Quote:

How did you get in?




They got into ADT with DenverDon's password. No hacking of ADT was required.

I quit reading that thread after a day after it was started but it appears to have been a somewhat carefully planned attack on ADT by someone who has been on ADT before.

My guess is that someone used the ADT chats to get the IP addresses for a few ADT mods and then used various script kiddie tools to attack the ADT mod's systems, probably within hours of each chat in order to get in before the IP address changed. Smartt could certainly do this - there's ample off-the-shelf tools for it (although some minimal intelligence is needed - see The Story of a Mighty Hacker thead).

There's no telling how many tries this took or how many ADT mods were attacked, but at some point an attack succeeded with DD and (at least) his ADT password was retrieved.

Note that they don't know when this happened. I assume that by now Drew has correlated every login by DD from the fake DD's IP and knows when the first fake DD login occurred, but DD's password may have been retrieved much earlier.

The reason I'm suspicious of the timing here is that Drew has been on vacation, and temporarily granted DD elevated permissions to take care of things. Someone in the ADT chats trolling for mod's IP address might have overheard this and decide this was the time to make use of DD's password.

This is less likely to happen here. I don't think Jeff lets Tony take vacation time, except maybe to relax with a Donkey Punch shoot, and mods here can't access or change nearly as much as DD while he had elevated privileges in Drew's absence.

PS. I would assume xxxpt also uses reversible or plaintext storage for passwords. I'm told that most off-the-shelf forum software does it. I think ADT uses custom forum software so they have a choice, but they're probably not any different than anyone else in this regard.
_________________________
"If they can't picture me with a knife, forcing them to strip in an alley, I don't want any part of it. It's humiliating." - windsock