Posting Freak
Posts: 9,907
Threads: 379
Joined: 2010-02
SaptaZapta Wrote:Wasn't your password too long to bruteforce?
No?
My Dual Blader got hacked, and I never bothered to change the password on it. It got hacked completely out of my idiocy and I understand that. Password was 8 characters long, the one I use for my actual account is 64 characters long.
Posting Freak
Posts: 8,478
Threads: 128
Joined: 2008-07
Gender: Neuter
Country Flag: canada
IGN: Oooh
Server: Bera
Job: Empress
Farm: Stereo
I haven't seen any signs that I've been hacked, regardless of the length of password on my account. (main + primary mule both have more than 10 characters, but I do have quite a few accounts I use semi-regularly)
Then again, my least secure account has maybe 600k on it, so maybe cracking its 7 character password wasn't deemed worthwhile. I don't know how they sort out good accounts from worthless ones.
Member
Posts: 240
Threads: 3
Joined: 2010-06
SaptaZapta Wrote:I know about that method.
What I meant to point out, however, is that if the hackers happen to be using a bypass that makes it unnecessary for them to crack or type in the password, that lock is utterly useless. The door to Fort Knox is unbreakable, but the window is wide open.
Don't believe there is a password bypass. Doesn't matter anyway, NO passwords can be used. The most logical way the hackers are hacking is a database leak. Which contains your stored passwords.
Posting Freak
Posts: 3,414
Threads: 191
Joined: 2008-07
jhkplaya888 Wrote:Don't believe there is a password bypass. Doesn't matter anyway, NO passwords can be used. The most logical way the hackers are hacking is a database leak. Which contains your stored passwords.
I believe it has been said several times that Nexon stated that they do NOT store actual passwords ANYWHERE. They only store the encrypted ones, which are then decrypted by the server itself. So, unless someone also got his hands on the server files or the algorithm used for the encryption, I doubt that getting your hands on the database could be of any use.
Posting Freak
Posts: 8,478
Threads: 128
Joined: 2008-07
Gender: Neuter
Country Flag: canada
IGN: Oooh
Server: Bera
Job: Empress
Farm: Stereo
Combattente Wrote:I believe it has been said several times that Nexon stated that they do NOT store actual passwords ANYWHERE. They only store the encrypted ones, which are then decrypted by the server itself. So, unless someone also got his hands on the server files or the algorithm used for the encryption, I doubt that getting your hands on the database could be of any use. Not quite right; the client encrypts what you type in, then compares the two encrypted versions. Unencrypting passwords isn't easy or they wouldn't be useful.
However, if you can grab the encrypted version, and you know the exact input parameters (or just be man in the middle), you could fake it. But that's more a question of client-server security than anything players can do.
Senior Member
Posts: 558
Threads: 3
Joined: 2011-04
SaptaZapta Wrote:Wasn't your password too long to bruteforce?
How long is too long? I'm at 12 characters on my account that I lost my email on (it has all my high level characters though D  , and 30 something on the account where I moved all my gear and mesos to.
Junior Member
Posts: 18
Threads: 0
Joined: 2011-10
Last night I witnessed a guild member get hacked.
All I could do was watch on my mule as all her stuff was taken away
Could not even communicate with the culprit through chat, trade requests, etc...the times I wish I could dc hack 
Apparently they are taking sok-able items now since I checked her items as the process happened. Lost a VL glove and scar helm as well as other equips
Posting Freak
Posts: 3,671
Threads: 116
Joined: 2010-03
Gender: Male
Sexual Orientation: Straight
Country Flag: Louisiana
Server: Scania
Job: Luminous
Guild: Tempted
Guild Alliance: Origins
Someone on my BL was hacked but he was an idiot. He said his pw was 123981645 and his PIC was 012345. Also my friends oldest acc was hacked with the passwords 123456789 and pic of 123456. We don't care there was nothing on there. -No sarcasm-
Posting Freak
Posts: 9,907
Threads: 379
Joined: 2010-02
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
Not actually new, either.
It's not having what you want - It's wanting what you've got.
