Mario Making Mods

  • Owner
Since: 05-17-17
From: Mushroom Kingdom
Well, sort-of. I'm making this thread to explain what happened, I'm also going to put some clarifications.

Basically, on March 30th, I wanted to make a "lead-up" to our supposed-to-be april fools. Remember when I said that Epic_Stuff was supposed to be promoted on that day? Well, what I did was disable Epic_Stuff's permissions on the board (so he wouldn't be able to do anything bad), promote him to owner, and ban myself, for the reasons of "being an evil dictator". Obviously, this was supposed to be a joke, leading up to Epic_Stuff taking over on April 1st. However, a serious ban had taken place a few days before to a certain user, and that user was MoonlightCapital.

Somehow, he found out how we handle the database and what our password was. He then later on went over to Jamie Dignam, another previous friend of mine, and told him/her to destroy the board. What ended up happening was every post, thread, and user was changed into being a "ClownYoshi" theme. The end result was the April Fools joke was changed into "Wario Washing Woods" theme started by Buntendo, and the forum was shut down temporarely. We only did april fools on the discord, though. It was really nice to see how Huseyin changed things up.

While all this was happening, I was offline for March 31st and April 1st, and left the site to my mods. Since I didn't expect this whole drama to happen, I didn't tell my server admin (JeDa) to be on the lookout. I also didn't do a database backup due to me thinking that I had one from a week ago. While I was gone, the server admin (JeDa) thought that it was a prank made by me, so he didn't do anything. However, once he realised it wasn't, it was a bit too late.

When I returned, I tried to see if I had a newer DB backup, only to get shot down by Explos and co.:


Yeah, true, making backups is important, but you don't need to harass someone just because he didn't take a backup. In fact, he's really hated in the community and everyone wanted him gone and banned. I, however, didn't ban him, because he was right. Although, as I've said above, I've tried to setup a auto-database backup system, but it refused to work with me. It only worked one time, and then failed. The turning point is, however, when a man named Conkerisanut recommended me to talk to a man called Jaku, a really famous computing security guy who even once appeared on a [news station](https://www.nbcchicago.com/on-air/as-seen-on/WEB-gaming-system-hacked-466008713.html). So I went into a DM conversation with him, and gave him all my logs, new SQL and old SQL. We have found out that Jamie, did indeed do a database backup before wrecking everything. He even taught me how to correctly set-up a auto-database backup system. I do have to thank a man called CLF78, who convinced jamie to atleast talk to me. After a long talk, he's handed over the database, and everything was restored.

What this means for you?

Well, little-to-no effect. The only changes is that jamie is now banned off of MMM, as he has previously broken too many rules, but this is the turning point. Other than that, nothing really changed.

What this means for us?

We're going to be improving our security measures.

First off, thanks to jaku, we can now take automatic backups. What's even more important, that they'll stay with us, so in-case anything bad happens, we have the latest backup. At worst, we'll just revert to a backup made the previous day.
Second off, we've realised that another neighboring site has also been affected due to permissions not being correctly setup. Thankfully, he didn't touch the other site, but it was still a huge risk. That can also mean that the other site can easily hack ours if they had the DB. It was fixed as well.

FAQ


Are all of our data compromised

Well, no. We mainly encrypt most data (passwords) using global and per-user SHA256. Basically, if he were to get your passwords, he'd need to have access to both the local files and the database.

Does "theninja100" have anything to do with this?

This was a complicated matter, seeing as how the whole IPS situation happened. Basically, he has been involved in other affairs relating to destroy the board (in the past). When Jaku looked through our access logs, we found an IP, matching the IPS of theninja1000. Because of all previous affairs and the fact that he sent me a DM around the time of the hack, we assumed it was him. However, as I've learned, both Jamie and theninja1000 share the same IPS. So theninja1000, if you are reading this, I'm terribly sorry for accusing you of hacking us.

Aftermath

1. We're using stronger security.
2. Jamie is now perma-banned.
3. During the time that I didn't know that Jamie had a backup, I've made a poll, talking about random stuff. You guys really want randomized posts, thread ID's and forum ID's. You guys also suggested that I don't allow two threads to have the same name. So I'm going to implement both of them. As such, if you want to request more features, just tell me! I'm always open to finding out how we can improve our site for the users.

That's all about the current situation. If there's a newer situation, I'll let you all know.
Old 3DS XL info:
I used to have a 3DSafe A9LH V11.3.0-36U with Luma in my CTRNAND. Since ReiNAND Reibooted and Re-Reileased, I "switch"ed back.
Right now, I have boot9strap with Luma 8.0 as my CFW. Though, I'd like to see other CFW's for B9S.
Posted on 04-02-18, 10:47 pm (rev. 1 by NightYoshi370 on 04-02-18, 10:51 pm)
teeUser is Offline
I'm tea. Live with it.
  • Normal user
Since: 01-16-18
From: Chemical Plant Zone

Glad this situation has gotten better. Nice that security has improved.
_________________________
Discord - tee#0151
Twitter - @teebeeYT
WiiU - beetle857
Switch - SW-1142-1551-7831
Posted on 04-02-18, 10:49 pm
  • Normal user
Since: 06-17-17
what a night it was. glad the forum was restored
Posted on 04-03-18, 02:01 am
  • Normal user
Since: 05-19-17
From: Italy
Yeah i was involved in this.

I got the password like months ago in a legitimate way, and after discovering no one changed it since than, I decided to send Jamie doing an April's fool, and before doing major damage, i even told them to make a backup of the database.

