Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Possible Nexon Database Exploit?
#81
This doesn't explain the people getting hacked without their email being compromised.

There's no mystery in how people get hacked when their email is compromised. At all. That's not impressive, mysterious, special or even remotely unclear and scary.
It's not having what you want - It's wanting what you've got.
Reply
#82
Referring to the post above yours?

At any rate, I'm not one-hundred percent positive that the email associated with the account wasn't tampered with, but there's no evidence that suggests it was. I mentioned the situation to my mom, but she hasn't changed the password; I'm assuming because there wasn't anything suspicious. There have also not been any unauthorized changes to my password and PIC since Monday, assuming that the hacker didn't just call it quits once I had sole access.

EDIT: Zzz, my mother. To confirm she looked into it I texted her just now and she replied with, "Totally forgot."

If she gives me any info that is worth relaying, I'll inform you guys.
Reply
#83
There is another possibility if you had login using the web site and using the wireless on a public (semi-public) network. As the web site login is not https, all information send/receive is not encrypted, someone can use wireless hacking tools to collect/filter information on all the wireless traffic.
Also another more remote possibility is some hacker is able to craft a "hacked" pdf/flash to install some sort of keylogger on your computer, if you have Adobe installed and haven't kept it up to date.
Reply
#84
Not sure if this relates, but here is an attempt last year to hijack my gmail acct... too bad it's only got my (now) empty mule on it...
 Spoiler

Someone got in, changed my email p/w and then attempted to forward a keylogger to everyone in my contacts. Funny, but I only use this gmail acct for my maple-related things. Norton and spyware s/d both show I was clean at the time- no keylogger, not a shared account. All I can maybe guess is that they got into the database of a forum (SW/HS/LOLBasil) and got my email that way and just brute forced my then so-so password.

LOL @ "aggonyking"
Reply
#85
ctblack Wrote:There is another possibility if you had login using the web site and using the wireless on a public (semi-public) network. As the web site login is not https, all information send/receive is not encrypted, someone can use wireless hacking tools to collect/filter information on all the wireless traffic.
Also another more remote possibility is some hacker is able to craft a "hacked" pdf to install some sort of keylogger on your computer, if you have Adobe installed and haven't kept it up to date.

I feel like I keep having to repeat myself; I'm tiring of it rather quickly. However there are some new points to make:

I live on my college's campus, whose wireless is completely secure. In order to access it you'd need to be an actual student/faculty member, as the only way to get in is through an ID and password. So that throws your first theory out.

Second, because of my classes, I'm required to use Adobe quite often. Therefore, my Adobe is up-to-date. Also, since I've already stated that I don't download anything out of the ordinary, I don't have a key logger. Second theory busted.

LostWraith Wrote:Not sure if this relates, but here is an attempt last year to hijack my gmail acct... too bad it's only got my (now) empty mule on it...
 Spoiler

Someone got in, changed my email p/w and then attempted to forward a keylogger to everyone in my contacts. Funny, but I only use this gmail acct for my maple-related things. Norton and spyware s/d both show I was clean at the time- no keylogger, not a shared account. All I can maybe guess is that they got into the database of a forum (SW/HS/LOLBasil) and got my email that way and just brute forced my then so-so password.

LOL @ "aggonyking"

Alluding to what Eos said: As far as I know, my account was not hacked because of a vulnerable email address. With that said, though I'm extremely sorry you were hacked, any that were a result of an email hijacking are... irrelevant.
Reply
#86
Panacea Wrote:I feel like I keep having to repeat myself; I'm tiring of it rather quickly. However there are some new points to make:

I live on my college's campus, whose wireless is completely secure. In order to access it you'd need to be an actual student/faculty member, as the only way to get in is through an ID and password. So that throws your first theory out.

Second, because of my classes, I'm required to use Adobe quite often. Therefore, my Adobe is up-to-date. Also, since I've already stated that I don't download anything out of the ordinary, I don't have a key logger. Second theory busted.

Have you consider another student that have access to the same wireless network can monitor all the traffic could be the one that hacked you? Also even if one doesn't have proper access to the "protect" wireless network, they can still monitor and crack the encryption without getting connected to the router.
You don't have to download anything out of the ordinary, as a lot of web sites have pfd/flash docs embedded into them. Just clicking on a simply link can trigger Adobe. Too quick to "busted"!
Reply
#87
ctblack Wrote:Have you consider another student that have access to the same wireless network can monitor all the traffic could be the one that hacked you? Also even if one doesn't have proper access to the "protect" wireless network, they can still monitor and crack the encryption without getting connected to the router.
You don't have to download anything out of the ordinary, as a lot of web sites have pfd/flash docs embedded into them. Just clicking on a simply link can trigger Adobe. Too quick to "busted"!

That other student would need to know that I play Maplestory, and also who I am, wouldn't they? That seems a little far-fetched, to be honest.

Most, if not all, of the sites I got to are college-related. If someone managed to get a key logger into any of the documents that are on my university's server, then kudos to them as I've stated before. I highly doubt it, however.
Reply
#88
Panacea Wrote:That other student would need to know that I play Maplestory, and also who I am, wouldn't they? That seems a little far-fetched, to be honest.

Most, if not all, of the sites I got to are college-related. If someone managed to get a key logger into any of the documents that are on my university's server, then kudos to them as I've stated before. I highly doubt it, however.

It not far fetch for someone that plays ms in the same campus that comes up with the ideal to farm ms login info on the campus network, or anyone that want to hack ms from looking for a large network that could have people logging into Nexon to farm. They don't have to target you specifically, you could be just one of the "fish" they netted. All they need is to add a filter for Nexon's IP in the data they collected.

I did say the second possibility is rather remote, the hacker would have to be highly skilled to pull that one off and seems you don't know how it actually hacked, so just throwing this out there, as this is how RSA SecureID firm was hacked recently.
Reply
#89
ctblack Wrote:It not far fetch for someone that plays ms in the same campus that comes up with the ideal to farm ms login info on the campus network, or anyone that want to hack ms from looking for a large network that could have people logging into Nexon to farm. They don't have to target you specifically, you could be just one of the "fish" they netted. All they need is to add a filter for Nexon's IP in the data they collected.

I did say the second possibility is rather remote, the hacker would have to be highly skilled to pull that one off and seems you don't know how it actually hacked, so just throwing this out there, as this is how RSA SecureID firm was hacked recently.

I'll acknowledge that both are possible, then.
Reply
#90
Panacea Wrote:That other student would need to know that I play Maplestory, and also who I am, wouldn't they? That seems a little far-fetched, to be honest.
Nope, wireless signals are broadcasted. Theoretically, they just have to capture all the signals sent by everyone in the network and use a filter to only keep the ones that match login signatures.
Reply
#91
rhpot03 Wrote:Nope, wireless signals are broadcasted. Theoretically, they just have to capture all the signals sent by everyone in the network and use a filter to only keep the ones that match login signatures.

I won't lie, I'm not knowledgeable in how networks work, or even how a network could be infiltrated. With that said, I'm trying to think logically.

What I'm getting out of what the two of you have said is that it's possible that some kid sat at his computer, monitoring log-in ID's for about 50,000 students, not to mention all the faculty and staff that work here, pinned in on my "signature", saw I played Maplestory, then proceeded to hack me. Am I following correctly?
Reply
#92
Panacea Wrote:I won't lie, I'm not knowledgeable in how networks work, or even how a network could be infiltrated. With that said, I'm trying to think logically.

What I'm getting out of what the two of you have said is that it's possible that some kid sat at his computer, monitoring log-in ID's for about 50,000 students, not to mention all the faculty and staff that work here, pinned in on my "signature", saw I played Maplestory, then proceeded to hack me. Am I following correctly?

Its not your "signature" per say, its Nexon login signature they are filtering on, so anyone login to Nexon, it would trigger their "trap" and the login info would get capture. To avoid it, login to ms using the game launcher, as it uses the in-game encryption for the login ID and password which is a lot harder to crack.
Reply
#93
ctblack Wrote:Its not your "signature" per say, its Nexon login signature they are filtering on, so anyone login to Nexon, it would trigger their "trap" and the login info would get capture. To avoid it, login to ms using the game launcher, as it uses the in-game encryption for the login ID and password which is a lot harder to crack.

And this is all under the assumption that someone would take the time to target my university? Let it be known that I do, in fact, sign in through game launcher, save for the rare occurrence that I don't, and even then I merely click "Start Game" and my info is already in the boxes; I don't need to physically type anything.
Reply
#94
Panacea Wrote:And this is all under the assumption that someone would take the time to target my university? Let it be known that I do, in fact, sign in through game launcher, save for the rare occurrence that I don't, and even then I merely click "Start Game" and my info is already in the boxes; I don't need to physically type anything.

Do a web cache/cookie cleanup or download a private data deleter. It will get rid of the auto login info kept on your computer, but it will erase ALL auto login info for not just Nexon's site.
Reply
#95
ctblack Wrote:Do a web cache/cookie cleanup or download a private data deleter. It will get rid of the auto login info kept on your computer, but it will erase ALL auto login info for not just Nexon's site.

In firefox it's under preference->security->saved password, no need to delete everything
Reply
#96
ctblack Wrote:Do a web cache/cookie cleanup or download a private data deleter. It will get rid of the auto login info kept on your computer, but it will erase ALL auto login info for not just Nexon's site.

rhpot03 Wrote:In firefox it's under preference->security->saved password, no need to delete everything

Forgive me if I misunderstand, but the whole point of a key logger is to log keys that you type, right?

While I understand where the both of you are coming from, I personally do not feel as if the possibilities you suggested are likely causes.

(Out for math recitation.)
Reply
#97
Panacea Wrote:Forgive me if I misunderstand, but the whole point of a key logger is to log keys that you type, right?

While I understand where the both of you are coming from, I personally do not feel as if the possibilities you suggested are likely causes.

(Out for math recitation.)

Keylogger have nothing to do with farming ms info using wireless from an unsecure web site like Nexon, its 2 separate issues.
Reply
#98
Panacea Wrote:Forgive me if I misunderstand, but the whole point of a key logger is to log keys that you type, right?
If you saved your password, what's keeping them from directly tapping into your list of saved password in the browser instead of waiting for you to type it out?
Reply
#99
ctblack Wrote:Keylogger have nothing to do with farming ms info using wireless from an unsecure web site like Nexon, its 2 separate issues.

rhpot03 Wrote:If you saved your password, what's keeping them from directly tapping into your list of saved password in the browser instead of waiting for you to type it out?

And we're still under the assumption that they somehow got into my university's network, right? Had someone actually been able to leech off their network, I'm sure they would've noticed it and terminated it.
Reply
Panacea Wrote:And we're still under the assumption that they somehow got into my university's network, right? Had someone actually been able to leech off their network, I'm sure they would've noticed it and terminated it.

No.

1. Not if the hacker is one of the person had access to the network, possibility one of the students.
2. You don't need access to the network to sniff for wireless data, as "wireless" is broadcast and anyone within range can receive it.
Reply


Forum Jump:


Users browsing this thread: