• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Technical Issues - TPU Main Site & Forum (2021)

Status
Not open for further replies.

W1zzard

Administrator
Staff member
Joined
May 14, 2004
Messages
28,150 (3.72/day)
Processor Ryzen 7 5700X
Memory 48 GB
Video Card(s) RTX 4080
Storage 2x HDD RAID 1, 3x M.2 NVMe
Display(s) 30" 2560x1600 + 19" 1280x1024
Software Windows 10 64-bit
Oh, hell no. TPU starts that crap and there will be problems. It should be user choice, not mandatory.
Agreed. I'm thinking about making it mandatory for staff, but not even that is decided yet
 
Joined
Nov 23, 2020
Messages
543 (0.35/day)
Location
Not Chicago, Illinois
System Name Desktop-TJ84TBK
Processor Ryzen 5 3600
Motherboard Asus ROG Strix B350-F Gaming
Cooling ARCTIC Liquid Freezer II 120mm, Noctua NF-F12
Memory B-Die 2x8GB 3200 CL14, Vengeance LPX 2x8GB 3200 CL16, OC'd to 3333 MT/s C16-16-16-32 tRC 48
Video Card(s) PNY GTX 690
Storage Crucial MX500 1TB, MX500 500GB, WD Blue 1TB, WD Black 2TB, WD Caviar Green 3TB, Intel Optane 16GB
Display(s) Sceptre M25 1080p200, ASUS 1080p74, Apple Studio Display M7649 17"
Case Rosewill CRUISER Black Gaming
Audio Device(s) SupremeFX S1220A
Power Supply Seasonic FOCUS GM-750
Mouse Kensington K72369
Keyboard Razer BlackWidow Ultimate 2013
Software Windows 10 Home 64-bit, macOS 11.7.8
Benchmark Scores are good
Mandatory 2FA is cumbersome and annoying. I refuse to use Discord because of it. It's NOT needed if people use properly long and well crafted passwords and don't monkey about on the internet.
Plus there's some people (like me) who can't use 2FA. Requiring it would essentially boot me out of here.
 

FireFox

The Power Of Intel
Joined
Feb 19, 2014
Messages
7,507 (1.88/day)
Location
Germany
Processor Intel i7 10700K
Motherboard Asus ROG Maximus XII Hero
Cooling 2x Black Ice Nemesis GTX 480 - 1x Black Ice Nemesis GTX 420 - D5 VPP655P - 13x Corsair LL120 - LL140
Memory 32GB G.SKILL Trident Z RGB 3600Hz
Video Card(s) EVGA GEFORCE RTX 3080 XC3 Ultra
Storage Samsung 970 EVO PLUS 500GB/1TB - WD Blue SN550 1TB - 2 X WD Blue 1TB - 3 X WD Black 1TB
Display(s) Asus ROG PG278QR 2560x1440 144Hz (Overclocked 165Hz )/ Samsung
Case Corsair Obsidian 1000D
Audio Device(s) I prefer Gaming-Headset
Power Supply Enermax MaxTytan 1250W 80+ Titanium
Mouse Logitech G502 spectrum
Keyboard Virtuis Advanced Gaming Keyboard ( Batboard )
Software Windows 10 Enterprise/Windows 10 Pro/Windows 11 Pro
Benchmark Scores My PC runs FiFA
My login details can be stolen but they still need my fingerprint.
 
Joined
Sep 2, 2020
Messages
1,491 (0.92/day)
System Name Chip
Processor Amd 5600X
Motherboard MSI B450M Mortar Max
Cooling Hyper 212
Memory 2x 16g ddr4 3200mz
Video Card(s) RX 6700
Storage 5.5 tb hd 220 g ssd
Display(s) Normal moniter
Case something cheap
VR HMD Vive
Mandatory 2FA is cumbersome and annoying. I refuse to use Discord because of it. It's NOT needed if people use properly long and well crafted passwords and don't monkey about on the internet.
Discord does not require 2fa never has
 
