Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
People being hacked since the last Server Check.
Blades4hire Wrote:Most people seem to be getting bruteforced on their pw

It would be nice if some expert would put this myth of password brute-forcing at login to bed once and for all.
Even assuming a weakish 8-digit, lower-case only password, which would have 26^8 possible combinations,
and assuming Nexon's login server could somehow handle a million login attempts from one client per second without restrictions,
it would take up to 2.4 days to brute force. I'm not a hacker, so I don't know how many login attempts per second is possible, but I would imagine it is far below a million per second.
There is absolutely no way that this method could be practical given the rate at which hackings are occuring.

May I attempt a summary as I see it without starting a flame war? Well here goes anyway.
For an account to be hacked the hackers either:
1- Already knows the password, from sharing, social engineering, keylogging or other malware methods
This is what Nexon and a few vocal others claim is responsible for all account hackings, but is unlikely for many cases described in this thread.
2- Can discover the password from brute forcing (unlikely except for simplest pw) or reversing pw hash if these are stolen.
Nexon has admitted server leaks, so the reversed pw hash method is the possible hack method for some who have weakish pw AND rarely change them.
Having a strong pw and changing frequently will prevent this method of hacking.
3- Can reset the password, which requires prior access to the email
3a- Hacker resets pw/pin to his own email
This still happens occasionally, but is not the most common method recently, since pw usually unchanged.
4- Doesn't need the password - using some packet swap trickery to connect directly to an account without logging in normally.
Unfortunatly, there would be no way to avoid this method except to stay logging in 24/7, or possibly lock the account (no guarantee on that one).
Since Nexon is too secretive and proud to admit that such a thing might be possible, and too lazy and incompetent to fix it even if it were somehow proven to be happening, and too cheap and paranoid to hire expert consultants to find and fix it....
it will never be fixed.
Reply


Messages In This Thread
People being hacked since the last Server Check. - by MissingLink - 2011-12-30, 02:09 PM

Forum Jump:


Users browsing this thread: 2 Guest(s)