Item Search
     
BG-Wiki Search
Page 38 of 47 FirstFirst ... 28 36 37 38 39 40 ... LastLast
Results 741 to 760 of 931
  1. #741
    Relic Weapons
    Join Date
    Sep 2007
    Posts
    341
    BG Level
    4

    Edit: Well, beaten to this post, but it's still relevant. And to respond to you ^^^ SE is not going to put out a memo about a security breech unless customer information was lost, it would create a complete panic and do absolutely no good. A server breech is an educated and logical conclusion to the facts presented by multiple sources in this thread.

    -----

    Okay, I’m going to try to clear a few things up for all the people here who just aren’t getting it. I’m going to call this computer security logic 101, or, to any questions that are repeating after this, read this post again 101. I’m happy to answer questions if this is unclear, but really, with a bit of reading comprehension it shouldn’t be.

    There are two types of exploits being talked about in this thread, here they are:

    1) You get DC’d while playing and accessed from another location. RMT then logs on, changes your password, takes your stuff, and rapes both of your parents. Now, IF you have a token and you’re still being accessed/hacked, chances are you have a Trojan on your system. If you do not have a token you can be logged out simply by someone cracking your POL password, which brings us to the second kind of exploit…

    2) Your POL password is being cracked ON SE’S SERVER. This means they are going after the source that stores the information, not your PC, not your PS2/3, not your Xbox. Your console is not getting hacked, your PC isn’t even being hacked in this case. It is their server. You know how you submit your POL password to log on? It hits a server that stores it to authenticate you. Why attack the computer/console when you can go straight for the server? That’s like robbing the armed guard that’s standing outside Fort Knox when the door is open.

    So, tl;dr version: If you’re getting hacked with a token you likely have a Trojan on your system and need to reform your security / browsing habits. If you’re getting hacked and you’re relying solely on a POL password you may:

    A) Have a Trojan
    B) Have a ‘friend’ with your information
    C) Have done NOTHING WRONG AND HAVE A TOTALLY SECURE SYSTEM BUT YOUR PASSWORD IS BEING CHANGED ON THE SE SERVER THROUGH A SERVER-SIDE EXPLOIT.

    Reason C) is why SE released the token to begin with. POL is old, a piece of crap, and single-stage authentication is low-hanging fruit to take. In my case C) happened, but because I had a token and a secure system, they were never able to log on to my account past that first stage of authentication.

    You don’t need to put a firewall or something on your PS2/3 / Xbox, you need to buy a token.

  2. #742
    That SpellCast Guy
    Join Date
    Feb 2006
    Posts
    802
    BG Level
    5

    Quote Originally Posted by Mistress Stowastiq View Post
    Regarding the underlined part:

    I did not see any official information confirming the SE servers being compromised. Just one post from some one who claims to have an inside friend at SE. Are you basing your info on that or official information?
    There hasn't been any official information, I'm just assuming that it happened, since people on PS2/360 are getting hacked as well as PC players. The only ways that could be possible:
    • The login info was entered on a PC at some time, either by the owner or someone they gave the information to. That PC was compromised.
    • They gave their account information out to someone else, and that person stole their account, not some random "RMT hacker".
    • SE's server was compromised.


    The first two are certainly likely, but if even one person is being honest about never giving out their info, and never playing on PC, #3 is the only possibility.

  3. #743
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,514
    BG Level
    6

    My question was not about logic or the most likely possibility. I was inquiring as to whether anyone has an actual fact or data clarifying that SE's servers were indeed compromised. This has nothing to do with me not trusting a professional opinion.
    Speculation is different than fact.
    Opinion is different than confirmed truth.
    The informed -opinion- of an IT security professional, while very useful is still not fact.

    People should understand the difference, is all I am trying to point out.

    People including me who prefer to distinguish between the two.
    Something as simple as stating that you believe they were hacked is different than saying they were, indicating that you have confirmed it with official representatives of SE.

    Edit, posted while you were updating your post Deimos. Thanks for clarification.

    Quote Originally Posted by Gunslinger View Post
    Edit: Well, beaten to this post, but it's still relevant. And to respond to you ^^^ SE is not going to put out a memo about a security breech unless customer information was lost, it would create a complete panic and do absolutely no good. A server breech is an educated and logical conclusion to the facts presented by multiple sources in this thread.
    @Gunslinger, I also was posting while you were posting. Similar to the reason you assumed that SE is not likely to post a memo, causing panic amidst the community, I am attempting to clarify the information that they have not done so.

    People believing that some one has officially confirmed a breach of information at SE is also capable of causing panic.

