Lightbringer- recently announced
here abuse of the ladder and that several well-known accounts had been compromised. After looking into it this is what we believe happened:
- USA~Archer is responsible and most likely acted alone.
- He did not access the .ru database in any way. The winbotting/ladder abuse was most likely an attempt to do so.
- The passwords of the stolen accounts came from War2.me: he exploited the server database via an SQLi vulnerability in an open source ladder/stats script. (This is known for certain.) That allowed him to download the entire database and crack the password hashes, and then try the username/password combos on .ru to see if any were the same.
- So, only the accounts of people who registered on War2.me at some point AND used the same password both there and on .ru were vulnerable.
- USA~Archer has contacted a few people and denied that he had any part in this, but his story is very farfetched and impossible to verify. The most logical explanation is that Archer did everything himself, since it's known for a fact that he compromised war2.me. As of right now he's been permanently banned from forum & server.