Open Side Menu Go to the Top
Register
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password"

03-30-2012 , 03:47 PM
Quote:
Originally Posted by Hobbes614
Was this sent out as a general reminder or was there an issue identified?
there seems to be robots trying to login to accounts, guessing passwords.

anyone with a reasonable password will be unaffected.
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 03:47 PM
Quote:
Originally Posted by Sherman
I got the same e-mail a few minutes ago. Like other posters I would prefer to know why we received the e-mail.
.


"We urge all users to change their passwords periodically, but it is particularly important that you do so now."
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 03:48 PM
Quote:
Originally Posted by Sherman
I got the same e-mail a few minutes ago. Like other posters I would prefer to know why we received the e-mail.
Password cracking attack in progress.

http://forumserver.twoplustwo.com/55...cement214.html
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 03:48 PM
It was certainly written to look exactly like a phishing attack Every other place that has stored passwords always send emails of this sort with a disclaimer along the lines of "do not ever click on links contained in an email from us, we would never include such".
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 03:51 PM
I've tried to guess all the admins' passwords. None of them use "password" "poker" or "pokerpassword".

Just fyi.
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 03:51 PM
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 03:53 PM
Quote:
Originally Posted by swiz
It was certainly written to look exactly like a phishing attack Every other place that has stored passwords always send emails of this sort with a disclaimer along the lines of "do not ever click on links contained in an email from us, we would never include such".
This is actually a good piece of advice for future emails like that.
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 03:59 PM
Good ways to make a really strong password:

1) Use a sentence. It should be memorable and sort of detailed and not something ridic obvious like "iloveyou", which is a really common password. For example, just looking at my computer screen to think of something, "I usually use Chrome to browse the internet." comes to mind. Something like that's going to be very secure against dictionary attacks and really easy to remember.

2) If you suffer from typos, you can do something similar with an acronym, but you'll rpobably want to include a number somewhere in the middle. For example "I was in second grade when I was eight" Iwi2gwiw8. Again, easy to remember, very unlikely to be in a dictionary, and fairly easy to type.

Idea roughly stolen from xckd:


Last edited by NoahSD; 03-30-2012 at 04:17 PM.
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 04:01 PM
OMG A HACKING SCAM? PLEASE SEND $30 TO SHADYRUSSIANGUY ON POKERSTARS AND I WILL INVESTIGATE WHETHER YOUR ACCOUNT HAS BEEN HACKED
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 04:03 PM
Quote:
Originally Posted by Mat Sklansky
IT CAME FROM US
that sounds exactly like something a mat sklansky imposter would say.
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 04:03 PM
Is the email being sent to:

1) everyone
2) just people who are thought to have easy passwords
3) people whose account has been targeted
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 04:05 PM
Everyone.
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 04:06 PM
everyone. we don't have access to passwords. we can change them, however.
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 04:08 PM
Quote:
Originally Posted by Professionalpoker
Might be a possible exception, if said account holder buys lap dances for mod crew.
Excellent. I'll pay gobbo to perform if necessary.
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 04:15 PM
Quote:
We recommend that you make sure that the password has these characterisics:

- at least 8 characters long
- a mixture of upper and lower case letters, numbers, and special characters
- no English words
This is what had me wondering if it was legit or not.
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 04:22 PM
lol passwords without english words
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 04:26 PM
I don't really understand why 2p2 can't just block an IP address once it becomes clear that different passwords are being tried over and over again in a brute force attack?

Wouldn't that make sense and be very easy to implement?

My password is a lot safer now... thanks for the alert, Mat Sklansky.
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 04:27 PM
So Robot Mods are good, but Robot Hackers bad?
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 04:27 PM
Quote:
Originally Posted by swiz
It was certainly written to look exactly like a phishing attack Every other place that has stored passwords always send emails of this sort with a disclaimer along the lines of "do not ever click on links contained in an email from us, we would never include such".
Yeah. I came directly here because it seemed very sketchy. Very poorly conceived and executed Public Service Announcement. Pretty much SOP to never ask for/provide a direct link to a page that will ask for a PW.

But no harm, no foul.
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 04:31 PM
Quote:
Originally Posted by Alizona
I don't really understand why 2p2 can't just block an IP address once it becomes clear that different passwords are being tried over and over again in a brute force attack?

Wouldn't that make sense and be very easy to implement?
I tihnk hey already do this, but it's very easy to constantly change IP addresses. I made some suggestions in the mod forum for ways to prevent this attack in the future, and I'm told that they're looking into them.

Last edited by NoahSD; 03-30-2012 at 04:38 PM.
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 04:34 PM
your account may be cracked, its problem?
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 04:36 PM
Quote:
Originally Posted by NoahSD
Because it's very easy to constantly change IP addresses. I made some suggestions in the mod forum for ways to prevent this attack in the future, and I'm told that they're looking into them.
Also, because sometimes an IP ban would impact other accounts that aren't guilty of anything. I don't really get how that works, but once when I requested an IP ban of a troll, I was told it couldn't be done because other accounts would be banned as well.

An IP ban won't slow down anyone who is really determined. We've IP banned trolls in the past who just keep right on coming back on new IPs.
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 04:36 PM
Quote:
Originally Posted by Mayo
I've tried to guess all the admins' passwords. None of them use "password" "poker" or "pokerpassword".

Just fyi.
Did you try their names as their passwords?

Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote
03-30-2012 , 04:45 PM
tough to crack
FB5GO91&ZQ8W1IP10TO9UGK3#8B87RNDX8
Email from "forum-master@twoplustwo.com" -- "Please Change Your Two Plus Two Password" Quote

      
m