[TYPO3-english] TYPO3.ORG hacked

Luc Muller l.mul-nospam-ler at ameos.com
Fri Nov 14 14:45:25 CET 2008


My question is : Are the FE password md5 hashed or something on TYPO3.org

This is the mail I got :

-------------------------------------------------------

This is an important security warning. You are receiving it because your 
email address is registered on the TYPO3.org website.

 

We have to inform you that an unauthorized person has gained 
administrative access to the TYPO3.org website.

 

The offender had access to website user details including their 
passwords, and there have been reports of this data being used to access 
other websites.

It also has to be expected that the data may have been disclosed to 
third parties.

 

The attacker has been identified, and the TYPO3 Association has started 
to take legal action on the issue.

 

Important!

IF YOU HAVE USED THE SAME PASSWORD ON ANY OTHER SITE, PLEASE CHANGE IT 
IMMEDIATELY!

 

In a first step, all login accounts on TYPO3.org have been locked and 
will require a new password. We are currently working on an improved 
login procedure and will let you know when this is ready. Until then, 
you will not be able to log into the Community section of TYPO3.org.

 

We have set up an FAQ page at http://typo3.org/about/faq/t3org-issue/

The page may be updated with new questions from time to time, so make 
sure to check back before replying to this mail.

 

We apologize for the inconveniences and troubles that this might cause 
to you.

 

TYPO3 Association

-------------------------------------------------------


-- 

*Luc Muller*
/Web Developper/
/Formidable - Rapid Application Developpement Framework for Typo3 
<http://formidable.typo3.ug>/
/Typo3 Ameos <http://www.ameos.com>/


More information about the TYPO3-english mailing list