  4. #744
    Nikkei's Hoe
    Worse than her at uno

    Join Date
    Dec 2006
    Posts
    6,236
    BG Level
    8
    FFXIV Character
    Eanae Hikari
    FFXIV Server
    Gilgamesh
    FFXI Server
    Cerberus
    WoW Realm
    Hyjal

    A critical flash update was made avaliable two days ago that addressed an exploit that allowed hackers to remotely control PC's through the use of Flash. I'd assume this probably had something to do with some of the hackings.

    Adobe Flash Player 10 Security Release Update for Flash CS4 Professional

    07/30/2009 This download contains fixes for critical vulnerabilities identified in Security Bulletin APSB09-10 Flash Player update available to address security vulnerabilities. The update replaces the Debug and Release versions of Flash Player 10 browser plugins and standalone players that are included in the initial release of Flash CS4 Professional (player version 10.0.2.54). All users should apply this update. These new players are version 10.0.32.18.
    The Flash Player 10 updates are included in the ZIP file below. For instructions on how to update Flash CS4 Professional, please go to this technote.

  5. #745
    Relic Shield
    Join Date
    Oct 2006
    Posts
    1,599
    BG Level
    6
    FFXI Server
    Odin

    isnt 7/30 a month ago?

  6. #746
    Nikkei's Hoe
    Worse than her at uno

    Join Date
    Dec 2006
    Posts
    6,236
    BG Level
    8
    FFXIV Character
    Eanae Hikari
    FFXIV Server
    Gilgamesh
    FFXI Server
    Cerberus
    WoW Realm
    Hyjal

    Hm, appears I am a month behind lol.

  7. #747
    Relic Weapons
    Join Date
    Sep 2007
    Posts
    341
    BG Level
    4

    @Mistress Stowastiq

    No worries, I wasn't attacking you or anything, I just wanted to point out that's pretty much the only thing it could have been whether they admit it or not.

    The only confirmation that I had was that "something big happened" to a lot of people from a SE rep, and another person here said they were told a server was attacked.

    I 'believe' it happened because it's what everything points to, just like I 'believe' in evolution. I haven't witnessed either firsthand, from the inside out, but with enough evidence I reached a conclusion. Like I've said before, I'd be happy to be wrong so I know what to look for, but the burden of any other proof is on people who know more than I do. Frankly, it just seems like you're arguing semantics regarding whether this is official or not.

    If that's what you want- it's not official, it's my opinion, but it's extremely likely that's what happened and SE will probably never say anything about it.

    And for the record, I know this probably sounds a little hostile, but it's frustrating because I've been posting from the beginning that I doubted it was on my machine, that there was something else going on, only to have people all swear there has to be a keylogger or something completely illogical to the problem.

    I don't know how many times I can post "it's a problem with the servers" and have people ask "how do I secure my PS2"


    Edit: Here's a more recent flash flaw... flash is like the swiss cheese of security, that's why it's always good to run no-script and flash block

    http://www.totallymoney.com/news/ind...security-hole/

  8. #748
    That SpellCast Guy
    Join Date
    Feb 2006
    Posts
    802
    BG Level
    5

    It may not have even been a full server compromise anyway, to the level of "we've stolen full login info for all these people". It could have been something on a much smaller scale, such as SE doing their "failed login flood" protection through POL software instead of on the server.

    What I mean is, POL contains a security measure that locks your account for a short time (20 mins, I believe), if you fail your login attempts three times in a row. This is a preventative measure to stop people from brute-forcing passwords. However, if they implemented this protection in the POL client (so the client informs the server when you've failed too many times), instead of on the server side, someone could potentially write their own program to send login attempts directly to the server and see if they succeed. This could have allowed them to perform dictionary attacks on various accounts.

    Is this what actually happened? Again, we have absolutely no official info, so it's impossible to know. It's just another possibility of a way that your account could end up hacked without any system-compromise on your side.

  9. #749
    Relic Weapons
    Join Date
    Sep 2007
    Posts
    341
    BG Level
    4

    I think that is very likely. And anyway, what I like to point out is that if there was a server-wide compromise of a major system why would you take the character data? If you had server-wide access you should just take the credit card data and change your business model (I assume the billing servers are separate for PCI compliance, but a server-wide compromise and admin rights would probably get you pretty far if it was a huge hack).

    I think this was a pretty small breech, it probably could have been avoided, and hopefully it has been fixed. I can deal with Trojans and my system, lax security on their end is what drives me crazy.

  10. #750
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,514
    BG Level
    6

    Quote Originally Posted by Gunslinger View Post
    @Mistress Stowastiq

    No worries, I wasn't attacking you or anything, I just wanted to point out that's pretty much the only thing it could have been whether they admit it or not.

    The only confirmation that I had was that "something big happened" to a lot of people from a SE rep, and another person here said they were told a server was attacked.

    I 'believe' it happened because it's what everything points to, just like I 'believe' in evolution. I haven't witnessed either firsthand, from the inside out, but with enough evidence I reached a conclusion. Like I've said before, I'd be happy to be wrong so I know what to look for, but the burden of any other proof is on people who know more than I do. Frankly, it just seems like you're arguing semantics regarding whether this is official or not.

