MFGG Forums
  • Home
  • Members
  • Help
  • Search
MFGG Main Site MFGG Forums MFGG News and Events v
1 2 3 4 5 Next »
About the main site news
MFGG Forums MFGG News and Events v
1 2 3 4 5 Next »
About the main site news
MFGG Forums MFGG News and Events v
1 2 3 4 5 Next »
About the main site news
Mark All Posts Read Today's Posts

About the main site news
Turkey Mors
hey guys
Site Developer
Forum Moderator Main Site Moderator Discord Admin Site Developer/Webmasters Social Media Manager Submitter Super Reviewer Iso Collab Contributor Sprite Comp Runner-Up (2) Sprite Comp Top 5 Minigame Comp Runner-Up (2) Minigame Comp Top 5 (5) Music Comp Top 5 (2) Egg Hunter Skull Badge (2) E3 Bingo Event Winner Game of the Month Winner NCFC Contributor Secret Santa Holiday Tree MFGG 17th Anniversary MFGG 18th Anniversary MFGG 19th Anniversary MFGG Awards 2014 Winner MFGG Awards 2015 Winner MFGG Awards 2016 Winner MFGG Awards 2017 Winner (2) MFGG Awards 2018 Winner MFGG Awards 2019 Winner MFGG Awards 2020 Winner
#1
04-09-2024, 02:32 PM
So, if you've been to the main site you might have noticed that the last news post is from 2021. Whuh? What? You might have also heard about something along the lines of the main site getting compromised.

TL;DR: Someone compromised a staff account, deleted all the news posts, and promoted their own stuff. No need to worry though because we do have backups and will restore things fully soon.

That being said, if I was just a regular member of the community, and something like this had happened but the details were swept under the rug with just that, I'd be annoyed. So to have full transparency, this post will have a full explanation of the events that had transpired.

But before that, I will emphasize a few things:
  1. Nothing is lost permanently here. They deleted the news, but we temporarily restored all the ones from up to 2021 for now, and will bring back the rest shortly (from an off-site backup hopefully).
  2. Except for a certain specific user I'll get to, your account is safe and not accessed from outside.
  3. Nothing else is touched. The games and whatnot are intact and safe.
  4. There's no real big security risk going on. There's no backdoor as far as we know, it's just someone guessing a staff account's password.
  5. This is not connected to any other prior incident.
  6. They didn't have access to the full backend of the site. Only a specific portion, which they seemingly only used to snoop on one member, then spam on the news section.
How are we so sure about all this though? Well, it's because we can see everything. Every single move of these people has been logged, including the pages they have visited. So we know exactly what they did, in what order.

So here's what happened, based on what I heard from the staff members who were awake at the time, and my own investigation of the logs:
  1. They first visited a user's profile. When you google their name, MFGG is one of the first results to pop up, so that's likely how they discovered the site. This user had never done anything on the site, at least since the late 2000s.
  2. They tried to log in to it, but failed.
  3. So, they tried to log into various staff accounts instead. They got the password wrong many times in the process.
  4. But eventually one of them worked. Our guess is that the password was either super easy to guess, or it was included in a prior database leak from a different website. This is why you don't use the same password across multiple websites.
  5. Using the staff account they immediately took control of the mystery user's account as well. From what I can tell, they proceeded to do nothing with it, and the account itself did not contain much information. We ended up locking this account.
  6. They also banned me to prevent me from stopping them. I was asleep at the time, as this whole thing happened around at 6 AM for me, so I was not there to see my first MFGG ban, sadly.
  7. They deleted pretty much all the main site news posts as well. Come on man...
  8. They then started posting a bunch of news post of their own, flaunting their victory, and promoting their Twitter accounts. Those accounts are pretty barren though, and mostly have posts related to... Yep, you guessed it, Roblox.
  9. Fun With Despair noticed all this and tried banning them. Before he could though, they just changed the password of his account and started using it to spam instead.
  10. We quickly tried to sort things out, reverted back a quick backup we had from 2021 for emergencies, cleared session records to log them out of the staff accounts, reset the passwords of ALL staff accounts, and deleted the accounts they had made.
  11. Turns out this was not enough and they were still somehow logged into Despair's account, so we additionally IP banned them as well, and temporarily banned Despair's account also just to be safe.
Now, some of you might realize this all sounds eerily similar to two other incidents that had transpired before.

Some MFGG and Mario Flashback OGs will remember the Roblox raids. To sum it up, there used to be a group of people who would use exploits to put messages in popular Roblox games (I'm talking about games played by millions) that tell them to raid a server to receive free Robux (Roblox currency). MFGG was a target of these attacks. Why? No idea, none of us got anything to do with Roblox. But I'm almost certain that those people who organized the raids are not the same people who nuked the news posts here. It's just that Roblox attracts a lot of toxic kids. We also don't know the identity of those raiders, don't pay attention to anyone else who says otherwise.

