Forum Settings
Forums
New
Sep 12, 2013 2:30 PM
#1
Overlord

Offline
Nov 2004
5752
We believe we've fixed the majority of login issues. Terribly sorry it took so long to get this under control, but hopefully we can move forward from here. If your IP is changing frequently though, you'll still get logged out on each subsequent change.

Also, we've received information that the attacker who has hit MAL before may have compromised other anime sites as well. If you've reused usernames, e-mail addresses, and passwords on these sites, it is likely that the attacker has them, and can log in as you if he or she wants. We highly recommend that you change your password as soon as possible, to ensure that your profile and data aren't compromised.

Starting on September 20, we will no longer be able to restore profiles for users who have not changed their password since August 22. It takes a lot of work to restore hacked profiles, and we would rather put that effort into security improvements that can benefit everyone.

Thanks everyone!
Pages (3) [1] 2 3 »
Sep 12, 2013 2:36 PM
#2
Offline
Aug 2013
392
Yay! No more login issues finally! changed my password just now.
Sep 12, 2013 2:44 PM
#3

Offline
Mar 2013
357
I'll change my password

Soon...
Sep 12, 2013 2:50 PM
#4

Offline
Jan 2013
6644
I can log-in, even though I get randomly logged out at times, which is fine I suppose.

But the only thing that doesn't let me log in is when I check the "Stay logged in" box.
No matter how many tries.
Sep 12, 2013 2:51 PM
#5
Offline
Sep 2012
146
PrOxAnto said:
I can log-in, even though I get randomly logged out at times, which is fine I suppose.

But the only thing that doesn't let me log in is when I check the "Stay logged in" box.
No matter how many tries.


yep yep same here
Sep 12, 2013 2:54 PM
#6

Offline
May 2012
18470
I'm still kinda getting logged out sometimes...even though I'm using the same computer without changing.
Sep 12, 2013 2:57 PM
#7

Offline
Dec 2012
4876
Will do. Thank you for your advice & your hard work.
I like anime.
Sep 12, 2013 3:00 PM
#8

Offline
Aug 2010
2344
PrOxAnto said:
But the only thing that doesn't let me log in is when I check the "Stay logged in" box.
No matter how many tries.
It hasn't been working for some time now and yes, it won't let you log in at all.

Technically you'll remain logged in for as long as your IP remains the same though.
Sep 12, 2013 3:05 PM
#9
Offline
Jul 2013
13
I was logged out few minutes ago, and I just finished the review...all to waste. Thanks for all the hard works though.
It's so cooorrr
Sep 12, 2013 3:08 PM

Offline
May 2012
18470
DrsMadScientist said:
I was logged out few minutes ago, and I just finished the review...all to waste. Thanks for all the hard works though.
This is why you always copy what you wrote so that even if you lose them, you can still paste them back in.
Sep 12, 2013 3:08 PM

Offline
Jan 2013
6644
DrsMadScientist said:
I was logged out few minutes ago, and I just finished the review...all to waste. Thanks for all the hard works though.


If you backspaced to the last page the text should still be there.
Sep 12, 2013 3:12 PM
Offline
Jul 2018
564612
Thanks a ton. The frustration of having to relog every 5 minutes was really getting to me ._.
Sep 12, 2013 3:17 PM

Offline
Jun 2012
6491
Pls keep us safe.
Sep 12, 2013 3:18 PM

Offline
Feb 2010
565
Just changed my pw, interestingly I got DC immediately after that.
Stop the sequels high-ranking stupidity.
Group franchises in Top Anime page.
Because Gintama is just "one" anime and not 5.
Sep 12, 2013 3:21 PM

Offline
Apr 2010
74
Thank you. How will I know if my user is hacked or not?
Sep 12, 2013 3:28 PM

Offline
Nov 2007
31278
Thank you for your extremely hard work.
I Two Syaorans from Tsubasa RESERVoir CHRoNiCLE and TRC!!!
Sep 12, 2013 3:30 PM

Offline
Feb 2012
6700
Can you name the other anime sites that got attacked?

The only big anime site I'm active on is MAL, so now I dunno should I change my pw or not.

