Item Search
     
BG-Wiki Search
Page 8 of 16 FirstFirst ... 6 7 8 9 10 ... LastLast
Results 141 to 160 of 304
  1. #141
    E. Body
    Join Date
    Jul 2006
    Posts
    2,184
    BG Level
    7

    Re: Recent Hackings and Steps to Insure Account Safety.

    O yah, completely forgot about those attacks, but referring to this incident it appears it is through keyloggers and such and that SE is not to blame?

  2. #142
    Ridill
    Join Date
    May 2005
    Posts
    13,568
    BG Level
    9

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by Seditedi
    O yah, completely forgot about those attacks, but referring to this incident it appears it is through keyloggers and such and that SE is not to blame?
    There's no way SE can stop someone from logging into your account with a valid account ID and password. The security of the player's ID/password is the player's responsibility by necessity.

    But, regardless of how the account is hacked, SE's policy for recovering accounts still complete shit.

  3. #143
    The Defense is ready, Your Honor
    Join Date
    Sep 2007
    Posts
    20,631
    BG Level
    10
    FFXIV Character
    Lord Longhaft
    FFXIV Server
    Gilgamesh
    FFXI Server
    Cerberus
    WoW Realm
    Mug'thol

    Re: Recent Hackings and Steps to Insure Account Safety.

    What second request? You asked "and/or" he chose "or", fulfilling your request!
    Curses! Foiled again! I'll be back, you meddling do-gooder! *pulls on handlebar mustache and exits, stage left*

  4. #144
    Sci
    Sci is offline
    Sea Torques
    Join Date
    Jul 2006
    Posts
    584
    BG Level
    5
    FFXIV Character
    Sci Gauss
    FFXIV Server
    Excalibur
    FFXI Server
    Phoenix

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by phoenik
    First mentioned at lolalla, but it's imporant for everyone to know.

    Right now on the front page of ffxi.somepage.com there is a hidden iframe that loads a page with a javascript exploit.
    If you right click and view sauce and search for iframe, it should be the first to pop up. If you don't and to risk going, I made an image found here
    http://img409.imageshack.us/img409/9725/iframegm0.jpg
    (Would have uploaded it to my own server, but being at school and all lol.)

    The iframe loads up the url
    Code:
    ttp://www.miorsocft.com/help/help.htm
    , at first glance some might say "oh it's just microsoft", but look at the url closely.. they're exploiting the fact that you read words as a whole and not letter by letter. On that page is the javascript exploit, pretty sure it uses a realplayer exploit, but I'm not positive.

    The fact that it's embedded in the last news post is what gets me, curious as to if the admin of the site realizes it's there or not. I suggest not going to somepage, at least for now, and to use FF with No Script enabled, I've seen a couple ads on ffxiah that try to get you to download fake antivirus software. RMT are desperate to make ends meet, I have a feeling our favorite sites are going to be targeted for some time...

    edit: put the nasty url in code to help prevent clicking.
    Yeah, someone mentioned it looking like the Realplayer exploit in the hacked player thread as well and that's definitely what it seems like. So somepage is 100% not safe to go to unless you're properly secure. But also keep in mind, this same exploit was released on ads as well. If you want to read more about it you can check these links:

    http://www.symantec.com/enterprise/secu ... _loos.html
    http://www.networkworld.com/news/2007/1 ... stery.html

  5. #145
    Nidhogg
    Join Date
    Jul 2006
    Posts
    3,999
    BG Level
    7

    Re: Recent Hackings and Steps to Insure Account Safety.

    i have iFrmewrk running in my current processes is this malicious? I just assumed it was something from apple <,<.

  6. #146
    E. Body
    Join Date
    Jul 2006
    Posts
    2,184
    BG Level
    7

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by aurik
    Quote Originally Posted by Seditedi
    O yah, completely forgot about those attacks, but referring to this incident it appears it is through keyloggers and such and that SE is not to blame?
    There's no way SE can stop someone from logging into your account with a valid account ID and password. The security of the player's ID/password is the player's responsibility by necessity.

    But, regardless of how the account is hacked, SE's policy for recovering accounts still complete shit.
    Yea, I realize that once someone gets the password SE can't do anything. I'm just saying it appears this latest set of hacked accounts is through virus infections either from email or web browsers, which SE can't/shouldn't be blamed for.