Joined
Sep 2, 2020
Messages
1,491 (0.92/day)
System Name Chip
Processor Amd 5600X
Motherboard MSI B450M Mortar Max
Cooling Hyper 212
Memory 2x 16g ddr4 3200mz
Video Card(s) RX 6700
Storage 5.5 tb hd 220 g ssd
Display(s) Normal moniter
Case something cheap
VR HMD Vive
Joined
Sep 10, 2016
Messages
824 (0.27/day)
Location
Riverwood, Skyrim
System Name Storm Wrought | Blackwood (HTPC)
Processor AMD Ryzen 9 5900x @stock | i7 2600k
Motherboard Gigabyte X570 Aorus Pro WIFI m-ITX | Some POS gigabyte board
Cooling Deepcool AK620, BQ shadow wings 3 High Spd, stock 180mm |BQ Shadow rock LP + 4x120mm Noctua redux
Memory G.Skill Ripjaws V 2x32GB 4000MHz | 2x4GB 2000MHz @1866
Video Card(s) Powercolor RX 6800XT Red Dragon | PNY a2000 6GB
Storage SX8200 Pro 1TB, 1TB KC3000, 850EVO 500GB, 2+8TB Seagate, LG Blu-ray | 120GB Sandisk SSD, 4TB WD red
Display(s) Samsung UJ590UDE 32" UHD monitor | LG CS 55" OLED
Case Silverstone TJ08B-E | Custom built wooden case (Aus native timbers)
Audio Device(s) Onboard, Sennheiser HD 599 cans / Logitech z163's | Edifier S2000 MKIII via toslink
Power Supply Corsair HX 750 | Corsair SF 450
Mouse Microsoft Pro Intellimouse| Some logitech one
Keyboard GMMK w/ Zelio V2 62g (78g for spacebar) tactile switches & Glorious black keycaps| Some logitech one
VR HMD HTC Vive
Software Win 10 Edu | Ubuntu 22.04
Benchmark Scores Look in the various benchmark threads

FreedomEclipse

~Technological Technocrat~
Joined
Apr 20, 2007
Messages
24,400 (3.75/day)
Location
Hong Kong
System Name WorkInProgress
Processor AMD 7800X3D
Motherboard MSI X670E GAMING PLUS
Cooling Thermalright AM5 Contact Frame + Phantom Spirit 120SE
Memory 2x32GB G.Skill Trident Z5 NEO DDR5 6000 CL32
Video Card(s) Asus Dual Radeon™ RX 6700 XT OC Edition
Storage WD SN770 1TB (Boot)|1x WD SN850X 8TB (Gaming)| 2x2TB WD SN770| 2x2TB+2x4TB Crucial BX500
Display(s) LG GP850-B
Case Corsair 760T (White) {1xCorsair ML120 Pro|5xML140 Pro}
Audio Device(s) Yamaha RX-V573|Speakers: JBL Control One|Auna 300-CN|Wharfedale Diamond SW150
Power Supply Seasonic Focus GX-850 80+ GOLD
Mouse Logitech G502 X
Keyboard Duckyshine Dead LED(s) III
Software Windows 11 Home
Benchmark Scores ლ(ಠ益ಠ)ლ
Im curious as to how @Durvelle27 machine was exploited also where the exploit originated from and how and when. Was there some malicious code written to the FP that injected some other code and started hijacking or logging the users keypresses? what was TPUs involvement in all of it if multiple users was hacked? It couldnt of been a freak accident unless the affected accounts are either all run by the same person which is against ToS or the users both visted the same website or clicked on the same link that lead to their details being stolen or hacked. Im guessing it wasnt a brute force attack because TPU would have banned many I.Ps already
 
Joined
Jul 5, 2013
Messages
28,958 (6.84/day)
I've used it for 3 years and only ever received one email saying verify your account when I made it'
I have it and I've never had to use 2FA for it
Anytime your IP address changes Discord requires re-authentication via email. That is a form of 2FA. My IP often changes daily, so for me and people who have a similar situation, it's a unnecessary and annoying hassle. It's also totally pointless. No fraking thank you.
 
