You are viewing an archive of Victory Road.
Victory Road closed on January 8, 2018. Thank you for making us a part of your lives since 2006! Please read this thread for details if you missed it.
Has anybody heard of that hacker that hacked many Pokemon websites, and made I link to his twitter page and stuff like that?! He got some major websites too including Smogon, Serebii and ******* ********. I found out about this because of another forum I reside on got hacked by this hacker as well. Apparently the name is; Rootinabox
It is confirmed that Smogon is doing perfectly fine, they are using this downtime to upgrade!
4 – Reuniclus, PureAurorae, TurtwigX, TwiggyI'm not much of a fan of what the sole hacker did on the Pokémon forums. It seems to be done to prove a point. For what, though? Leaking user data isn't the nicest thing you can do in such a situation.
It's like... The hacker knows what he is doing in a weird way. All this screams "script kiddie", but it's still bad when it cones to user data.
I don't even think smaller sites will be safe. Stay on your guard, everyone.
1 – PHANTOMxTRAINERPerhaps all this hacker wants is publicity. Unfortunately...people seem to be talking about him all over the place by now. I think the best thing anyone can do in this situation is to just ignore him.
This reminds me of the Conjopi incident that happened on Youtube a couple years ago. Back then, he would exploit Youtube's horrendous flagging system and falsely-flag LPer's videos to get them off Youtube. I remember people like Chugga and NCS were affected by this for nearly a week. Some other LPer I was watching at the time actually took down all of his videos and put them in private to avoid them getting falsely flagged.
1 – PHANTOMxTRAINERI'm going to perform another security audit to make sure we're good to go.
By the way, I've gotten some more details about a certain other forum getting hacked. Apparently, they allowed their moderators the permission to modify user details, including their passwords. A moderator was hacked, and that account was used to modify an administrator's password. That administrator account was used to upload a plugin to the admin panel, which returned the login details for the forum user on the MySQL database server, effectively giving them access to the entire forum database.
Another thing to note: all of these sites are running vBulletin, so the plugin is practically universal.
2 – Cyrus, PHANTOMxTRAINER
1 – PHANTOMxTRAINERYeah, the version of the software we're using doesn't matter. The biggest problem is that many of the sites entrusted their moderators (if even not deliberately) with those powers. There's a reason I wiped a lot of Freeze's stuff after he left. I don't need more backdoors for hackers.
1 – PHANTOMxTRAINER
1 – PHANTOMxTRAINERKYA is still an admin on the server, and he's pretty serious about system security.
1 – PHANTOMxTRAINER|
I'm going to perform another security audit to make sure we're good to go.
By the way, I've gotten some more details about a certain other forum getting hacked. Apparently, they allowed their moderators the permission to modify user details, including their passwords. A moderator was hacked, and that account was used to modify an administrator's password. That administrator account was used to upload a plugin to the admin panel, which returned the login details for the forum user on the MySQL database server, effectively giving them access to the entire forum database. Another thing to note: all of these sites are running vBulletin, so the plugin is practically universal. |
1 – PHANTOMxTRAINERI think the most likely candidates are those who know very little about security--typically those with a fairly new site and no record of previous webmaster work--and follow poorly-written guides for setting things up that include stuff like:
GRANT ALL PRIVILEGES ON *.* TO 'forumuser'@'%'
IDENTIFIED BY 'password' WITH GRANT OPTION
1 – PHANTOMxTRAINERYeah, I'm a member on ***, & I started to change my passwords when the hacking stuff started to happen. I'm going back & changing everything again since BMGf got hit.
The recommendation I've heard is to change all passwords associated with your email address on forums. I'm doing it 'cause I'd rather be safe than sorry.
| "hacking" |

3 – Cat333Pokémon, Twiggy, GTP_NickSkyline

Good to see Cat Triple Three has security and backups in place. It's nice to know we are at least not caught unprepared for this kinda thing. I don't use the other Pokemon websites unless I'm looking for Lopunny and Absol in a game, but other than that I just come here when I get a Pokemon itch.
I digress.
I know some users here are underage, so I'll reiterate: Guys, never give out your passwords. Oftentimes when someone says hacked in a website or game or something, it usually means they gave away the email cause they wanted free premium content, or a mysterious user that typew in disjointed Engrish wants to give YOU super secret admin powers for seemingly no reason at all. Be on the look out guys.
1 – AquablastOf all fandoms to be attacked... why Pokémon? There are far worse.... of which I shall not name as to not offend >.>
1 – GalliumGrant