    If that's what you want- it's not official, it's my opinion, but it's extremely likely that's what happened and SE will probably never say anything about it.

    And for the record, I know this probably sounds a little hostile, but it's frustrating because I've been posting from the beginning that I doubted it was on my machine, that there was something else going on, only to have people all swear there has to be a keylogger or something completely illogical to the problem.

    I don't know how many times I can post "it's a problem with the servers" and have people ask "how do I secure my PS2"
    I also was not attacking you or trying to discredit your information. I consulted another professional regarding this info and have been having him read the thread from the beginning, he also said that he would not rule out the possibility of SE/POL being compromised but would not confirm anything as fact without having proof himself.

    It is not about semantics for me.

    Knowing that my info is at a company whos security has been compromised is completely different than knowing it is a possibility based on several occurrences. They both have different consequences to me.

    I think we both have the same goals, we want to help inform the community and be informed ourselves. Your frustration with having to repeat posts is also similar. I want a central spot for everyone to look at so that people like you who have information for us can be assured that their advice is being put to use and not ignored.

  11. #751
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    Quote Originally Posted by Gunslinger View Post
    If you had server-wide access you should just take the credit card data and change your business model
    Stealing FFXI accounts and selling them is not illegal. Stealing credit cards and using them is.

  12. #752
    THAT MACHINE IS NOT A SIR, YOU HAVE TO CALL IT "MR. MACHINE"
    Join Date
    Jul 2006
    Posts
    1,204
    BG Level
    6
    FFXI Server
    Caitsith

    Quote Originally Posted by Izzy View Post
    Stealing FFXI accounts and selling them is not illegal. Stealing credit cards and using them is.
    Bingo, if I had to steal something to make money it would definitely be something I wouldn't get prosecuted and thrown in pound me in the ass prison for.

  13. #753
    Relic Weapons
    Join Date
    Sep 2007
    Posts
    341
    BG Level
    4

    You think Chinese people (or all people for that matter) don't steal credit card numbers online because it's illegal? Since when is stealing a FFXI account by breaking into a server and changing data not illegal? It's rarely prosecuted because of the difficultly of the prosecution, not because it's okay to do. Remember we're not talking about a single account, we're talking about multiple customer records being accessed and changed. It's also not about the 'taking' of virtual property, it's about the intrusion and altering of someone else's property. Does anyone else remember Taj meeting the ass-end of lawyers? Or is my memory that fuzzy in my old age?

    Hacking their servers is illegal, whether you're after the CC numbers or not. Once you have 'caused damage' you have committed a crime. I'm not going to argue one intent has 'less malice' than another, but they have the same ultimate goal, to make money. Just because one is easy to explain to a jury doesn't make it any less illegal.

    Yes, credit cards are easier to prosecute and you can hand it over to the FBI (if you're in the US), but that doesn't mean you can't prosecute for other actions. The fact is many of these crimes go unpunished: credit cards, social security numbers, or FFXI characters, whatever.

    So if you're in china and you had the ability to compromise SE's entire server system (which they obviously don't), you might as well just go for credit card numbers.

    My point, however roundabout, is that SE security obviously isn't so bad that we're losing PII (personally identifiable information). This was likely a very small hack or injection that they shutdown quickly. If they had access to everything and SE was totally off the ball, they might as well go for the credit card numbers, because if you're that good you're not likely to get caught anytime soon.

    Anyway, back to more hackings or w/e, I won't argue anymore

  14. #754
    Sea Torques
    Join Date
    Jul 2007
    Posts
    543
    BG Level
    5
    FFXI Server
    Bismarck

    Quote Originally Posted by Izzy View Post
    Stealing FFXI accounts and selling them is not illegal. Stealing credit cards and using them is.
    I think there are at least 3 felonies involved:

    1) obtaining access to someone else's computer and software (federal law passed by congress dealing with unauthorised access to someone else's computer property)
    2) taking someone else's property (SE's account is their's and taking control of it without authoirity is therefore theft)
    3) selling it to someone while pretending to be the rightful owners (fraud)

    So: trespass, theft and fraud.

  15. #755
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    Quote Originally Posted by Vodou View Post
    I think there are at least 3 felonies involved:

    1) obtaining access to someone else's computer and software (federal law passed by congress dealing with unauthorised access to someone else's computer property)
    2) taking someone else's property (SE's account is their's and taking control of it without authoirity is therefore theft)
    3) selling it to someone while pretending to be the rightful owners (fraud)

    So: trespass, theft and fraud.
    All 3 are not enforceable in China. Stealing someone's money is going to raise a bit more attention don't you think?

    Does anyone else remember Taj meeting the ass-end of lawyers? Or is my memory that fuzzy in my old age?
    Taj is also a US resident.

