Log in to ZYGOR
Log in with social media
OR
Log in with Zygor account

Announcement

Collapse
No announcement yet.

*CRITICAL* Purchase Activation & Website Security Issues Resolved

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    *CRITICAL* Purchase Activation & Website Security Issues Resolved

    Hello,

    Unfortunately, there are two issues we need to address with you.


    -------------------------------------------------------------
    Issue #1: Guides Not Adding to Accounts After Purchase
    -------------------------------------------------------------

    Recently, there has been an issue with some people's guides
    not activating correctly in their account after making their
    purchase.

    We have identified the issue and fixed it in our system. At
    the same time, we've gone through and activated everyone's
    purchases that did not correctly activate upon payment.

    So, if this issue effected you, please update your guides, as
    you should now be able to download and use all of your guides.

    We apologize for the inconvenience.


    -------------------------------------------------------------
    Issue #2: Email Addresses Leaked to Spammers
    -------------------------------------------------------------

    Many of you are aware of this issue, as it effected everyone
    that was a Zygor member before a few weeks ago. Somehow,
    spammers were able to breach our website security to obtain
    the email addresses and usernames of all of Zygor Guides'
    members. They used this information to promote their scam
    product to you via email.

    Immediately upon learning of this situation, we contacted a
    few internet security experts to analyze our website, identify
    the weakness and, essentially, plug the holes so this does not
    happen again.

    A few weaknesses were identified and allowed us to determine
    how the intruders broke in. Those security holes have now been
    fixed and measures have been taken to prevent this situation
    from happening again in the future.

    There is not reason to believe the intruders went after members'
    passwords, as their motive seemed to be to promote their product
    through spam.

    However, just to be safe, we highly encourage you to change
    your password immediately. You can do this inside the Zygor
    Guides Members Area here:
    http://zygorguides.com/members/

    This is a serious issue and not one we've taken lightly. We
    will continually test and improve the security of our service
    and are deeply sorry this was allowed to happen in the first
    place.

    And that's all for now, stay tuned for more news coming soon
    on the brand new products we'll be releasing in the next few
    weeks!

    Take care.

    John Cook
    Zygor Guides, LLC
    http://www.zygorguides.com
    Become a Fan of Zygor Guides on Facebook:
    http://www.facebook.com/zygorguides

    Follow Zygor Guides on Twitter:
    http://twitter.com/zygorguides

    #2
    Do you store our passwords in an encrypted form in your database, or cleartext?

    Comment


      #3
      Currently, cleartext. However, we are actively working on changing our system to store them in encrypted form. Should be done within the next day or two. Will update here when it is.
      Become a Fan of Zygor Guides on Facebook:
      http://www.facebook.com/zygorguides

      Follow Zygor Guides on Twitter:
      http://twitter.com/zygorguides

      Comment


        #4
        Originally posted by Zygor View Post
        Currently, cleartext. However, we are actively working on changing our system to store them in encrypted form. Should be done within the next day or two. Will update here when it is.
        Very good to read the change on how the PWs will be stored.

        Thanks for the update.

        Comment


          #5
          I think the hackers DID (or might have) gotten user's passwords. Zygor has my email. Please email me directly for more information if you wish. Thanks.

          Comment


            #6
            It is possible they may have, but based on reports so far, there isn't anything to suggest they are interested in using them. In either case, we highly recommend changing your password immediately to keep yourself safe.
            Become a Fan of Zygor Guides on Facebook:
            http://www.facebook.com/zygorguides

            Follow Zygor Guides on Twitter:
            http://twitter.com/zygorguides

            Comment


              #7
              There have been recent attempts to hack my WoW account, so they may have gotten passwords. No, I don't use the same password there.

