Forum Settings
Forums
New
Oct 26, 2017 1:17 PM
#1
Lead Admin
Faerie Queen

Offline
Aug 2007
6264
We have noticed an increase in brute force hacking attempts on user accounts recently. While we have increased the strength of our login system, there are limits to what we can do to combat this when users are not taking basic account security precautions themselves. Thus, we are hoping to remind everyone of some things you should be doing (both on and off MAL) to help prevent your accounts from being compromised.


If you have a simple password, please update it immediately.
Within the last two years, MAL has considerably increased its password requirements in attempt to help you keep your account safe. However, if you have not changed your password since 2015 or before, you may still be using a very simple password. Please update this immediately. All passwords should consist of upper and lower case letters, numbers, and special characters for maximum security.

Change your passwords frequently.
Even a complex password can be brute forced: it simply requires more time than a simple one. By keeping your passwords complex and changing them often, you can greatly reduce the chances of having your account stolen from you.

Do not use the same passwords on many accounts across the internet.
Doing so increases your risk of losing access to all of your accounts, including email, Amazon, Paypal, Facebook, blogs, etc. By having them all the same, a potential hacker only needs to compromise one site to have all of your personal information.

Make sure your email address on your account is up-to-date.
This ensures you can receive password resets if you forget your complex password, and that we can contact you if need be. You can change your email address here: http://myanimelist.net/editprofile.php?go=myoptions Please note that the following domains often bounce MAL's emails: http://myanimelist.net/forum/?topicid=252840

Do not enter your personal details into any form on the internet that you are not 100% aware of.
In the last year or two, we've seen a dramatic increase in the rise of phishing sites, pretending to be MAL. Do not enter your login information to any site before checking your address bar to ensure you are on the correct website.

Consider backing-up your list from time to time.
You can use our list export feature any time from this link: http://myanimelist.net/panel.php?go=export or the "file" icon on your Anime/Manga list navigation.


We will continue to do everything we can to ensure your accounts are kept safe. However, we need you to be committed to performing basic account security precautions as well; otherwise, everything we do will only be partially effective.

And for those who already are aware of, and practising, the above—have yourself a cookie ;)

KinetaMar 29, 2018 3:59 AM
Pages (3) [1] 2 3 »
Oct 26, 2017 1:23 PM
#2
Offline
May 2017
16
Oohh, this is scary. Just what I needed for Spooktober
Oct 26, 2017 1:28 PM
#3

Offline
Sep 2012
3601
Not sure but from what I know MAL is still not using OAuth2. I hope I am wrong.

Also another way to prevent this is using a system like gmail where it send a email to you if the IP of login-try is different.

Or maybe a system like steam but that would be overkill.
Oct 26, 2017 1:44 PM
#4

Offline
Oct 2014
3648
Are passwords still sent in plaintext?? What is point of changing passwords if they can spoof it?
Oct 26, 2017 1:53 PM
#5

Offline
Jan 2009
92571
maybe its time for a multi-factor authentication login? like steams 2 factor authentication but ye just make this optional since not everyone likes that kind of login
Oct 26, 2017 2:06 PM
#6

Offline
Mar 2014
18200
All MAL really needs is a timer to retry the password, 10 seconds should be good for every try and have an email sent after like 5 tries.
MAL doesn't really have anything important to have really heavy login security and the only thing you should worry about is not giving crackers the chance to test a user's password so they could use it on another website. Obviously, protecting the passwords themselves should also be done but that's a given.
Oct 26, 2017 2:12 PM
#7
Offline
May 2016
2
MAL also doesn't really need a super secure website, the worst personal info in here is email. The failed attempt delay would be nice, but two step could kill the fanbase
Oct 26, 2017 2:19 PM
#8
Offline
Jul 2018
564610
Paulo27 said:

MAL doesn't really have anything important to have really heavy login security .


