Forum Settings
Forums
New
Pages (3) « 1 2 [3]
Nov 5, 2017 2:59 PM
Offline
Oct 2017
2
1.) Apache can be as safe as any other server, I don't get why everyone is freaking out about Apache, they just have to secure it.

2.) Nothing wrong with BBCode

3.) Your passwords are not send over plaintext, I checked, they're two-way encrypted through an SSL-certificate

4.) For strong passwords, avoid common words (like "anime" and "love"), for the love of whatever god you pray to (like Haruhi-chan) use a password manager and generate long, random passwords!

5.) How long till you replace it? If you're paranoid, every 3 months and when MAL knowns they have been hacked. If you're not paranoid, only when they're hacked.
Nov 6, 2017 12:06 AM

Offline
Feb 2015
6845
What I'm wondering is why are people going through the trouble to hack MAL accounts? What is there to gain?
Nov 6, 2017 1:55 AM

Offline
Nov 2012
44
Milennin said:
What I'm wondering is why are people going through the trouble to hack MAL accounts? What is there to gain?


refer to this post for the answer vvvvvvv

sreimund said:
To all of those who ask why someone would hack MAL:


A vast majority of internet users use a password or similar passwords for other websites and services. If you don't do this then obviously you're already ahead of the program but you wouldn't be asking this question either.

Do you know what internet users also like? That's right, unique handles.

Once a hacker obtains one of your passwords that corresponds to your e-mail address or handle elsewhere his chances of being able to get into much more sensitive places increases a thousandfold. From there he could see emails from your bank, possible other websites you're registered to and so forth. Should your security really be lacking even more... Well you get the point.

The question isn't "Why would he want my MAL account", he doesn't want it. The real question is "Is he going to access more than just my MAL account"


tl;dr hackers have little to no interest in your MAL account itself, they simply want working credentials that can be used to access more important services (email, bank, etc).
Nov 6, 2017 6:37 AM

Offline
Oct 2016
229
Tiffanys said:
tbh if someone manages to bruteforce my password, they deserve the account. There's nothing on here except my anime/manga list. Like what the heck do they think they're going to do with my account? There's no incentive to even bother hacking into accounts on this site, it's nonsensical. What are you gonna do hacker-chan, edit/delete people's lists? Not a very good use of your time...


The reason you can't understand their motive is due to the limited scope of your thoughts. This is practice. MAL is a small, relatively helpless target. Such sites are where a hacker will want to trial their automated tools.

edit.

Vampire said:

In my opinion, they should at least:

  • Use OAuth2 for API authorization
  • Hash user passwords with a secure algorithm like argon2 or scrypt
  • Add software and hardware 2FA support (ex. Authy, U2F, backup codes)
  • Send users an email if someone logs in with an unusual IP and/or user agent


Vote Vamp' for prez'.
FelkyrNov 6, 2017 6:41 AM
Nov 6, 2017 6:39 AM
Offline
Jul 2016
32
omg that's scary!
Nov 6, 2017 11:03 AM
Teto

Offline
Sep 2017
607
Tiffanys said:
tbh if someone manages to bruteforce my password, they deserve the account. There's nothing on here except my anime/manga list. Like what the heck do they think they're going to do with my account? There's no incentive to even bother hacking into accounts on this site, it's nonsensical. What are you gonna do hacker-chan, edit/delete people's lists? Not a very good use of your time...


Well if i hacked your acc. i can get ur IP using ur email address. And then there are a few things i can do like send u a virus that steals all your personal info including credit card numbers. Or if ur on a public internet Hackers can easily find ur ip and tap on all ur http infos using arp poisoning.
Nov 6, 2017 9:32 PM

Offline
Nov 2015
73
Thanks for being transparent about this matter~
Nov 7, 2017 9:07 AM

Offline
Apr 2015
20
KADAIMISE said:
1.) Apache can be as safe as any other server, I don't get why everyone is freaking out about Apache, they just have to secure it.


I don't disagree with you about Apache, however, MAL has some security issues with their Apache and SSL setup.