  16. #756
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,514
    BG Level
    6

    Quote Originally Posted by Gunslinger View Post
    You think Chinese people (or all people for that matter) don't steal credit card numbers online because it's illegal? Since when is stealing a FFXI account by breaking into a server and changing data not illegal? It's rarely prosecuted because of the difficultly of the prosecution, not because it's okay to do. Remember we're not talking about a single account, we're talking about multiple customer records being accessed and changed. It's also not about the 'taking' of virtual property, it's about the intrusion and altering of someone else's property. Does anyone else remember Taj meeting the ass-end of lawyers? Or is my memory that fuzzy in my old age?

    Hacking their servers is illegal, whether you're after the CC numbers or not. Once you have 'caused damage' you have committed a crime. I'm not going to argue one intent has 'less malice' than another, but they have the same ultimate goal, to make money. Just because one is easy to explain to a jury doesn't make it any less illegal.

    Yes, credit cards are easier to prosecute and you can hand it over to the FBI (if you're in the US), but that doesn't mean you can't prosecute for other actions. The fact is many of these crimes go unpunished: credit cards, social security numbers, or FFXI characters, whatever.

    So if you're in china and you had the ability to compromise SE's entire server system (which they obviously don't), you might as well just go for credit card numbers.

    My point, however roundabout, is that SE security obviously isn't so bad that we're losing PII (personally identifiable information). This was likely a very small hack or injection that they shutdown quickly. If they had access to everything and SE was totally off the ball, they might as well go for the credit card numbers, because if you're that good you're not likely to get caught anytime soon.

    Anyway, back to more hackings or w/e, I won't argue anymore
    ^
    Agreed.
    Pretty clear because it is almost accepted as routine. People often think that SE's lack of a effort to prosecute people for selling their property, some how makes it legal to do so.

  17. #757
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    Quote Originally Posted by Mistress Stowastiq View Post
    ^
    Agreed.
    Pretty clear because it is almost accepted as routine. People often think that SE's lack of a effort to prosecute people for selling their property, some how makes it legal to do so.
    What about Blizzard/Gravity/any other MMO company that has failed/is unable to prosecute anyone for RMT? It's not due to SE's terrible infrastructure (make no mistake, it is terrible). Do you think China is going to deport/enforce US laws in their country?

  18. #758
    A. Body
    Join Date
    Jan 2006
    Posts
    4,008
    BG Level
    7
    WoW Realm
    Area 52

    Never heard of people getting hacked while on a Blizzard authenticator, maybe SE just made their shit ghetto? I find it highly amusing though that the gilsellers are making this big push at the end of FFXI's life with 14 looming sometime next year.

  19. #759
    Relic Weapons
    Join Date
    Sep 2007
    Posts
    341
    BG Level
    4

    That's my point Izzy, Visa/Mastercard are both US companies too, what gives them any more protection than SE in China?

    Also remember that from a legal standpoint you're not stealing money when you take a credit card number, you're stealing data. You only steal money when you tender a transaction with that card number. Up until that point the crime is the same for stealing an account or a credit card number, and after that point it can be harder to track due to the real life trail getting fuzzy. Often times card numbers are sold, so the people using them aren't even the people who obtained them. Throw in international law and it's not worth anyones time for small potatoes.

    MMO companies don't prosecute RMT for the same reason credit card companies don't prosecute a ton of stolen card numbers (even in the US!)- the cost of prosecution outweighs the benefit. That doesn't make either legal. They steal accounts because it's easier, not because they wouldn't steal credit card numbers if given the chance. It's like when they asked Dillinger why he robs banks, "because that's where the money is."

    This is why we can't have nice things

  20. #760
    THAT MACHINE IS NOT A SIR, YOU HAVE TO CALL IT "MR. MACHINE"
    Join Date
    Jul 2006
    Posts
    1,204
    BG Level
    6
    FFXI Server
    Caitsith

    Wait

    what if

    http://i31.tinypic.com/ix9k5k.gifSE IS HACKING THEIR OWN ACCOUNTS TO CLEAR OUT FF11 FOR THE COMING OF FF14http://i31.tinypic.com/ix9k5k.gif

Page 38 of 47 FirstFirst ... 28 36 37 38 39 40 ... LastLast

Similar Threads

  1. What in the fuck is going on with Ancient Currency prices?
    By Avarice in forum FFXI: Everything
    Replies: 22
    Last Post: 2009-01-12, 05:21
  2. Ok what the hell is up with Roc?
    By S N K in forum FFXI: Everything
    Replies: 49
    Last Post: 2008-06-28, 21:00
  3. Oldschool players with JP Accounts & The new Expansion
    By Lyramion in forum FFXI: Everything
    Replies: 39
    Last Post: 2007-11-24, 01:31