|
Silkroad Online
|
Silkroad Forums
|
Affiliates
|



|
|
View unanswered posts | View active topics
|
Page 1 of 1
|
[ 15 posts ] |
|
Author |
Message |
The Invisible
|
Post subject: Joymax Major Security Issue Database Leak Still On Going iss Posted: Tue Feb 21, 2012 8:57 am |
|
Addicted Member |
 |
 |
Joined: Jan 2011 Posts: 2626 Location: Home ._.
|
Kyle wrote: If you have a stall in Hotan selling item, global chat, reverse scroll... You might be the next on their list. Stall in Hotan on the following servers got hacked in the past few weeks. Azteca, Eos, Mena, Mercury, Oasis, Olympus, 2xTibet, Venus, Xian
Do not WAIT any longer, CHANGE YOUR PASSWORD IMMEDIATELY!
Over the past few months, many user have started thread related to database leaks. I use accounts on each server to record stats on rev6, those account are level 1, naked, useless account... 10 of the 48 accounts I have got hacked in the past few week, which 6 of them got hacked this week ALONE!
If you have a stall in hotan in those town: Mercury, Oasis, Olympus, 2xTibet, Venus, Xian Odds are the hacker emptied your account, or logged your account and will hack your account RIGHT before or after this inspection. Change your password now if you are in those server. Keep reading for more information.
I have personally forwarded the information to Joymax. Though, I believe again, that I am being ignored. Time to make this subject public.
Is there a Database Leak: Yes Can you prove it: Yes
In the past 3 months, due to multiple complaints from users, we at rev6 started a new program to have a dedicated player login on every ISRO server on Silkroad Online. Thus for the past 3 months, there hasn't be any or rarely any unique kill that was missed, and the new Global Chat section rarely miss recording any global chat.
How did we manage to do such a thing? We have 48 accounts which login to Silkroad after each Server inspection and stay online 24/7 recording all the statistic. In the past 3 weeks, there was a total of 10/48 accounts which we use that have been hacked.
First I will go in detail about what account I used. Due to my laziness, I didn't felt like creating 48 accounts. We released publicly in the past a list of 40,000 Silkroad account created in 2006 using the password 123456. Those are super old unused account created by random player all around the world.
So we took the courtesy to use those account, created a new player for each server in early January 2012. Everything was running smoothly up until the beginning of February. In the past 3 weeks, there was 4 accounts which got a password change from 123456 to something else. Weird... Maybe the account wasn't inactive, thus I though.
This week alone, past 4 days, there are 6 accounts that got a password change. Now that wasn't just weird, but suspicious. Those account contain a level 1 player to record stats for rev6, they are useless account but are setup near the Global chat/reverse scroll Silk seller stall in Hotan (figured recently that the account got hacked because the hacker is attacking every stall in Hotan now)
I started analyzing all the account that got their password change and realized something. The 10 accounts that got a password change do not have any e-mail confirmed but still use the secret answer method. The accounts where created in 2006 and have no silk on them and most of them have no players or a player lv1-30 range and the account was abandoned.
How can someone be able to change the password of 6 accounts in 1 week? or 10 accounts in 3 weeks?
There is 2 theories: #1 - The player who created the account in 2006 realized that someone logged on he's account and he used he's secret answer to change the password. #2 - There a database leak (SQL Injection most likely live still happening now as you read this).
Please note, the account was created in 2006. There is no player on those account higher than level 30. The account has been dead for 5 years Nobody should know the secret answer on those account, even those that created the account must of forgotten the secret answer by then. Nobody should be able to know the account name just by looking at a level 1 player in hotan.
Now the question is Why would someone hack a level 1 player standing still in Hotan inside the following servers: Azteca, Eos, Mena, Mercury, Oasis, Olympus, 2xTibet, Venus, Xian
Those server are at HIGH risk of player being hacked. Thus the question, why would a level 1 standing in a crowd of stall selling global chat and reverse scroll get hacked? The hacker has targeted high level on lots of servers and is now targeting Silk seller and stall in Hotan. Odds are if you have a stall char, you have lots of gold/silk.
So basically by looking at a level 1 stall with a random name. The hacker is able to obtain the following information:
Account Name MD5(Password) Hash E-mail address Secret Answer
In my case, he changed the password as my accounts where logged 24/7 and auto re-log in the server on disconnect. But he was able to get the account name and secret answer, the only thing that truly confirm that it a database leak. Is that the hacker was able to get the Secret answer.
Thus if your account isn't email protected. The hacker can just use your secret answer and change your password. Then he can hack your account and empty it or create an email and steal your account forever.
If your account is e-mail protected, your only line of defense stand in your Password MD5 HASH When you send a password to joymax, they apply the famous MD5 algorithm without any SALT to protect your password. If Joymax would of used a SALT to secure your password, your account would of been safe from a database exploit.
