Poll: How do you log in Maplestory, were you ever hacked if so how do you think it happened
You do not have permission to vote in this poll.
Website & was never hacked
47.62%
20 47.62%
Game Launcher & was never hacked
42.86%
18 42.86%
Website & was hacked via keylogger
0%
0 0%
Game Launcher & was hacked via keylogger
2.38%
1 2.38%
Website & was hacked via remote/hijack
0%
0 0%
Game Launcher & was hacked via remote/hijack
7.14%
3 7.14%
Total 42 vote(s) 100%
* You voted for this item. [Show Results]

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
How do you log in Maplestory? & Which method is more secure?
#1
How do you log in maplestory? Game Launcher or website?

I used to log on from website ever since that made it easier to relog in but my account was almost hijacked that way like a year ago and since then I have stopped logging in the game via website and stuck with game launcher but I am still worried about keyloggers.
At least when logging through the website I can use the keyscrambler add-on with firefox but with game launcher I cannot use keyscrambler.

Some data collection could help reveal which method is the most secure
So what are your thoughts on this?

Thanks
Reply
#2
gamelauncher.exe

I wasn't hacked, but I haven't played since before Chaos (came back this weekend).
Reply
#3
Oh, welcome back to ms.

ever since the mts ID leak I have been worried about account security and so I'm trying to beef up my computer security and anything else I possibly do.
Reply
#4
Always done website. I also always use the auto complete form so...I guess if I did have a keylogger I wouldn't actually be hacked, unless it came with some ridiculous program to decrypt stored passwords.
Reply
#5
Lots of hidden assumptions there.

Personally I'm most concerned about the current hacking wave. Trouble is, nobody knows how it's being done. Including, apparently, Nexon.

Almost all the people I know who were hacked in the past two months or so, were hacked while offline. So, even if connection hijacking ("remote hack") is currently possible, it's obviously not the biggest danger you need concern yourself with. I also don't know why you'd think website login is more susceptible to this (and in this case "I don't know" literally means that, not "I think you're wrong").

As for keyloggers... one theory that has been proposed for these recent hackings was some kind of magical keylogger that lies in wait for months (some people hacked hadn't logged onto maple in months, which means a more recent logger would have had nothing to record) and is indetectible by any of the malware scanners around (many people who got hacked had their computer scanned and found squeaky clean). Somehow I have a hard time believing in such a beast, mainly because I can't think why the keylogger's owners would wait so long to start reaping their rewards, instead of hacking accounts as soon as they have their info.

Another theory that has been advanced is that Nexon's user database has been leaked again, same as two years ago. That is possible, but the problem is that some people who were hacked claim to have changed their password recently (after the start of the hacking wave - hence the leak is continuous or at least periodic), and others claim to have had a password so complex it couldn't possibly be un-hashed by rainbow tables and the like. The second issue is especially problematic because I tend to believe Nexon that they don't store cleartext passwords anywhere. If some of their web pages are indeed unecrypted, the cleartext password could be intercepted by someone tapping their lines - but then how do inactive people get hacked? Same issue as with the keylogger, if a person isn't entering their password anywhere, nothing can record it.

The last theory is that the hackers have a "bypass", a way to fool the game servers into thinking they have been authenticated, when they haven't. This bears some similarity to "hijacks", but doesn't require that the legitimate user log in before his connection can be stolen. This is not too farfetched, considering the number of servers involved and the general quality of Nexon's coding. If this is so, however, no level of securing your password would protect you, because the hackers never need to find it out.
Reply
#6
SaptaZapta Wrote:The last theory is that the hackers have a "bypass", a way to fool the game servers into thinking they have been authenticated, when they haven't. This bears some similarity to "hijacks", but doesn't require that the legitimate user log in before his connection can be stolen. This is not too farfetched, considering the number of servers involved and the general quality of Nexon's coding. If this is so, however, no level of securing your password would protect you, because the hackers never need to find it out.

I lumped impersonation/spoofing in with remote/hijack because they both follow the same principle of "beyond the victims control" whereas a keylogger falls into the realm of "he had it coming" in the eyes of people who look for any excuse to blame the victim.
It's not having what you want - It's wanting what you've got.
Reply
#7
When I log into GMS, I use GameLauncher.exe. I haven't been hacked so far. I'll feel sorry for the poor soul who tries to hack me, if it happens. They'll get absolutely nothing out of it - not even a single f'uck will be given by me.
Reply
#8
I only used the gamelauncher, still got hacked.

