By using this site, you agree to our Privacy Policy and our Terms of Use. Close

Forums - Gaming - Polytron and Phil Fish Hacked, tons of Personal Info Leaked

Since Polytron is on CloudFlare, and their provisions include a triple-redundancy to prevent hackers from changing the website unless they simultaneously hack all three server centers (which would be nothing short of a miracle), the only way these main page changes happened are through the admin account. (Not to mention the authentication protocol...)

So either Phil doesn't do much to protect his passwords/usernames or he's (or someone close to him is) going to be in a lot of deep shit when CloudFlare does an IP track on the admin account.

Having read up on what is in the data file, Microsoft, Sony, and the FBI will possibly get involved... is any hacker who could actually do this stupid enough to get said parties involved?

For more info as stuff comes out from /v/ and others digging into this: http://www.neogaf.com/forum/showpost.php?p=126556583&postcount=1296



Around the Network
Lawlight said:
How were passwords obtained when a website is hacked?

if you have access its not difficult to do a remote Mysql dump (database of a site) that like 1 line of code..
Phil probably didn't have the 2 step authentication that cloudflare offers activated (lets be honest, who does that.. its a pain to use)
and his password was probably easy to hack.. something like.. "iloveme" or "philisthebest"



 

Face the future.. Gamecenter ID: nikkom_nl (oh no he didn't!!) 

NiKKoM said:
Lawlight said:
How were passwords obtained when a website is hacked?

if you have access its not difficult to do a remote Mysql dump (database of a site) that like 1 line of code..
Phil probably didn't have the 2 step authentication that cloudflare offers activated (lets be honest, who does that.. its a pain to use)
and his password was probably easy to hack.. something like.. "iloveme" or "philisthebest"


Pretty sure the passwords would be encrypted. Also, passwords to what exactly?



Not saying he deserves this but the internet is a hornets nest and if you make people dislike you and you get caught in a situation like the whole SJ chaos prepare to take cover. The whole censorship of the net over the situation caught the attention of groups like Anonymous like how Scientology did when they tried censoring the net, that situation was asking for trouble.



this is disgusting. i know phill phish is a dick. but hacking other people's private accounts is disgusting. i refuse to read anything that was posted about them. i hope the person who did this gets caught in thrown in jail.



Around the Network
Lawlight said:
NiKKoM said:

if you have access its not difficult to do a remote Mysql dump (database of a site) that like 1 line of code..
Phil probably didn't have the 2 step authentication that cloudflare offers activated (lets be honest, who does that.. its a pain to use)
and his password was probably easy to hack.. something like.. "iloveme" or "philisthebest"


Pretty sure the passwords would be encrypted. Also, passwords to what exactly?

Password encryption is a pretty big joke on a wordpress (think polytron was a wordpress site) site.. heck I do it from time to time for some websites if for example the old webmaster has died and no one has the admin password. All the user accounts can be exposed fairly easily.. and since most people use the same password for a lot of sites..



 

Face the future.. Gamecenter ID: nikkom_nl (oh no he didn't!!) 

NiKKoM said:
Lawlight said:
NiKKoM said:

if you have access its not difficult to do a remote Mysql dump (database of a site) that like 1 line of code..
Phil probably didn't have the 2 step authentication that cloudflare offers activated (lets be honest, who does that.. its a pain to use)
and his password was probably easy to hack.. something like.. "iloveme" or "philisthebest"


Pretty sure the passwords would be encrypted. Also, passwords to what exactly?

Password encryption is a pretty big joke on a wordpress (think polytron was a wordpress site) site.. heck I do it from time to time for some websites if for example the old webmaster has died and no one has the admin password. All the user accounts can be exposed fairly easily.. and since most people use the same password for a lot of sites..

Allow me to be skeptic of this. And again, passwords to what?



He mostly, he's spent the past few days defending someone who is known for faking attacks against herself to gain sympathy, and likely wanted a way out of all this for months. So I would not be surprised if he did this himself. Thus, I'm not going to feel too strongly about this until after the inevitable investigation.



More rage from phil fish incoming.

Sad for him. Fun for me



Vena said:

I've been following this for a while...

... Pretty sure he either did this himself or someone really, really stupid and dedicated hacked him but didn't hack his twitter for some reason and the extent of the hack was a doxx and simple HTML page replacement. Doesn't make much sense. I'm going to err on the side of himself.


I mean, people reveal info for slander or benefit. What's the point in revealing financials? Fez was a success. And anyone who woukd do this knows people would have more sympathy for him abd that he did not need help in ruining his reputation. Until further notice I'm gonna say this was planned by him and possibly suggezted by Zoe.