Putting the 'role' back in role-playing games since 2002.
Donate to Codex
Good Old Games
  • Welcome to rpgcodex.net, a site dedicated to discussing computer based role-playing games in a free and open fashion. We're less strict than other forums, but please refer to the rules.

    "This message is awaiting moderator approval": All new users must pass through our moderation queue before they will be able to post normally. Until your account has "passed" your posts will only be visible to yourself (and moderators) until they are approved. Give us a week to get around to approving / deleting / ignoring your mundane opinion on crap before hassling us about it. Once you have passed the moderation period (think of it as a test), you will be able to post normally, just like all the other retards.

Increase in hacked accounts posting advertising content

Camel

Scholar
Joined
Sep 10, 2021
Messages
2,080
1. Install Authy on your phone

2. Every month, Codex tells you to enter the code from Authy

3. Enter the code from Authy

4. Go back to 2.

Me trying to use this advice...

s1IpQvC.png
I had exactly the same phone at home.
elrond-lotr.gif
 
Unwanted

†††

Patron
Joined
Sep 21, 2015
Messages
3,544
Just use different usernames and passwords on every site and have a healthy selection of emails to register. Using 2FA is cucked beyond belief, I seriously hope you guys don't do this.
 

Melcar

Arcane
Joined
Oct 20, 2008
Messages
35,393
Location
Merida, again
You would think all the millions of $$$ in Codex simp donations would afford top notch forum security and service reliability.
 
Last edited:

CHEMS

Scholar
Joined
Nov 17, 2020
Messages
1,504
You would think all the millions of $$$ in Codex simp donations would afford top notch from security and service reliability.
Codex can't stop dumb people from clicking in weird links that promises you a bigger wang
 

Infinitron

I post news
Staff Member
Joined
Jan 28, 2011
Messages
97,442
Codex Year of the Donut Serpent in the Staglands Dead State Divinity: Original Sin Project: Eternity Torment: Tides of Numenera Wasteland 2 Shadorwun: Hong Kong Divinity: Original Sin 2 A Beautifully Desolate Campaign Pillars of Eternity 2: Deadfire Pathfinder: Kingmaker Pathfinder: Wrath I'm very into cock and ball torture I helped put crap in Monomyth
Add Meme Knight to the list.

I remember Musaab i think, definitely not a plant, proper user. So yeah, most likely hacked accounts (if not a coincidence).

Perhaps you can if possible 'freeze' the accounts, but not delete them? In case the rest of them have been hacked too; sooner or later, we all return to the codex after all.

We're banning these users, not deleting them. If they care, they can contact us and ask to be unbanned after securing their accounts.
 

Ontopoly

Disco Hitler
Joined
Jan 28, 2020
Messages
2,993
Location
Fairy land
I can only hope that one day after I'm sick enough of this place that i leave forever my account can continue to make even a single person here even slightly inconvenienced. If the account was able to scam someone of their life savings? Even better
 

Bigg Boss

Arcane
Joined
Sep 23, 2012
Messages
7,528
Since the start of this year, we've noticed an increasing number of accounts of users posting out-right advertising content. Usually the accounts are a bit older (a few years) and haven't posted for a while since their registration.

Accounts affected so far:
Bishamonten (visit website and win smartphone!)
Ghost Creations (best crypto pumps on telegram Make 1000% and more within 1 day, join channel)
OrcHeart
Musaab
Torian Kel
YanBG

It's possible they're some kind of long-term advertising strategy but we highly suspect these users use the same username / password combo on other websites which have been hacked, and bots are trawling the web for their accounts and trying to log in with them to post advertising content.

We encourage people to enable 2 factor authentication before your account ends up advertising crypto, or whatever the latest ponzi scheme is the cool kids are getting into these days. And also don't re-use passwords you nubs.

This isn't related to yesterday's down-time. We haven't been hacked in any way.
This is happening at NMA too so I guess they learned a new method.
 

Melcar

Arcane
Joined
Oct 20, 2008
Messages
35,393
Location
Merida, again
It happens on many boards. A couple that I also frequent had a similar problem a few months ago. People would come back from the dead and spam with advertisements. Spam zombies.
 
Last edited:

OSK

Arcane
Patron
Joined
Jan 24, 2007
Messages
8,017
Codex 2012 Codex 2013 Codex 2014 PC RPG Website of the Year, 2015 Codex 2016 - The Age of Grimoire Make the Codex Great Again! Serpent in the Staglands Dead State Divinity: Original Sin Project: Eternity Torment: Tides of Numenera Wasteland 2 Shadorwun: Hong Kong Divinity: Original Sin 2 BattleTech Pillars of Eternity 2: Deadfire
My guess would be a reverse brute-force attack.