Junior Member
Posts: 18
Threads: 0
Joined: 2011-10
Well, at least its there
Gives me a tiny sliver of hope for my dream of a safe Mapling environment.:f6:
Posting Freak
Posts: 3,414
Threads: 191
Joined: 2008-07
The fun fact is that whenever it asks me to log-in it DOESN'T redirect me to the https URL but to the http one. Making the SSL unused. Or at least in some cases. :|
Posting Freak
Posts: 4,278
Threads: 103
Joined: 2011-07
Gender: Male
Sexual Orientation: Straight
Ketchup Wrote:Last night I witnessed a guild member get hacked.
All I could do was watch on my mule as all her stuff was taken away
Could not even communicate with the culprit through chat, trade requests, etc...the times I wish I could dc hack
Apparently they are taking sok-able items now since I checked her items as the process happened. Lost a VL glove and scar helm as well as other equips
D:
Who got hacked?
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
Combattente Wrote:The fun fact is that whenever it asks me to log-in it DOESN'T redirect me to the https URL but to the http one. Making the SSL unused. Or at least in some cases. :| If you look at the form, the action is using the https address and ultimately that is all that matters.
At no point is your information sending to them without SSL. The fact it's sending the page back to you in normal HTTP is irrelevant unless it sends something that should be protected back unsecured, which it doesn't appear to do.
It's not having what you want - It's wanting what you've got.
Posting Freak
Posts: 3,414
Threads: 191
Joined: 2008-07
Eos Wrote:If you look at the form, the action is using the https address and ultimately that is all that matters.
At no point is your information sending to them without SSL. The fact it's sending the page back to you in normal HTTP is irrelevant unless it sends something that should be protected back unsecured, which it doesn't appear to do.
Oh, okay. Nevermind then. That looked a little strange.
Member
Posts: 59
Threads: 5
Joined: 2010-12
I was hacked back in September when just about everyone else was. I haven't spent any time with Maple since I completely lost my faith and reasoning for playing, but I did manage to check my account. They left everything that was untradeable, pots, all my etc. items, even most of my other tradeable equips that weren't worth 10m+. They literally got onto my character, took all valuable tradeables along with mesos, and left it alone. They were even (nice) enough to leave my 31int Zhelm, just because it was untradeable.
I haven't read all 33 pages of this thread, but does anyone have a generally accepted answer as to why/how the accounts were hacked? It seemed a little strange since in the... 6 years? that I had the account, I shared information with absolutely nobody, and at the time I (assume) got hacked, I had been inactive for around a month.
Did Nexon ever release a statement or (naive) an offer of compensation/improvement? Or was it a: "We don't know what you're talking about... hey! Change your passwords everyone!"?
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
nope
It's not having what you want - It's wanting what you've got.
Junior Member
Posts: 18
Threads: 0
Joined: 2011-10
Guitarist17 Wrote:Did Nexon ever release a statement or (naive) an offer of compensation/improvement? Or was it a: "We don't know what you're talking about... hey! Change your passwords everyone!"?
Nexon is offering "compensation" for players that have been hacked.
The "compensation" consists of clean weapons and armors and I believe NX?...
The generally accepted answer as to why this is happening is: Nexon
Other than that, there is no concrete reason and the simple answer is nope as stated before me.
Unless the culprits actually come out, reveal who they are, show how they are doing it, and tell us exactly why, we may never know for sure.
Unless of course Nexon is doing all they can by backtracing and calling the cyber police
Senior Member
Posts: 558
Threads: 3
Joined: 2011-04
I want to point out that all the people I know who have been hacked have had their items appear in the shops of level 16 evans with nonsensical names. I still see these Evans around, and they're always in highly crowded areas. It makes me feel insecure.
Posting Freak
Posts: 12,000
Threads: 634
Joined: 2009-07
Ketchup Wrote:Unless the culprits actually come out, reveal who they are, show how they are doing it, and tell us exactly why, we may never know for sure.
Unless of course Nexon is doing all they can by backtracing and calling the cyber police
Actually, I think somewhere upthread is someone saying he spoke at length with the owner of the hacked-items shop (trying to buy back a hacked friend's gear), and discovered he is working for a gold-selling site.
They are doing it for $, pure and simple. They steal meso and NX in order to sell them back to us for cold hard cash.
So, we know who, and we know why, but they will never tell how. They're not doing it for fun or for hacker pride, so they will not tire of it nor feel the need to brag on hacking boards. And since they make $ directly, they have no motivation to sell whatever they are using. About the only way that would happen is if they're working off a one-time stolen database, and exhaust their list of cracked passwords.
@Mibs: You are insecure. The hackings have not stopped.
|