some kind of hacker trying to mess with Xinil and MAL.
Anyways, i hope they fix this, right now it's an annoyance to filter Animes by studios/Producers. xD
A true man never dies.
May 24, 2015 1:45 AM

Offline
Mar 2014
8
femto999 said:
Happened to me! So should I change password?


Probably. You should also be using noscript and adblock if you use firefox (or their equivalent addons if you are on a different browser), otherwise browsing the internet may cause irritable bowel syndrome, ulcers, high blood pressure, anxiety, insomnia, restless leg syndrome, weight loss, weight gain, nausea, incontinence, constipation, dizziness, shortness of breath, skin rash, hives, or seizures. Stop browsing and see your doctor immediately if you experience any of these symptoms.
May 24, 2015 1:48 AM

Offline
Dec 2013
369
SSJMaster vs. Xinil - A story of epic battles!
May 24, 2015 4:55 AM

Offline
Feb 2008
1132
one day MAL will switch to SSL. i just hope it is before an epic collapse of the site. 4 people hold the power to this site and if one of their accounts gets hacked because the login server isn't on a secure server then it is the end of MAL as we know it.
May 24, 2015 5:45 AM

Offline
Jan 2009
14175
Kuma-Kuma said:
one day MAL will switch to SSLTLS. i just hope it is before an epic collapse of the site. 4 people hold the power to this site and if one of their accounts gets hacked because the login server isn't on a secure server then it is the end of MAL as we know it.
SSL is already outdated, in Case you've never heard of POODLE: http://arstechnica.com/security/2014/10/ssl-broken-again-in-poodle-attack/

As for the Scenario with the Accounts of those 4 Persons being hacked, I personally hope that there is at least some Safeguard Measurement like confirming critical Actions with a secondary Password and/or with the Approval of another (DB) Administrator.
NoboruMay 24, 2015 5:51 AM
May 24, 2015 6:45 AM

Offline
Oct 2012
700
MisakaTheRailgun said:
SSJMaster vs. Xinil - A story of epic battles!

It never gets old!
I'm learning English so maybe I make mistakes :)
May 24, 2015 6:46 AM

Offline
Sep 2013
2184
Jeanathan said:
Welp, good thing I have Adblock. Good luck MAL staff, I hope you follow everyone's advice and do what is necessary to stop this.
adblock doesn't stop the popups or gore, u 0 ssjmaster 1
May 24, 2015 7:54 AM
Offline
Jul 2018
564612
AnimeHonor said:
Jeanathan said:
Welp, good thing I have Adblock. Good luck MAL staff, I hope you follow everyone's advice and do what is necessary to stop this.
adblock doesn't stop the popups or gore, u 0 ssjmaster 1

I never heard about these pop-ups until now or even seen them. And I use AdBlock, if it is not that, then my computer has some special power or something.
May 24, 2015 8:05 AM
Offline
Jul 2018
564612
Is it fixed now?
May 24, 2015 1:07 PM

Offline
Feb 2008
1132
Noboru said:
Kuma-Kuma said:
one day MAL will switch to SSLTLS. i just hope it is before an epic collapse of the site. 4 people hold the power to this site and if one of their accounts gets hacked because the login server isn't on a secure server then it is the end of MAL as we know it.
SSL is already outdated, in Case you've never heard of POODLE: http://arstechnica.com/security/2014/10/ssl-broken-again-in-poodle-attack/

As for the Scenario with the Accounts of those 4 Persons being hacked, I personally hope that there is at least some Safeguard Measurement like confirming critical Actions with a secondary Password and/or with the Approval of another (DB) Administrator.
i only mentioned SSL because MAL seems too cheap to pay for TLS or whatever the most secure server is nowadays but it would be great if they used one for the login page or do like some websites and have separate pages for your login name and password. but at the end of the day if someone wants to hack MAL i guess they will find a way to do so.
May 24, 2015 1:24 PM

Offline
Jan 2009
14175
SSL would be useless to implement, as the three big Browsers (Internet Explorer, Firefox and Chrome) already disabled Support for SSL (3.0) after a respective Update. So if Users had to change their Settings to allow SSL 3.0 just for MAL, it would be counter-productive.

