Posting Freak
Posts: 2,118
Threads: 100
Joined: 2008-08
Gender: Male
Sexual Orientation: Straight
Country Flag: brazil
IGN: Crazynomad
Server: Azralon
Job: Prot Paladin
Guild: Pro Pug Society
not sure if it is real or FUD:
http://yanflychannel.wordpress.com/2011/...-hackings/
Quote:Apparently, going to the login page and inputting the wrong password will yield the right password but encrypted. This is unfathomable security if anything. Any one with a mediocre level of programming and logic base understanding can break and decrypt what Nexon put out. I managed to decrypt the jumble of text in a matter of less than a half hour. Now, I did nothing to the persons account that I decrypted, but I seriously have to question Nexons campaign for players protecting their own accounts.
EDIT: and here is a list of people that already got hacked:
http://www.basilmarket.com/forum/2192681/19
Posting Freak
Posts: 1,214
Threads: 39
Joined: 2010-09
CrazyNomad Wrote:not sure if it is real or FUD:
http://yanflychannel.wordpress.com/2011/...-hackings/
EDIT: and here is a list of people that already got hacked:
http://www.basilmarket.com/forum/2192681/19
Well, I guess the only way around this is to lock your account with an invalid password. You can then only relog when you request a password change and input a valid one.
inb4 Nexon's announcement:
Nexam Wrote:Now you can use special characters such as ¶, ®, ☺ and even ♥ in your passwords! Keep your accounts safe, maplers!
Don't forget your ♥ for NX. Get some ☺ today!
Posting Freak
Posts: 1,723
Threads: 165
Joined: 2009-12
Gender: Male
IGN: GrafZeppelin
Server: Reboot
Level: 190
Job: Marksman
CrazyNomad Wrote:not sure if it is real or FUD:
http://yanflychannel.wordpress.com/2011/...-hackings/
EDIT: and here is a list of people that already got hacked:
http://www.basilmarket.com/forum/2192681/19
I used to use his RMVX scripts. He/she is a genius and a very knowledgeable fellow & knows a lot about coding, and knowing Nexon... I wouldn't be the least surprised if it turned out to be true.
./run on sentence
Posting Freak
Posts: 2,118
Threads: 100
Joined: 2008-08
Gender: Male
Sexual Orientation: Straight
Country Flag: brazil
IGN: Crazynomad
Server: Azralon
Job: Prot Paladin
Guild: Pro Pug Society
Phoenix Wright Wrote:I used to use his RMVX scripts. He/she is a genius and a very knowledgeable fellow & knows a lot about coding, and knowing Nexon... I wouldn't be the least surprised if it turned out to be true.
./run on sentence
well, as of now, its the only explanation about what is happening, sw.net database leak, hacker probably trying every email he got to find if it is valid(since you can use your email address to log on your maple account), then he look at the sp/sw.net user accounts, and try it as login ID too.
can be rumor, can be real, but its the best explanation about the case.
Posting Freak
Posts: 1,069
Threads: 14
Joined: 2009-03
Gender: Male
Country Flag: canada
Server: Khaini
Job: Various
Yanfly:
Quote:Apparently, going to the login page and inputting the wrong password will yield the right password but encrypted. This is unfathomable security if anything. Any one with a mediocre level of programming and logic base understanding can break and decrypt what Nexon put out. I managed to decrypt the jumble of text in a matter of less than a half hour. Now, I did nothing to the persons account that I decrypted, but I seriously have to question Nexons campaign for players protecting their own accounts.
So password hashes are that easily cracked nowadays? Or does he mean that Nexon is using some inferior encryption method.
Also sounds like the PIC is totally useless. May as well set it to 111111 for efficient relogging.
Posting Freak
Posts: 1,809
Threads: 44
Joined: 2009-11
Gender: Male
Sexual Orientation: Straight
Country Flag: usa
IGN: ZekkenAdele
Server: Scania
Level: 246
Job: Adele
Guild: DarkLily
Guild Alliance: Arcane
Farm: HarvestxMoon
so all u have to do is keep forum email and maple email diff
Posting Freak
Posts: 1,723
Threads: 165
Joined: 2009-12
Gender: Male
IGN: GrafZeppelin
Server: Reboot
Level: 190
Job: Marksman
Sheer dumb luck and a bit of paranoia is probably all that's keeping my account mostly safe at the moment.
I don't touch the MTS, never log in through the site, and my email/log-in name is so old that it doesn't relate in any way to any character name I possess or any screen name I use on SP or Basil.
And I have a PIC and password from hell but at this point I don't think either of those accomplish very much.
Posting Freak
Posts: 3,213
Threads: 466
Joined: 2008-07
MissingLink Wrote:So password hashes are that easily cracked nowadays? Or does he mean that Nexon is using some inferior encryption method.
Blowfish/bcrypt with the correct adaptivity secures passwords damn good, so it would mean the latter.
If they're using SHA or MD5, then they're messing around:
[imgspoiler]http://i.imgur.com/B7iy7.png[/imgspoiler]
See that you have the possibility to use a checksum to check if the data is correctly downloaded? The reason those algorithms are there is because they're able to check whether a file give the correct checksum with those algorithms damn fast. Because of that, there's no problem to try out very many different passwords in a very short amount of time, and with enough computing power, you'll eventually get a hit.
Posting Freak
Posts: 12,000
Threads: 634
Joined: 2009-07
A link to the same article was posted on Nexon forums, and promptly deleted.
When asked why it was deleted, -Hime- replied:
http://forum.nexon.net/MapleStory/forums...79200.aspx
-Hime- Wrote:I'm sorry but theories and speculations are not truths.
