Michael Toennies has also accused Atrinik of hacking Daimonin server, saying that happened because users had same password for both servers:
http://www.daimonin.org/11237/important-security-issue/More sadly, it is/was with a 99% chance an older developer.
- he had some trusted access to maintain the website which he used to guess and compare
passwords from the game against the website and emails
- he was able to login as admin to the website and change some content
- he setup some time ago a hidden link to Atrinik by using script cloaking
to get the page rank power of daimonin for atrinik. He did not hacked the site -
he simply abused admin power to inject a link to a block
- he logged in to the system for several days under the IP 78.98.94.212
- he logged in to some old versions of the website using his new passwords to get more access
He abused the TRUSTED security level of our system to leak in the next security level.
Trusted means, that of course people from the dev team have access to system parts.
Thats means he was able to check people used the same password on the server as for the
website (to geht login to the website) and he used his developer powers to hack deeper in the
system.
He was NOT able to break in the higher security levels. That means all our ssh keys, non password logins,
SVN and system/game data was and are still secure.
Well, there is little what you can do, when the trusted people helping to hold the security goes to the dark site
itself. At last it was not a member since some time anymore.
When you are an older member of daimonin you get an idea who was the hacker with a high chance.
Anyway, here is the action:
IF you are using for the game server here OR ON ATRINIK - AND ON THE WEBSITE: Then change your password ASAP.
I would suggest to change your website password anyway.
DO NOT USE YOUR PASSWORD FOR BOTH.
Well, sorry for the trouble
MT