The other incident in question is the previous main site takeover. There was another incident of another staff account getting compromised in the exact same way, and someone spamming stuff in the news, with far less impact. We had taken precautions after the said incident, and even revamped the entire backend to improve the site's security as a whole, but it clearly wasn't enough and some staff members still kept using unsecure passwords.

We have also been dealing with the issue of an individual from an affiliated community joining our Discord server to spam slurs and random screenshots. That's also unrelated.

As the MFGG staff we made one big crucial mistake here. We did not make absolutely sure that all staff accounts, including the inactive ones, used secure passwords. We kinda just trusted each other, but that was clearly not enough. Thankfully, nothing serious happened outside the temporary loss of news posts, but things could be so SO much worse. Still, we are going to take full responsibility for this breach, and make ABSOLUTELY SURE nobody's able to brute force into staff accounts in the future. We are terribly sorry for all that happened.

There are a few lessons to learn here:
  1. Do not reuse the same password in multiple places. Use a password manager if necessary.
  2. If you have old, unused accounts on sites where the account getting compromised would be a problem, please make sure that they have strong passwords.
  3. Make frequent backups.
  4. Don't let your kids play Roblox.
And lastly, I want to just say that please remember that all the staff members here are just volunteers who like the Mario franchise and the underground fangaming culture MFGG represents. We don't make money from running this site, and it's not fun to constantly deal with raids and stuff like this. Please try to be understanding.
[-] The following 14 users Like Mors's post:14 users Like Mors's post
  ↳ DogToon64, Fun With Despair, GeneralGuy, Klug, KrystalPhantasm, littlelum, matrix, OssieTheOstrich, Q-Nova, Randomanian Creatomertist, Roo, SonicKade2048, Vert, VinnyVideo
Fun With Despair
least useful staff member
Discord Admin
Main Site Moderator Discord Admin Submitter
#2
04-09-2024, 02:41 PM (This post was last modified: 04-09-2024, 02:41 PM by Fun With Despair.)
To add to this, while we did not have any passwords or information leaked as a result of this attack, I would still highly recommend changing your password, especially if your account is rather old.

It is somewhat likely that they got this password from an external leak of passwords that happened to be shared with their MFGG password as Mors summarized, and as a result it is unknown if they have other passwords. Shortly after their removal from the site, they used an account made in 2006 to submit an empty "game" with a description containing the spam they were posting on the main page likely as another form of taunt.

Whether they got into this account via resetting the password or via similar means (using leaked passwords from elsewhere) isn't really known but I would play it safe just in case. While it's unlikely that an average user account getting hacked would lead to anything beyond more spam, it's still good to stay on top of your passwords and make sure you aren't using a password shared with another site.
[-] The following 6 users Like Fun With Despair's post:6 users Like Fun With Despair's post
  ↳ DogToon64, KrystalPhantasm, matrix, Mors, Roo, SonicKade2048
Vert
Eternal wage slave
Members
#3
04-09-2024, 03:21 PM (This post was last modified: 04-09-2024, 03:23 PM by Vert.)
Why do Roblox kids hate Mario fangames so much? It boggles the mind.

Anyway, seeing as they failed to break into the site through other ways, it really reinforces how the weakest link in computer security is the guy behind the screen. Maybe there should be an official procedure for dealing with old staff accounts to prevent this in the future?
I make games with my friend DJ Coco sometimes. Check them out here: https://cliax-games.com/
Or check out my blog: https://vertette.github.io/

  ↳
Fun With Despair
least useful staff member
Discord Admin
#4
04-09-2024, 03:31 PM
(04-09-2024, 03:21 PM)Vert Wrote: Why do Roblox kids hate Mario fangames so much? It boggles the mind.

Anyway, seeing as they failed to break into the site through other ways, it really reinforces how the weakest link in computer security is the guy behind the screen. Maybe there should be an official procedure for dealing with old staff accounts to prevent this in the future?
This is actually being discussed right now. Its probably going to be the case that we go through and make sure no previous staff members or inactive staff accounts in general still have any access above that of a normal member.
[-] The following 2 users Like Fun With Despair's post:2 users Like Fun With Despair's post
  ↳ Roo, Vert
Namedude
Lenolol
Members
#5
04-09-2024, 03:40 PM
(04-09-2024, 03:21 PM)Vert Wrote: Why do Roblox kids hate Mario fangames so much? It boggles the mind.

