Register for your free account! | Forgot your password?

Go Back   elitepvpers > General Gaming > General Gaming Discussion
You last visited: Today at 23:46

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



This looks like fun (RoM password security)

Discussion on This looks like fun (RoM password security) within the General Gaming Discussion forum part of the General Gaming category.

Closed Thread
 
Old   #1
 
elite*gold: 0
Join Date: Jun 2009
Posts: 203
Received Thanks: 21
This looks like fun (RoM password security)

Seems like a bunch of people are raging now on both EU and US forums after this video was made about unencrypted passwords. Looks like fun to me lol

EU thread:
Video:

I so do love how secure Runes of Magic is.
rawrgodzilla is offline  
Old 06/15/2010, 00:12   #2
 
elite*gold: 24
Join Date: Apr 2010
Posts: 35,931
Received Thanks: 6,344
A way to hack users?
anonymous-f4h279 is offline  
Old 06/15/2010, 01:30   #3
 
Atheuz's Avatar
 
elite*gold: 81
Join Date: Jul 2005
Posts: 1,921
Received Thanks: 2,239
Quote:
Originally Posted by Drewfire View Post
A way to hack users?
No, it's the issue about the client sending the server the login in plaintext. Basically this means, even if the server calculates a hash serverside before comparing it to the database, a person who has access to this kind of interface could log the incomming authentication packets.

However, it's no indication or evidence that frogster breaks any law of saving private information. It simply means that the Client is running on a non certificated or encrypted stream, which alot of things do. And like many things it could be abused by someone bad working for them that has access to the server.
Atheuz is offline  
Thanks
1 User
Old 06/15/2010, 13:07   #4
 
ivits's Avatar
 
elite*gold: 1
Join Date: Jul 2008
Posts: 419
Received Thanks: 89
thats not really interesting, because every game uses this way, so if someone hacks your account, he has to hack your pc, or th server.
What you need is a computercode trojan or an, trojaner which is always activate.

edit says: computercode = programmcode
ivits is offline  
Old 06/15/2010, 14:10   #5
 
Fir3andIc3's Avatar
 
elite*gold: 50
Join Date: Dec 2007
Posts: 598
Received Thanks: 81
Quote:
Originally Posted by ivits View Post
thats not really interesting, because every game uses this way, so if someone hacks your account, he has to hack your pc, or th server.
What you need is a computercode trojan or an, trojaner which is always activate.
/sign


A hacker needs to be in the middle. Something like this:

Server <-----> Trojan Horse (maybe) <-----> Your PC


p.s. Trojan is on your pc ^^
Fir3andIc3 is offline  
Old 06/15/2010, 15:18   #6
 
elite*gold: 24
Join Date: Apr 2010
Posts: 35,931
Received Thanks: 6,344
Quote:
Originally Posted by Fir3andIc3 View Post
/sign


A hacker needs to be in the middle. Something like this:

Server <-----> Trojan Horse (maybe) <-----> Your PC


p.s. Trojan is on your pc ^^
It's unnecessary
anonymous-f4h279 is offline  
Old 06/15/2010, 16:35   #7
 
Digital Shadow's Avatar
 
elite*gold: 6
Join Date: Dec 2007
Posts: 249
Received Thanks: 205
Quote:
Originally Posted by Drewfire View Post
It's unnecessary
No it's not! Your username and your password from your pc will be send unencrypted straight to the loginserver if you press the login button. Skillful hackerz have to use packet sniffing tools or something like (keylogger) trojans or other security vulnerabilities to steal your account data.

Quote:
thats not really interesting, because every game uses this way
someone posted somewhere that in other mmo games they use an encryption, while sending personal access data.
Digital Shadow is offline  
Old 06/15/2010, 16:58   #8
 
elite*gold: 24
Join Date: Apr 2010
Posts: 35,931
Received Thanks: 6,344
It's unnecesarry to use it, if a hack came on your pc.
anonymous-f4h279 is offline  
Old 06/15/2010, 17:05   #9
 
Deset's Avatar
 
elite*gold: 0
Join Date: Feb 2010
Posts: 760
Received Thanks: 204
yeah but you can hack the pw if its unencrypted without having a keylogger on your pc

and its easier to make a keylogger for unencrypted data
Deset is offline  
Old 06/15/2010, 17:28   #10
 
elite*gold: 24
Join Date: Apr 2010
Posts: 35,931
Received Thanks: 6,344
Then it's useless to use it, if no virus came on your pc.
anonymous-f4h279 is offline  
Old 06/15/2010, 22:24   #11
 
ivits's Avatar
 
elite*gold: 1
Join Date: Jul 2008
Posts: 419
Received Thanks: 89
Quote:
Originally Posted by Fir3andIc3 View Post
/sign