  • Cipher suite should be "EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH" with weaker options as a fallback (this can be done by adding "SSLHonorCipherOrder on").
  • Add "X-Frame-Options DENY" and "X-Content-Type-Options nosniff" headers.
  • Add Public-Key-Pins


Also, I hope that they have disabled SSL compression and session tickets and enabled OCSP stapling with a size of 128000-150000 bytes.
Nov 8, 2017 6:15 AM
Offline
Jul 2014
49
Good, it's about time that somebody changes all of the overblown Gintama ratings to 1/10.
Nov 8, 2017 9:11 AM
Offline
Jan 2014
8
I'm not sure entirely where to say this (whether this is the correct place or whether I should make my own thread in heaven knows what subforum) but maybe it's an idea to be clearer about what a password should look like? I just tried to change my password and it constantly said my password was too weak without specifying why. I didn't really know what the problem could be with a password like Banana01! so in the end I had to solve the problem by making a keysmash password, which isn't really a thing you can possibly remember.
Nov 8, 2017 9:37 AM
Teto

Offline
Sep 2017
607
@Mautris How about BananaHello01 try combing words
Nov 8, 2017 2:10 PM
Offline
Oct 2017
2
Maurits said:
I didn't really know what the problem could be with a password like Banana01!

TL;DR: Throw a bunch of random words in there and be done with it #ConfusedAbashedObceneBananaForLife2017

  1. A common word can easily be cracked through a dictionary attack (the kind of brute forcing MAL was talking about in the first place)
  2. Some numbers don't help too much, especially not an order like 01234 or a common birth year like 1997
  3. A single punctuation mark, especially at the end, doesn't help too much either.

But I agree, MAL should give an explanation or some hints, check this demo and try some 'passwords' out yourself!
MAL seems to use the same password checking library.
Hit the "Break it down!" button to see a breakdown of what the password checker did, although some things might be cryptic to read.

Some tips that apply to that code library (I've used it myself and even expanded it with common Dutch words; the language in question for the website I was developing for at the time):

  1. Avoid common words, or use multiple words, make a password like "ConfusedAbashedObceneBanana", it's safe and funny enough to remember!
  2. Avoid common substitutions, all hackers know the simple i=1 tricks, so "Tr1ck" isn't a whole lot harder to crack, it is a whole lot harder to remember
  3. This goes without saying for any website ever: Use a different password for each account, use a password manager (like KeePass2 for safe offline use or LastPass for easy multiple-device access)
    Like seriously, using a password manager and completely random passwords is the best way to go with passwords ever.
TheRamenDutchmanNov 8, 2017 2:16 PM
Nov 8, 2017 6:07 PM
Offline
Aug 2017
3
Thanks for the information . But how to change the password
Nov 9, 2017 6:42 AM
Offline
Jan 2014
8
KADAIMISE said:
Maurits said:
I didn't really know what the problem could be with a password like Banana01!

TL;DR: Throw a bunch of random words in there and be done with it #ConfusedAbashedObceneBananaForLife2017

  1. A common word can easily be cracked through a dictionary attack (the kind of brute forcing MAL was talking about in the first place)
  2. Some numbers don't help too much, especially not an order like 01234 or a common birth year like 1997
  3. A single punctuation mark, especially at the end, doesn't help too much either.

But I agree, MAL should give an explanation or some hints, check this demo and try some 'passwords' out yourself!
MAL seems to use the same password checking library.
Hit the "Break it down!" button to see a breakdown of what the password checker did, although some things might be cryptic to read.

Some tips that apply to that code library (I've used it myself and even expanded it with common Dutch words; the language in question for the website I was developing for at the time):

  1. Avoid common words, or use multiple words, make a password like "ConfusedAbashedObceneBanana", it's safe and funny enough to remember!
  2. Avoid common substitutions, all hackers know the simple i=1 tricks, so "Tr1ck" isn't a whole lot harder to crack, it is a whole lot harder to remember
  3. This goes without saying for any website ever: Use a different password for each account, use a password manager (like KeePass2 for safe offline use or LastPass for easy multiple-device access)
    Like seriously, using a password manager and completely random passwords is the best way to go with passwords ever.


