Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Speculating about Nexon Databse Admin
#1
A little bit of research
This isn’t to promote the hackings or what ifs these are some facts that I would like you all to know.
Just doing a little bit of research nexon has been doing a lot of searching for database administrators.

Jan 14th Database Administrator
Jan 12 Sr. Database Administrator

Qualifications: (lets scratch out the useless stuff)
-3-5 years relative experience, preferably with gaming industry experience
- Bachelor’s Degree in Computer Science preferred or equivalent combination of education and experience
- Experience with managing multipleMS SQL 2000 & 2005 RDBMS on large systems
- Experience with monitoring and tuning a database to provide a high availability service.
- Practical experience of managing the MySQL database a plus
- Proven hands on experience is required
- Must be willing to work additional hours as necessary
- Local candidates preferred
Now we know what database management system nexon uses

Well like its sister msea was recently hacked could be through sql injections and various loopholes and exploits in their system. Nexon is subject to these exploits as well.
So nexon is vulnerable to sql attacks? Yes maybe no hackers find the loopholes and exploits and try it out sometimes maybe they get lucky before big company's patch fix the problem.
Just some of the few that you find while searching job boards.
Usually when you search for a new person to employ someone gets the cut. Put 2 and 2 together.
How many database admins does nexon have how many have been fired how many take their job seriously and do things securely in the workplace and the home to prevent compromised data.
And before you call me person who conspires but just take a look at this.
[Google Destructoid 16 year old hacks nexon]

he basically found a disgruntled employee used some illegal programs comprised his acc on nexon jp and did all of that to the database





Also a tip why nexon isn’t replying to most inquiry's etc is because they want to keep things under rap
Anytime data is lost and a consumer finds out they have rights.
Harvard, Yale, oxford and many schools have been hacked since 2000-2009 some even had compiled data in zips put onto the pirate bay , rapid share, mega download etc. They were required to provide identity assistance for life.
Currently nexon has our names and bdays which is a valuable piece of information.

Maybe its china hacking nexon? After all they hacked Google no one knows
Also nexon has done server upgrades in the past hmm I wonder why? That also opens up vulnerabilities

Every year there is a blackhat conference where the “best” hackers get to gether and discuss trade secrets script kiddies love this because there is a small window of opportunity once these loopholes are found.

Also is it just me or have you guys been getting weird ads (when closing ms)?. Usually when I got weird ads on websites they led to rogue viruses be careful with them

Some end facts. This is just me thinking out loud putting pieces together.

links Google Destructoid 16 year old hacks nexon
Google Man charged with hacking USC database - CNET News
Google THE WEB HACKING INCIDENTS DATABASE 2009
Reply
#2
I read to the part where you said Nexon America's database is also open.

Derp. Thats how so many of us got hacked.
Reply
#3
...I very much doubt the hackings were done through injection.
Reply
#4
Mind you i forgot the rest

there are many ways to hack a database
Mind you the timeline for this could be anywhere from 2005-preasent

Nexon was notorious for having malformed urls back in the day where you could search through nexons hidden files
and see planed events and gms/ nexon people talking to eachother

Mind you SQl injections were plausible in 2005-2007
same with google hacking databases
same with malformed url hacking

whats to say a backdoor hasnt been made to the system i know once i gain access to something thats not mine i make a new way for me to gain access
Cross Site Scripting is plausible too.


you take into account that todays security measures were actually inuse back then, i remember highschool messing with sql injections
they worked till they got patched.
Reply
#5
Quote:Now we know what database management system nexon uses
The website is an ASP.NET site, there was never really any doubt that it uses MS SQL Server.
Reply
#6
To be fair, you can use ASP.NET with ODBC connectors for other databases. But I remember seeing a generic ASP.NET error page (stupid nexon hadn't turn on custom errors on the web.config back then) that said it was using MS SQL
Reply
#7
XTOTHEL Wrote:...I very much doubt the hackings were done through injection.

Ive seen a 3 page list of usernames, passwords, and pins that suggest otherwise.
Reply
#8
Izzy Wrote:Ive seen a 3 page list of usernames, passwords, and pins that suggest otherwise.

and how does the list prove that it was done through injection? They could very well have been pulled from their phishing database.
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)