[Merged]Closed Threads due to Forum Rules Violation

02/21/2008 22:43 incredibleparkcollegeissh#30796
They won't realise it "yet". So maybe they will if people keep trying to hack them lol
02/21/2008 22:47 shamir#30797
HHAHAHAHh guys look I will guess what will be the next move of deepshit7..
They will steal clearscreen sources rewritten emu and they will change GUI and some things and they'll say "SES is done we made it!!"...
Like they always do...
02/21/2008 22:59 incredibleparkcollegeissh#30798
Can anyone translate the official pServer website, so we actually know what is going on!?! Or if they have even posted anything?

Thanks
02/21/2008 23:59 Domino369#30799
run as administrator :)
02/22/2008 00:14 sketz44#30800
And what is the specific time published on the website ?
02/22/2008 01:07 neyo_adidas#30801
I say this message deserves a sticky. I certianly don't need to take the time to post or write this - but - I am, for everyone's good. Many people can benefit from my advice - this deserves attention.
This is real insight into the problem. I did this for your users, and ALL users of SRO. I also did this to reassure a few people that my intentions were NOT bad, and I do NOT intend to wrong them.

I've noticed a rash of hackers running about SRO - and truthfully, it pisses me off. I was confronted by one in-game, warning me to "watch out and don't try to offend the wrong people."

Yeah, right.

Well, the guy didn't know who he was dealing with. My curiosity was sparked. So - a few days ago - I set out to test my skills once more, it's been a long time ... but hey, once they're there - they're there for good. If you care to get an idea of what I am & what I do, this sums it up:

I picked a few people. I ravaged their accounts. I gave them back when I was done. Why, why do all of this when you don't need to? Why waste so much time when you have nothing to gain? Do you want to know how long I've spent doing this?

Account 1: 10 minutes

Account 2: 6 minutes

Account 3: 5 minutes

Account4: 1 hour ( This guy was a L70+, 33 years old - and a *programmer* no less. I dug up his secret question, I prepared a dictionary attack. If I wanted this guy's account - it was mine. I'm not about to go as far as bruting someone's account. But, I can. I left him alone.)

Account 5: This guy was smart. His snotty posts on boards pissed me off... I had a tough time digging up info on him. Lucky for him - he didn't publicize an e-mail address... except for one that he did not use as his login.

*Gasp* e-mail address.

Let me shed some light on this "hacking" we're all hearing about. Most everyone online, even the so called "bad" people in-game, are pretty good folks. I really - after getting to know people - haven't found a single person I did NOT like. There ARE people that I do not like - and that's braggards, script-kiddies, and goldfarmers. So you want to know what I'm going to do today? I'm going to potentially destroy the SRO account hacking problem. I'm going to let YOU know how THEY do it. Why? Because when you KNOW how people can DO something, you also can figure out HOW TO STOP IT. This is especially true when you _ARE_ the security hole.

Here we go:

HOW a SRO account gets hacked & stolen

1- A victim is picked.

2- Find their username

3- Find their e-mail address

4- Owned


Your secret answer is irrelevant at the moment. Your password does not matter. Once they have your username and e-mail, your account is theirs. So, I'd like everyone to take a moment ... and think of how you can correct this problem......

YES!

You need to treat your E-MAIL ADDRESS as your new SRO PASSWORD - DO NOT USE YOUR USERNAME(S)

You need to use a STRONG password on top of this. Use at least 8-10 characters, numbers AND letters. DO NOT USE A WORD IN A DICTIONARY.

People _CAN_ figure out your secret question. One person ... took "birthplace" as a question on their account. I found out the user's country.
I pulled up a list of the 10 major cities in that person's country. (towns & villages don't have hospitals). They were born in city #4. Account is hacked.

Another person - they listed their pet as their secret answer. So, I searched for their username - and an animal. Found their pet's name. Account is hacked.

Are you following a trend here?

The more you post online, the more information there is about you, the easier it is for people to "hack" your account. Yes, this *IS* what hacking *REALLY* is. Taking all of the facts you have available. Building on them. Finding out more information. Building on it ... keep building ... build more ... until you have the answer. My success rate was 80% in taking accounts I set out to take - using my head alone, and NO hacking tools, NO programming, NO cracking.

Let me sum this up for you, in a SHORT list of things you should keep in mind to safeguard your account from someone like ME.

1- Strong password. Press random keys on your keyboard, or use a password randomizer.

2- RECORD YOUR PASSWORDS. Write them down, that way you can use STRONGER passwords.

3- TREAT YOUR E-MAIL ADDRESS LIKE A PASSWORD. Use a NEW e-mail for ALL of your SRO accounts. Under NO circumstances should your username be in your password.

4- Don't fill in public profiles. People use them to hack your account.

5- Don't use the same username to post on boards as you use as a login. Can't stress this enough. That's 50% of your account lost.

6- Search for your OWN information on google. Anything you find - DON'T EVER USE IT AGAIN. This information is now INSECURE.

7- Watch out for XFIRE accounts. They show how much of a PRIME TARGET you are. (1K hours+ logged into SRO? You've got a fat account.)

If you've made a mistake with your account, DON'T PANIC. You can still save it - even if it has been compromised before.

Change your e-mail to something completely out of the ordinary. Something you've never used before.

Make it NOT a word, or a combination of 2 words and some numbers - the longer it is - the harder it is to figure out.

Change your actual name. Use the same fake name for _all_ of your logins.

When you set your passwords - don't be afraid to combine things. If your old pass was dog133 - change it to a combo of words plus numbers: car133bird331 - dumb as it looks - is a GOOD password VS a brute force attack. It's simple for you to remember, and it's HUGE when a scriptkiddie goes to attack it.

Nobody can advise you like someone who is REALLY into security. Joymax's security is shoddy. They suck. You have to take measures for your own good. You've just gotten advice from someone who's pretty good. I won't say I'm one of the best - as there are many better than me. Hey, give me credit - at least I'll admit it.

[ PS: About those guys who claim to break into Joymax's databases: 100% bull. I read that "chat with a hacker" - the guy either bruted or engineered. Trust me on that.]

Good luck everyone. I sincerely apologize to anyone whose account I've gotten into. You know who you are man. I hope you can forgive me. I took 1 global of yours - if you want the dime back, I'll send you a quarter.

I've also tried to give Joymax some of my own insight on their problems. You want to know what they say?

Nothing. They don't give a **** about anyone. Keep that in mind.

Peace.

All credits go to moderator from ogpal :D

Press Thanks if i HELPED!!!

[Only registered and activated users can see links. Click Here To Register...]

[Only registered and activated users can see links. Click Here To Register...]
[Only registered and activated users can see links. Click Here To Register...]
[Only registered and activated users can see links. Click Here To Register...]
02/22/2008 01:09 keller12#30802
were i can get account for 0x33 maybe have any no need and can give 1 for free im was in order to grateful ;] who have pm for me
02/22/2008 01:47 nathanflom#30803
i wonder if were even gonna be able to play on this server by the weekend, man i wanna play so badddddddd
02/22/2008 01:49 nedtheone#30804
Account 5 i bet it was me. i trash talk on the sro forums all the time. and if you where to hack it. it is just a lvl 1 account just to talk in the forums.
nothing on the account info is true not even email. and secret pass is something like dsfaersaf i just hit keys and hit next
not trying to piss you off just sick of all the bot post, my accounts blocked for chargeback and so on
02/22/2008 02:23 liutauras#30805
sorry i cant tell u that. because they dont have specific time ;( i talked to GM's because 1 gm is my friend and my union member... in our forums he said that someone tried to hack their server. They think it was deepblue7.com a.k.a. DB7 hmm and he said its gona take a while to get server up and running because the people that tried to hack it wanted to get all files to make their own private server. and they also saw that after server got hacked DB7 forum went off too. but yeah i can tell you that my GM said that server should start running again 02-22-08 and if it wont start running dont be mad at me i am just saying what one of our GM's that speaks english said. I will try get more information from my union forum because thats where he usually tells us whats going on. Thank You


Sincerely, IceBlade ;)
02/22/2008 02:38 sketz44#30806
So it should be up by tomorow no biggie i guess and if its not up ill just wait :)
thanks for the info
02/22/2008 03:04 xMedeia#30807
Nice.. but aren't you also giving tips how to hack here?..
02/22/2008 03:15 ratafank#30808
Yes! What is good tough little! Let's see if the they can repair the server. Good luck: :) ;)
02/22/2008 03:25 ihavenoname#30809
Thats cool, I have an email I use for all my accounts that nobody knows but me.
There are some really good tips there.

Hey neyo_adidas whats your email? XD
02/22/2008 04:07 sketz44#30810
This is thread is pointless you shouldn't have to explain to some1 how to not get there account hacked they should already know and if they don't then they don't deserve to play
thats about all there is to it