What do you mean with "separate page"? There is already one if you click on login (http://myanimelist.net/login.php?from=%2F).
May 24, 2015 1:39 PM

Offline
Feb 2008
1132
Noboru said:
SSL would be useless to implement, as the three big Browsers (Internet Explorer, Firefox and Chrome) already disabled Support for SSL (3.0) after a respective Update. So if Users had to change their Settings to allow SSL 3.0 just for MAL, it would be counter-productive.

What do you mean with "separate page"? There is already one if you click on login (http://myanimelist.net/login.php?from=%2F).
one page for your login name and a separate page for your password.
a lot of sites that hold personal info have that kind of set up for logging in. i know MAL doesn't have hold any personal info but having a 2 page log in system on a secure server wouldn't hurt
May 24, 2015 2:29 PM

Offline
Jan 2009
14175
I have never seen the Login Name and Password being on two separate Pages, in which you enter your ID/Account Name on the one and the Password on the other.
Or did you mean they should be stored on two different Locations on the Database Servers? That Passwords (if possible: at least salted/hashed and not in plain Text) shouldn't be saved in the same File in which the respective Username/ID is stored as well?

If it's the former, I'd like to see an Example.
If it's the latter, I'm all for it (if it isn't already done like that).
May 24, 2015 2:35 PM

Offline
Feb 2008
1132
Noboru said:
I have never seen the Login Name and Password being on two separate Pages, in which you enter your ID/Account Name on the one and the Password on the other.
Or did you mean they should be stored on two different Locations on the Database Servers? That Passwords (if possible: at least salted/hashed and not in plain Text) shouldn't be saved in the same File in which the respective Username/ID is stored as well?

If it's the former, I'd like to see an Example.
If it's the latter, I'm all for it (if it isn't already done like that).
that's because right now on the login page you enter both your login ID & password on the same page.
Passwords should be on a different server at least for Forum Mods & DB admins & DB mods.

so far, only an Anime DB Mod's account has been compromised and we all saw what chaos that wreaked but image if Kineta's or Xinil's account got compromised. it would be the end of MAL as we know it
May 24, 2015 2:41 PM

Offline
Jan 2009
14175
Well, it's not like they don't do Backups and can't roll back or restore Data. It's still inconvenient, though.
May 24, 2015 3:49 PM

Offline
Mar 2014
18200
I want my money back.
May 24, 2015 6:13 PM

Offline
Feb 2013
6196
Roth said:
Awe man! (fixed the tags on my list)

Getting access to an admin's MAL account isn't very useful. About all they can do is ban everyone and mess up the anime DB. The real concern is if someone figures out the FTP account to the webserver... security measures don't matter if that happens. (I'm not downplaying the need for SSL)
May 24, 2015 7:44 PM

Offline
Dec 2012
2737
BurntJelly said:
Roth said:
Awe man! (fixed the tags on my list)

Getting access to an admin's MAL account isn't very useful. About all they can do is ban everyone and mess up the anime DB. The real concern is if someone figures out the FTP account to the webserver... security measures don't matter if that happens. (I'm not downplaying the need for SSL)
ftp account? Don't you mean the database, I'd be really concerned if they were storing everything in ftp folders.

Besides, you'd have to find the ftp port and well firstly hope it's not disabled.



May 24, 2015 8:55 PM

Offline
Feb 2008
1132
BurntJelly said:
Roth said:
Awe man! (fixed the tags on my list)

Getting access to an admin's MAL account isn't very useful. About all they can do is ban everyone and mess up the anime DB. The real concern is if someone figures out the FTP account to the webserver... security measures don't matter if that happens. (I'm not downplaying the need for SSL)
you must not realize how much power Xinil's or Kineta's account has on MAL. they can delete your account if they want to. if a hacker gets control of one of their accounts then they can start deleting active users' accounts.
May 25, 2015 12:03 AM

Offline
Dec 2012
2737
Kuma-Kuma said:
BurntJelly said:
Awe man! (fixed the tags on my list)

Getting access to an admin's MAL account isn't very useful. About all they can do is ban everyone and mess up the anime DB. The real concern is if someone figures out the FTP account to the webserver... security measures don't matter if that happens. (I'm not downplaying the need for SSL)
you must not realize how much power Xinil's or Kineta's account has on MAL. they can delete your account if they want to. if a hacker gets control of one of their accounts then they can start deleting active users' accounts.
They can and has happened before, but there is worse.