Hmm, you're probably right about that. Those are some good tips.^^ I usually use a password manager+generator, but not currently, so I guess I was out of practice with thinking of passwords.XD
Nov 9, 2017 12:28 PM
Offline
Jul 2012
5
Fistric said:
Thanks for the information . But how to change the password


In the right hand corner of the main page (or any page really) select the drop-down list (the one with your username and arrow near it) and select account settings.
That's it. Now you can change your password.
Nov 10, 2017 8:07 AM
Offline
May 2013
381
Kineta said:
We have noticed an increase in brute force hacking attempts on user accounts recently. While we have increased the strength of our login system, there are limits to what we can do to combat this when users are not taking basic account security precautions themselves. Thus, we are hoping to remind everyone of some things you should be doing (both on and off MAL) to help prevent your accounts from being compromised.


If you have a simple password, please update it immediately.
Within the last two years, MAL has considerably increased its password requirements in attempt to help you keep your account safe. However, if you have not changed your password since 2015 or before, you may still be using a very simple password. Please update this immediately. All passwords should consist of upper and lower case letters, numbers, and special characters for maximum security.

Change your passwords frequently.
Even a complex password can be brute forced: it simply requires more time than a simple one. By keeping your passwords complex and changing them often, you can greatly reduce the chances of having your account stolen from you.

Do not use the same passwords on many accounts across the internet.
Doing so increases your risk of losing access to all of your accounts, including email, Amazon, Paypal, Facebook, blogs, etc. By having them all the same, a potential hacker only needs to compromise one site to have all of your personal information.

Make sure your email address on your account is up-to-date.
This ensures you can receive password resets if you forget your complex password, and that we can contact you if need be. You can change your email address here: http://myanimelist.net/editprofile.php?go=myoptions Please note that the following domains often bounce MAL's emails: http://myanimelist.net/forum/?topicid=252840

Do not enter your personal details into any form on the internet that you are not 100% aware of.
In the last year or two, we've seen a dramatic increase in the rise of phishing sites, pretending to be MAL. Do not enter your login information to any site before checking your address bar to ensure you are on the correct website.

Consider backing-up your list from time to time.
You can use our list export feature any time from this link: http://myanimelist.net/panel.php?go=export or the "file" icon on your Anime/Manga list navigation.


We will continue to do everything we can to ensure your accounts are kept safe. However, we need you to be committed to performing basic account security precautions as well; otherwise, everything we do will only be partially effective.

And for those who already are aware of, and practising, the above—have yourself a cookie ;)



Thanks for update
Have Great Day =)
Animekid3


I'm level on mal-badges. View my badges.
Nov 10, 2017 1:22 PM

Offline
Mar 2017
34
so , this is . i even can't access MAL right now without vpn.
under construction
Nov 10, 2017 3:56 PM
Offline
Feb 2016
4
Signing up for some kind of a password manager is a good option. I like having my passwords be a random jumble of at least 24 characters, letters, and numbers. No possible way I could remember all of them. I like 1password. I tried last pass for a night and absolutely hated it. Immediately went back to 1password.
Nov 11, 2017 7:10 AM
Teto

Offline
Sep 2017
607
Tiffanys said:
tbh if someone manages to bruteforce my password, they deserve the account. There's nothing on here except my anime/manga list. Like what the heck do they think they're going to do with my account? There's no incentive to even bother hacking into accounts on this site, it's nonsensical. What are you gonna do hacker-chan, edit/delete people's lists? Not a very good use of your time...

Well ur email is the only real problem. I can track ur email. Or send viruses to ur mail and much more.
Nov 11, 2017 2:43 PM
Offline
Oct 2015
50
Hackers are just sad people with nothing better to do than ruin other people's lives because theirs is so crap. Mum probably didn't love them and give them hugs as a child.
Nov 12, 2017 9:40 AM
Teto

Offline
Sep 2017
607
Remrin said:
Hackers are just sad people with nothing better to do than ruin other people's lives because theirs is so crap. Mum probably didn't love them and give them hugs as a child.

