Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
People being hacked since the last Server Check.
#96
I read through Nexon's "venting" thread and at least two people reported that Nexon removed the feature that locks you out of your account after too many failed password attempts, allowing hackers to potentially brute-force people's passwords.

After running some experiments on a secondary account, I've found this to have mostly truth but some falseness...
While I never experienced it personally, I understand that, at some point (or by some method), trying too many passwords for an account would lock the account until it was "verified" through an email.
This no longer seems to be the case.

After too many password attempts (five), you are indeed unable to attempt to login to any account for a certain duration of time.
Seems this block is done based on IP as deleting cookies or hopping to another browser doesn't allow for it to be bypassed.
However the duration of this lock is rather short. I roughly estimate about a minute.
So it does seem that brute-forcing is a very real possibility.

It is possible that the old lock-out is still around as I conducted these tests through the website, but I'd imagine the Gamelauncher is a poor platform through which to brute-force.
Notably, there is the fact that it's impossible to attempt to use Gamelauncher to login to an account which is already logged in while the web portal doesn't feature the same inability.
Reply


Messages In This Thread
People being hacked since the last Server Check. - by Viaje - 2011-09-05, 04:07 PM

Forum Jump:


Users browsing this thread: 2 Guest(s)