May 25, 2015 4:44 PM

Offline
Jan 2015
3461
I didn't read it completely but I don't understand why anyone would do this ...

But thanks for the heads up ;)

May 25, 2015 6:40 PM

Offline
Sep 2013
3323
Kazilik said:
AnimeHonor said:
adblock doesn't stop the popups or gore, u 0 ssjmaster 1

I never heard about these pop-ups until now or even seen them. And I use AdBlock, if it is not that, then my computer has some special power or something.


I did a test myself about this what you call a "theory".

During the winter holiday SSJMaster escapades, I was moderating a club and out of no where some freak posts a giant anime girl w/ some ugly pantsu. I'm like "Too large a pic, please dont post." Like 30 min later back again and does it. I'm told people are getting some sort of pop-up, and others then linked it to this picture that is being posted. I never had a pop-up, why didn't I get it? I was told that Adblocker could be preventing these pop-ups and that's why I wasn't getting it. I mean, makes sense right? Adblocker preventing Ads and what's a pop-up, but another Ad? Anyways, I disabled the adblocker and discovered I was getting these pop-ups. Enabled it, and they stopped. Did the cycle once more to be sure.

Anywho, tl;dr

It's a fact that adblocker will block these pop-ups.
May 25, 2015 7:58 PM

Offline
Jan 2014
60
This is retarded. What is it about hackers and this site. Oh my god, you have access to my anime account, I'm scared?

If you want control of MAL, try to take the Admins account and be done with it. Trying to ruin an anime website is already lame enough.
Jul 26, 2015 7:02 PM

Offline
Jun 2013
1763
It often happens lately on my mobile. Sometimes, it says I was banned or access denied. I reloaded it, then I should type verification numbers and not rarely I was directed to appstore. The struggle is real. What's wrong?
ImpalaJul 26, 2015 7:10 PM
Jul 26, 2015 9:09 PM

Offline
May 2013
2029
Impala said:
It often happens lately on my mobile. Sometimes, it says I was banned or access denied. I reloaded it, then I should type verification numbers and not rarely I was directed to appstore. The struggle is real. What's wrong?

Different case from him. I never had to type any verification number. Sometimes reloading few times helps, sometimes I reloaded so many times I gave up and tried later after few hours and it finally worked. Happened few times to me already.

Jul 28, 2015 9:53 PM

Offline
Dec 2014
12508
ok so off we go
Dec 1, 2015 10:08 PM

Offline
Dec 2012
24356
Does this still happen (ban messages)? I got one and I didn't change my IP. Removed my cookies twice then I was able to see the site.
Pages (3) « 1 2 [3]

More topics from this board

» Try MAL's New Mobile Site! ( 1 2 3 4 5 ... Last Page )

Xinil - Feb 15, 2015

421 by Seiidou »»
2 hours ago

» Planned 5hr Maintenance, Thursday April 25 @ 1am-6am PT

Kineta - 4 hours ago

0 by Kineta »»
4 hours ago

» [Challenge] You Should Read This Manga 2024 ( 1 2 3 4 5 )

Kineta - Feb 23

204 by Dekom »»
Yesterday, 10:52 AM

» New Site Update: Peak Anime 🗻 ( 1 2 3 4 5 )

Kineta - Mar 31

213 by Lancelot73 »»
Apr 21, 4:28 AM

» Heavenly Easter Delusion: Devil and Dolce ( 1 2 3 4 5 ... Last Page )

Kineta - Mar 27

3332 by Terra_strong »»
Apr 17, 8:26 PM
It’s time to ditch the text file.
Keep track of your anime easily by creating your own list.
Sign Up Login