A hacker needs to be in the middle. Something like this:

Server <-----> Trojan Horse (maybe) <-----> Your PC


p.s. Trojan is on your pc ^^
the hardest part will be to place the trojan on the pc.
ivits is offline  
Old 06/16/2010, 01:50   #12
 
elite*gold: 0
Join Date: May 2010
Posts: 14
Received Thanks: 6
You just have to sniff his complete network traffic. Just search for his accountname & pw, and you should get it.
LCG is offline  
Old 06/16/2010, 12:34   #13
 
Atheuz's Avatar
 
elite*gold: 81
Join Date: Jul 2005
Posts: 1,921
Received Thanks: 2,239
Quote:
Originally Posted by LCG View Post
You just have to sniff his complete network traffic. Just search for his accountname & pw, and you should get it.
Sometimes I believe people think sniffing a computer outside their own network is "easy" or even doable without installing third party programs on the victims PC.
Atheuz is offline  
Old 06/16/2010, 15:11   #14
 
run32.dll's Avatar
 
elite*gold: 0
Join Date: Jan 2007
Posts: 126
Received Thanks: 83
Yes - having the username and password in plain text in the packets is bad. But its not THAT bad - there are much bigger threads to the account security. How is the the attacker suppose to find out the clients ip address? That's right - he can't. Unless he knows his "friend" uses an unprotected or cheap WEP 128bit encrypted wireless connection and plays Runes of Magic.

If somebody wants to steal accounts he could just upload a video on YouTube. Name the Video "Runes of Magic Godmode" ... or "...Onehitkill". Place a link in the description to a program that reads the usename and password from the memory and send the stuff to an emailaddress. There are so many retards in this world that would download and start the "cheattool". Even on this forum some "bad guy" already tried to upload his fake "cheattool". But the funny part was I found out his scamemail-address and pass because there were in plain text in his "cheattool". So I logged into his account, deleted all emails, changed to password, made a few screenshots and reported the scammer to the admin. A few hours later the post about his "cheattool" was deleted and the raged scammer pm'ed me lol.

If you ask me the biggest thread to account security is ALWAYS the accountuser. The "raged guys" in the official forum are probably the 13yr old "I-got-scammed-by-a-youtubevideo"-stereotype. But they don't wont to admit it was their fault or they don't even know they got scammed. They probably think "hey I have a firewall and AV that detects EVERY virus/trojan/scam/etc, I'm save!" ... lol.

ps: f***ing maintance on EU servers ****** me off -.-
run32.dll is offline  
Thanks
3 Users
Old 06/16/2010, 19:58   #15
 
elle56's Avatar
 
elite*gold: 0
Join Date: Feb 2008
Posts: 116
Received Thanks: 4
XD Iīm yust 14, too. But i Programm little keyloggers into little Games. So i can spy out my friendīs ^^ Thatīs better than find out what uncrypted packages send my Runes of magic^^
elle56 is offline  
Closed Thread


Similar Threads Similar Threads
NCsoft Password Security Update
05/13/2010 - Aion - 1 Replies
As of May 12, 2010, the NCsoft Account Management and game account password features were updated to provide better security for our customers. For customers with existing accounts, these updates will take effect after you have logged into your NCsoft master account to update your NCsoft master account password and password hints. For customers creating new accounts, the new features will automatically take effect. The new features include: Removal of date of birth verification for the...
NCsoft Password Security Update
05/13/2010 - Lineage 2 - 1 Replies
As of May 12, 2010, the NCsoft Account Management and game account password features were updated to provide better security for our customers. For customers with existing accounts, these updates will take effect after you have logged into your NCsoft master account to update your NCsoft master account password and password hints. For customers creating new accounts, the new features will automatically take effect. The new features include: Removal of date of birth verification for the...
Change Password without Security Question???
06/16/2008 - Silkroad Online - 4 Replies
Hi guys; is it possible to change my password in Silkroad without answering the Security Question (i forgot the answer, so long ago:().



All times are GMT +2. The time now is 23:46.


Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2024 elitepvpers All Rights Reserved.