Ah U don't know much about hackers, do u? There are many types of hackers the ones u're talking about are black hats. There are white hat hackers who hack for the good of humanking.
Nov 12, 2017 11:51 AM
Offline
Oct 2015
50
Yuki_10 said:
Remrin said:
Hackers are just sad people with nothing better to do than ruin other people's lives because theirs is so crap. Mum probably didn't love them and give them hugs as a child.

Ah U don't know much about hackers, do u? There are many types of hackers the ones u're talking about are black hats. There are white hat hackers who hack for the good of humanking.


Good hacking, like?
Nov 12, 2017 12:13 PM
Teto

Offline
Sep 2017
607
Remrin said:
Yuki_10 said:

Ah U don't know much about hackers, do u? There are many types of hackers the ones u're talking about are black hats. There are white hat hackers who hack for the good of humanking.


Good hacking, like?

The white hats are the ones who work for companies and gvernments.
They hack the company's system and check for vunerablities. They tell the company how to improve their security and etc. This job is called Ethical hacking.
Nov 12, 2017 1:04 PM
Offline
Oct 2015
50
Yuki_10 said:
Remrin said:


Good hacking, like?

The white hats are the ones who work for companies and gvernments.
They hack the company's system and check for vunerablities. They tell the company how to improve their security and etc. This job is called Ethical hacking.


Oh right, so they hack to stop other hackers.
Nov 12, 2017 8:13 PM
Teto

Offline
Sep 2017
607
@Remrin In a way yes. But the problem is nothiing is unhackable for a trained hacker.
Nov 13, 2017 8:53 AM

Offline
Jan 2015
17
Thanks for warning. Good job :)
Nov 15, 2017 6:53 AM
Offline
Sep 2015
70
Now this is scary...
Nov 15, 2017 7:12 AM

Offline
Nov 2017
384
A hack attack? D'awww.... How lovely to read about it on each anime website I give/gave a little visit from time to time. How sad it must be for the hackers that I never even use the same e-mail twice anywhere.
Have fun on hacking a 24h old account 'pal'. You got user -Mikoto- my pw here and... I dunno. lmfao
𝘠𝘰𝘶 𝘫𝘶𝘴𝘵 𝘥𝘰𝘯'𝘵 𝘨𝘦𝘵 𝘪𝘵 𝘥𝘰 𝘺𝘰𝘶?
𝘐'𝘮 𝘯𝘰𝘵 𝘴𝘵𝘶𝘤𝘬 𝘩𝘦𝘳𝘦 𝘸𝘪𝘵𝘩 𝘺𝘰𝘶.

¡ǝɯ ɥʇᴉʍ ǝɹǝɥ uᴉ ʞɔnʇs ǝɹ,no⅄
Nov 17, 2017 4:46 AM
Offline
Nov 2017
1
Don't worry about ol' me, we here at The Flava-macs aren't getting hacked. Don't really know the logic behind the decision but this here is a shared account... :^ ))
Nov 21, 2017 5:25 AM
Offline
Jul 2017
10
Personally,it's good for me tho...security is on decent level 👌
Nov 23, 2017 8:37 AM
Offline
Mar 2008
106
Just as a personal grumbling... by asking OLD password after hitting next and after entering the NEW password twice, you are overwriting the new PW entries stored in password managers with the old password when a user clicks "update entries" on the relevant plugin prompt in the wrong moment..... and if a user stores the randomly genned password after hitting NEXT, he won't have an "old" password to enter to actually facilitate the change, thus locking em out of the account ;p

The other way around, if you DON'T update the new pw, you can't actually login after changing the pw, since the old pw is stored because of how the process goes, not the new pws.