This. I would understand if someone were to put personal info, but what could the crackers do with a simple profile with only the bare minimum? Make one look like he has bad taste? Delete entries? It would be like getting a key without knowing wich door it opens.
This could be scary only in two accounts that I am aware of:
1)both the MAL and e-mail accounts were to share the password
2)were one a MAL supporter and linked the PayPal account to the website
MAL adminship can do only so much though. Anyone at least a bit understanding of the Web's dangers should have been aware of this already. Still, thanks for putting a big Wet Floor sign.
Oct 26, 2017 2:23 PM
#9

Offline
Sep 2012
3601
@Petrosino

Well tell that to Apache server MAL is using. I am just lazy to open my VM Manjaro and find which apache version MAL is using via Wireshark then list all the vulnerabilities of that version.
Oct 26, 2017 2:31 PM

Offline
Feb 2013
24143
Thanks for the reminder.
Normally, how much time it's recommended to keep the same password without changing it?
Even if it's super strong.
Oct 26, 2017 2:36 PM

Offline
Sep 2012
3601
@Ulquiorra

Until someone hacks the DB really.

Brute force is the worst way to steal an account when it comes to long and strong passwords. Here some graphs:

Oct 26, 2017 2:37 PM
Offline
Jul 2018
564610
@sasalx

I always thought that scammers and bad folk, if they really wanted to, could find any information they could on anyone simply by crosschecking information coming from different websites and then doing the maths, if what you're referring to is identity theft.
It's not that hard, I'm no IT guy and I've tried myself. It's super fun gathering all kind of information one spreads on the net. Were one aided by software it would be even easier.
Oct 26, 2017 2:45 PM

Offline
Sep 2017
2999
Hacking is inevitable although it is a pain to change passwords ill do it.
"When you made this thread, I cried and screamed"


-Swagernator 2017
Oct 26, 2017 3:00 PM

Offline
Sep 2012
3601
@Petrosino

Well yes but my point is a dev should try his/her best to secure the site.

Why are we still using Apache?
Why are we still using BBCode? (Post date of article: 2009-09-18 01:54:17. Fixed 6 days ago)
Why are we not using OAuth2?

All I can praise is they are using lodash and latest versions of it has no vulnerabilities.

Oct 26, 2017 3:14 PM
Offline
Jul 2017
1
I recommend passwords with
Caplocks.

like : AnIMeLoVEEEr89(or)ANIMELOVER89<= this kind of password works 100%.
Reminder : Dont Post Any Important Imformations in the internet.
Internet can be a dangerous place.
Dont even bother being famous and take a pic about your self and post in the internet because those things will forever be in the net once its posted.
-Have a good day.
Oct 26, 2017 3:24 PM
Offline
Oct 2017
1
When you are in the internet
Avoid Posting your pics about you
and also remember to use fake names fake data fake info about you.
Keep your real life and net life apart.Internet is indeed "Dangerous" since billions of people use it and people are trolls and hackers.
Oct 26, 2017 3:27 PM

Offline
Jan 2009
92571
Silent____MAL said:

Avoid Posting your pics about you


too late for me lol

well they will not find anything valuable/profitable on a poor person like me living in a poor country anyway
Oct 26, 2017 3:36 PM

Offline
Feb 2015
13840
If you have a simple password, please update it immediately.
Within the last two years, MAL has considerably increased its password requirements in attempt to help you keep your account safe. However, if you have not changed your password since 2015 or before, you may still be using a very simple password. Please update this immediately. All passwords should consist of upper and lower case letters, numbers, and special characters for maximum security.


Dear Hacker-sama,
If you are even thinking of hacking my account, please spare my hentai list. Thank you and have a good day!

