Results 1 to 12 of 12
  1. #1
    Cerberus
    Join Date
    Sep 2008
    Posts
    492
    BG Level
    4
    FFXI Server
    Valefor

    Password reset request made by someone in Korea

    Got an email a while ago stating that a request to reset my master password was made. The email was from NCSoft and they showed which IP address the password request was made from. So I looked up the location of the IP address using ip2location website and I get this:

    IP Address Country (Short) Country (Full) Flag Region City ISP Map
    218.237.2.142 KR KOREA, REPUBLIC OF KYONGGI-DO SEOUL WONKWANG UNIVERSITY BIZ CENTER
    Essentially, the request to have my password reset was made in Seoul, Korea from the Wonkwang University. Now how this person(s) got a hold of my user ID to take an attempt at my account is baffling. There has been no other place but the official Aion website that I've used my account information. This leads me to suspect that official site maybe have been somehow compromised. I am not trying to start something, but I would advise people from not entering their account info there.

    Also pleasantly puzzling is that they were able to get my user ID but not my password. I've changed my passwords, but I really don't know if my account is already compromised. I can log on fine for now...

  2. #2
    Ridill
    Join Date
    Feb 2007
    Posts
    15,537
    BG Level
    9

    Your account name wouldn't happen to be a common word or even Hagun, would it? I wouldn't put it past some to just randomly try such things by trolling boards for handles. I guess I'm also curious if the request process will error out if a specific name doesn't exist, because if it does it pretty much tells them they do have a valid handle to try and crack then.

    Otherwise, would suggest checking your system for viruses/trojans. Gonna assume you haven't given your info out to anyone or possibly play from other peoples' places. Have you ever replied to any of the RMT whispers? Makes me wonder how much they've hacked the game themselves to read data, and direct interaction may point them toward various things.

  3. #3
    Cerberus
    Join Date
    Sep 2008
    Posts
    492
    BG Level
    4
    FFXI Server
    Valefor

    My account name isn't hagun or remotely common so I dunno.

  4. #4
    Every day I'm wafflin'
    Join Date
    Feb 2007
    Posts
    2,453
    BG Level
    7
    FFXI Server
    Fenrir

    I'm sorry but the name "Wonkwang" is too fucking awesome for me not to point out then leave without saying anything constructive.

  5. #5
    Banned.

    Join Date
    Oct 2008
    Posts
    10
    BG Level
    1

    Quote Originally Posted by drwaffles View Post
    I'm sorry but the name "Wonkwang" is too fucking awesome for me not to point out then leave without saying anything constructive.
    beat me to it

  6. #6
    2600klub
    Sweaty Dick Punching Enthusiast

    Join Date
    Dec 2008
    Posts
    5,467
    BG Level
    8
    FFXI Server
    Bismarck

    Someone got a username/password database from somewhere and is causing havok across a lot of MMOs with account jacking, not just Aion.

    fwiw I think the curse network may be the source but who knows.

  7. #7
    Old Merits
    Join Date
    Oct 2006
    Posts
    1,136
    BG Level
    6
    FFXIV Character
    Veyron Snow
    FFXIV Server
    Excalibur

    Quote Originally Posted by Gryffes View Post
    I think the curse network may be the source but who knows.
    Seconded, I got a virus warning from AA with my good ol' AVG a while back, haven't gone back without noscript or adblock.

  8. #8
    Sta
    Sta is offline
    Cerberus
    Join Date
    Sep 2007
    Posts
    461
    BG Level
    4

    Quote Originally Posted by drwaffles View Post
    I'm sorry but the name "Wonkwang" is too fucking awesome for me not to point out then leave without saying anything constructive.
    And there I was feeling like I was the only childish person reading that

  9. #9
    Salvage Bans
    Join Date
    Jul 2008
    Posts
    994
    BG Level
    5
    FFXI Server
    Quetzalcoatl

    To request a password reset, assuming there is no exploit to bypass this, they need the username and email address used for your account. The password in the email is a 1 time use password, so if you were able to log in with that password, then they probably never got in to mess with your stuff. Somebody probably got a hold of your user/email address combination, which could be possible if you use the same username + email as your NC account on another site and perhaps they weren't able to get into your email account to retrieve the reset password.

    There are rumors that the nc master account system can randomly log you in as somebody else's account at a low probability, similar to how the main aion site can show you logged in under somebody else's account, and you would have full access to their account including the ability to change passwords to their game accounts. I don't know for sure if this is really happening, but there may be some credibility to this claim. http://na.aiononline.com/forums/supp...articleID=3179

  10. #10
    Sea Torques
    Join Date
    Feb 2006
    Posts
    621
    BG Level
    5
    FFXIV Character
    Vega Castro
    FFXIV Server
    Midgardsormr
    FFXI Server
    Ragnarok

    They need security tokens for this game asap

  11. #11
    E. Body
    Join Date
    Mar 2007
    Posts
    1,899
    BG Level
    6
    WoW Realm
    Arathor

    I wish I could say I study at Wonkwang University.

  12. #12
    New Spam Forum
    Join Date
    May 2009
    Posts
    156
    BG Level
    3
    FFXI Server
    Leviathan
    WoW Realm
    Gorgonnash

    Quote Originally Posted by Jodwahh View Post
    I wish I could say I study at Wonkwang University.
    Wonder what you could major in at Wonkwang University...

    Anyways, you get the same error message with a correct username + incorrect password as you do with an incorrect username + any password.

    RMT are usually quick and dirty when it comes to account stealing so you're prolly in the clear now, but meh, if it were me id be watching my shit real close for the next week or so if I were in your position.

    -insert all other obvious advise here-