Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


TheStudentRoom Hacked! (Maybe a little old?)
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

TheStudentRoom Hacked! (Maybe a little old?)

eastoncheastonch Member
edited June 2012 in General

http://www.thestudentroom.co.uk/announcement.php?f=148&a=854

First time i've been on in a week or so, looks like it's like, 8 days old news.. But just a heads up for any students on there (like myself...).

Can somebody please explain how these sites are not using "secure" hashing methods?

Comments

  • rskrsk Member, Patron Provider

    There are more advanced "hashing" methods, but maybe the student room was developed like ages ago and they never re-coded their site to use newer hashing techniques?

  • Would you expect it to be, being it the largest student forum in the UK, atleast.

  • rskrsk Member, Patron Provider

    Well, the site might have been developed before like i said, and thus they might have never revisited the code to update their hashing methods.

  • InfinityInfinity Member, Host Rep

    Don't they use vB forums? So won't they use vB's hashing techniques? I have an account there.

  • TaylorTaylor Member

    They didnt even email me about this....

  • I wasnt even informed, until I saw this post on the "important" threads ...

    Quite irresponsible of them to be honest, are they using VB? There must be a way to tell... And I wonder if this was done by one of them UGN guys?

  • joepie91joepie91 Member, Patron Provider

    @rsk said: There are more advanced "hashing" methods, but maybe the student room was developed like ages ago and they never re-coded their site to use newer hashing techniques?

    SHA256/SHA512 (SHA-2) has existed for the past 11 years.

    @eastonch said: And I wonder if this was done by one of them UGN guys?

    Why would you think that?

  • PADPAD Member
    edited June 2012

    Haha. Great to know that most techies still think that one lock pad is enough. Security is a joke on the Internet. :D

    The way forward for anyone that likes to leave their servers unsecure, make your own hashing method. Get on my level.

  • rskrsk Member, Patron Provider

    @eastonch said: Quite irresponsible of them to be honest, are they using VB? There must be a way to tell... And I wonder if this was done by one of them UGN guys?

    If it is run via VB forums software, then it should be secure - kind of, atleast - that is if it is the latest version they are running.

Sign In or Register to comment.