Get Account And Pass With ID

07/13/2005 20:49 AngelusInkubus#1
Hiya,long time i dun post here,but since things r going patched i get stucked on this... I know a guy who made a program which steals acc and pass just looking the ID of the player... Since he not tells anyone how to do,i leave this idea to the pros,at least i dun know a way to do this without modifiing real packets on the game... it's kinda amazing... anyway,if someone knows please post it up,or pm... Hugs to all epvpers.
07/13/2005 20:59 roundknot#2
I am pro hacking and what not, but I don't approve of getting into someone's account. If this really exists, please don't post it here. Just imagine, all these proggys to randomly input IDs and test them. That would suck.
07/13/2005 21:05 bonesaw#3
Yeah it would really suck. The game would just die.. although I don't think it can be that easy unless you have direct acess to their account database. But you could get jailed for this. ^_^
07/13/2005 21:07 chocoman4k#4
Well, your "friend" was lying then. The password verification is based on a 128bit hash of your password, making it impossible to break for nowaday's computers.
You think the opposite? Tell your friend to meet me somewhere, I will tell him my player ID and he can try to break into my account.
07/13/2005 21:08 roundknot#5
Yea you really could, and I am sure Conquer could simply roll back their servers to a day before the whole hacking incident happened, then they could slowly go though the massive swamp of mail saying "I lost 40 dragonballs" and "My lvl 130 rb trojan with full socket equipment was hacked" I doubt that anyone could actually make this work though. Now that I think about it, accounts are probably the most secure about Conquer.
07/13/2005 21:22 chocoman4k#6
Our only chance would be finding some really nasty bug made by the authors eg. the Win98 NULL session where you simply used no password to succesfully login to a remote machine, which I doubt exists in Conquer Online as it uses an hash to verify, and an empty hash is counted as an hash also :P
07/13/2005 21:31 roundknot#7
So it is pretty much impossible to tell if we can actually hack an account. I mean of course there is always social hacking. :)
07/14/2005 00:44 Bukshi#8
err.anyone tryed recording packets from IE with db pruchass? lol
07/14/2005 01:55 KitsunePaws#9
>.> You serious? XD
Packets wont help you at all with that. I am pretty sure DB purchase is a mysql thing
07/14/2005 03:28 AngelusInkubus#10
What about the meteor buying at shops??? i heard of an archer who was able to do that,never saw it tho... And after all that packet sending stuff spreading like fire around the servers it will be hard to do something really usefull by now... I been caught using coproxy,gm talked to me,he asked me to tell how i did that and i said i'll won't tell you because i have superior order to not tell,then he asked me if it has something to do with file edition or crack version of conquer.exe,and i said u r really far from the truth man...later i said it has nothing to do with file editing or cracking the exe...this i can tell you...and no matter what you do always will be someone to hack/exploit/cheat on this game...what a human can do,a human can undo...PS: i talked to Engputer[GM]. And my banned account was SupaCute at dragon server.
07/14/2005 06:09 roundknot#11
ouch not fun, How did you get caught using COProxy? Once a GM started to talk to me and I am like hey did you see that dude called Mr. X jumphack? He went looking for him and I logged out. No bannage here.
12/08/2005 09:46 Souless#12
lol...ppl...i got hacked like 4-5 times....the rule is simple....NEVER and i do mean NEVER input a number password. every time i got hacked i got a 32154+9+874136497 pass....and...ding (met) i got hacked.since i use letters ...nobody bothers me anymore.
Ding ( another met).
buh bye
12/08/2005 09:58 Qonquer#13
The account server deals with username/password verification and directs the client to the correct game server IP along with an encryption key. There must be some kind of internal communication between each game server and the account server that could be exploitable, but would take a lot of trial and error and could end up to be a wild goose chase.
03/18/2006 23:56 master_ge#14
yo guys i know how to...but u should pay me dbs first before i tell ya! it takes me 3 months to do that! >:o so guys....good luck for hunting!
03/18/2006 23:59 tsu#15
Quote:
Originally posted by master_ge@Mar 18 2006, 23:56
yo guys i know how to...but u should pay me dbs first before i tell ya! it takes me 3 months to do that! >:o so guys....good luck for hunting!
DAFAKK?!
where is my axe..

moron...