Thanks for the great work tho. :)
Sep 12, 2013 3:33 PM

Offline
Oct 2012
1649
hopefully security will get better from now on :P

Sep 12, 2013 3:33 PM

Offline
Apr 2008
902
Thank you!
Sep 12, 2013 3:43 PM

Offline
Jun 2009
691
Password changed and thanks. Also could you guys post a list of what other sites were hit so we know.
Sep 12, 2013 3:53 PM

Offline
Apr 2013
3284
Yey! Thank you sir!!! xD

Sep 12, 2013 4:01 PM

Offline
Dec 2012
16083
Hallelujah, I've gone 45 minutes without a forced log out! Hopefully that settles it then, changed my pw as well. Any news on when BBCodes will be up again?
Sep 12, 2013 4:03 PM

Offline
Mar 2013
85
Thanks for the hardwork!
Changed my password just now.
Really great that the logging out issue is fixed. :D
Sep 12, 2013 4:05 PM

Offline
Jul 2010
40
Thanks, thats great. Still it sux that changing IP = loging out. Are there any chances it will soon be back as it was? If yes - when? If no - why?
Sep 12, 2013 4:16 PM
Offline
Aug 2013
186
Urizithar said:
Thanks, thats great. Still it sux that changing IP = loging out. Are there any chances it will soon be back as it was? If yes - when? If no - why?


It probably won't be for a while. The TL;DR is that they went to to this system for security reasons.
agaffeSep 12, 2013 5:50 PM
Sep 12, 2013 4:26 PM
Offline
Jul 2018
564612
Thanks man, you're amazing!
Sep 12, 2013 4:56 PM

Offline
Jul 2013
434
I logged out after 15 minutes... ok, that's a progress, at least isn't every 2 minutes xD!
I really appreciate all your effort.... but the problem still remains :(

100% of all dead people have never complained about being dead. So I guess it isnt that bad.
Sep 12, 2013 5:01 PM
Offline
Jun 2013
7
still having problems signing in though and i did change my password
Sep 12, 2013 5:08 PM

Offline
Aug 2011
2513
AT LONG LAST
Sep 12, 2013 5:14 PM

Offline
Apr 2013
174
agaffe said:
Urizithar said:
Thanks, thats great. Still it sux that changing IP = loging out. Are there any chances it will soon be back as it was? If yes - when? If no - why?


It probably won't be for a while. The TL;DR is that they went to to this system for security reasons. http://myanimelist.net/forum/?topicid=613857


That's old news. And not to mention the fact that site went down WITH ip changing thingy on.

Are DDoS attacks made with created accounts?
Is it viable to DDoS attack by creating accounts?
How about protection for creating accounts? (captcha, questions, etc)
If attacks made without creating accounts, then why log-in issues?
If attacks made without creating accounts, then why ip-change sensivity thingy?

There are lots of unanswered questions.
Open to chat about any storytelling related subject as long as it's clever and respectful.
Myanimelist
Sep 12, 2013 5:16 PM

Offline
Apr 2013
14519
Haven't been logged out in a while.
an egomaniac and a fool

Sep 12, 2013 5:33 PM

Offline
Jul 2012
48248
Yay I haven't been logged out for an hour or so. *happy dance*
Sep 12, 2013 5:49 PM

Offline
Mar 2010
55468
So basically if someone doesn't Read this Site Update and does not change their password (Between Aug 22 - Sept 20)won't be able to have their profile Restored? Sorry If I sound unsure since there are 1M + Members that probably won't get the memo.

Behold of my awesomeness~
controversial and/or sensitive topics likely devolve into the same repetitive, derogatory, abusive, and harassing comments can no longer be posted.
But my feels.
Sep 12, 2013 6:19 PM

Offline
Jul 2007
6105
This was the most annoying bug ever in MAL, so glad its fixed. Although i do have a question, if you can't tick the box that enables you to stay logged in, doesn't that mean eventually when you go idle, it will log you out, or close your browser?

Essentially i could tick that box on my computer and i could stay logged in forever.

Also on another note, when is the BBcode going to be fixed for sigs and such?



Sep 12, 2013 6:30 PM

Offline
Jun 2007
5649
koleare said:
PrOxAnto said:
But the only thing that doesn't let me log in is when I check the "Stay logged in" box.
No matter how many tries.
It hasn't been working for some time now


That's not true, I've used it up until the hacking incidents and it never gave me a single problem. Saying it wasn't ever working perfectly would maybe be true (not for me), but saying it just hasn't been working 'for some time now' (implying more than just since the hacker) isn't accurate.
Sep 12, 2013 6:33 PM
Offline
Jul 2013
1473
This is too Beautiful !

Arigato Gozaimasu.
Sep 12, 2013 7:47 PM
Sep 12, 2013 7:59 PM

Offline
Mar 2012
18961
I'm still getting forced log-out though. Or is it because I'm using dial-up?
Kickstarter for Rokujouma is fully funded. Good work everyone. Lets wait for the result of our hard work together.
Sep 12, 2013 9:36 PM

Offline
Aug 2012
659
It got fixed . Thank you for your hard work.
Sep 12, 2013 9:40 PM

Offline
May 2012
871
Rapha_Lamperouge said:
Just changed my pw, interestingly I got DC immediately after that.