Since that just happened to me (maybe shouldn't do this when falling asleep) I figured I write about it ;p

Ps.: Basically I am saying the order of that is backwards, first ask old password, then next, then new passwords -> Submit thus a pw manager like lastpass, or indeed Firefox and Chromes inbuilt ones are not confused by the process and lock you out of your account because the old password was overwritten, and pw overwrites can't be undone. ;P
eRe4s3rNov 23, 2017 8:44 AM
Nov 23, 2017 3:51 PM

Offline
Jun 2012
1402
Wait, there were phishing sites similar to MAL? Never saw one...
Nov 25, 2017 2:45 AM

Offline
Feb 2016
1414
I login by SNS. So, am I fine or should I strengthen my security for the app that I use for SNS too?
-Haoto-May 25, 12:56 AM

YouTubeWeird Videos
Anime Edits
PixivSheetHost

"Salvation is a thin thread dangling from heaven."
- Mary ~ Death Mark

Nov 25, 2017 5:53 PM

Offline
Jul 2017
110
Please add two-step verification to MAL accounts.
Nov 26, 2017 12:40 PM

Offline
Jul 2015
1632
Btw, what can we do if our account gets hacked?
Nov 27, 2017 7:54 AM
Offline
Apr 2011
457
I guess it's time to update my password!
Nov 27, 2017 10:05 AM
Teto

Offline
Sep 2017
607
Orion_Gospel said:
Btw, what can we do if our account gets hacked?

Good question, Ask Mal. Normally we have to verify our identity.
Nov 27, 2017 10:14 AM

Offline
Jul 2015
1632
Yuki_10 said:
Orion_Gospel said:
Btw, what can we do if our account gets hacked?

Good question, Ask Mal. Normally we have to verify our identity.


I didn't find anything about hacking at all. Neither about verification.
Nov 27, 2017 8:50 PM

Offline
Apr 2011
13785
Haven't changed my password, not going to. Besides, they hack into it and what're they gonna do? Remove my list? Post porn using my account? Didn't care, don't care, won't care.
Nov 27, 2017 11:34 PM
Offline
Sep 2016
2
What exactly could someone gets by hacking a MAL account ?
Nov 28, 2017 10:26 AM
Teto

Offline
Sep 2017
607
GeneralEcchi said:
What exactly could someone gets by hacking a MAL account ?

Many things Your Ip(not sure), your Email, your credit card numbers(maybe), he can also use your accounts for other purposes like starting a discussion and putting a malicious link, and etc.
Dec 4, 2017 2:45 PM
Photojournalist

Offline
Apr 2007
666
Many people here do not seem to care if someone broke into their account but some of us, like me, do. I would hate to lose any part of my account after spending 10 YEARS and counting on my database. It would suck even worse if it was because MAL has lazy or incompetent admin who didn't bother to update anything. That would be a slap in the face of us users who actually trust MAL to make sure their website is safe and secure to use.
Feb 20, 2018 12:52 PM

Offline
Sep 2017
4
aight
Mar 24, 2018 1:37 AM
Offline
Mar 2018
1
I cannot login my palpocket
Mar 24, 2018 4:52 PM
Offline
Jan 2018
1
wow lit
Pages (3) « 1 2 [3]

More topics from this board

» Related Anime/Manga Section Changes ( 1 2 )

Kineta - May 23

97 by RobbiRobb »»
4 hours ago

» MAL Game "Fantasy Anime League" Opens for Spring 2024 ( 1 2 3 )

Kineta - Mar 17

145 by Vulpix98 »»
7 hours ago

» [Challenge] You Should Read This Manga 2024 ( 1 2 3 4 5 )

Kineta - Feb 23

246 by tingy »»
8 hours ago

» Favorites Boosting Accounts: Ranking Recalculations ( 1 2 3 4 5 ... Last Page )

Kineta - May 6, 2021

404 by bastek66 »»
Yesterday, 7:41 PM

» Planned 3hr Maintenance, Wednesday May 29 @ 1am-4am PT

Kineta - May 26

0 by Kineta »»
May 26, 3:57 PM
It’s time to ditch the text file.
Keep track of your anime easily by creating your own list.
Sign Up Login