(precaution) Shard owners, please change your passwords

Learn what's new on the UO Gateway site
Post Reply
User avatar
Red Squirrel
Posts: 29231
Joined: Wed Dec 18, 2002 12:14 am
Location: Northern Ontario
Contact:

(precaution) Shard owners, please change your passwords

Post by Red Squirrel »

I detected some really odd activity in the logs that is sus and while I have no reason to think accounts have been compromised, I am also not 100% sure they have or not. I strongly suggest you change your passwords once you are able to. If you use the same password for other services, change it there too. Passwords are hashed but currently not using the best algorithm, this is old code that I have been meaning to revamp and now it has become a little more urgent.

I don't want to alarm anyone with this, as it's most likely a nothingburger, but I am just taking precautions as I do see some things that can be improved in the code and I want to play it safe.
Honk if you love Jesus, text if you want to meet Him!
User avatar
Red Squirrel
Posts: 29231
Joined: Wed Dec 18, 2002 12:14 am
Location: Northern Ontario
Contact:

Re: (precaution) Shard owners, please change your passwords

Post by Red Squirrel »

Upon further investigation today I really don't think there is anything to worry about as far as compromise goes, but there is some questionable code that still makes me a bit uncomfortable as it does open the site up to some XSS issues so for now that section will be disabled. I do plan to completely revamp the site, so I will just do a temp fix for the time being to get account functionality back again hopefully in next few days.

With that said, it's always a good idea to change your passwords on all websites regularly, so take this as a reminder to do so anyway.
Honk if you love Jesus, text if you want to meet Him!
User avatar
Red Squirrel
Posts: 29231
Joined: Wed Dec 18, 2002 12:14 am
Location: Northern Ontario
Contact:

Re: (precaution) Shard owners, please change your passwords

Post by Red Squirrel »

Account management is now back online. I fixed a few things but in general I don't think there actually was an real issue that could result in a data breach so all is good. I still suggest changing passwords JUST in case though.
Honk if you love Jesus, text if you want to meet Him!
Post Reply