Yeah that clears things up a bit. I thought people were saying they just got disconnected and were hacked at that point, which seems improbable and impossible. Hanyo's explanation makes sense if that is what is going on.
Yeah that clears things up a bit. I thought people were saying they just got disconnected and were hacked at that point, which seems improbable and impossible. Hanyo's explanation makes sense if that is what is going on.
30 pages and still "lolIE" in the title? I'm curious how many Firefox/PS2 readers feel *safe* reading this thread.
PS2 readers should feel pretty safe about this, I think. Much like Macs, they are virus proof by virtue of their incompatibility.
PS2 has no browser, can't browse the internet and get a keylogger. Even if they could get a virus the RMT would have to write it for the PS2, which is probably too much of a pain in the ass to bother with.
I skipped the last 25 pages of this thread, but based on the exchange that took place on the top of this page I don't think I've missed much. Prz to has excuse if some PS2 onry users who don't share info have gotten hacked.
SE's servers have allegedly been compromised, several PS2 or Xbox only players claim to have gotten hacked. As someone else said, there is the spyware going around stealing codes via crash->intercept on relog, but there is also an unexplained method that can be best explained by RMT getting info straight from SE somehow.
Anytime i crash now or attempt to login at the start, I always login firstly with:
Password: wocaonima (aka fuck you)
Onetime: 000000
If i get the PW incorrect screen, i log in normally.
Otherwise I'll know i'm infected and have sent a message to said RMT.
Yes, the other method they are using is session hijacking whereby they exploit the very network code and trick the servers into thinking that they are you and you are not you. This is the one where you DC and your characters just gets a red dot for a little bit; but then recovers and runs off to sell your stuff.
At least that is the best working theory on how that case could occur; which is supported by the 'unofficial statements' that the SE server got hacked.
You've been watching too many Apple commercials...
To be clear, Macs may be incompatible with PC viruses (assuming they're not bootcamping), but they are definitely compatible with viruses designed for them. Or, if you're playing FFXI on Windows on a Mac, you're just as vulnerable as someone running Windows.
Macs get viruses too. And people who play PS2 exclusively have been hacked (though not 'infected'), don't forget that.
As for the session hijacking thing during play (and not kicking the player), this is the first I've heard of it? Where are there examples of this actually happening?
MAC is not inherently more secure then a PC. Sure there are less malware developed for a MAC, but one can equally say there is less malware detection software for a MAC. So one could conclude that the malware for MAC is potentially worse cause it could reside and do its agenda for a longer duration.
@ gunslinger post #13 in this thread
There were other notes of similar happening in this thread and I want to say a mention of it in one of the alla threads.
I dual boot on a powerbook, I have had zero issues on my mac side and I do all my sensitive activities on my mac side. I have to constantly keep things up to date and scan for shit on my PC side. I have own both for quite a few years now, PCs have caused far more migraines. But in the end there are still things you can't do on a MAC al be it far less than it used to be.
I can add to this myself now, my main account which I use on a PC was not hacked, my dual account I use on my ps2 was hacked. Token on my main account on the PC, no token on my dual account on the ps2.
Windows has a 93.06% share of the market.
Mac has a 4.87% share of the market.
If you were trying to steal stuff and write a virus to infect as many people as possible, which one would you write for? Windows is attacked because it has been exponentially more successful, that is all. But yes, your Mac is probably more secure because of this fact, but as you've said... can't play FFXI on a Mac
As for the session thing, that is really, really bizarre. Maybe they're just logging in really fast (skipping POL) from another location?
Even if they skip POL, if you try to log in before the char d/cs it'll say 'Another character is logged on blahblahblah' and not let you on until it fully d/cs. I've done this to myself using 2 computers before, I used to have bad crashing problems because of old spellcast so I'd immediately log on my alternate computer and often have to wait for myself to finish d/cing to get online.
Well if they really were in control of some of the servers; they could in theory cut off a client and forge their client to "claim to be them". Kinda like your IP lease changes and you get a R0 for a moment. Though I only know of the basics of these sorts of thing; I'm not too fond of felonies.
Either way, its not like we will get any usefull data from SE to confirm/deny any of this. Its just that they are doing old as well as new tricks. And some of these new tricks appear to either a) clean themselves off the PC after completion or b) were never on the PC to begin with.
i really hope they fix this issue..
I don't play FF but forums are anice break now and then and my post was halted since I type links *sigh* But I'll make it brief since I hate retyping crap. I asked a friend who plays Fallen Earth with me (he used to play FF) about it and he said the tokens are based on the Vasco Digipass6 Go design. While its nearly impossible to *copy* a user's token, you can clone he said.
The difference with copy vs cloning is important because a copy can in theory replace a user's token but due how the technology works, its not feasible he said (said why but ty deleted prior post attempt so not going into it). A clone however works short-time within the duration of a 32 second interval. The problem with cloning however is that there are several criteria that have to be in place for it to work properly.
The end result is what he called a "man-in-the-middle" scheme where a user's token unique ID have been copied to another token causing the new user to be able to use his tokens algorithm properly. As to why it works short time, as he explained (and best I can sum up) its only a clone, so the original copy would force the clone to eventually fail and d/c when it transmits its data. He said this failure was first noted in 2005 at John Hopkins University and became more well known in 2006 where security tokens similar to the digipass in design and programming were used to access bank accounts in Russia.
If its any consolation he did say cloning a security token isn't easy nor 100% doable given the required criteria that need to be in place with one of them being a measure that keeps the original user blocked in some way from inputting their security token. He did ask me to do something that if your on PC and have 2 PC's can do. If you put your player info on both PC's and log on properly, you can force them to d/c by accessing the same account on another pc with the wrong token password. A reason he said the user needs to be blocked from accessing whatever program/software uses the token (which explains why some systems need to be blocked). Info on the security token is at vasco.com/Images/e-Gaming%20and%20B-2-C_072008_version1.pdf
Seriously not a troll, just a low post count. I hadn't logged in for about a month. Password was different when I tried logging in again to cancel my account (didn't want to play anymore). Reset it through tech support, and my characters were stripped and had undergone individual server transfers. Also, the hacjer bought another content ID for a fdsnmgi mule. PC user, noscript, ad block plus, avast, avg, spyway search and destroy, no token. I don't get how a keylogger would get my password if I hadn't logged on for so long. Hell, I don't even get how a keylogger would've made it past all my shit to begin with.
On a side note, it looked like my character had been sold as I had a brand new minstrel's coat for my bard which was near the Nussnacker spawn point in Quicksand Caves.
Just a heads up...
I was browsing ffxiwiki and my firefox NoScript picked up an XSS (Cross-site scripting) attempt. It was successfully blocked thanks to NoScript.
I just find it odd that a ffxi community website is not safe... Just a thought... but maybe the linkshell community site is compromised as well and account information we enter into it is being extracted from it so RMT's can access your account and steal it...
Generally it's the ads that aren't safe, not the site itself. Internet advertising is in a disgustingly poor state at the moment, sites get their ads through ad agencies, which get their ads through other agencies, and etc. At some point, someone shoves in a malicious ad with a javascript or flash exploit embedded, and since everyone up the chain doesn't bother to do any sort of validation on the ads, it gets served out to people visiting the site. For example, see the recent publicized controversy about this happening on the New York Times's site: Anatomy of a Malware Ad on NYTimes.com
It's best to use AdBlock Plus and NoScript as much as possible. Sorry, sites that I visit, I'd like to support you by viewing your advertising, but I just can't trust it.
go buy yourselves some god damn anti-virus programs. Kaspersky works great. tough shit dude