Senior Member
Posts: 614
Threads: 88
Joined: 2010-08
Gender: Male
Country Flag: thailand
IGN: Knight52
Server: Earth
Level: 534
Job: Thread Breaker
Guild: I'm bored of
Guild Alliance: political sh'it
Long story short; Nexon's ex-employees do it.
According from Asiasoft board, Asiasoft changes whoever that does game's system admin job very often. So one of them that was fired could have... copied player's info from the server and hack those accounts afterward. I think there's no difference at Nexon. I don't know for sure how deep do you have permission to access as a system admin, but it must be a lot if not all.
What do you think?
This is just a theory, of course.
Member
Posts: 143
Threads: 16
Joined: 2009-07
More reasonable than other crap people come up with
Senior Member
Posts: 354
Threads: 13
Joined: 2008-12
didn't nexon accidentally release the client debug information a couple patches ago? I just think that hackers used nexon's mistake. If they can see how the client works it's just that much easier to make hacks
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
ArbalistMaster Wrote:didn't nexon accidentally release the client debug information a couple patches ago? I just think that hackers used nexon's mistake. If they can see how the client works it's just that much easier to make hacks
He's talking about user account breaches, not client mods and packet edits.
It's not having what you want - It's wanting what you've got.
Posting Freak
Posts: 9,625
Threads: 523
Joined: 2008-09
I'm pretty sure they have to be trusted not to and if they do so, they would get in huge trouble with the law. Besides, wouldn't the passwords all be encrypted? Unless that person knew how to decrypt them, there's no point in taking a bunch of random numbers and letters you can't figure out.
Senior Member
Posts: 614
Threads: 88
Joined: 2010-08
Gender: Male
Country Flag: thailand
IGN: Knight52
Server: Earth
Level: 534
Job: Thread Breaker
Guild: I'm bored of
Guild Alliance: political sh'it
Asiasoft fired almost whole maplestory team last November because they were caught pumping VIP items out of nowhere and sell them in FM, or so I've heard. That pretty much invalidated their honesty.
And about password encryption. Is it possible to plant some bug on the server to copy account name and passwords before they go to encryption process?
Posting Freak
Posts: 811
Threads: 32
Joined: 2010-07
Unauthorized Intruder Wrote:And about password encryption. Is it possible to plant some bug on the server to copy account name and passwords before they go to encryption process?
If they did anything of the sort, they'd be in more legal trouble than they could handle.
Senior Member
Posts: 470
Threads: 49
Joined: 2009-02
Gender: Female
Sexual Orientation: Straight
Country Flag: usa
IGN: TaliaNCo
Server: Mardia
Level: 193
Job: Arch Mage (i/l)
Guild: Animus
Killed Wrote:If they did anything of the sort, they'd be in more legal trouble than they could handle.
Yes, if it could br proven who did it. Fire an entire team........good luck figuring out who it was.
Posting Freak
Posts: 854
Threads: 71
Joined: 2008-07
Gender: Male
Sexual Orientation: Straight
Country Flag: usa
Job: Software Dev.
Unauthorized Intruder Wrote:Asiasoft fired almost whole maplestory team last November because they were caught pumping VIP items out of nowhere and sell them in FM, or so I've heard. That pretty much invalidated their honesty.
And about password encryption. Is it possible to plant some bug on the server to copy account name and passwords before they go to encryption process? For the website, absolutely, if the person has access to the website code. It's also possible to use rainbow tables crack the "encrypted" (actually hashed) passwords that are stored in the database if the hash is not salted first.
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
Spaz Wrote:For the website, absolutely, if the person has access to the website code. It's also possible to use rainbow tables crack the "encrypted" (actually hashed) passwords that are stored in the database if the hash is not salted first.
If they worked for the company they'd fairly likely know the salt used too so that wouldn't even begin to be a barrier
It's not having what you want - It's wanting what you've got.
Test Mushroom
Posts: 10,045
Threads: 1,506
Joined: 2008-06
Gender: Male
Sexual Orientation: Straight
Country Flag: usa
IGN: GuavaCowboy
Server: Zenith
Level: 10x
Job: Jett
Guild: L>
A former system admin or disgruntled employee with access to admin or secret accounts has no incentive to log in and cause mayhem. Doing so could jeopardize his whole career as all businesses like to talk to former bosses, and as you climb up the food chain the reason for leaving your previous job becomes more and more important. Also, any half-assed sysadmin is going to create logs which show who logged in from where and what all was performed on admin accounts. That's basic security protocol. It's not too hard to use a little computer forensics to figure out who compromised the system and go after him for tampering with their data.
So, it boils down to this:
1. The company in question does not have a security protocol in place dealing with firing of leadership in regards to passwords, permissions, and notes about the system.
2. The employee was stupid enough to actually compromise corporate data.
A corporation has no incentive to state that user information was compromised by a disgruntled employee. That reflects poorly on the company in many ways. So, instead, there's just silence.
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
Actually with an MSSQL server all they have to do is copy the *.bak files from the fileshare where they're being dumped to and restore them to their own private MSSQL installation they can set up anywhere for free and there'd be virtually nothing logged but a touch to the files, which they could easily do using an internal service account that any admin had access to. Wouldn't actually require any real login, just a remote authentication that would blend right in with normal traffic.
And of course those event logs can easily be wiped without anyone noticing.
That said, it's still unlikely. If you're qualified enough to be doing the job in the first place you have little to no incentive to make a few bucks ripping off the player base after you're gone when you make far more money gainfully employed and the associated risks of being caught and prosecuted far outweigh anything you could possibly get in either satisfaction or compensation.
Course that might only apply in the Americas.
It's not having what you want - It's wanting what you've got.
Posting Freak
Posts: 2,426
Threads: 88
Joined: 2009-06
When -Hime- was on basil chat thing, I asked her if she could ban my Maple chars for something I said on basil chat.
She said that she could do it, but she would file a report instead.
?
Posting Freak
Posts: 9,625
Threads: 523
Joined: 2008-09
OB3LISK Wrote:When -Hime- was on basil chat thing, I asked her if she could ban my Maple chars for something I said on basil chat.
She said that she could do it, but she would file a report instead.
?
That doesn't really have anything to do with the topic at hand, though. Banning players and stealing from the database for personal gain are two different things.
Like Eos said, the chances of having someone who can do such a thing, working for a huge company like Nexon, and having them take database information to hack game accounts for little to no profit is pretty low. Why would ANYONE do such a thing? Especially when they have the abilities to make far much more money doing legitimate work?
Posting Freak
Posts: 9,129
Threads: 484
Joined: 2009-03
Gender: Female
OB3LISK Wrote:When -Hime- was on basil chat thing, I asked her if she could ban my Maple chars for something I said on basil chat.
She said that she could do it, but she would file a report instead.
? Just to be clear though, Hime couldn't actually do that because there's no proof that you are who you say you are on Basil. And the last thing Nexon needs is reports of a rogue employee banning accounts for saying something mean to her, which is exactly how it would go down.
Posting Freak
Posts: 9,625
Threads: 523
Joined: 2008-09
Sarah Wrote:Just to be clear though, Hime couldn't actually do that because there's no proof that you are who you say you are on Basil. And the last thing Nexon needs is reports of a rogue employee banning accounts for saying something mean to her, which is exactly how it would go down.
I don't think it has anything to do with Basil. O_o I think it's mean to be that she can ban in-game players if she needed to.
Posting Freak
Posts: 2,361
Threads: 57
Joined: 2010-06
Gender: Male
Sexual Orientation: Straight
Country Flag: usa
Sarah Wrote:Just to be clear though, Hime couldn't actually do that because there's no proof that you are who you say you are on Basil. And the last thing Nexon needs is reports of a rogue employee banning accounts for saying something mean to her, which is exactly how it would go down.
Agreed. And if she were able to ban people for being mean to her, half of the Nexon forums would've gotten smacked upside the head with the banhammer by now, anyways.
|