In some cases though, you still long onto the website for stuff, then it just needs a PIC cracker.
Reply
#9
or if you have a wordlist you can brute force nexons site . a big missconception about hacking is that specific people are being targetted , in most cases a cracker just throws coordinated fecal matter at the metaphorical wall and sees the results. its especialy easy to brute force nexon's site now that emails = usernames
Reply
#10
Last I looked bruteforcing the website still resulted in lock outs.
It's not having what you want - It's wanting what you've got.
Reply
#11
Eos Wrote:Last I looked bruteforcing the website still resulted in lock outs.

configure your registry so you look like a google bot, jump proxies every x atempts = no lockouts.
also depends on what tool you use.
Reply
#12
I've logged in from the website ever since that became a thing, lol

In fact, recently my gamelauncher broke...never did get it working again. Oh well.
Reply
#13
EndlessAxis Wrote:configure your registry so you look like a google bot, jump proxies every x atempts = no lockouts.
also depends on what tool you use.

It locks the account after X unsuccessful tries.

None of what you described alters that any more than it would help you brute force an account here.
It's not having what you want - It's wanting what you've got.
Reply
#14
Eos Wrote:It locks the account after X unsuccessful tries.

None of what you described alters that any more than it would help you brute force an account here.
that's the thing, you're not trying to brute one account, you're trying thousands or millions even. to try each acc 10 times is a waste of time. if you have 25 million hotmail accounts and roughly 40% havn't changed their passwowrds then its likley a good chunk of them use the same pw for MS, meaning you should only try each account once.
Reply
#15
Are you even considering what you're saying?
How successful do you think it would be to try a single (random) guess on every possible account?

And if you're claiming they're using the email pass that they mysteriously already have, that's not brute forcing.
It's not having what you want - It's wanting what you've got.
Reply
#16
Eos Wrote:Are you even considering what you're saying?
How successful do you think it would be to try a single (random) guess on every possible account?

And if you're claiming they're using the email pass that they mysteriously already have, that's not brute forcing.

its not that complicated , I take a 100 million user/pw combo list, fire it at hotmail I got roughly 33 million accounts (out of them I have full access to roughly 22million ) from those its easy to assume some of them play mmos, I try hitting every mmo site I'm interested in/accs are worth anything on , I get roughly out of that 22 million a few thousand mmo accounts.

this isn't rocket science. besides that, this is just one method, I can theoreticaly get someones info via skype,messenger,facebook with a few cmd tools and Cain&Abel, other method is using google "hack" to get .pwds decrypt them and get login info that way. nexon.net maybe be relatively secure but things attached to it and related to it (forums) arn't.

I work at an ISP I know this stuff to keep myself safe.

at the end of the day, the more amiguous you are online the less common users/pw you have,using diff ones for everything, etc make you more secure.

its relatively easy to get someones email if they use facebook, if they use facebook they usualy check their email , getting the pw from an email that's being acessed isn't very hard, now assuming they play ms adventures its prolly the same email they used for GMS to make their FB account, now you have their facebook,email and nexon account. GG
Reply
#17
This character is a week or so younger than broa, and I am yet to get hacked. Gamelauncher, btw
Reply
#18
I use GameLauncher cause the site sucked in Opera when the site-login was launched, and probably still does. And starting a new browser just adds an additional step to the login process.

That and when the site login first appeared, I found a PIC bypass that only worked on people who logged in by the site. Seems to have been fixed but doesn't mean it's the best security you can get.
Reply
#19
EndlessAxis Wrote:gibberish

A) That's not brute forcing maplestory, or anything
B) You completely leave out how they got the password to the email
C) most of the last rounds of hackings had no email tie in whatsoever
D) Being a janitor at NASA doesn't mean you're a rocket scientist any more than 'working at an ISP' makes you a security, or technology, expert.

You've more or less pulled a very random idea out of some orifice and tried to shoe-horn it into making sense here or being relevant.

Let's straighten up what you said and what you really meant;

Said Wrote:or if you have a wordlist you can brute force nexons site . a big missconception about hacking is that specific people are being targetted , in most cases a cracker just throws coordinated fecal matter at the metaphorical wall and sees the results. its especialy easy to brute force nexon's site now that emails = usernames

Meant Wrote:If you magically have a super huge list of already compromised email accounts' passwords you can try each email & pass one by one until you find some that also work on maplestory

Yeah. Big risk there. highly on topic. Thanks for contributing. Please drive through. Rolleyes
It's not having what you want - It's wanting what you've got.
Reply
#20
Always used GameLauncher and never been hacked.
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)