Joined
Sep 2, 2020
Messages
1,491 (0.92/day)
System Name Chip
Processor Amd 5600X
Motherboard MSI B450M Mortar Max
Cooling Hyper 212
Memory 2x 16g ddr4 3200mz
Video Card(s) RX 6700
Storage 5.5 tb hd 220 g ssd
Display(s) Normal moniter
Case something cheap
VR HMD Vive
Anytime your IP address changes Discord requires re-authentication via email. That is a form of 2FA. My IP often changes daily, so for me and people who have a similar situation, it's a unnecessary and annoying hassle. It's also totally pointless. No fraking thank you.
My IP changes monthly and I move around quite a bit still never ever received a 2fa email
 
Joined
Sep 2, 2020
Messages
1,491 (0.92/day)
System Name Chip
Processor Amd 5600X
Motherboard MSI B450M Mortar Max
Cooling Hyper 212
Memory 2x 16g ddr4 3200mz
Video Card(s) RX 6700
Storage 5.5 tb hd 220 g ssd
Display(s) Normal moniter
Case something cheap
VR HMD Vive

W1zzard

Administrator
Staff member
Joined
May 14, 2004
Messages
28,150 (3.72/day)
Processor Ryzen 7 5700X
Memory 48 GB
Video Card(s) RTX 4080
Storage 2x HDD RAID 1, 3x M.2 NVMe
Display(s) 30" 2560x1600 + 19" 1280x1024
Software Windows 10 64-bit
what was TPUs involvement in all of it if multiple users was hacked?
Im guessing it wasnt a brute force attack because TPU would have banned many I.Ps already
- all our passwords are hashed and salted, using modern methods, so they can't be reversed, even if we have a data leak
- i looked in the logs, and it simply looks like they knew the correct password
- brute force isn't feasible, because XF blocks brute force on both a username and IP level
- my current theory is that they used the same password on multiple sites, and the attacker simply collected multiple working logins, before making a targeted attack to create FSFT threads for graphics cards
- so far zero hacks today
 
Joined
Jul 5, 2013
Messages
28,958 (6.84/day)
- all our passwords are hashed and salted, using modern methods, so they can't be reversed, even if we have a data leak
- i looked in the logs, and it simply looks like they knew the correct password
- brute force isn't feasible, because XF blocks brute force on both a username and IP level
- my current theory is that they used the same password on multiple sites, and the attacker simply collected multiple working logins, before making a targeted attack to create FSFT threads for graphics cards
- so far zero hacks today
Ok, so this was a social hacking job not a site hacking problem. Good to know.
 

qubit

Overclocked quantum bit
Joined
Dec 6, 2007
Messages
17,865 (2.85/day)
Location
Quantum Well UK
System Name Quantumville™
Processor Intel Core i7-2700K @ 4GHz
Motherboard Asus P8Z68-V PRO/GEN3
Cooling Noctua NH-D14
Memory 16GB (2 x 8GB Corsair Vengeance Black DDR3 PC3-12800 C9 1600MHz)
Video Card(s) MSI RTX 2080 SUPER Gaming X Trio
Storage Samsung 850 Pro 256GB | WD Black 4TB | WD Blue 6TB
Display(s) ASUS ROG Strix XG27UQR (4K, 144Hz, G-SYNC compatible) | Asus MG28UQ (4K, 60Hz, FreeSync compatible)
Case Cooler Master HAF 922
Audio Device(s) Creative Sound Blaster X-Fi Fatal1ty PCIe
Power Supply Corsair AX1600i
Mouse Microsoft Intellimouse Pro - Black Shadow
Keyboard Yes
Software Windows 10 Pro 64-bit
Agreed. I'm thinking about making it mandatory for staff, but not even that is decided yet
I think it should be mandatory for admins, since they've got the power to really screw up the forum. This will be my policy for my forum when it's finally up and running. Mods are not too bad, because their actions can usually be reversed without too much trouble, so it would be recommended, not enforced.
 