I didn't really have malicious intentions, just having fun and saying "do stuff securely next time".


Certificate for nickname MoonlightCapital, is registered to: MoonlightCapital
Nickname database
Posted on 04-03-18, 07:19 pm
  • Owner
Since: 05-17-17
From: Mushroom Kingdom
Wait, how exactly did you get the password? That's the one thing I'm legitimately curious about?

Also, we had our own april fools joke going on. We didn't need yours, which is not funny.
Destroying data is not funny, at all.
Harassing me is not funny, at all.
Old 3DS XL info:
I used to have a 3DSafe A9LH V11.3.0-36U with Luma in my CTRNAND. Since ReiNAND Reibooted and Re-Reileased, I "switch"ed back.
Right now, I have boot9strap with Luma 8.0 as my CFW. Though, I'd like to see other CFW's for B9S.
Posted on 04-03-18, 07:21 pm (rev. 1 by NightYoshi370 on 04-03-18, 07:21 pm)
WillyMakerUser is Offline
Smell like... create a mod!
  • Normal user
Since: 04-03-18
From: My home
What? Im saying what an youtuber can change the bg in Nsmbu skin.
_________________________
YT: https://www.youtube.com/channel/UCBDaY5sapkDhqlBBNJnW-Og
Wii U ID: guillebros
3DS ID: 3411 1273 2115


Smell like... Create a level!
Posted on 04-03-18, 07:22 pm
  • Owner
Since: 05-17-17
From: Mushroom Kingdom
Erm, this is a toatally seperate thread. You already had your own thread to post this in.
Old 3DS XL info:
I used to have a 3DSafe A9LH V11.3.0-36U with Luma in my CTRNAND. Since ReiNAND Reibooted and Re-Reileased, I "switch"ed back.
Right now, I have boot9strap with Luma 8.0 as my CFW. Though, I'd like to see other CFW's for B9S.
Posted on 04-03-18, 07:23 pm
  • Normal user
Since: 05-19-17
From: Italy
Wait, how exactly did you get the password? That's the one thing I'm legitimately curious about?

Remember when you gave me access to the old VPS to trying host my bot?

You accidentally gave me access to the board files, which is where I downloaded the config file.

Oh and let's not create drama like there isn't enough already.


Certificate for nickname MoonlightCapital, is registered to: MoonlightCapital
Nickname database
Posted on 04-03-18, 07:24 pm
WillyMakerUser is Offline
Smell like... create a mod!
  • Normal user
Since: 04-03-18
From: My home
*facepalm* im confused i take the wrong forum and i think what you say to me what i hacked the page sorry xd.
_________________________
YT: https://www.youtube.com/channel/UCBDaY5sapkDhqlBBNJnW-Og
Wii U ID: guillebros
3DS ID: 3411 1273 2115


Smell like... Create a level!
Posted on 04-03-18, 07:26 pm (rev. 1 by WillyMaker on 04-03-18, 07:26 pm)
  • Owner
Since: 05-17-17
From: Mushroom Kingdom
Remember when you gave me access to the old VPS to trying host my bot?

You accidentally gave me access to the board files, which is where I downloaded the config file.

Oh and let's not create drama like there isn't enough already.
Ahh, so in the end, it wasn't an exploit. Problem solved then.

Also, why did you tell Jamie to destroy the board?
Old 3DS XL info:
I used to have a 3DSafe A9LH V11.3.0-36U with Luma in my CTRNAND. Since ReiNAND Reibooted and Re-Reileased, I "switch"ed back.
Right now, I have boot9strap with Luma 8.0 as my CFW. Though, I'd like to see other CFW's for B9S.
Posted on 04-03-18, 07:29 pm
JamieUser is Offline
Banned permanently: Reregging multiple times
  • Banned
Since: 07-20-18
From: England
pretty much gonna apologise for this, though it at least did help maor get the site secure (at least that what he told me)

though look on the bright side, I didn't actually destroy the DB dump, and did give it to maor in the end

and it was really immature, true, but meh, it's just another thing i can reflect on in the hall of failure

sorry for bumping this btw just felt it had to be said

also maor said i could be unbanned here :)
Posted on 07-20-18, 03:50 pm (rev. 1 by Jamie on 07-20-18, 03:51 pm)
  • Owner
Since: 05-17-17
From: Mushroom Kingdom
What I meant by that ("more secure") was, basically that I am now taking a lot more backups then I used to (instead of once every month, once every week (if I'm available though, meaning no DB backups when I'm in camp)).

Yeah, it was nice of you to give me the board back, and thanks for that, actually.

Just because you can reflect on it doesn't mean it isn't bad.

Bumping threads is fine as long as your don't bump it randomly without any purpose. Since you did use this thread to apologize, I guess its fine.

1. When did I say that?
2. Even if I did (which I'm not sure of myself at this point), you could have asked me on Twitter to restore your old password instead of making a new rereg.

Oh well, this thread is useless anyways. I'll trash this.
Old 3DS XL info:
I used to have a 3DSafe A9LH V11.3.0-36U with Luma in my CTRNAND. Since ReiNAND Reibooted and Re-Reileased, I "switch"ed back.
Right now, I have boot9strap with Luma 8.0 as my CFW. Though, I'd like to see other CFW's for B9S.
Posted on 07-20-18, 04:06 pm (rev. 1 by NightYoshi370 on 07-20-18, 04:06 pm)