Sincerely yours,
_Ako_


>currently thinking of adding emojis in my password

Oct 26, 2017 4:43 PM

Offline
Mar 2008
333
what about putting up a recaptcha as hotfix. Might break 3rd party client tho
Oct 26, 2017 4:51 PM

Offline
Jul 2012
660
Cool. Immidiately changed my password to a very strong one.
Tom's Hardware graphics veteran++ (Legacy)
i7 6700K@4.0 GHz, ASUS Z170 PRO GAMING, RTX 2080, G. Skill RipJaws V 3200MHz 16GB,
Noctua NH-D15, CorsairRM 850x, Win10x64, 1920x1080

MyAnimeList!
Oct 26, 2017 4:52 PM

Offline
Apr 2017
2682
wow, I have all of these


surprised I didn't get hacked...
mal's raccoon

boop !
‎ ‎ ‎‎ ‎ ‎ ‎ ‎ ‎ ‎ ‎ ‎ ‎ hell yeah !
from the distant
year of


the
are after me !
Oct 26, 2017 4:57 PM
Offline
Jan 2013
10764
A crackdown to the sexbots I see
gone bai bai
Oct 26, 2017 4:59 PM

Offline
Sep 2017
60
Kineta said:
Consider backing-up your list from time to time.
You can use our list export feature any time from this link: http://myanimelist.net/panel.php?go=export or the "file" icon on your Anime/Manga list navigation.


Relevant question: Is there a (user)way to import the document?
I´ve read a post, stating it could be done with the help of a mod.

Well, if there is an way, I got some nifty ideas.
I did go over some apps using the MAL-API, but so far I did not encounter anything that would allow me to import a complete document.
Oct 26, 2017 5:13 PM

Offline
Sep 2017
60
dragonshade said:
what about putting up a recaptcha as hotfix. Might break 3rd party client tho


BUUUURN! My anti-captcha only solves ~20%, so no, don´t.
The option for a 2-step-verification however...

Either way would put stress on the team and server, for little to no gain.
Oct 26, 2017 5:16 PM

Offline
Sep 2012
3601
@Dustbreath

MAL sadly still using XML so by sending the file they can put it to DB for you. You might do with API but you have to code from 0.
Oct 26, 2017 6:42 PM

Offline
Sep 2017
60
@sasalx

Excel is love, Excel is live!
I did go thru the database-file of said apps, but nothing was up for the task in mind.

Will dive into the API documentation, but coding from scratch....nmhhhh, maybe with my next reincarnation...
Oct 26, 2017 6:50 PM
Offline
May 2009
149
@Kineta
Thanks mate that is really great to know disaster might be just right around the corner :( does this happen everywhere? How many account has be stolen by theses hackers? I hope its not North Korea doing, i read in the news that North Korea is stepping up its cyber attack.


Mod Edit: Removed unnecessary quote of long OP post for readability.
KinetaOct 26, 2017 9:03 PM
Oct 26, 2017 6:51 PM
Offline
Feb 2017
8
Back in the 1970s, one of the engineers who built the early internet sent out a memo: Passwords need to have uppers, lowers, digits, emoji, special characters, Russian letters and katakanas. That will make it un-hackable! (With 1970s technology.)

I wish I could remember his name. He recently gave an interview admitting he was wrong, 40 years later. Those $00per H4xx0rz passwords are actually the worst kind. They're just as easy to crack, but impossible to remember. So what does everybody do? Write them down!

A much more secure system is to use 6-8 ordinary words that are random but easy to remember. Brute forcing your ampersands is easy, but 6-8 words is 30-40 letters, and NO computer can brute force a password that's long. I wonder if MAL would let you use "battery sent apple your tsumugi honey awful"?
Oct 26, 2017 7:05 PM
Offline
May 2009
149
8 word? You mean a silly password like this example: toilet need to take a **** and **** the girls.

