Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Another Nexon Mistake
CrazyNomad Wrote:the ch/server method crash are only released to the public when it get leaked and whoever found it spam every hacking forum so people will abuse it to get it patched fast.

spamming a packet is easy, but find said packet to be spammed isn't

Understandable, but the group in Khaini has it long before it got released to the public. They mostly have these kinds of BS long before the leaks occur.
ShinkuDragon Wrote:just a quick update, a certain hacking site removed the list from it's site, so did basil, and it hasn't been posted here, dunno about other sites.
Oddly enough, a link still exists on Nexon's own forum.

Locked Wrote:I removed my stuff from MTS pretty fast yet it was still on the list. I'm guessing the person who did this had the method before the public release. Well to be honest, I think a vast majority of you people are overreacting to the ID thing. A bunch of people of my BL are cleaning out their accounts and stuff. Really there isn't much people can do with your ID alone now, sure back then Jimmy, Mikey and Bruno were able to brute into your account by changing the email redirect to theirs supposedly but the site has changed and so have hacking methods. Stop being afraid.
Agreed; people are freaking out far too much.
Even with your ID, there are, theoretically, at least two barriers in their way: your password and your PIC.

"BUT I'VE HEARD THAT THERE ARE BYPASSES THAT GO AROUND PASSWORD AND PICS," some may cry.
Well, then quit.

Unless you're planning to abandon your account, transferring all of your stuff is just a temporary fix.
If they can get in now without knowing your password and PIC, there's nothing stopping them from getting back in as soon as they see you on your main, fully-equipped.

As for those who are transferring in an attempt to start over, they stand looking even more foolish.
Let me get this right...
...they distrust Nexon's security so little that the feel an ID leak may be the end of their accounts, but they also plan to spend even more time getting back to where they were despite the fact that another leak could (and probably will) happen?

I've come to the point where I play here and there because enjoy it (I enjoyed it far more before they borked PvP), but, if I login one day and find my account stripped, I'll quit without ever looking back.

PS. It still should be perfectly safe to use the MTS as long as you use it on mule characters. Sure, they'll get your ID, but who's going to try brute force N4rutoOWNZ52? I usually apply this rule to any transaction I make in the game.
I was only worried about getting brute-force hacked through e-mail (again), but now we can change our e-mail (which I did).
I'm not too worried anymore.
I think nexon finally took out the link to the list o_O
is there a way to quickly search to see if we are on this list?
IMNOTSAM Wrote:is there a way to quickly search to see if we are on this list?
There's a list on basil of IGNs that are on the list.
Ctrl+f
phew not on it
Locked Wrote:I removed my stuff from MTS pretty fast yet it was still on the list. I'm guessing the person who did this had the method before the public release. Well to be honest, I think a vast majority of you people are overreacting to the ID thing. A bunch of people of my BL are cleaning out their accounts and stuff. Really there isn't much people can do with your ID alone now, sure back then Jimmy, Mikey and Bruno were able to brute into your account by changing the email redirect to theirs supposedly but the site has changed and so have hacking methods. Stop being afraid.

Danny people here dont listen. Let them panic. I said the same thing few pages back before the list was public and posted my login id on top of that.
who cares if its just useless ID that hackers cant do anything about? stolen info is still stolen info, which shouldnt have happened
There's a list of ign's without the user IDs on basil. For the people who think it makes a difference whether or not they know.
Liteness Wrote:who cares if its just useless ID that hackers cant do anything about? stolen info is still stolen info, which shouldnt have happened

Careful, your forum id is showing here, don't want them stealing it, the hackers may get you. Rolleyes
It's not having what you want - It's wanting what you've got.
Mibs Wrote:There's a list of ign's without the user IDs on basil. For the people who think it makes a difference whether or not they know.

link is broken on the thread now o_o
Well, I found out that my character is on the list on Basil, so meh. I've never been hacked before (played since early 2006 IIRC), so it wouldn't matter much to me. I have a strong password & PIC. Although my bro's account got hacked during the database leak a year or so ago, but he had a weak password. It's now changed to a stronger password, but it's funny to see him and I on the list.