              Comment


                #8
                Originally posted by manicmaniac View Post
                There have been recent attempts to hack my WoW account, so they may have gotten passwords. No, I don't use the same password there.
                Hmm, then it is even more important to change your password. Also, make sure not to use the same password for your account here (or anywhere else) as you use for your WoW account(s) - as manicmaniac said. It's just good practice.
                Become a Fan of Zygor Guides on Facebook:
                http://www.facebook.com/zygorguides

                Follow Zygor Guides on Twitter:
                http://twitter.com/zygorguides

                Comment


                  #9
                  If it is a serious hacking group they might try email/pw combinations on major sites like facebook or twitter. I would strongly encourage anyone who does not use separate passwords for all of their accounts to change the compromised password. Please encrypt the PW file, it make me nervous that you have access to the PW list let lone hackers.

                  Comment


                    #10
                    During my training for ITSec we ran across several situations where this kind of event was discussed the easiest and most practical solution would most likely be to hash the pw's for each user, but DO NOT SALT them.. if you salt them then you can not do a password recovery unless you wish to reassign the pw to the user as it is permanently hashed and unable to be backward converted. The bad part of this is depending on how the salting is implemented it can either be permanent (which is most of the applications where i have seen it) where if you loose your password you have to create a new account and permissions re-assigned. (highly secure with proper owner authentication but takes up admin time responding to request) but there is another method where the password can be reset. It is a very big field and all encryption methods have their own benefits and cons.

                    *edit*
                    Just for reference for Zygor's sake the reason that i suggested normal hashing and not salting as it takes more money and development to implement and he doesn't have unlimited funding. This is a personal opinion as I'm still in training and from what I have been taught thus far. But again Salting would be ideal but it depends on multiple factors. =)

                    Comment


                      #11
                      my biggest problem is that the hacking was discovered 2 weeks ago and everyone have only been notified now.

                      Comment


                        #12
                        Originally posted by icewolfdw View Post
                        During my training for ITSec we ran across several situations where this kind of event was discussed the easiest and most practical solution would most likely be to hash the pw's for each user, but DO NOT SALT them.. if you salt them then you can not do a password recovery unless you wish to reassign the pw to the user as it is permanently hashed and unable to be backward converted.
                        Good to know, thanks. Apparently with our membership software, hashes cannot be used due to integration issues with other plugins the software offers. However, we are looking into whether we can customize our system to allow for hashes, or if some other solution is necessary.
                        Become a Fan of Zygor Guides on Facebook:
                        http://www.facebook.com/zygorguides

                        Follow Zygor Guides on Twitter:
                        http://twitter.com/zygorguides

                        Comment


                          #13
                          Originally posted by kinsten View Post
                          my biggest problem is that the hacking was discovered 2 weeks ago and everyone have only been notified now.
                          We figured it was much better to fix the issue first, so when you changed your password, it was safe to do so - rather than everyone creating a panic for something we were already putting all our effort into fixing.
                          Become a Fan of Zygor Guides on Facebook:
                          http://www.facebook.com/zygorguides

                          Follow Zygor Guides on Twitter:
                          http://twitter.com/zygorguides

                          Comment


                            #14
                            Ahh, that does explain then the sudden email I'd gotten for a group following me on Twitter that I have never had any affiliation with... My twitter & here handles are the same... and I follow you there as well.

                            May want to reword the email to get us here though, I was a bit overly cautious at first until I was able to verify the links matched what you usually send out... sorry, I'm sure I'm not the only one leery of emails that talk about account security and link here...

                            Thanks though, glad you found the marks and are doing what is needed to keep us further protected in the future, all the more reason I support /your/ guide and not someone elses

                            --RaKlavin

                            Comment


                              #15
                              This explain why 2 weeks ago I got an email from some weirf company to my WORK email address claim they had an addon that could level and farm my toon even when im off line..????

                              Wondered how on earth they got my WORK email address. My WoW account is not linked to my work email.....but ZYGOR is! ahhhh!

                              I change my WoW account password every two weeks anywho. I got hacked and cleaned out about 2 years ago. Will go change my Zygor password now.

                              Comment

                              Working...
                              X