O yah, completely forgot about those attacks, but referring to this incident it appears it is through keyloggers and such and that SE is not to blame?
O yah, completely forgot about those attacks, but referring to this incident it appears it is through keyloggers and such and that SE is not to blame?
There's no way SE can stop someone from logging into your account with a valid account ID and password. The security of the player's ID/password is the player's responsibility by necessity.Originally Posted by Seditedi
But, regardless of how the account is hacked, SE's policy for recovering accounts still complete shit.
Curses! Foiled again! I'll be back, you meddling do-gooder! *pulls on handlebar mustache and exits, stage left*What second request? You asked "and/or"he chose "or", fulfilling your request!
Yeah, someone mentioned it looking like the Realplayer exploit in the hacked player thread as well and that's definitely what it seems like. So somepage is 100% not safe to go to unless you're properly secure. But also keep in mind, this same exploit was released on ads as well. If you want to read more about it you can check these links:Originally Posted by phoenik
http://www.symantec.com/enterprise/secu ... _loos.html
http://www.networkworld.com/news/2007/1 ... stery.html
i have iFrmewrk running in my current processes is this malicious? I just assumed it was something from apple <,<.
Yea, I realize that once someone gets the password SE can't do anything. I'm just saying it appears this latest set of hacked accounts is through virus infections either from email or web browsers, which SE can't/shouldn't be blamed for.Originally Posted by aurik
All I ask is SE have you set a separate password to change the information on the account. Not the POL login password. In order to change the login info require a different password. Same goes for credit card etc.
Ok i concede that, seeing as i didnt hear anything about that exploit until SE patched the password issue. The issue with FL Plus what was what? Your password set to like the last 4 digits of your POL ID?Not true, over 300 accounts were vulnerable due to the FriendList Plus attack (ask Taj for the actual number), and I'm sure even more were at risk since you could derive the password on many accounts once you had the account number.
The standard "ok we reset your password" password was your account ID. You could obtain Account IDs on FL Plus. So if you didn't change your password after they reset it, and were signed up to FL Plus, the account was basically just waiting to be stolen. Something like 300 accounts were in this state.Originally Posted by ronin sparthos
Now the system rejects weak passwords.
Seems like this new account hacking issue is quickly gonna pass 300 accounts at this rate. If it already isnt past 300...
Damn lol, the amount of files AVG just picked up on my laptop that Norton missed is just insane..
Can anyone do a check on ffxi mysterytour is safe? I just went there and now im kinda scared <,<
1) Userland is not a word. IE does not use an API to the kernel (NTLDLR) because, well, it can't. It does however use a bunch of already windows embedded functions resulting in extra throughput, which is what matters to me.1) Since IE is integrated with the OS (hooray, throughput?) that means exploits happen in kernel space instead of user space. Firefox is at least theoretically a userland application, therefore if you have permissions on your computer set right, malicious code will need to find a local exploit to get into kernel space to load a backdoor.
2) Since IE's userbase is larger and less technically sophisticated on average, they are a more appealing target for exploits. See also why 99% of virus makers target windows instead of Mac OS
3) Since IE's code is closed source, it is impossible to audit and, even worse, only Microsoft has the ability to respond effectively to exploits. With Firefox, exploits can be patched by virtually anyone, and thus their turnaround time on exploits is generally much better.
2) Not the fault of those who make IE. Besides, have you ever heard of an IE exploit since the JPEG buffer overflow? I can name a number of exploits that still exsist with Gekko and Mozilla as a whole.
3) OSS is also more easily exploitable than close source IN GENERAL because the code is readiliy available. It's just the willingness of people to actualy exploit the code.
4) The only reason I ever use firefox is for "Down them all".Originally Posted by Builttolast
http://en.wikipedia.org/wiki/UserlandOriginally Posted by Zero Serenity
http://en.wikipedia.org/wiki/Userland_%28computing%29
I've heard of AVG giving some false positives, I use it, haven't seen any yet though. Free version btw, works great for me, <3 daily updates as well.Originally Posted by Draggy
:ashira:Originally Posted by Ashira
Hamur'd
Originally Posted by aurik
Now that shit was funny.
1) Userland is a word. (As Ashira pointed out while I was typing damnit)Originally Posted by Zero Serenity
2) Please spare us your bullshit. Stop acting like you know what you're talking about, you don't. I've tried to be subtle, I've tried to be polite (in IRC)...But quite frankly, most of what you say is bullshit. Your insinuations that you are well versed in the world of computers are tiring, and, seemingly, ill founded. You have a broad, generalized, text book like knowledge of a lot of things...but don't know shit about what it actually means. You attempt to downplay your weaknesses (of which there are many) by trying to play them off as "areas of current learning" as though you know everything else already and are just trying to flesh out that last bit. It's bullshit.
The day you said, and I quote, "you and I know that, Taj, but the average computer user isn't as smart as us" you lost...a lot of whatever blossoms of respect for you I had.
In case I'm not being blunt enough: You try too hard. You're insecure. You need to stop. People would respect what you actually do know a lot more if you stopped trying to act like you know things you don't.
Thanks for playing.
<3Originally Posted by aurik
I may just be a poor linux guy, but isn't "ntldlr" a misspelling of the ntldr bootloader?
Which has nothing to do with making system calls or any other sort of kernel mode stuff?