Not to mention I'm not into the idea of changing my password often, but I guess the mandatory DFO password change was a good timing since I changed my own password as well as my bro's password yesterday.
Aww poop. I'm on the list Sad
Liteness Wrote:who cares if its just useless ID that hackers cant do anything about? stolen info is still stolen info, which shouldnt have happened

Hey things happen. Their is so much a company can do towards hackers attacking them. Look at sony and others companies that have felt the wrath of hackers.

Also dont give me the bs that the login id packet shouldn't have been in the code, because all the original code comes from kms. So give gms a break on an issue they could not control. I dont know how packet editing works, but i doubt to get rid of a packet is as easy as pressing backspace.
Eos Wrote:Careful, your forum id is showing here, don't want them stealing it, the hackers may get you. Rolleyes

dam you !! didn't know my forum name is the same as my forum id.

brb panicking
Viaje Wrote:Agreed; people are freaking out far too much.
Even with your ID, there are, theoretically, at least two barriers in their way: your password and your PIC.

"BUT I'VE HEARD THAT THERE ARE BYPASSES THAT GO AROUND PASSWORD AND PICS," some may cry.
Well, then quit.

Unless you're planning to abandon your account, transferring all of your stuff is just a temporary fix.
If they can get in now without knowing your password and PIC, there's nothing stopping them from getting back in as soon as they see you on your main, fully-equipped.

As for those who are transferring in an attempt to start over, they stand looking even more foolish.
Let me get this right...
...they distrust Nexon's security so little that the feel an ID leak may be the end of their accounts, but they also plan to spend even more time getting back to where they were despite the fact that another leak could (and probably will) happen?

I've come to the point where I play here and there because enjoy it (I enjoyed it far more before they borked PvP), but, if I login one day and find my account stripped, I'll quit without ever looking back.

Let ME get this right...
1/
> Nexon ID compromise poses no harm at all!
>> The leaked data is permanent and subject to abuse in the future with more security loopholes in conjunction.
> Well then, quit.

2/
> Lulz @ people trying to keep their information as secure as possible.

What are you trying to say? That it's ridiculous for other people to care about their pomegranate if you yourself don't care about yours?
Kalovale Wrote:What are you trying to say? That it's ridiculous for other people to care about their pomegranate if you yourself don't care about yours?

It's ridiculous to freak out about things that are only a risk in a situation that they'd have no defense against in the first place.
It's not having what you want - It's wanting what you've got.
Eos Wrote:It's ridiculous to freak out about things that are only a risk in a situation that they'd have no defense against in the first place.

I wasn't aware there was an ID bypass.

The ID can be either an extra layer of security (by obscurity) or the ONLY piece of identification to you. If you're going on a massacre, any ID is as good as the next and is, thus, not very valuable.
However, if you're targeting Eos' characters, he only has ONE ID.

Instead of relying on Passwords and PICs, would it not be better in the first place if the hacker had no idea how to target you specifically?
street Wrote:Also dont give me the bs that the login id packet shouldn't have been in the code, because all the original code comes from kms. So give gms a break on an issue they could not control. I dont know how packet editing works, but i doubt to get rid of a packet is as easy as pressing backspace.

It's jMS, not kMS. Yes, the ID should have never been in the packet in the first place.

Kalovale Wrote:What are you trying to say? That it's ridiculous for other people to care about their pomegranate if you yourself don't care about yours?

Since this is indirectly talking about me, I'll go ahead and say it that no. I think people are overreacting at best, and that they should just wait until Nexon handles it. Until then you can provide yourself a very strong password and a good email that is linked to nothing. That's what everyone should do at the moment.


Forum Jump:


Users browsing this thread: 1 Guest(s)