  7. #147
    Corwens a slot
    Join Date
    Apr 2006
    Posts
    4,115
    BG Level
    7

    Re: Recent Hackings and Steps to Insure Account Safety.

    All I ask is SE have you set a separate password to change the information on the account. Not the POL login password. In order to change the login info require a different password. Same goes for credit card etc.

  8. #148
    New Odin
    Join Date
    Jul 2006
    Posts
    8,659
    BG Level
    8
    FFXIV Character
    Sparthia Abysseant
    FFXIV Server
    Excalibur
    FFXI Server
    Lakshmi

    Re: Recent Hackings and Steps to Insure Account Safety.

    Not true, over 300 accounts were vulnerable due to the FriendList Plus attack (ask Taj for the actual number), and I'm sure even more were at risk since you could derive the password on many accounts once you had the account number.
    Ok i concede that, seeing as i didnt hear anything about that exploit until SE patched the password issue. The issue with FL Plus what was what? Your password set to like the last 4 digits of your POL ID?

  9. #149
    Ridill
    Join Date
    May 2005
    Posts
    13,568
    BG Level
    9

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by ronin sparthos
    Not true, over 300 accounts were vulnerable due to the FriendList Plus attack (ask Taj for the actual number), and I'm sure even more were at risk since you could derive the password on many accounts once you had the account number.
    Ok i concede that, seeing as i didnt hear anything about that exploit until SE patched the password issue. The issue with FL Plus what was what? Your password set to like the last 4 digits of your POL ID?
    The standard "ok we reset your password" password was your account ID. You could obtain Account IDs on FL Plus. So if you didn't change your password after they reset it, and were signed up to FL Plus, the account was basically just waiting to be stolen. Something like 300 accounts were in this state.

    Now the system rejects weak passwords.

  10. #150
    New Odin
    Join Date
    Jul 2006
    Posts
    8,659
    BG Level
    8
    FFXIV Character
    Sparthia Abysseant
    FFXIV Server
    Excalibur
    FFXI Server
    Lakshmi

    Re: Recent Hackings and Steps to Insure Account Safety.

    Seems like this new account hacking issue is quickly gonna pass 300 accounts at this rate. If it already isnt past 300...

  11. #151
    Bagel
    Join Date
    Aug 2007
    Posts
    1,457
    BG Level
    6
    FFXIV Character
    E'jusana Rhea
    FFXIV Server
    Cactuar
    FFXI Server
    Carbuncle

    Re: Recent Hackings and Steps to Insure Account Safety.

    Damn lol, the amount of files AVG just picked up on my laptop that Norton missed is just insane..

  12. #152
    Nidhogg
    Join Date
    Jul 2006
    Posts
    3,999
    BG Level
    7

    Re: Recent Hackings and Steps to Insure Account Safety.

    Can anyone do a check on ffxi mysterytour is safe? I just went there and now im kinda scared <,<

  13. #153
    Sea Torques
    Join Date
    Jun 2007
    Posts
    682
    BG Level
    5
    FFXI Server
    Odin

    Re: Recent Hackings and Steps to Insure Account Safety.

    1) Since IE is integrated with the OS (hooray, throughput?) that means exploits happen in kernel space instead of user space. Firefox is at least theoretically a userland application, therefore if you have permissions on your computer set right, malicious code will need to find a local exploit to get into kernel space to load a backdoor.

    2) Since IE's userbase is larger and less technically sophisticated on average, they are a more appealing target for exploits. See also why 99% of virus makers target windows instead of Mac OS

    3) Since IE's code is closed source, it is impossible to audit and, even worse, only Microsoft has the ability to respond effectively to exploits. With Firefox, exploits can be patched by virtually anyone, and thus their turnaround time on exploits is generally much better.
    1) Userland is not a word. IE does not use an API to the kernel (NTLDLR) because, well, it can't. It does however use a bunch of already windows embedded functions resulting in extra throughput, which is what matters to me.
    2) Not the fault of those who make IE. Besides, have you ever heard of an IE exploit since the JPEG buffer overflow? I can name a number of exploits that still exsist with Gekko and Mozilla as a whole.
    3) OSS is also more easily exploitable than close source IN GENERAL because the code is readiliy available. It's just the willingness of people to actualy exploit the code.

    Quote Originally Posted by Builttolast
    You forgot 4.