Joined
Aug 4, 2020
Messages
1,634 (0.99/day)
Location
::1
it would remember all your recent IPs of course, not just the last one


XF already records this IP history, so just piggybacking on it with an addon should be easy
How about making that IP history visible to the user? Like, their personal history. Some sites do that, and it's a really neat tool for the technically adept to spot potential breaches.
If it is feasible, even failed attempts; at the very least the ones where the password was breached but not the tfauth (idt XF logs those per default/stock, would require an addon).

Speaking of tfauth, I'd recommend this: https://winauth.github.io/winauth/download.html
Saves you the trouble of having a phone or something. However, it does mean that compromising your computer would also compromise your accounts - something to keep in mind. Personally, I am fine with that because I am confident enough in my abilities to keep my computer secure, but obviously your mileage may vary.
 
Joined
Dec 16, 2017
Messages
2,990 (1.15/day)
System Name System V
Processor AMD Ryzen 5 3600
Motherboard Asus Prime X570-P
Cooling Cooler Master Hyper 212 // a bunch of 120 mm Xigmatek 1500 RPM fans (2 ins, 3 outs)
Memory 2x8GB Ballistix Sport LT 3200 MHz (BLS8G4D32AESCK.M8FE) (CL16-18-18-36)
Video Card(s) Gigabyte AORUS Radeon RX 580 8 GB
Storage SHFS37A240G / DT01ACA200 / ST10000VN0008 / ST8000VN004 / SA400S37960G / SNV21000G / NM620 2TB
Display(s) LG 22MP55 IPS Display
Case NZXT Source 210
Audio Device(s) Logitech G430 Headset
Power Supply Corsair CX650M
Software Whatever build of Windows 11 is being served in Canary channel at the time.
Benchmark Scores Corona 1.3: 3120620 r/s Cinebench R20: 3355 FireStrike: 12490 TimeSpy: 4624
You would be mistaken. Try using it.
That's a per-server directive, it's not everywhere. Without going too far, TPU's own Discord server doesn't even require me to wait ten minutes (or at least it didn't when I joined in)
20210421-094404.png

20210421-094410.png


BTW, @W1zzard , is it possible to implement some sort of list of where you're logged in, where you can log out all open sessions? Something like this, I mean:
1619009244533.png


Though I'm not sure about the ramifications (say, attacker gets access and the first thing it does is kick out the legitimate user and keep kicking them out every time they try to log in/get control back), it's just a thought.
 
Joined
Jul 18, 2016
Messages
520 (0.17/day)
System Name Gaming PC / I7 XEON
Processor I7 4790K @stock / XEON W3680 @ stock
Motherboard Asus Z97 MAXIMUS VII FORMULA / GIGABYTE X58 UD7
Cooling X61 Kraken / X61 Kraken
Memory 32gb Vengeance 2133 Mhz / 24b Corsair XMS3 1600 Mhz
Video Card(s) Gainward GLH 1080 / MSI Gaming X Radeon RX480 8 GB
Storage Samsung EVO 850 500gb ,3 tb seagate, 2 samsung 1tb in raid 0 / Kingdian 240 gb, megaraid SAS 9341-8
Display(s) 2 BENQ 27" GL2706PQ / Dell UP2716D LCD Monitor 27 "
Case Corsair Graphite Series 780T / Corsair Obsidian 750 D
Audio Device(s) ON BOARD / ON BOARD
Power Supply Sapphire Pure 950w / Corsair RMI 750w
Mouse Steelseries Sesnsei / Steelseries Sensei raw
Keyboard Razer BlackWidow Chroma / Razer BlackWidow Chroma
Software Windows 1064bit PRO / Windows 1064bit PRO
Several forum members have been hacked yesterday, please be ultra-careful when making purchases or doing some other kind of money transfer. Feel free to report suspicious activity directly to W1zzard

Are you sure that the forum was not compromised?
 