You take a list of common passwords and then iterate through all the users trying those passwords on each account. You're bound to get a few idiots on any decently sized message board.
 

Tarkleigh

Learned
Patron
Joined
Jan 25, 2021
Messages
407
Location
Germany
Strap Yourselves In Codex Year of the Donut Codex+ Now Streaming!
I can only hope that one day after I'm sick enough of this place that i leave forever my account can continue to make even a single person here even slightly inconvenienced. If the account was able to scam someone of their life savings? Even better
I am sure pictures of your butthole will play a role in this scheme
 

Jonathan "Zee Nekomimi

Hoarder of loli kats./ Funny ^._.^= ∫
Patron
Joined
Mar 4, 2019
Messages
6,531
Location
Brasilien
Codex+ Now Streaming!
I can only hope that one day after I'm sick enough of this place that i leave forever my account can continue to make even a single person here even slightly inconvenienced. If the account was able to scam someone of their life savings? Even better
I am sure pictures of your butthole will play a role in this scheme
image.png
 

LostHisMarbles

Learned
Joined
Apr 28, 2021
Messages
956
By the way, just saw this: https://www.techspot.com/news/97325...unts-breached-credential-stuffing-attack.html
Now that's scary. Fortunately however -according to Paypal- they only took names, births, social secs, cc details and emails! Phew!

* Seriously:
i) one email, one registration. Always. New registration anywhere, anywhere else? New email.
ii) emails' names and passwords cannot contain names, hints, habbits or items that can link to our real person.
iii) different email, different name, different password; i mean different, not marbles1@mymail.com and marbles2@mymail.com
iv) never use same pass (say for email here, website there)
v) use the password logic i outlined before.
vi) if until now you've been a retard, change your basic email now. At the cost of then changing it everywhere yes, but.. you follow the above, you're in for that anyhow.

Don't be a lazy Panamerican, don't trust randoms with your credentials because bacon(TM).
And wheel chairs for fat people, how could i forget. Also weapunz, such shooting, much freedom.

** lazy Panamericans also tend to go to websites "checking" your email, in order to tell you if it's been "used" or "leaked" in the wild. Do not do that, lol. See above about trusting randoms.
 
Last edited:

Ontopoly

Disco Hitler
Joined
Jan 28, 2020
Messages
2,993
Location
Fairy land
I can only hope that one day after I'm sick enough of this place that i leave forever my account can continue to make even a single person here even slightly inconvenienced. If the account was able to scam someone of their life savings? Even better
I am sure pictures of your butthole will play a role in this scheme
image.png
Way better positioning than I i had. Next one i post will be more like this, I promise
 

Taluntain

Most Frabjous
Staff Member
Joined
Oct 7, 2003
Messages
5,442
Location
Your Mind
Guide for setting up TOTP locally:
https://rpgcodex.net/forums/threads/how-to-setup-2fa-on-your-desktop.139952/

you can skip the QR code part because codex provides the key needed directly, just copy-paste it

If you just want to set up 2FA on the forums here, it's not nearly as convoluted as in rusty's guide. It's basically this:

The Comprehensive Guide to Avoiding Getting Your Codex Account Hacked:

1) Enable 2FA: https://rpgcodex.net/forums/account/two-step
2) Install Authy on your smartphone and add the Codex.
3) ????
4) PROFIT!!!!

Don't use the e-mail option, it's less secure and prone to issues for some reason. Install Authy.
 
Joined
Jan 14, 2018
Messages
50,754
Codex Year of the Donut
Guide for setting up TOTP locally:
https://rpgcodex.net/forums/threads/how-to-setup-2fa-on-your-desktop.139952/

you can skip the QR code part because codex provides the key needed directly, just copy-paste it

If you just want to set up 2FA on the forums here, it's not nearly as convoluted as in rusty's guide. It's basically this:

The Comprehensive Guide to Avoiding Getting Your Codex Account Hacked:

1) Enable 2FA: https://rpgcodex.net/forums/account/two-step
2) Install Authy on your smartphone and add the Codex.
3) ????
4) PROFIT!!!!

Don't use the e-mail option, it's less secure and prone to issues for some reason. Install Authy.
I don't like smartphones

took me about 15 seconds to setup 2fa here using my method
 

As an Amazon Associate, rpgcodex.net earns from qualifying purchases.
Back
Top Bottom