The thread was deleted because it was adding more fuel to an already sensitive situation. Thank you.
When locking another thread about the current hacking epidemic, she said:
http://forum.nexon.net/MapleStory/forums...px#8248670
-Hime- Wrote:To be realistic accounts takeovers happen with any online game. There are others who see value in your virtual items. Regardless of how your account was compromised please submit a ticket. I know many of you know that there are a good handful of players still waiting to be helped but their ticket is open for a reason. Please submit a ticket so we can investigate how your account was compromised and how we can help.
I understand many of you are frustrated and curious, but your theories are only adding more fuel to the already sensitive situation. Thank you.
Ah well. At least we know someone at Nexon is aware of this "already sensitive situation".
Can anyone check whether they've changed the website login page not to give out the (hashed) password anymore?
Posting Freak
Posts: 1,416
Threads: 25
Joined: 2009-12
Please send a ticket to nexon that'll work!! (or not... going off of my still open ticket from well over a year ago now.)
I would expect nothing less than total denial of anything on nexon's end. That's their game always has been and most likely always will be.
Posting Freak
Posts: 1,214
Threads: 39
Joined: 2010-09
At least they're acknowledging that this pomegranate is real.
Too bad they won't ever come out and say that it's their fault for failing so much so many times and on so many levels.
Member
Posts: 51
Threads: 1
Joined: 2009-03
Inputting a wrong password yields the actual (encrypted) password? -___________- seriously?
Posting Freak
Posts: 9,907
Threads: 379
Joined: 2010-02
I can't seem to reproduce YanFly's supposed explanation. There's nothing there o.o
lol
What a load of bullcrap.
Posting Freak
Posts: 1,746
Threads: 68
Joined: 2008-07
Fimbulvetr Wrote:Inputting a wrong password yields the actual (encrypted) password? -___________- seriously?
i doubt if you put the wrong password in. It will show the pw right in front of you.
This goes back to what i was saying before about nexon changing their password section. Before under manage account it would show your actual password when you request to change it in plain text. Now it doesn't do it anymore since they changed it.
@danny maybe he is using a special program that you dont have. This guy knows his stuff you know.
Posting Freak
Posts: 12,000
Threads: 634
Joined: 2009-07
Locked Wrote:I can't seem to reproduce YanFly's supposed explanation. There's nothing there o.o
lol
What a load of bullcrap.
They might have changed it already. They've been changing their web pages related to login, on the sly, for several days now (length of passwords and such)
Senior Member
Posts: 558
Threads: 3
Joined: 2011-04
Fimbulvetr Wrote:Inputting a wrong password yields the actual (encrypted) password? -___________- seriously?
I actually asked if this was possible on the very first page. Nobody has replied yet, but it's interesting that somebody else posted it in the thread. I also found a third person on Basil who told me he has been using this method himself for several months.
Posting Freak
Posts: 18,970
Threads: 319
Joined: 2008-07
Locked Wrote:I can't seem to reproduce YanFly's supposed explanation. There's nothing there o.o
lol
What a load of bullcrap.
If it was deleted off Nexon forums, it was already tested, and it was already fixed probably within the hour they caught wind of it.
Senior Member
Posts: 493
Threads: 8
Joined: 2011-08
Gender: Male
Sexual Orientation: Straight
Country Flag: peru
IGN: DarkForgeRev
Server: Scania
Level: 210
Job: Night Lord
Guild: IDissOrtis
Guild Alliance: R.I.P
Phoenix Wright Wrote:Sheer dumb luck and a bit of paranoia is probably all that's keeping my account mostly safe at the moment.
I don't touch the MTS, never log in through the site, and my email/log-in name is so old that it doesn't relate in any way to any character name I possess or any screen name I use on SP or Basil.
And I have a PIC and password from hell but at this point I don't think either of those accomplish very much.
Same for me... all you say applies for me but the difference is:
I got hacked like 1 week ago....
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
Locked Wrote:I can't seem to reproduce YanFly's supposed explanation. There's nothing there o.o
lol
What a load of bullcrap.
I stepped through all the JSON and Ajax and whatnot and saw nothing incriminating. It has it's own base 62 function to do comparisons with but that's just to hash the input for the server to compare.
It's not having what you want - It's wanting what you've got.
Senior Member
Posts: 572
Threads: 1
Joined: 2010-11
CrazyNomad Wrote:not sure if it is real or FUD:
http://yanflychannel.wordpress.com/2011/...-hackings/
EDIT: and here is a list of people that already got hacked:
http://www.basilmarket.com/forum/2192681/19 Post from basil on the same subject as the blog( http://www.basilmarket.com/forum/2196294/7)
"myrdrex: That doesn't seem right- the response is a simply JSON message:
"error":{"code":"1510","type":"Unauthorized","message":"INCORRECT_ID_OR_PASSWORD"}}
Just set up a SSL proxy, decrypt it, and you'll see that. There's no embedded password at all on the response that comes back from a failed login.
"PepsiMin; ^ This is correct. Also, -Hime- on the nexon forums stated that they do not store any passwords on their end (believe it or not).
SO, THIS THREAD IS 100% INCORRECT. There's no proof (SS) of any encrypted passwords being sent back posted by the person who started this rumor, and until I see one, you should all regard this as a false scare.
About the hackings going on for the past month or so, I honestly don't know what's causing it. There could be other security holes in the game that hackers are exploiting."
This guy(Judging by my eyes and perhaps my disbelief in his theory) and what he said seems more reliable then the thread starter. I also could not re-create what the TS was talking about, so as far as I'm concerned. It's bullcrap unless he posts actual proof, instead of words.
|