Now that would be somethings that would be tough to brute force (maybe lol), but don't ask me to use something so stupid as a password that i just worded here as an example, i am not that dumb and beside this password is too normal and has no number or capital letters.
Oct 26, 2017 7:06 PM
先輩

Offline
Apr 2016
172
what actual use could there be in trying to hack accounts on an anime website where people keep track of episodes/chapters...
Oct 26, 2017 7:16 PM

Offline
Apr 2015
2866
As some have suggested, optional 2 factor auth would be nice for the site for those of us who prefer extra security. There's only so much that making our passwords more complex can do. Perhaps sending a notification if there have been multiple failed login attempts in a short span of time or timing out attempts temporarily after a number of tries could be other solutions.
Oct 26, 2017 7:26 PM
Offline
Apr 2015
4
Brute Force hacking basically runs through every single combination that the password can be. No matter how strong the password is, it could take as little as a minute to years to crack a simple to encrypted password.
Oct 26, 2017 7:51 PM

Offline
Sep 2017
60
hazekashi said:
They're just as easy to crack, but impossible to remember.

Every good hacking tool does a dictionary attack first, being creativ or having a long password does help.
and NO computer can brute force a password that's long

We will see what cloud-computing / bot-net can do in a not so distant future. Every major nation is looking into brute-forcing military standards. Some might even accomplished that.
Oct 26, 2017 8:25 PM

Offline
Jan 2008
18122
Ah, it is about that time of year again isn't it?

For anyone new, it was pretty common for MAL to get hacked by a certain individual around this time, or I think it was around this time. Took several years but MAL finally did something about it.
Oct 26, 2017 8:27 PM

Offline
Jan 2009
92571
Paul said:
Ah, it is about that time of year again isn't it?


SSJMaster is coming back?
Oct 26, 2017 8:30 PM

Offline
Jan 2008
18122
isekai said:
Paul said:
Ah, it is about that time of year again isn't it?


SSJMaster is coming back?


The only one I've ever seen care to repeatedly hack MAL on a yearly basis so I would assume it's him.
Oct 26, 2017 8:37 PM
Offline
May 2009
149
Paul said:
isekai said:


SSJMaster is coming back?


The only one I've ever seen care to repeatedly hack MAL on a yearly basis so I would assume it's him.


Does SSJMaster do this as an Halloween prank? Does he do this every years? Man what a way to start the event :(
Oct 26, 2017 8:39 PM

Offline
Jan 2008
18122
Redlotusx said:
Paul said:


The only one I've ever seen care to repeatedly hack MAL on a yearly basis so I would assume it's him.


Does SSJMaster do this as an Halloween prank? Does he do this every years? Man what a way to start the event :(


MAL has been able to stop his attacks for the past couple years. Not exactly sure if hacking dozens of MAL accounts and using their accounts to post uncensored gore and mutilation counts as a prank.
Oct 26, 2017 8:58 PM

Offline
Feb 2009
97
Might admin consider increasing the password limit from 50 characters in lieu of these bruteforce attacks?
Oct 27, 2017 12:03 AM

Offline
Aug 2014
70729
Definitely don't use the same password across multiple sites people :P
Databases get hacked all the time, so a lot of your information is just out there on the internet. I've been hacked in a game before simply because I used the same password on another game. That other game had their database hacked, so it was just a matter of time until someone hacked me.

Be safe peeps :3
Oct 27, 2017 12:33 AM

Offline
Feb 2016
1436
So, I guess this is why the password strength is what it is?

I remember when I signed up it took me a minute making my password since I couldn't use my typical run of the mill password due to the strengthened requirements compared to the typical site.

I practice all of the above though aside from "change your passwords frequently". I've only gotten hacked twice, both times on Steam. I was a kid and I had a pretty simple and plain password and Steam Guard wasn't a thing yet =/ Hoorah for Two-Factor Authentication.