Same here but it hasn't happened again since then.
Sep 12, 2013 11:06 PM

Offline
Apr 2011
13
Thanks a lot ^_^
Sep 12, 2013 11:58 PM

Offline
Mar 2011
2731
Thank you! =)
Sep 13, 2013 12:20 AM
Offline
Jul 2018
564612
Oh shit this guy has my passwords for everything.... meh wutever
Sep 13, 2013 12:22 AM

Offline
Apr 2012
4896
Thanks, logging off issue seems resolved so far.
EratiKSep 13, 2013 9:04 AM
Sep 13, 2013 12:27 AM

Offline
Aug 2013
150
Thanks, now i'm can Stay Logged in. Great for your hardwork.
Signature removed. Please follow the signature rules, as defined in the Site & Forum Guidelines.
Sep 13, 2013 12:32 AM

Offline
Apr 2007
92
I'm glad I changed my password after the 2nd attack.
Sep 13, 2013 12:44 AM

Offline
Jan 2010
214
Changing my password now.
Sep 13, 2013 1:25 AM

Offline
Aug 2010
2344
Prequel said:
Are DDoS attacks made with created accounts?
No way.
Prequel said:
Is it viable to DDoS attack by creating accounts?
No.
Prequel said:
How about protection for creating accounts? (captcha, questions, etc)
There already is a captcha (the one from Google even).
Prequel said:
If attacks made without creating accounts, then why log-in issues?
Incompatibilities.
Prequel said:
If attacks made without creating accounts, then why ip-change sensivity thingy?
The same individual who attacked MAL now, attacked it two years ago as well. He could take accounts without any problem. Now he can't, because there's an ip block.

There you go.
TallonKarrde23 said:
koleare said:
PrOxAnto said:
But the only thing that doesn't let me log in is when I check the "Stay logged in" box.
No matter how many tries.
It hasn't been working for some time now


That's not true, I've used it up until the hacking incidents and it never gave me a single problem. Saying it wasn't ever working perfectly would maybe be true (not for me), but saying it just hasn't been working 'for some time now' (implying more than just since the hacker) isn't accurate.
Well, since it hasn't been worked out for me at all, and all posts I read about it until now were having the same problem, I simply went on and thought it wasn't working for everyone.
Sep 13, 2013 2:07 AM

Offline
Apr 2013
174
koleare said:

Prequel said:
If attacks made without creating accounts, then why ip-change sensivity thingy?
The same individual who attacked MAL now, attacked it two years ago as well. He could take accounts without any problem. Now he can't, because there's an ip block.


First of all, thanks for answering.

Now, I don't understand how forced log-outs can be related to IP block to a malicious person. It must be possible to block an IP without applying IP sensivity to whole site. Why exactly do we have to re-login when we change our IPs?
Open to chat about any storytelling related subject as long as it's clever and respectful.
Myanimelist
Sep 13, 2013 2:30 AM

Offline
Aug 2010
2344
Prequel said:
Now, I don't understand how forced log-outs can be related to IP block to a malicious person. It must be possible to block an IP without applying IP sensivity to whole site. Why exactly do we have to re-login when we change our IPs?
The IP block isn't for the malicious person. Well, blocking isn't really the best word either. Mostly and in simpler terms, your IP is used in the authentication process and session, so when your IP changes, the previous session isn't valid anymore and you have to authenticate/log in again. This pretty much prevents your session from being hijacked (http://en.wikipedia.org/wiki/Session_hijacking) like it happened two years ago.

Ah, and the forced log outs aren't related to the IPs. As I said, those were incompatibilities with the new security updates which fight DDoSes.
koleareSep 13, 2013 2:36 AM
Pages (3) [1] 2 3 »

More topics from this board

» [Challenge] You Should Read This Manga 2024 ( 1 2 3 4 5 )

Kineta - Feb 23

201 by EverySportsAnime »»
5 hours ago

» New Site Update: Peak Anime đź—» ( 1 2 3 4 5 )

Kineta - Mar 31

213 by Destinesia »»
8 hours ago

» Heavenly Easter Delusion: Devil and Dolce ( 1 2 3 4 5 ... Last Page )

Kineta - Mar 27

3340 by Terra_strong »»
Apr 17, 8:26 PM

» MAL Game "Fantasy Anime League" Opens for Spring 2024 ( 1 2 3 )

Kineta - Mar 17

144 by The_real_maomao »»
Apr 9, 4:26 PM

» English Titles Added to Desktop; Moving Towards a Romanized/English Toggle ( 1 2 3 )

Kineta - Feb 12, 2020

121 by Vaturna »»
Apr 4, 5:31 AM
It’s time to ditch the text file.
Keep track of your anime easily by creating your own list.
Sign Up Login