<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Boards.ie Forums have been hacked &#8211; don&#8217;t panic!</title>
	<atom:link href="http://www.stottmeister.com/blog/2010/01/21/boards-ie-forums-have-been-hacked-dont-panic/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.stottmeister.com/blog/2010/01/21/boards-ie-forums-have-been-hacked-dont-panic/</link>
	<description>Christian Stottmeister on code, security and projectmanagement.</description>
	<lastBuildDate>Fri, 04 Jun 2010 07:53:13 +0200</lastBuildDate>
	
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: James Beckett</title>
		<link>http://www.stottmeister.com/blog/2010/01/21/boards-ie-forums-have-been-hacked-dont-panic/comment-page-1/#comment-17035</link>
		<dc:creator>James Beckett</dc:creator>
		<pubDate>Fri, 22 Jan 2010 12:08:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.stottmeister.com/blog/?p=724#comment-17035</guid>
		<description>@m4rkiz vBulletin salts are generated randomly per user at registration time, so that won&#039;t help them in a bulk attack.</description>
		<content:encoded><![CDATA[<p>@m4rkiz vBulletin salts are generated randomly per user at registration time, so that won&#8217;t help them in a bulk attack.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: m4rkiz</title>
		<link>http://www.stottmeister.com/blog/2010/01/21/boards-ie-forums-have-been-hacked-dont-panic/comment-page-1/#comment-17033</link>
		<dc:creator>m4rkiz</dc:creator>
		<pubDate>Fri, 22 Jan 2010 00:18:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.stottmeister.com/blog/?p=724#comment-17033</guid>
		<description>@James Beckett

or if they created some accounts prior to hack they may have a known password with proper hash so finding a salt can be done if it is same for all (or some) passwords in database</description>
		<content:encoded><![CDATA[<p>@James Beckett</p>
<p>or if they created some accounts prior to hack they may have a known password with proper hash so finding a salt can be done if it is same for all (or some) passwords in database</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James Beckett</title>
		<link>http://www.stottmeister.com/blog/2010/01/21/boards-ie-forums-have-been-hacked-dont-panic/comment-page-1/#comment-17032</link>
		<dc:creator>James Beckett</dc:creator>
		<pubDate>Thu, 21 Jan 2010 21:46:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.stottmeister.com/blog/?p=724#comment-17032</guid>
		<description>If the attackers were after the passwords (rather than other useful things in the user database) you have to assume that they also managed to snag a copy of the salt in use.

However, the only likely attack on the password database is brute force, so it might be reasonable to consider only &lt;i&gt;weak&lt;/i&gt; passwords to be at risk - if you used digits only, a dictionary word, a name, or some minor perturbation thereof, you&#039;d be first in the firing line.</description>
		<content:encoded><![CDATA[<p>If the attackers were after the passwords (rather than other useful things in the user database) you have to assume that they also managed to snag a copy of the salt in use.</p>
<p>However, the only likely attack on the password database is brute force, so it might be reasonable to consider only <i>weak</i> passwords to be at risk &#8211; if you used digits only, a dictionary word, a name, or some minor perturbation thereof, you&#8217;d be first in the firing line.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darragh @ Boards.ie</title>
		<link>http://www.stottmeister.com/blog/2010/01/21/boards-ie-forums-have-been-hacked-dont-panic/comment-page-1/#comment-17029</link>
		<dc:creator>Darragh @ Boards.ie</dc:creator>
		<pubDate>Thu, 21 Jan 2010 20:14:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.stottmeister.com/blog/?p=724#comment-17029</guid>
		<description>Thanks very much for this post. Just want to confirm that Boards.ie will NOT be sending out emails with passwords or links. If you receive an email from Boards.ie that asks you to do anything like click a link, log into a website or any other action, please forward it to hello@boards.ie.

DO NOT CLICK IT!

If there&#039;s anything we can help you with, please contact us at hello@boards.ie 

Thanks very much

Darragh</description>
		<content:encoded><![CDATA[<p>Thanks very much for this post. Just want to confirm that Boards.ie will NOT be sending out emails with passwords or links. If you receive an email from Boards.ie that asks you to do anything like click a link, log into a website or any other action, please forward it to <a href="mailto:hello@boards.ie">hello@boards.ie</a>.</p>
<p>DO NOT CLICK IT!</p>
<p>If there&#8217;s anything we can help you with, please contact us at <a href="mailto:hello@boards.ie">hello@boards.ie</a> </p>
<p>Thanks very much</p>
<p>Darragh</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tweets that mention Boards.ie Forums have been hacked – don’t panic! -- Topsy.com</title>
		<link>http://www.stottmeister.com/blog/2010/01/21/boards-ie-forums-have-been-hacked-dont-panic/comment-page-1/#comment-17027</link>
		<dc:creator>Tweets that mention Boards.ie Forums have been hacked – don’t panic! -- Topsy.com</dc:creator>
		<pubDate>Thu, 21 Jan 2010 18:05:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.stottmeister.com/blog/?p=724#comment-17027</guid>
		<description>[...] This post was mentioned on Twitter by thumped.com, Stotti. Stotti said: Article on the security implications of the @boards_ie hack: http://bit.ly/7jcqZ4 Please RT! @basquille @davidcochrane @thumped and others [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by thumped.com, Stotti. Stotti said: Article on the security implications of the @boards_ie hack: <a href="http://bit.ly/7jcqZ4" rel="nofollow">http://bit.ly/7jcqZ4</a> Please RT! @basquille @davidcochrane @thumped and others [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
