SoFurry hacked; users advised to change passwords

Edited as of 12:26
Users of SoFurry and its predecessor Yiffstar are being told to change their passwords, as the site's MD5 hashes have been compromised. [gsw/]

Toumal admitted the site had been vulnerable for the past eighteen months, but said the "security hole" had been fixed. New passwords will be salted to reduce the damage of any future breach. He also cautioned against using the same password on different sites.

While a hash does not contain the password, it is possible to deduce commonly-used passwords by comparing against a list of pre-made hashes. Salting adds an extra component to the password, rendering this so-called "rainbow table" technique infeasible.

The reporter of the security vulnerability has not publicly distributed the hashes, and is currently assisting with a review of the site's security. According to Toumal, this is the second time in as many years that a third-party has "helped" in this fashion.

Online multiplayer social game Furcadia suffered a similar security breach last October.


I'm sorry but I actually got a chuckle. Looks like hackers got tired of Twitter, and are now moving onto bigger and better things.

Well, it's a brand-new codebase, so it's bound to have all sorts of bugs, including security bugs. Also, security (which includes authentication) and cryptography is hard to get correct.

In before a certain mouse starts spewing (elsewhere, probably) crap about being a furry making one incapable of programming well.

Alas, Toumal has stated that the bug was present in Yiffstar as well; it was an XSS vulnerability in the private messaging system.

Of course they are not the only furry art site with major security holes, some far more easily exploited. :-p

Ugh, I think I got to my account too little toolate, I will have to remake my account on there.

