Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
People being hacked since the last Server Check.
Blades4hire Wrote:Ok, so i found something very interesting, and could possibly be relevant.
I found a youtube video(probably not allowed to be posted) of a guy.
1. He logged into his account and showed his characters on the character selection screen
2. He returned to world selection, then sent a "Receive" packet
3. upon selecting the same world again, it showed completely different characters(although they were his aswell.)
I tried to replicate this myself.
Logged onto a mule account.
went to world select
Sent the same recv packet.
And lo and behold, all of his characters showed up on my character select instead of mine.
I couldnt log in to any one of them however because it said something about "PIC must be created, please create PIC and try again."
From what I understand, he posted the recv packet that he used, and you used the same one, then it showed you his characters? :f6:

If that's the case, you would need to know the appropriate packet for each account you want to hack... and I don't see how one could go about obtaining it without already having the account ID & pass, and then sniffing it...

Correct me if I'm wrong.
Reply
Eos Wrote:That's one I'd hypothesized before, or a variation thereof.

Erm what banned him? :f6:
Reply
Leaves Wrote:If that's the case, you would need to know the appropriate packet for each account you want to hack... and I don't see how one could go about obtaining it without already having the account ID & pass, and then sniffing it...

Id's aren't random. All you'd need to do is understand how the packet in question related to the account it brought back and extrapolate it to use on other characters by simple incrementation and guesswork. Tedious, but going account by account will eventually strike it rich.


KhainiWest Wrote:Erm what banned him? :f6:

The blatant admission of having packet edited the game?
It's not having what you want - It's wanting what you've got.
Reply
We are not safe.
Reply
Zelkova Wrote:We are not safe.

I think we all came to that conclusion a while ago. This just goes a hell of a lot closer to affirming it.
Reply
Eos Wrote:Id's aren't random. All you'd need to do is understand how the packet in question related to the account it brought back and extrapolate it to use on other characters by simple incrementation and guesswork. Tedious, but going account by account will eventually strike it rich.

Going by that, I would assume that this sort of method would not be very widespread, as it would require a fair amount of technical knowledge to operate. Furthermore, like you said, it would be difficult to target a specific account, and far easier to simply hit random ones.

Since most of the account hackings (or at least the ones we hear about) seem to target big fish, I'd say this packet method isn't the main way people are being hacked.

Either way, I'm quite alarmed that this kind of security hole exists... it's pretty inexcusable for a game of this magnitude. All goes back to the very poorly designed server/client relationship.
Reply
Leaves Wrote:Going by that, I would assume that this sort of method would not be very widespread, as it would require a fair amount of technical knowledge to operate. Furthermore, like you said, it would be difficult to target a specific account, and far easier to simply hit random ones.

Since most of the account hackings (or at least the ones we hear about) seem to target big fish, I'd say this packet method isn't the main way people are being hacked.

Your logic is absolutely appalling.
Do you understand what a hacker is? Do you somehow not equate the concept of 'hacker' and 'require a fair amount of technical knowledge'? A real hacker is not an idiot.
As to targeting; Are you going to bother robbing every piddly account you hit, or are you going to rob the big ones, and who's going to complain? The guy who misplaced his maple dana or the one who lost 20 trillion? If it were truly "targeted" all the big ones would be hit at once, not spread out over days and weeks as we've seen.
It's not having what you want - It's wanting what you've got.
Reply
Well Pineapple.

Getting banned/trouble logging in?/ID already logged in seems to be the only way to avoid that I think... that's really scary.
Reply
Leaves Wrote:Going by that, I would assume that this sort of method would not be very widespread, as it would require a fair amount of technical knowledge to operate. Furthermore, like you said, it would be difficult to target a specific account, and far easier to simply hit random ones.

Since most of the account hackings (or at least the ones we hear about) seem to target big fish, I'd say this packet method isn't the main way people are being hacked.
The fact that it hits random accounts make me think this is the method and most of the account hackings we hear about are not from rich people o.o.
Mazz Wrote:Well Pineapple.

Getting banned/trouble logging in?/ID already logged in seems to be the only way to avoid that I think... that's really scary.
Yeah, probably. I know a few people who never log off and they are still safe (for now), but other mules were already hacked.
Reply
Eos Wrote:Your logic is absolutely appalling.
Do you understand what a hacker is? Do you somehow not equate the concept of 'hacker' and 'require a fair amount of technical knowledge'? A real hacker is not an idiot.
As to targeting; Are you going to bother robbing every piddly account you hit, or are you going to rob the big ones, and who's going to complain? The guy who misplaced his maple dana or the one who lost 20 trillion? If it were truly "targeted" all the big ones would be hit at once, not spread out over days and weeks as we've seen.
I think it's fair to assume that these hacking methods are not *SO* private that only experienced hackers have access to them. Script kiddies must have access to them, too, just going by the sheer amount of people that have been hacked. My point was that I don't think an average script kiddie could pull off the packet hack, which leads me to believe that it's not the root cause of this fiasco.

Do you believe that the majority of these hackings are completely random?
Reply
Well I guess the only method is to do the hotspot shield..otherwise we're screwed by default no matter if we have fort knox or fort dumb ass security lol
Reply
The only problem with this method is that it has, as Eos pointed out, been hypothesized before. In fact I think it's been suggested as far back as when the website login was introduced?
And yet, as far as I can tell, the method or leak behind this ongoing hacking wave is in very few hands, possibly only one. Doesn't sound reasonable that with all this time and all these minds working on it, only one got it right.
Reply
SaptaZapta Wrote:Doesn't sound reasonable that with all this time and all these minds working on it, only one got it right.

Why? Infinite monkeys with infinite typewriters only guarantees one will succeed eventually, not all of them at once.
It's not having what you want - It's wanting what you've got.
Reply
Could this possibly why I get this message randomly, even when the server status is completely green all over and my internet connection is just fine? I got it a lot when the servers were crashing all the time and just assumed it to be related to lag... but I wasn't even tabbed in when this happened.

 Spoiler
Reply
No it's not, it's only when you're trying to do certain actions during the game. Like if you try to keep dropping something or try to smega x amount of times in a row.
Reply
theres a database leak its almost confirmed. We can only use Hotspot Shield as for Now.

The funniest thing is that most of this stupid Basilers says its keylogger.
Reply
MisterA Wrote:theres a database leak its almost confirmed. We can only use Hotspot Shield as for Now.

The funniest thing is that most of this stupid Basilers says its keylogger.

I wonder, how will Hotspot shield protect you?
Reply
Unleashing Wrote:I wonder, how will Hotspot shield protect you?

It blocks your account from logging in until you reactivate your account. I think?
Reply
Unleashing Wrote:I wonder, how will Hotspot shield protect you?

Using Hotspot shield suspends your account for "suspicious activity". You need to respond to an e-mail to reactivate it. So, presumably, the hackers can't get into your account either (unless they break into your e-mail too).

If, however, the hackers are somehow circumventing the normal login process (as described above, logging into one account and then somehow pulling up the chars of another), this might not be good enough, either.
Reply
Here is something scary.

When my IP was banned and I had to reactivate some accounts, I forgot one of my email addresses so I was routinely going through my many many email accounts.

I came upon an email account for my friends long since banned account (We are talking years ago). This account had recently gotten a message from nexon stating that "suspicious activity blahblah". << How in the pineapple are hackers getting information for an account that has been banned/not in use for YEARS?

This whole situation just sucks.
Reply


Forum Jump:


Users browsing this thread: 6 Guest(s)