The Student Room – security breach

Hear the latest site news, get help with using TSR or share your suggests to improve the site.

Announcements Posted on
Enter our travel-writing competition for the chance to win a Nikon 1 J3 camera 21-05-2013
IMPORTANT: You must wait until midnight (morning exams)/4.30AM (afternoon exams) to discuss Edexcel exams and until 1pm/6pm the following day for STEP and IB exams. Please read before posting, including for rules for practical and oral exams. 28-04-2013
READ BEFORE POSTING: Some frequently asked questions 16-06-2010
Sign in to Reply
  1. CJ's Avatar
    • TSR Community Team
    • :badger:
    • Location: Brighton
    The Student Room – security breach
    The latest post from the TSR Blog:

    Like a number of websites recently, The Student Room has been the victim of an attack by someone intent on capturing user data. The minute we found out we took every possible step to protect our members’ data and we are continuing to increase our security. However, if you are a member of The Student [...]

    Read more on the TSR Blog...
  2. Metrobeans's Avatar
    • TSR Idol
    • Location: London
    • Posts: 9,549
    TSR Usernames/Passwords
    I've changed my password as suggested, but I was wondering - do you guys know if details have been taken for everyone on the site or just a certain number? When did this happen?

    Admin edit: See here for information and advice regarding the security breach.
    Last edited by fleur de lis; 22-06-2012 at 15:13.
  3. Chrosson's Avatar
    • PS Helper
    • Vengeful, Imperial Overlord of The Student Room
    • Posts: 4,187
    Re: TSR Usernames/Passwords
    Additionally regarding the usernames and passwords, I'm curious - can you tell us the hashing+salting method (formerly?) used by TSR?
  4. thunder_chunky's Avatar
    • And all the roads we have to walk are winding
    • Location: Eternia
    Re: TSR Usernames/Passwords
    I changed my password, here's hoping it's nothing more than a safety precaution.
  5. estel's Avatar
    • TSR Idol
    • Location: Bristol
    • Posts: 9,352
    Re: TSR Usernames/Passwords
    (Original post by Chrosson)
    Additionally regarding the usernames and passwords, I'm curious - can you tell us the hashing+salting method (formerly?) used by TSR?
    Default vB hash is:

    Code:
    $password_hash = md5(md5($password_text) . $user_salt);
    With a per-user three character salt which is also stored in the database.
    Last edited by estel; 22-06-2012 at 01:02.
  6. Iqbal007's Avatar
    • TSR Legend
    • Posts: 13,345
    So TSR has been compromised!
    "IMPORTANT - Your Password has been compromised. You need to act.
    Unfortunately it has come to our attention that TSR has been compromised in a similar way to the recently publicised Linked In attack. At a minimum, username, hashed password and email addresses have been taken. Although the passwords were hashed/salted, they were unfortunately not secured to a level which would prevent them being cracked with modern approaches. You therefore need to act as if your actual password has been compromised.
    We therefore recommend that everyone changes their password immediately not only on TSR, but anywhere else they have used the same password.
    We will be reviewing our security measures over the coming days and communicating in a range of ways with all members to ensure that everyone receives this message.
    We are really sorry for the nuisance that this will cause."


    All I got was this to change my password.

    But seriously, what would a bunch people want to do with our user accounts.....seriously

    They are either very dumb "hackers" or the trolls are back for revenge :troll:
  7. Naarim's Avatar
    • Respected Member
    • Posts: 236
    Re: TSR Usernames/Passwords
    Urgh. Last.fm and now TSR.
  8. internet tough guy's Avatar
    • Overlord in Training
    • Posts: 2,509
    Re: TSR Usernames/Passwords
    Why do I keep getting this windows security pop-up when I'm on TSR:

    ''The server static2.staging.tsrfiles.co.uk at staging server requires a username and password.

    Warning. This server is requesting your username and password be sent in an insecure manner (basic authentication without a secure connection).''




    btw I'm on internet explorer 9.

    Edit: seems like this is happening on all browsers not just IE9
    Last edited by internet tough guy; 22-06-2012 at 01:09.
  9. SecondHand's Avatar
    • PS Helper
    • Exalted Member
    • Posts: 392
    Re: TSR Usernames/Passwords
    Here's an article which will explain the vulnerability (or what I imagine the vulnerability was).

    http://krebsonsecurity.com/2012/06/h...word-security/
  10. Ethereal's Avatar
    • PS Helper
    • TSR Legend
    • Location: Twilight where the worlds collide
    • Posts: 13,783
    Pop up saying something about a staging server
    I keep getting a pop up box with the following message in it:

    A user name and password are being requested by http://static2.staging.tsrfiles.co.uk. The site says: "Staging Server"

    it then has a space for username and password to be entered. I close it and the site works fine, but it's odd.
  11. Isometrix's Avatar
    • TSR Idol
    • Location: London
    • Posts: 7,929
    Re: TSR Usernames/Passwords
    (Original post by internet tough guy)
    Why do I keep getting this windows security pop-up when I'm on TSR:

    ''The server static2.staging.tsrfiles.co.uk at staging server requires a username and password.

    Warning. This server is requesting your username and password be sent in an insecure manner (basic authentication without a secure connection).''




    btw I'm on internet explorer 9
    Yep I'm getting some similar message popping up. I keep cancelling it though cos it's never come up before.

    I'm on the latest firefox on Mac.
  12. Morgsie's Avatar
    • TSR Idol
    • Location: Stoke-On-Trent
    • Posts: 9,017
    Re: TSR Usernames/Passwords
    (Original post by internet tough guy)
    Why do I keep getting this windows security pop-up when I'm on TSR:

    ''The server static2.staging.tsrfiles.co.uk at staging server requires a username and password.

    Warning. This server is requesting your username and password be sent in an insecure manner (basic authentication without a secure connection).''




    btw I'm on internet explorer 9
    I have just changed my password and I keep getting this message
  13. EierVonSatan's Avatar
    • PS Helper
    • TSR Royalty
    • Location: UK
    • Posts: 20,989
    Re: TSR Usernames/Passwords
    (Original post by internet tough guy)
    Why do I keep getting this windows security pop-up when I'm on TSR:

    ''The server static2.staging.tsrfiles.co.uk at staging server requires a username and password.

    Warning. This server is requesting your username and password be sent in an insecure manner (basic authentication without a secure connection).''




    btw I'm on internet explorer 9
    It looks as though the banner is currently using an image hosted on a restricted site - nothing to worry about just press cancel. I'm sure they'll get around to fixing that
  14. pinkangelgirl's Avatar
    • Overlord in Training
    • Posts: 2,700
    Re: TSR Usernames/Passwords
    i dont get it!! if ive changed my password will i be ok now?

    Also, do they only have our current password or will they have all the passwords weve ever used.

    Ive just had to log in everywhere and change everything to brane new passwords
  15. estel's Avatar
    • TSR Idol
    • Location: Bristol
    • Posts: 9,352
    Re: So TSR has been compromised!
    (Original post by Iqbal007)
    But seriously, what would a bunch people want to do with our user accounts.....seriously
    A huge percentage of people use their same account details for their email and forums such as TSR. Given access to someone's email account it's usually quite possible to find most of their other passwords, and quite likely access their Paypal / other bank details, or give a wealth of information that would allow the hacker to steal your identity.
  16. estel's Avatar
    • TSR Idol
    • Location: Bristol
    • Posts: 9,352
    Re: TSR Usernames/Passwords
    (Original post by pinkangelgirl)
    i dont get it!! if ive changed my password will i be ok now?

    Also, do they only have our current password or will they have all the passwords weve ever used.
    VB / TSR will need a massive glare if it's the latter, but I imagine it will be the former.

    If your TSR password isn't being used on any other sites, and TSR's original vulnerability has been fixed, there's not much more you can do for now.
  17. pinkangelgirl's Avatar
    • Overlord in Training
    • Posts: 2,700
    Re: So TSR has been compromised!
    i have literally just this second created a new password and already ive forgotten it!! what is wrong with me and my memory.
  18. tehforum's Avatar
    • TSR Legend
    • Location: England
    Re: So TSR has been compromised!
    . Although the passwords were hashed/salted, they were unfortunately not secured to a level which would prevent them being cracked with modern approaches.

    Why not?

    Is TSR not a modern website? Is TSR benevolent towards the threat of cyber-hacking? Evidently so.

    Does it not care about the millions of users personal information?

    Please do not lecture me with cries of "oh, all you have to do is change your password", it is a case of principle and the mere reality that this has occurred.

    I have changed my password.
  19. TheSownRose's Avatar
    • PS Helper
    • TSR Royalty
    • Location: Alone up on the hills and snow
    Re: So TSR has been compromised!
    (Original post by estel)
    A huge percentage of people use their same account details for their email and forums such as TSR. Given access to someone's email account it's usually quite possible to find most of their other passwords, and quite likely access their Paypal / other bank details, or give a wealth of information that would allow the hacker to steal your identity.
    ^ This.


    Using a different username and password for everything doesn't look so silly now.
  20. I Kant Spall's Avatar
    • Exalted and Worshipped Member
    • Location: Turin
    Re: TSR Usernames/Passwords
    Changed my TSR password.
    Changed my e-mail password.
    Installed noscript.
    Ran a virus scan.
    Turned off laptop.
    Turned off router.
    Fled the country.
    Renounced citizenship.
    Joined a monastery.

    Guess I had the last laugh--shows you, hackers.
Sign in to Reply
Share this discussion:  
Article updates
Moderators

We have a brilliant team of more than 60 volunteers looking after discussions on The Student Room, helping to make it a fun, safe and useful place to hang out.

Reputation gems:
The Reputation gems seen here indicate how well reputed the user is, red gem indicate negative reputation and green indicates a good rep.
Post rating score:
These scores show if a post has been positively or negatively rated by our members.