![]() |
|
Possible Nexon Database Exploit? - Printable Version +- Southperry.net (https://www.southperry.net) +-- Forum: Maplestory (https://www.southperry.net/forumdisplay.php?fid=15) +--- Forum: Maplestory Discussion (https://www.southperry.net/forumdisplay.php?fid=31) +--- Thread: Possible Nexon Database Exploit? (/showthread.php?tid=40167) |
Possible Nexon Database Exploit? - Panacea - 2011-04-06 Okay, well, to put you at ease I just cleared any and all saved data that my browser had stored. I'm also installing Avast! to check for possible key loggers, just in case McAfee missed anything. I'll let you know the results. EDIT: Quick scan yielded nothing to report. Still waiting for full scan. Possible Nexon Database Exploit? - Toastyc12 - 2011-04-06 Do you have a Tivo account? All emails in Tivo's database was recently exploited and exposed, though I'm not sure if that would lead to getting hacked. That's actually a pretty extreme scenario. Possible Nexon Database Exploit? - Panacea - 2011-04-06 Toastyc12 Wrote:Do you have a Tivo account? All emails in Tivo's database was recently exploited and exposed, though I'm not sure if that would lead to getting hacked. That's actually a pretty extreme scenario. Nope. Possible Nexon Database Exploit? - ctblack - 2011-04-06 Panacea Wrote:Okay, well, to put you at ease I just cleared any and all saved data that my browser had stored. I'm also installing Avast! to check for possible key loggers, just in case McAfee missed anything. I'll let you know the results. You mention keyloggers! Not sure you understand the concept of this current discussion of possible hacking via wireless data? Its got nothing to do with keyloggers and don't need a keylogger to get hacked. Since Nexon's web site login is not https, all data transmitted are in plain unencrypted text including your login ID and password over wireless frequency, so anyone that had legit access to the network just need to use a readily available wireless hacking tools to "read" all data from the network and then able to pick out what they want by using some type of filtering. As for person without legit access, they will need to use a encryption key mining tool which also readily available and then do the above. Keylogger was another discussed possibility in this thread, maybe thats why it causes the confusion. Keylogger are very rare in my opinion, you really have to go out of your way to get infected with it, so I think your scan won't show any infection, but still a good action to perform after a event like this. Possible Nexon Database Exploit? - Panacea - 2011-04-06 ctblack Wrote:You mention keyloggers! Not sure you understand the concept of this current discussion of possible hacking via wireless data? Its got nothing to do with keyloggers and don't need a keylogger to get hacked. Since Nexon's web site login is not https, all data transmitted are in plain unencrypted text including your login ID and password over wireless frequency, so anyone that had legit access to the network just need to use a readily available wireless hacking tools to "read" all data from the network and then able to pick out what they want by using some type of filtering. As for person without legit access, they will need to use a encryption key mining tool which also readily available and then do the above. I think I understand now. Would the outcome be the same if when I access the game I'm wired directly to the university server instead of wireless? Possible Nexon Database Exploit? - ctblack - 2011-04-06 Panacea Wrote:I think I understand now. Would the outcome be the same if when I access the game I'm wired directly to the university server instead of wireless? If you are wire connected it would be more difficult for the hacker to "read" your activities, but if they are in the same network access point (switch/hud) as you, they can still sniff all the data arriving at that point using a similar tool as the wireless hacking tools. If you had gotten hacked while you were wire connect, you would have to be either targeted or very unlucky. Bottom line is when passing personal information on any non encrypted site is not safe. Always check the url to see if it is https or just plain http. Possible Nexon Database Exploit? - Panacea - 2011-04-06 ctblack Wrote:Bottom line is when passing personal information on any non encrypted site is not safe. Always check the url to see if it is https or just plain http. The Maplestory website is the only place I enter my Maplestory info, if I for some reason decide not to go through Gamelauncher. Possible Nexon Database Exploit? - JoeTang - 2011-04-06 Can't explain that. Possible Nexon Database Exploit? - Toastyc12 - 2011-04-06 Panacea Wrote:The Maplestory website is the only place I enter my Maplestory info, if I for some reason decide not to go through Gamelauncher. Maplestory website is not exactly secure. In the instance you were to use the site, what browser are you running when you do sign on? Possible Nexon Database Exploit? - Panacea - 2011-04-06 Toastyc12 Wrote:Maplestory website is not exactly secure. In the instance you were to use the site, what browser are you running when you do sign on? Chrome. Possible Nexon Database Exploit? - iananderson - 2011-04-07 Sounds very similar to what happened to me about a month ago. I was training my UA and got off right before a server check happened. It ended an hour before I got on again and I noticed that my characters weren't wearing what I logged off with. I tried to log on to one of my characters and my PIC was changed. I went directly to my email and there was no notice of a change, so I changed my email password and reset my PIC. When I finally got on everything that wasn't nailed down(untradable) was gone so it was clearly for pure profit. I checked through the FM and found mushroom shop with all my stuff. I monitored it for a while and now it seems that everything that wasn't sold on that mules shop is now in this guy's shop. I hadn't downloaded anything for about a month before this happened unless it was school related, my userID was something I never shared and I never used the ID on any other sites. My password and PIC were not something easy like "password" "111111" and would have been impossible to guess. I scanned with multiple scanners and nothing was found with any of them. Possible Nexon Database Exploit? - Panacea - 2011-04-07 iananderson Wrote:Sounds very similar to what happened to me about a month ago. I was training my UA and got off right before a server check happened. It ended an hour before I got on again and I noticed that my characters weren't wearing what I logged off with. I tried to log on to one of my characters and my PIC was changed. I went directly to my email and there was no notice of a change, so I changed my email password and reset my PIC. That's really strange, and I don't like it, lol. Especially happening right after a server check. I'm sorry it happened to you, too. Possible Nexon Database Exploit? - knlbr - 2011-04-08 well, back in 2009 my e-mail was definitely not compromised when my account was hacked. unless they decided to cover their tracks for some reason... no info was changed anywhere, my account just went naked between days >_> Possible Nexon Database Exploit? - Locked - 2011-04-08 knlbr Wrote:unless they decided to cover their tracks for some reason... Why wouldn't you cover your tracks... Possible Nexon Database Exploit? - knlbr - 2011-04-08 Locked Wrote:Why wouldn't you cover your tracks... is it worth the effort when you take a low level account stuff worth 200mish? xd Possible Nexon Database Exploit? - Locked - 2011-04-08 knlbr Wrote:is it worth the effort when you take a low level account stuff worth 200mish? xd ..Yes. It isn't hard to delete 4 emails, that completely clean off your record and cause confusion like is currently happening. Possible Nexon Database Exploit? - Muppy - 2011-04-08 Ugh... Could it be that they really did get some info (lol nexonsecurity) but instead of going wild with them they're just taking it slow, in order to not raise too much suspicion?
Possible Nexon Database Exploit? - Panacea - 2011-04-08 Locked Wrote:..Yes. I agree. They hadn't changed my password at all, so I can't confirm whether they actually had access to my email or not. My mom asked my dad if anything suspicious had been emailed to him and he said no, but I was like, "F7". I know they don't understand, so I just told my mom to change the password and watch out for anything else such as eBay, PayPal, etc. Muppy Wrote:Ugh... Could it be that they really did get some info (lol nexonsecurity) but instead of going wild with them they're just taking it slow, in order to not raise too much suspicion? Danny's proposition is the most plausible to me, at the moment. It's possible they've had my UserID since '09 and just now hit me with it, despite how long it's been. Possible Nexon Database Exploit? - vnthi3f - 2011-04-08 sorry for your loss Floe Possible Nexon Database Exploit? - Panacea - 2011-04-08 No worries, Tepp. Thanks. |