Because Roblox kids hate fun.
[-] The following 1 user Likes Namedude's post:1 user Likes Namedude's post
  ↳ AGuyCalledKlaz
Brazil AGuyCalledKlaz
Koopa
Members
Submitter Drawing Comp Top 5 Holiday Tree
#6
04-09-2024, 05:05 PM
Good lord. This has got to be the worst security breach incident in MFGG's 20 or so year history.
At least nobody else got their accounts hacked, NOR were fan-games and such affected thankfully. The worst thing that can happen to a fan-game site is if the fan-games get removed.

  ↳
United States VinnyVideo
Can't have an avatar without a Shy-Guy
Site Developer
Main Site Moderator Site Developer/Webmasters Wiki SysOp Big Help Submitter Super Reviewer (2) Wiki Contributor Sprite Comp Runner-Up Minigame Comp Winner Minigame Comp Runner-Up Minigame Comp Top 5 (3) Music Comp Winner Music Comp Runner-Up Music Comp Top 5 (2) Drawing Comp Top 5 Game of the Month Winner NCFC Contributor (4) Secret Santa (5) MFGG 17th Anniversary MFGG 18th Anniversary MFGG 19th Anniversary Ye Olde MFGGe Retro Game Jam Participant MFGG Awards 2010 Winner MFGG Awards 2011 Winner MFGG Awards 2012 Winner MFGG Awards 2013 Winner MFGG Awards 2014 Winner MFGG Awards 2015 Winner MFGG Awards 2017 Winner (3) MFGG Awards 2019 Winner MFGG Awards 2024 Winner
#7
04-09-2024, 10:01 PM
Oh joy... it's been a while since we've run into this kind of shenanigans. Yes, this is another reason why it's important to use strong passwords and to avoid reusing important passwords!

I have a mainsite backup dating to February 29, so I was able to restore all the missing updates except for the ones made in the past month or so. It might be possible to recover the handful of remaining updates, since those get posted on the MFGG Discord.
Course clear! You got a card.

[Image: CourseClear.gif]


  ↳
OssieTheOstrich Away
"Gone fishing", as they say
Members
Submitter Iso Collab Contributor (2) Sprite Comp Runner-Up Sprite Comp Top 5 Drawing Comp Runner-Up Secret Santa (2) MFGG 17th Anniversary MFGG 18th Anniversary MFGG 19th Anniversary Joke Game Contest Runner Up MFGG Awards 2020 Winner
#8
04-09-2024, 11:27 PM (This post was last modified: 04-09-2024, 11:28 PM by OssieTheOstrich.)
When I first witnessed the updates being missing I thought my computer or internet was acting up. The idea of the site being hacked was the last thing that crossed my mind; This is really one of the strangest things to have happened here.

Hopefully any new security measures ensures this doesn't happen again..
Other socials:
Sonic Retro
NCFC
YouTube

List of projects I eventually plan to finish after the indefinite hiatus is over, assuming I don't abruptly cancel them:
[+]Spoiler
Mario's Rather Unusual Trilogy (Mario's slightly unusual Boss Rush (Completed), Mario vs. Some Unusual Foes (In development), Mario's VERY Unusual Final Frontier (In development))
Sonic's Foray into Random/Unusual Zones (spin-off of Unusual Trilogy, in development)
Angry Birds Slingshot Frenzy (In development)
Super Mario Flashback: Really Good Edition (In development)
Super Hilda DX (In only conceptual phase)

Yes, I am aware that I have about 6 or so fangame projects currently in development at the same time. And yes, I am also aware that all of this is very ambitious.
+ List of projects I'm helping out with in some small capacity during my hiatus:
[+]Spoiler
Super Mario Bros Dimensions 2 (as a spriter, only for Mario's sprites)
MFGG Community Fangame Project 3 (as a spriter)
WordGirl ReWired (as a artist)

  ↳
Poland TonyBalonneViper
CLEAN HIT
Members
MFGG 19th Anniversary
#9
04-10-2024, 12:29 AM
Hoping this doesn't happen again.
         

  ↳
United States VinnyVideo
Can't have an avatar without a Shy-Guy
Site Developer
#10
04-14-2024, 03:53 PM
All the missing updates and update comments should be back now!

The only thing that could possibly be missing would be comments made to mainsite updates #888, #889, or #890.

Let me know if you run into any issues.
Course clear! You got a card.

[Image: CourseClear.gif]

[-] The following 4 users Like VinnyVideo's post:4 users Like VinnyVideo's post
  ↳ DogToon64, littlelum, Roo, SonicKade2048
« Next Oldest | Next Newest »

Users browsing this thread: 1 Guest(s)



  • View a Printable Version
Forum Jump:

Mario Fan Games Galaxy - Powered by MyBB | MFGG Staff | Contact Us

Linear Mode
Threaded Mode