04-09-2024, 02:32 PM
So, if you've been to the main site you might have noticed that the last news post is from 2021. Whuh? What? You might have also heard about something along the lines of the main site getting compromised.
TL;DR: Someone compromised a staff account, deleted all the news posts, and promoted their own stuff. No need to worry though because we do have backups and will restore things fully soon.
That being said, if I was just a regular member of the community, and something like this had happened but the details were swept under the rug with just that, I'd be annoyed. So to have full transparency, this post will have a full explanation of the events that had transpired.
But before that, I will emphasize a few things:
So here's what happened, based on what I heard from the staff members who were awake at the time, and my own investigation of the logs:
Some MFGG and Mario Flashback OGs will remember the Roblox raids. To sum it up, there used to be a group of people who would use exploits to put messages in popular Roblox games (I'm talking about games played by millions) that tell them to raid a server to receive free Robux (Roblox currency). MFGG was a target of these attacks. Why? No idea, none of us got anything to do with Roblox. But I'm almost certain that those people who organized the raids are not the same people who nuked the news posts here. It's just that Roblox attracts a lot of toxic kids. We also don't know the identity of those raiders, don't pay attention to anyone else who says otherwise.
The other incident in question is the previous main site takeover. There was another incident of another staff account getting compromised in the exact same way, and someone spamming stuff in the news, with far less impact. We had taken precautions after the said incident, and even revamped the entire backend to improve the site's security as a whole, but it clearly wasn't enough and some staff members still kept using unsecure passwords.
We have also been dealing with the issue of an individual from an affiliated community joining our Discord server to spam slurs and random screenshots. That's also unrelated.
As the MFGG staff we made one big crucial mistake here. We did not make absolutely sure that all staff accounts, including the inactive ones, used secure passwords. We kinda just trusted each other, but that was clearly not enough. Thankfully, nothing serious happened outside the temporary loss of news posts, but things could be so SO much worse. Still, we are going to take full responsibility for this breach, and make ABSOLUTELY SURE nobody's able to brute force into staff accounts in the future. We are terribly sorry for all that happened.
There are a few lessons to learn here:
TL;DR: Someone compromised a staff account, deleted all the news posts, and promoted their own stuff. No need to worry though because we do have backups and will restore things fully soon.
That being said, if I was just a regular member of the community, and something like this had happened but the details were swept under the rug with just that, I'd be annoyed. So to have full transparency, this post will have a full explanation of the events that had transpired.
But before that, I will emphasize a few things:
- Nothing is lost permanently here. They deleted the news, but we temporarily restored all the ones from up to 2021 for now, and will bring back the rest shortly (from an off-site backup hopefully).
- Except for a certain specific user I'll get to, your account is safe and not accessed from outside.
- Nothing else is touched. The games and whatnot are intact and safe.
- There's no real big security risk going on. There's no backdoor as far as we know, it's just someone guessing a staff account's password.
- This is not connected to any other prior incident.
- They didn't have access to the full backend of the site. Only a specific portion, which they seemingly only used to snoop on one member, then spam on the news section.
So here's what happened, based on what I heard from the staff members who were awake at the time, and my own investigation of the logs:
- They first visited a user's profile. When you google their name, MFGG is one of the first results to pop up, so that's likely how they discovered the site. This user had never done anything on the site, at least since the late 2000s.
- They tried to log in to it, but failed.
- So, they tried to log into various staff accounts instead. They got the password wrong many times in the process.
- But eventually one of them worked. Our guess is that the password was either super easy to guess, or it was included in a prior database leak from a different website. This is why you don't use the same password across multiple websites.
- Using the staff account they immediately took control of the mystery user's account as well. From what I can tell, they proceeded to do nothing with it, and the account itself did not contain much information. We ended up locking this account.
- They also banned me to prevent me from stopping them. I was asleep at the time, as this whole thing happened around at 6 AM for me, so I was not there to see my first MFGG ban, sadly.
- They deleted pretty much all the main site news posts as well. Come on man...
- They then started posting a bunch of news post of their own, flaunting their victory, and promoting their Twitter accounts. Those accounts are pretty barren though, and mostly have posts related to... Yep, you guessed it, Roblox.
- Fun With Despair noticed all this and tried banning them. Before he could though, they just changed the password of his account and started using it to spam instead.
- We quickly tried to sort things out, reverted back a quick backup we had from 2021 for emergencies, cleared session records to log them out of the staff accounts, reset the passwords of ALL staff accounts, and deleted the accounts they had made.
- Turns out this was not enough and they were still somehow logged into Despair's account, so we additionally IP banned them as well, and temporarily banned Despair's account also just to be safe.
Some MFGG and Mario Flashback OGs will remember the Roblox raids. To sum it up, there used to be a group of people who would use exploits to put messages in popular Roblox games (I'm talking about games played by millions) that tell them to raid a server to receive free Robux (Roblox currency). MFGG was a target of these attacks. Why? No idea, none of us got anything to do with Roblox. But I'm almost certain that those people who organized the raids are not the same people who nuked the news posts here. It's just that Roblox attracts a lot of toxic kids. We also don't know the identity of those raiders, don't pay attention to anyone else who says otherwise.
The other incident in question is the previous main site takeover. There was another incident of another staff account getting compromised in the exact same way, and someone spamming stuff in the news, with far less impact. We had taken precautions after the said incident, and even revamped the entire backend to improve the site's security as a whole, but it clearly wasn't enough and some staff members still kept using unsecure passwords.
We have also been dealing with the issue of an individual from an affiliated community joining our Discord server to spam slurs and random screenshots. That's also unrelated.
As the MFGG staff we made one big crucial mistake here. We did not make absolutely sure that all staff accounts, including the inactive ones, used secure passwords. We kinda just trusted each other, but that was clearly not enough. Thankfully, nothing serious happened outside the temporary loss of news posts, but things could be so SO much worse. Still, we are going to take full responsibility for this breach, and make ABSOLUTELY SURE nobody's able to brute force into staff accounts in the future. We are terribly sorry for all that happened.
There are a few lessons to learn here:
- Do not reuse the same password in multiple places. Use a password manager if necessary.
- If you have old, unused accounts on sites where the account getting compromised would be a problem, please make sure that they have strong passwords.
- Make frequent backups.
- Don't let your kids play Roblox.