I use a unique/strong password on each of my most important accounts now. Although they're all kinda spinoffs of each other. Steam is my strongest one out of the bunch, since that's kinda my #1. Google was #2 but I kept forgetting the password and they keep a log of like every password you use for x amount of time, so I kept running into "You already used this password, Please make something new" >_>

“Don’t just mindlessly judge people as you please.” – Rin Okumura
“Your past shouldn’t stop you from achieving your goals and dreams.” – Rin Okumura
Oct 27, 2017 3:41 AM

Offline
Mar 2013
5831
Fishing with dem phishing
Oct 27, 2017 7:44 AM
Offline
Jan 2016
2
I know im doing something wrong because i keep getting told something along the lines of "confirm passwords are not the same as new passwords" but it doesn't then tell me what i need to change or what a confirm password is plz help.
Oct 27, 2017 8:07 AM

Offline
Sep 2017
840
Maybe add a feature like two authentication like in FB to keep our account safe. Maybe add another email as a backup rather than one.
Oct 27, 2017 8:48 AM

Offline
Dec 2016
255
not sure why people would try to hack my MAL account but w/e, gonna change my password just for safety
WorthinessOct 27, 2017 9:00 AM
Oct 27, 2017 8:57 AM
Offline
Feb 2016
1
Actually, studies show that users shouldn't change their passwords. When a user changes their password often, they're more likely to make it something short and simple that will be dictionary cracked. Also, the longer your password is the harder it is to brute force. Anything longer than 8 characters is generally considered secure against brute force attacks if you're using a secure hashing method. While long passwords can eventually be cracked, most attackers aren't willing to spend years on a single password. It's dictionary attacks that are hard to deal with, and even then a strong password can generally stand up to them (XKCD uses the example "Correct Horse Staple Battery" which is easy to remember and would be secure if it weren't used as a password in a webcomic). The password advice people really need is to make higher entropy passwords that don't follow the general formula (no pet names/last names, no keyboard patterns, no monkeys, no dates, leet speak isn't helpful, etc.)
Oct 27, 2017 10:26 AM

Offline
Jul 2015
88
I don't even know my password hahaha
I login through Facebook... Probably I'm in even more danger lawl
"I died long ago. This is just a bad dream"
Oct 27, 2017 12:26 PM

Offline
Apr 2010
123
tbh if someone manages to bruteforce my password, they deserve the account. There's nothing on here except my anime/manga list. Like what the heck do they think they're going to do with my account? There's no incentive to even bother hacking into accounts on this site, it's nonsensical. What are you gonna do hacker-chan, edit/delete people's lists? Not a very good use of your time...
Oct 27, 2017 2:56 PM

Offline
Dec 2011
766
@EveryOneStillAskingWhyMALPasswordsAreValuable

because you lazy bastards use the same password everywhere. Or similar, one key phrase mixed with some variation of your SSN and bam every password you've ever had for anything.

(Also, if you're an American, and have not done so, please go put a freeze on your credit right now.)
Oct 27, 2017 4:43 PM
Offline
May 2017
15
Hacking is always there... but anime must always be here!!! oWo (lol please don't mind me)
Pages (3) [1] 2 3 »

More topics from this board

» [Challenge] You Should Read This Manga 2024 ( 1 2 3 4 5 )

Kineta - Feb 23

218 by httplatte »»
Yesterday, 4:04 PM

» Moderators Wanted! Accepting applications for all positions

Kineta - Apr 26

0 by Kineta »»
Apr 26, 6:46 PM

» Try MAL's New Mobile Site! ( 1 2 3 4 5 ... Last Page )

Xinil - Feb 15, 2015

423 by RED-clover12 »»
Apr 24, 10:19 AM

» Planned 5hr Maintenance, Thursday April 25 @ 1am-6am PT

Kineta - Apr 22

0 by Kineta »»
Apr 22, 8:10 PM

» New Site Update: Peak Anime 🗻 ( 1 2 3 4 5 )

Kineta - Mar 31

213 by Lancelot73 »»
Apr 21, 4:28 AM
It’s time to ditch the text file.
Keep track of your anime easily by creating your own list.
Sign Up Login