Page 15 of 61 FirstFirst ... 5131415161725 ... LastLast
Results 281 to 300 of 1202
  1. Default


    Well, I guess the only way around this is to lock your account with an invalid password. You can then only relog when you request a password change and input a valid one.

    inb4 Nexon's announcement:


  2. Default


    I used to use his RMVX scripts. He/she is a genius and a very knowledgeable fellow & knows a lot about coding, and knowing Nexon... I wouldn't be the least surprised if it turned out to be true.

    ./run on sentence

  3. Default


    well, as of now, its the only explanation about what is happening, sw.net database leak, hacker probably trying every email he got to find if it is valid(since you can use your email address to log on your maple account), then he look at the sp/sw.net user accounts, and try it as login ID too.

    can be rumor, can be real, but its the best explanation about the case.

  4. Default


    Yanfly:
    So password hashes are that easily cracked nowadays? Or does he mean that Nexon is using some inferior encryption method.

    Also sounds like the PIC is totally useless. May as well set it to 111111 for efficient relogging.

  5. Euro Minicar Straight Male
    IGN: ZekkenAdele
    Server: Scania
    Level: 246
    Job: Adele
    Guild: DarkLily
    Alliance: Arcane
    Farm: HarvestxMoon
    usa

    Default


    so all u have to do is keep forum email and maple email diff

  6. Default


    Sheer dumb luck and a bit of paranoia is probably all that's keeping my account mostly safe at the moment.

    I don't touch the MTS, never log in through the site, and my email/log-in name is so old that it doesn't relate in any way to any character name I possess or any screen name I use on SP or Basil.

    And I have a PIC and password from hell but at this point I don't think either of those accomplish very much.

  7. DUCKS
    IGN: Mondays
    Server: Bellocan
    Level: 170
    Job: White Knight
    Guild: Affinity
    Alliance: Honour
    norway

    Default


    Blowfish/bcrypt with the correct adaptivity secures passwords damn good, so it would mean the latter.

    If they're using SHA or MD5, then they're messing around:
    Spoiler


    See that you have the possibility to use a checksum to check if the data is correctly downloaded? The reason those algorithms are there is because they're able to check whether a file give the correct checksum with those algorithms damn fast. Because of that, there's no problem to try out very many different passwords in a very short amount of time, and with enough computing power, you'll eventually get a hit.

  8. Orbital Bee Cannon
    IGN: SaptaZapta
    Server: Kradia
    Level: 275
    Job: Hero
    Guild: Matriarchy
    Alliance: Peaceful

    Default


    A link to the same article was posted on Nexon forums, and promptly deleted.

    When asked why it was deleted, -Hime- replied:
    http://forum.nexon.net/MapleStory/fo...d/8279200.aspx
    When locking another thread about the current hacking epidemic, she said:
    http://forum.nexon.net/MapleStory/fo...d.aspx#8248670
    Ah well. At least we know someone at Nexon is aware of this "already sensitive situation".
    Can anyone check whether they've changed the website login page not to give out the (hashed) password anymore?

  9. Default


    Please send a ticket to nexon that'll work!! (or not... going off of my still open ticket from well over a year ago now.)

    I would expect nothing less than total denial of anything on nexon's end. That's their game always has been and most likely always will be.

  10. Default


    At least they're acknowledging that this pomegranate is real.

    Too bad they won't ever come out and say that it's their fault for failing so much so many times and on so many levels.

  11. Default


    Inputting a wrong password yields the actual (encrypted) password? -___________- seriously?

  12. Default


    I can't seem to reproduce YanFly's supposed explanation. There's nothing there o.o

    lol

    What a load of bullcrap.

  13. Can you hear it?
    street's Avatar [Jr. Event Coordinator]

    IGN: Street
    Server: Windia
    Level: 15x
    Job: I/l mage
    Guild: Imperial
    Alliance: Royal
    Washington

    Default


    i doubt if you put the wrong password in. It will show the pw right in front of you.

    This goes back to what i was saying before about nexon changing their password section. Before under manage account it would show your actual password when you request to change it in plain text. Now it doesn't do it anymore since they changed it.

    @danny maybe he is using a special program that you dont have. This guy knows his stuff you know.

  14. Orbital Bee Cannon
    IGN: SaptaZapta
    Server: Kradia
    Level: 275
    Job: Hero
    Guild: Matriarchy
    Alliance: Peaceful

    Default


    They might have changed it already. They've been changing their web pages related to login, on the sly, for several days now (length of passwords and such)

  15. Default



    I actually asked if this was possible on the very first page. Nobody has replied yet, but it's interesting that somebody else posted it in the thread. I also found a third person on Basil who told me he has been using this method himself for several months.

  16. GLADIGATORS
    IGN: Overburnd
    Server: Khaini
    Level: 210
    Job: Cannoneer
    Guild: Contagious
    usa

    Default


    If it was deleted off Nexon forums, it was already tested, and it was already fixed probably within the hour they caught wind of it.

  17. Default


    Same for me... all you say applies for me but the difference is:
    I got hacked like 1 week ago....

  18. Default


    I stepped through all the JSON and Ajax and whatnot and saw nothing incriminating. It has it's own base 62 function to do comparisons with but that's just to hash the input for the server to compare.

  19. Water
    IGN: JerrysHero
    Server: Khaini
    Level: 200
    Job: Evan
    Guild: Imperious
    Alliance: TheAlmightys
    canada

    Default


    Post from basil on the same subject as the blog(http://www.basilmarket.com/forum/2196294/7)
    "myrdrex: That doesn't seem right- the response is a simply JSON message:
    "error":{"code":"1510","type":"Unauthorized","mess age":"INCORRECT_ID_OR_PASSWORD"}}

    Just set up a SSL proxy, decrypt it, and you'll see that. There's no embedded password at all on the response that comes back from a failed login.

    "PepsiMin; ^ This is correct. Also, -Hime- on the nexon forums stated that they do not store any passwords on their end (believe it or not).

    SO, THIS THREAD IS 100% INCORRECT. There's no proof (SS) of any encrypted passwords being sent back posted by the person who started this rumor, and until I see one, you should all regard this as a false scare.

    About the hackings going on for the past month or so, I honestly don't know what's causing it. There could be other security holes in the game that hackers are exploiting."

    This guy(Judging by my eyes and perhaps my disbelief in his theory) and what he said seems more reliable then the thread starter. I also could not re-create what the TS was talking about, so as far as I'm concerned. It's bullcrap unless he posts actual proof, instead of words.

  20. Default


    lol I remember back in the days when nexon did that hackers started logging in by changing the verification packet from a no to a yes so they could log in with the wrong password. It would be kinda odd that they could fix that but still send the password packet (encrypted) for verification.

    How hard is it to decrypt those passwords in the packet (if they exist)?

    In before new pw requirement is 64 digits long at least one number, at least one lowercase letter, at least one uppercase letter, at least one symbol, have no words found in a dictionary, and must be changed every 10 days.

    About the hackings: I have not been hacked yet to my knowledge on any of my 31+ accounts. Though with some of my mules maybe I wouldn't know because maybe they didn't take anything, though I would think they would take the mesos even though most of my accounts only have a mil or less mesos per character. My mules all have maple chairs, some have whips, but maybe those things just aren't valuable enough to mess with. My mains or stores certainly have not been hit (but that's much smaller, like 6 accounts - and much harder because they are logged in a lot).

  21.  

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •