Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
People being hacked since the last Server Check.
not sure if it is real or FUD:

http://yanflychannel.wordpress.com/2011/...-hackings/

Quote:Apparently, going to the login page and inputting the wrong password will yield the right password but encrypted. This is unfathomable security if anything. Any one with a mediocre level of programming and logic base understanding can break and decrypt what Nexon put out. I managed to decrypt the jumble of text in a matter of less than a half hour. Now, I did nothing to the person’s account that I decrypted, but I seriously have to question Nexon’s campaign for players protecting their own accounts.

EDIT: and here is a list of people that already got hacked:

http://www.basilmarket.com/forum/2192681/19
Reply
CrazyNomad Wrote:not sure if it is real or FUD:

http://yanflychannel.wordpress.com/2011/...-hackings/



EDIT: and here is a list of people that already got hacked:

http://www.basilmarket.com/forum/2192681/19

Well, I guess the only way around this is to lock your account with an invalid password. You can then only relog when you request a password change and input a valid one.

inb4 Nexon's announcement:

Nexam Wrote:Now you can use special characters such as ¶, ®, ☺ and even ♥ in your passwords! Keep your accounts safe, maplers!

Don't forget your ♥ for NX. Get some ☺ today!
Reply
CrazyNomad Wrote:not sure if it is real or FUD:

http://yanflychannel.wordpress.com/2011/...-hackings/



EDIT: and here is a list of people that already got hacked:

http://www.basilmarket.com/forum/2192681/19

I used to use his RMVX scripts. He/she is a genius and a very knowledgeable fellow & knows a lot about coding, and knowing Nexon... I wouldn't be the least surprised if it turned out to be true.

./run on sentence
Reply
Phoenix Wright Wrote:I used to use his RMVX scripts. He/she is a genius and a very knowledgeable fellow & knows a lot about coding, and knowing Nexon... I wouldn't be the least surprised if it turned out to be true.

./run on sentence

well, as of now, its the only explanation about what is happening, sw.net database leak, hacker probably trying every email he got to find if it is valid(since you can use your email address to log on your maple account), then he look at the sp/sw.net user accounts, and try it as login ID too.

can be rumor, can be real, but its the best explanation about the case.
Reply
Yanfly:
Quote:Apparently, going to the login page and inputting the wrong password will yield the right password but encrypted. This is unfathomable security if anything. Any one with a mediocre level of programming and logic base understanding can break and decrypt what Nexon put out. I managed to decrypt the jumble of text in a matter of less than a half hour. Now, I did nothing to the person’s account that I decrypted, but I seriously have to question Nexon’s campaign for players protecting their own accounts.

So password hashes are that easily cracked nowadays? Or does he mean that Nexon is using some inferior encryption method.

Also sounds like the PIC is totally useless. May as well set it to 111111 for efficient relogging.
Reply
so all u have to do is keep forum email and maple email diff Rolleyes
Reply
Sheer dumb luck and a bit of paranoia is probably all that's keeping my account mostly safe at the moment.

I don't touch the MTS, never log in through the site, and my email/log-in name is so old that it doesn't relate in any way to any character name I possess or any screen name I use on SP or Basil.

And I have a PIC and password from hell but at this point I don't think either of those accomplish very much.
Reply
MissingLink Wrote:So password hashes are that easily cracked nowadays? Or does he mean that Nexon is using some inferior encryption method.

Blowfish/bcrypt with the correct adaptivity secures passwords damn good, so it would mean the latter.

If they're using SHA or MD5, then they're messing around:
[imgspoiler]http://i.imgur.com/B7iy7.png[/imgspoiler]

See that you have the possibility to use a checksum to check if the data is correctly downloaded? The reason those algorithms are there is because they're able to check whether a file give the correct checksum with those algorithms damn fast. Because of that, there's no problem to try out very many different passwords in a very short amount of time, and with enough computing power, you'll eventually get a hit.
Reply
A link to the same article was posted on Nexon forums, and promptly deleted.

When asked why it was deleted, -Hime- replied:
http://forum.nexon.net/MapleStory/forums...79200.aspx
-Hime- Wrote:I'm sorry but theories and speculations are not truths.

The thread was deleted because it was adding more fuel to an already sensitive situation. Thank you.

When locking another thread about the current hacking epidemic, she said:
http://forum.nexon.net/MapleStory/forums...px#8248670
-Hime- Wrote:To be realistic accounts takeovers happen with any online game. There are others who see value in your virtual items. Regardless of how your account was compromised please submit a ticket. I know many of you know that there are a good handful of players still waiting to be helped but their ticket is open for a reason. Please submit a ticket so we can investigate how your account was compromised and how we can help.

I understand many of you are frustrated and curious, but your theories are only adding more fuel to the already sensitive situation. Thank you.

Ah well. At least we know someone at Nexon is aware of this "already sensitive situation".
Can anyone check whether they've changed the website login page not to give out the (hashed) password anymore?
Reply
Please send a ticket to nexon that'll work!! (or not... going off of my still open ticket from well over a year ago now.)

I would expect nothing less than total denial of anything on nexon's end. That's their game always has been and most likely always will be.
Reply
At least they're acknowledging that this pomegranate is real.

Too bad they won't ever come out and say that it's their fault for failing so much so many times and on so many levels.
Reply
Inputting a wrong password yields the actual (encrypted) password? -___________- seriously?
Reply
I can't seem to reproduce YanFly's supposed explanation. There's nothing there o.o

lol

What a load of bullcrap.
Reply
Fimbulvetr Wrote:Inputting a wrong password yields the actual (encrypted) password? -___________- seriously?

i doubt if you put the wrong password in. It will show the pw right in front of you.

This goes back to what i was saying before about nexon changing their password section. Before under manage account it would show your actual password when you request to change it in plain text. Now it doesn't do it anymore since they changed it.

@danny maybe he is using a special program that you dont have. This guy knows his stuff you know.
Reply
Locked Wrote:I can't seem to reproduce YanFly's supposed explanation. There's nothing there o.o

lol

What a load of bullcrap.

They might have changed it already. They've been changing their web pages related to login, on the sly, for several days now (length of passwords and such)
Reply
Fimbulvetr Wrote:Inputting a wrong password yields the actual (encrypted) password? -___________- seriously?


I actually asked if this was possible on the very first page. Nobody has replied yet, but it's interesting that somebody else posted it in the thread. I also found a third person on Basil who told me he has been using this method himself for several months.
Reply
Locked Wrote:I can't seem to reproduce YanFly's supposed explanation. There's nothing there o.o

lol

What a load of bullcrap.

If it was deleted off Nexon forums, it was already tested, and it was already fixed probably within the hour they caught wind of it.
Reply
Phoenix Wright Wrote:Sheer dumb luck and a bit of paranoia is probably all that's keeping my account mostly safe at the moment.

I don't touch the MTS, never log in through the site, and my email/log-in name is so old that it doesn't relate in any way to any character name I possess or any screen name I use on SP or Basil.

And I have a PIC and password from hell but at this point I don't think either of those accomplish very much.

Same for me... all you say applies for me but the difference is:
I got hacked like 1 week ago....
Reply
Locked Wrote:I can't seem to reproduce YanFly's supposed explanation. There's nothing there o.o

lol

What a load of bullcrap.

I stepped through all the JSON and Ajax and whatnot and saw nothing incriminating. It has it's own base 62 function to do comparisons with but that's just to hash the input for the server to compare.
It's not having what you want - It's wanting what you've got.
Reply
CrazyNomad Wrote:not sure if it is real or FUD:

http://yanflychannel.wordpress.com/2011/...-hackings/



EDIT: and here is a list of people that already got hacked:

http://www.basilmarket.com/forum/2192681/19
Post from basil on the same subject as the blog(http://www.basilmarket.com/forum/2196294/7)
"myrdrex: That doesn't seem right- the response is a simply JSON message:
"error":{"code":"1510","type":"Unauthorized","message":"INCORRECT_ID_OR_PASSWORD"}}

Just set up a SSL proxy, decrypt it, and you'll see that. There's no embedded password at all on the response that comes back from a failed login.

"PepsiMin; ^ This is correct. Also, -Hime- on the nexon forums stated that they do not store any passwords on their end (believe it or not).

SO, THIS THREAD IS 100% INCORRECT. There's no proof (SS) of any encrypted passwords being sent back posted by the person who started this rumor, and until I see one, you should all regard this as a false scare.

About the hackings going on for the past month or so, I honestly don't know what's causing it. There could be other security holes in the game that hackers are exploiting."

This guy(Judging by my eyes and perhaps my disbelief in his theory) and what he said seems more reliable then the thread starter. I also could not re-create what the TS was talking about, so as far as I'm concerned. It's bullcrap unless he posts actual proof, instead of words.
Reply


Forum Jump:


Users browsing this thread: 4 Guest(s)