Senior Member
Posts: 614
Threads: 88
Joined: 2010-08
Gender: Male
Country Flag: thailand
IGN: Knight52
Server: Earth
Level: 534
Job: Thread Breaker
Guild: I'm bored of
Guild Alliance: political sh'it
There's no actual proof for this, but it can't be anyone else. It must be someone inside.
There's been hacking activities in TMS lately. And everyone who got hacked found same things, their account passwords got changed and hackers took only godly items, left other stuffs untouched.
What strange is their MS passwords got changed, anyone who changed their password must have access to @passport(We use @passport to create and edit MS account). Regular scammers, those you keep bumping into throughout the game, don't know or care about it. They will ask for your MS accounts only since they can't find any reason to ask for your @passport.
Keylogger?We barely use @passport, I mean typing the account name and password itself. Some even forgot their own. So it can't be keylogger. E-mail hack? Possible, but I can't see how hackers know @passport account name through email hacking. And a friend of mine, who got hacked too, is not stupid enough to give his @passport account and password or his e-mail password to anyone - even his g/f doesn't know.
So who else got access to their @passport? Asiasoft itself. It's very hard to believe, but as I said, it can't be anyone else.
If you can come up with how's other people, someone outside Asiasoft, know your @passport, I'm happy to hear that.
Posting Freak
Posts: 5,136
Threads: 50
Joined: 2009-09
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
XSS Attack?
Insert attack at the @passport level?
There's several possibilities, speculation about them all won't help anything, and declaring you know the One Possible Answer doesn't help either.
Posting Freak
Posts: 4,490
Threads: 167
Joined: 2008-07
Is it the same thing than happened to GMS earlier this year?
Senior Member
Posts: 614
Threads: 88
Joined: 2010-08
Gender: Male
Country Flag: thailand
IGN: Knight52
Server: Earth
Level: 534
Job: Thread Breaker
Guild: I'm bored of
Guild Alliance: political sh'it
Eosian Wrote:XSS Attack?
Insert attack at the @passport level?
There's several possibilities, speculation about them all won't help anything, and declaring you know the One Possible Answer doesn't help either.
What's XSS attack?
Senior Member
Posts: 277
Threads: 23
Joined: 2008-10
there was a major database from different website hacked this week that dumped emails, pass, and usernames on major hacker sites. Twilight was the site i think. so if people use the same username and pass on maple and for their email it is possible. who knows.
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
Unauthorized Intruder Wrote:What's XSS attack?
http://en.wikipedia.org/wiki/XSS
Was that so hard?
Senior Member
Posts: 737
Threads: 34
Joined: 2010-08
It's equally likely someone hacked the Asiasoft mainframe and stole all the customer data. Inside job seems like a sure-fire way to get yourself caught.
But I don't know how Thai hackers operate, speculations speculations.
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
larmie Wrote:It's equally likely someone hacked the Asiasoft mainframe and stole all the customer data.
ROFLMAO... " Mainframe"... A windows 2000 server cluster does not a mainframe make.
Senior Member
Posts: 613
Threads: 10
Joined: 2009-04
SunnySis Wrote:there was a major database from different website hacked this week that dumped emails, pass, and usernames on major hacker sites. Twilight was the site i think. so if people use the same username and pass on maple and for their email it is possible. who knows.
Reminds me of that recent article talking about login security being generally high on most sites, but everything after that is considered very flimsy in terms of security. We won't know for a while how these hackers got in, but man oh man will it be interesting.
Senior Member
Posts: 737
Threads: 34
Joined: 2010-08
Eosian Wrote:ROFLMAO... "Mainframe"... A windows 2000 server cluster does not a mainframe make.
"It's equally likely someone hacked the Asiasoft [SIZE="4"]mainframe [/SIZE]and stole [SIZE="3"]all [/SIZE]the customer data."
fixed. jesus.
Posting Freak
Posts: 4,163
Threads: 357
Joined: 2009-11
Gender: Male
Sexual Orientation: Straight
Country Flag: finland
IGN: Helsinki
Server: MYBCKN
Level: 220
Job: Aran
Guild: Friends
Guild Alliance: Unbreakable
The problem is in the users, until proved otherwise.
Posting Freak
Posts: 970
Threads: 25
Joined: 2010-03
Gender: Male
IGN: LunaMimosa
Server: El Nido
Level: 134
Job: OP Elf Queen
Guild: Some no-name guild
Guild Alliance: Read above.
It really does sound like the same exploit that hit us in GMS. Except the main difference is passwords WERE NOT changed. Which made more sense if they really had access to so many accounts: why waste time changing PWs?
So because of that main difference, still kinda unsure if it is the same exploit. But I'll ask, cause i'm not sure, does this version of MS still use the PIN system and not the PIC yet? cause this type of hacking stopped in GMS once PICs were added.
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
larmie Wrote:"It's equally likely someone hacked the Asiasoft [SIZE="4"]mainframe [/SIZE]and stole [SIZE="3"]all [/SIZE]the customer data."
fixed. jesus.
How is it fixed to continue calling something that is absolutely not even remotely a mainframe a mainframe?
You may as well be calling a ford focus a dirigible, or for that matter your own desktop/laptop a mainframe.
As usual you've missed the point.
As pointed out repeatedly you don't have to change passwords you have access to.
Senior Member
Posts: 428
Threads: 19
Joined: 2008-10
What? second time Asiasoft screwing up? First was the mass hacking at MSEA.
Eosian Wrote:http://en.wikipedia.org/wiki/XSS
Was that so hard? 
gewgle!  gooogle
Satellite Wrote:The problem is in the users, until proved otherwise.
Back in the 2008, Asiasoft kept insisting that it was user and they didn't even bother to check through the invulnerability in the website for at least 4 months. We'll see what happen to Asiasoft Thai this time
Senior Member
Posts: 613
Threads: 10
Joined: 2009-04
ZakumSlaYers Wrote:What? second time Asiasoft screwing up? First was the mass hacking at MSEA.
gewgle! gooogle
Back in the 2008, Asiasoft kept insisting that it was user and they didn't even bother to check through the invulnerability in the website for at least 4 months. We'll see what happen to Asiasoft Thai this time
Daaaaaaaaaaaaaaaaaaaayum... and I thought Nexon USA was bad.. =S
Posting Freak
Posts: 3,672
Threads: 116
Joined: 2010-03
Gender: Male
Sexual Orientation: Straight
Country Flag: Louisiana
IGN: AliceLiddel
Server: Hyperion
Job: Kinesis
Guild: Wayfinders
rayhovite Wrote:Daaaaaaaaaaaaaaaaaaaayum... and I thought Nexon USA was bad.. =S Compared to Asiasoft NEXON AM is almost like the god of programmers. I've heard from a few MSEA players that the glitches you find in MSEA are 100x worse and maybe 10x more than you would find in GMS.
Senior Member
Posts: 613
Threads: 10
Joined: 2009-04
Red Hot Chili Peppers: "OH my my!"
Account not Activated
Posts: 998
Threads: 43
Joined: 2010-09
rayhovite Wrote:Red Hot Chili Peppers: "OH my my!"
Tom Petty: Oh hell yes!
AsiaSoft has been one of the worst handled distributions of MapleStory since they got the license for it.
I honestly wouldn't be surprised if it was an inside-job with their track record.
Member
Posts: 50
Threads: 0
Joined: 2009-07
SwordStaker Wrote:Compared to Asiasoft NEXON AM is almost like the god of programmers. I've heard from a few MSEA players that the glitches you find in MSEA are 100x worse and maybe 10x more than you would find in GMS.
Haha...They are just trying to make it sound a 100x worst than the actual fact.
For example, we have free monthly 2X Drop Rate and several 2X Exp Events in MapleSEA. Just because the moderators neglected to update the information regarding the month's 2X drop rate event, several people would start to complain about it. Trust me, they will start to complain about this from the second last day of the previous month... -_-
In the first place, MapleSEA wasn't told to give free monthly 2X Drop Event. Yet, the players were demanding for it...
|