W1zzard

Administrator
Staff member
Joined
May 14, 2004
Messages
28,150 (3.72/day)
Processor Ryzen 7 5700X
Memory 48 GB
Video Card(s) RTX 4080
Storage 2x HDD RAID 1, 3x M.2 NVMe
Display(s) 30" 2560x1600 + 19" 1280x1024
Software Windows 10 64-bit

qubit

Overclocked quantum bit
Joined
Dec 6, 2007
Messages
17,865 (2.85/day)
Location
Quantum Well UK
System Name Quantumville™
Processor Intel Core i7-2700K @ 4GHz
Motherboard Asus P8Z68-V PRO/GEN3
Cooling Noctua NH-D14
Memory 16GB (2 x 8GB Corsair Vengeance Black DDR3 PC3-12800 C9 1600MHz)
Video Card(s) MSI RTX 2080 SUPER Gaming X Trio
Storage Samsung 850 Pro 256GB | WD Black 4TB | WD Blue 6TB
Display(s) ASUS ROG Strix XG27UQR (4K, 144Hz, G-SYNC compatible) | Asus MG28UQ (4K, 60Hz, FreeSync compatible)
Case Cooler Master HAF 922
Audio Device(s) Creative Sound Blaster X-Fi Fatal1ty PCIe
Power Supply Corsair AX1600i
Mouse Microsoft Intellimouse Pro - Black Shadow
Keyboard Yes
Software Windows 10 Pro 64-bit
- my current theory is that they used the same password on multiple sites, and the attacker simply collected multiple working logins, before making a targeted attack to create FSFT threads for graphics cards
An excellent real world example of why a password should only be used once per site. This is drummed into users all the time, but still there are those who won't listen.
 

Frick

Fishfaced Nincompoop
Joined
Feb 27, 2006
Messages
19,805 (2.86/day)
Location
north
System Name Black MC in Tokyo
Processor Ryzen 5 7600
Motherboard MSI X670E Gaming Plus Wifi
Cooling Be Quiet! Pure Rock 2
Memory 2 x 16GB Corsair Vengeance @ 6000Mhz
Video Card(s) XFX 6950XT Speedster MERC 319
Storage Kingston KC3000 1TB | WD Black SN750 2TB |WD Blue 1TB x 2 | Toshiba P300 2TB | Seagate Expansion 8TB
Display(s) Samsung U32J590U 4K + BenQ GL2450HT 1080p
Case Fractal Design Define R4
Audio Device(s) Plantronics 5220, Nektar SE61 keyboard
Power Supply Corsair RM850x v3
Mouse Logitech G602
Keyboard Dell SK3205
Software Windows 10 Pro
Benchmark Scores Rimworld 4K ready!
Plus there's some people (like me) who can't use 2FA. Requiring it would essentially boot me out of here.

So you don't have email?
Mandatory 2FA is cumbersome and annoying. I refuse to use Discord because of it. It's NOT needed if people use properly long and well crafted passwords and don't monkey about on the internet.

Or if you hang about on a targeted platform or forum.
 
Joined
Dec 16, 2017
Messages
2,990 (1.15/day)
System Name System V
Processor AMD Ryzen 5 3600
Motherboard Asus Prime X570-P
Cooling Cooler Master Hyper 212 // a bunch of 120 mm Xigmatek 1500 RPM fans (2 ins, 3 outs)
Memory 2x8GB Ballistix Sport LT 3200 MHz (BLS8G4D32AESCK.M8FE) (CL16-18-18-36)
Video Card(s) Gigabyte AORUS Radeon RX 580 8 GB
Storage SHFS37A240G / DT01ACA200 / ST10000VN0008 / ST8000VN004 / SA400S37960G / SNV21000G / NM620 2TB
Display(s) LG 22MP55 IPS Display
Case NZXT Source 210
Audio Device(s) Logitech G430 Headset
Power Supply Corsair CX650M
Software Whatever build of Windows 11 is being served in Canary channel at the time.
Benchmark Scores Corona 1.3: 3120620 r/s Cinebench R20: 3355 FireStrike: 12490 TimeSpy: 4624
would require me to study how this works on xf and write an addon, not sure if worth it
I see. In any case, though, I'd greatly appreciate just having the list of either open sessions or the IP history, the "force log out all other sessions" feature isn't really that important (honestly, by that point they already have my email, which is the only quickly exploitable data they'd get)
 
Status
Not open for further replies.
Top