    4) Plugins. Plugins. Plugins. The core difference between the 2 is you can increase security on your PC using plugins to block malicious ads and scripts for no added cost. Plugins are what make Firefox what it is. Lack of plugins coupled with complete OS integration make IE the most dangerous of all browsers.
    4) The only reason I ever use firefox is for "Down them all".

  14. #154
    Ashira
    Guest

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by Zero Serenity
    1) Userland is not a word.
    http://en.wikipedia.org/wiki/Userland

    http://en.wikipedia.org/wiki/Userland_%28computing%29

  15. #155
    E. Body
    Join Date
    Jul 2006
    Posts
    2,184
    BG Level
    7

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by Draggy
    Damn lol, the amount of files AVG just picked up on my laptop that Norton missed is just insane..
    I've heard of AVG giving some false positives, I use it, haven't seen any yet though. Free version btw, works great for me, <3 daily updates as well.

  16. #156
    Ridill
    Join Date
    May 2005
    Posts
    13,568
    BG Level
    9

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by Ashira
    Quote Originally Posted by Zero Serenity
    1) Userland is not a word.
    http://en.wikipedia.org/wiki/Userland

    http://en.wikipedia.org/wiki/Userland_%28computing%29
    :ashira:
    Hamur'd

  17. #157
    Nidhogg
    Join Date
    Apr 2007
    Posts
    3,895
    BG Level
    7

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by aurik
    Quote Originally Posted by Ashira
    Quote Originally Posted by Zero Serenity
    1) Userland is not a word.
    http://en.wikipedia.org/wiki/Userland

    http://en.wikipedia.org/wiki/Userland_%28computing%29
    :ashira:
    Hamur'd

    Now that shit was funny.

  18. #158
    ( o )( o )
    Join Date
    Apr 2007
    Posts
    121
    BG Level
    3

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by Zero Serenity
    1) Userland is not a word. IE does not use an API to the kernel (NTLDLR) because, well, it can't. It does however use a bunch of already windows embedded functions resulting in extra throughput, which is what matters to me.
    1) Userland is a word. (As Ashira pointed out while I was typing damnit)

    2) Please spare us your bullshit. Stop acting like you know what you're talking about, you don't. I've tried to be subtle, I've tried to be polite (in IRC)...But quite frankly, most of what you say is bullshit. Your insinuations that you are well versed in the world of computers are tiring, and, seemingly, ill founded. You have a broad, generalized, text book like knowledge of a lot of things...but don't know shit about what it actually means. You attempt to downplay your weaknesses (of which there are many) by trying to play them off as "areas of current learning" as though you know everything else already and are just trying to flesh out that last bit. It's bullshit.

    The day you said, and I quote, "you and I know that, Taj, but the average computer user isn't as smart as us" you lost...a lot of whatever blossoms of respect for you I had.

    In case I'm not being blunt enough: You try too hard. You're insecure. You need to stop. People would respect what you actually do know a lot more if you stopped trying to act like you know things you don't.

    Thanks for playing.

  19. #159
    Ashira
    Guest

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by aurik
    Quote Originally Posted by Ashira
    Quote Originally Posted by Zero Serenity
    1) Userland is not a word.
    http://en.wikipedia.org/wiki/Userland

    http://en.wikipedia.org/wiki/Userland_%28computing%29
    :ashira:
    Hamur'd
    <3

  20. #160
    Puppetmaster
    Join Date
    Feb 2007
    Posts
    71
    BG Level
    2

    Re: Recent Hackings and Steps to Insure Account Safety.

    I may just be a poor linux guy, but isn't "ntldlr" a misspelling of the ntldr bootloader?
    Which has nothing to do with making system calls or any other sort of kernel mode stuff?

Page 8 of 16 FirstFirst ... 6 7 8 9 10 ... LastLast

Similar Threads

  1. Additions and Adjustments to Chocobo Raising (25/09/2006)
    By spooky in forum FFXI: Everything
    Replies: 64
    Last Post: 2006-09-27, 10:43
  2. Mijin Gakure damage and how to boost it
    By Benadar in forum FFXI: Everything
    Replies: 63
    Last Post: 2006-08-04, 22:52
  3. Hacking FFXI registry to up the back buffer
    By Russta in forum FFXI: Everything
    Replies: 28
    Last Post: 2006-03-24, 10:35
  4. I think the FFXI dev team gave up and left to play WoW
    By Razz in forum FFXI: Everything
    Replies: 10
    Last Post: 2005-04-24, 15:58