The only way you can protect your account at this point is by the following: Change your password into a 10-16 characters password using lower case, upper case, numbers and symbol inside your password. If you want to be truly secure, use one of the following symbol in your password: ,./;'[]\<>?:"{}| There exist a lot of database and website dedicated to reverse MD5 password that do not use SALT. Most database reverse password using symbol such as: !@#$%^&*()-=_+
At this point of time, blocking the best player stats or any type of Rev6 stats page would be meaningless. If anyone know anything about how or where the exploit is executed, please come forward.
We forward the issue 24h ago to Joymax, we believe that they will maybe fix the issue. But we fear that when they do find and fix the issue, they won't let anyone know about it. Thus, until Joymax claim that the issue is fixed, your Silkroad Account on Silkroad or Silkroad-R security is compromised.
It is your choice to trust or not what I'm saying. Due to the increase of player complaints I have released a prevention method on if a database leak existed. Now this exploit confirm that the database leak DOES exist.
Hacker was able to obtain the secret answer of 6 accounts within 5 days and change their password. For those that believe Joymax will do a rollback, there has been worst exploit made public that Joymax refused to acknowledge that existed and refused to do any rollback.
If you have any information related to people that have talked related to this exploit. Please come forward as soon as possible. I am currently doing an investigation to figure out where the exploit is coming from. I suspect a SQL injection Read-Only on a Joymax page.
Thus any help related this matter would be GREATLY appreciated. This exploits has existed for too long, iSro server are taking huge damage due to that exploit. I believe iSro server will die and SroR will be targeted next.
Please ASK EVERYONE TO SECURE AND CHANGE THEIR ACCOUNT Password! THIS IS A TOP PRIORITY
_________________ So in the first week in college i went with jeans and the pajama's shirt. Didn't notice what i was wearing till after i returned home.
|
|
Top |
|
 |
omier
|
Post subject: Re: Joymax Major Security Issue Database Leak Still On Going iss Posted: Tue Feb 21, 2012 2:04 pm |
|
Elite Member |
 |
 |
Joined: Aug 2006 Posts: 5985 Location: ...
|
Saw some info on Rev6 a while back. Changed my PWs right away. So it only gets stallers? Good thing i use consignment.
_________________
|
|
Top |
|
 |
Kutt
|
Post subject: Re: Joymax Major Security Issue Database Leak Still On Going iss Posted: Tue Feb 21, 2012 3:32 pm |
|
Casual Member |
 |
 |
Joined: Jan 2011 Posts: 57 Location:
|
123456 isn't particularly secure....
|
|
Top |
|
 |
heroo
|
Post subject: Re: Joymax Major Security Issue Database Leak Still On Going iss Posted: Tue Feb 21, 2012 3:47 pm |
|
Forum Legend |
 |
 |
Joined: Sep 2006 Posts: 6618 Location:
|
Kutt wrote: 123456 isn't particularly secure.... 123456 was my SRF password for 4 years lol.
_________________
''When I die, make sure they bury me upside down, so that the world can kiss my ass.''
|
|
Top |
|
 |
ltsune
|
Post subject: Re: Joymax Major Security Issue Database Leak Still On Going iss Posted: Tue Feb 21, 2012 4:53 pm |
|
Elite Member |
 |
 |
Joined: Mar 2008 Posts: 5751 Location:
|
Don't know what to think. I mean, true, this does sound really odd. Well, I guess it's a good thing I don't play on isro anymore 
_________________ Dubious ・ Lvl 101 ・ STR Archer ・ jSRO-R ・ active PillowFight ・ Lvl 69 ・ STR Archer ・ jSRO-R ・ inactive Aggrobatic ・ Lvl 101 ・ Warrior / Cleric ・ jSRO-R ・ inactive
Check out our music-video! http://www.youtube.com/watch?v=iMxZWMWRjSM I'm on the drums, beaches!
|
|
Top |
|
 |
NuclearSilo
|
Post subject: Re: Joymax Major Security Issue Database Leak Still On Going iss Posted: Tue Feb 21, 2012 7:40 pm |
|
Forum God |
 |
 |
Joined: Aug 2006 Posts: 8834 Location: Age of Wushu
|
Quote: Nobody should know the secret answer on those account, even those that created the account must of forgotten the secret answer by then. I didn't forget mine. If someone created an account, it's his property.
_________________ Playing Age of Wushu, dota IMBA
|
|
Top |
|
 |
*BlackFox
|
Post subject: Re: Joymax Major Security Issue Database Leak Still On Going iss Posted: Tue Feb 21, 2012 8:05 pm |
|
Forum Legend |
 |
 |
Joined: Sep 2008 Posts: 7923 Location:
|
Scumbag Hackers !
_________________
|
|
Top |
|
 |
penfold1992
|
Post subject: Re: Joymax Major Security Issue Database Leak Still On Going iss Posted: Wed Feb 22, 2012 9:32 am |
|
Senior Member |
 |
 |
Joined: Apr 2007 Posts: 4060 Location:
|
heroo wrote: Kutt wrote: 123456 isn't particularly secure.... 123456 was my SRF password for 4 years lol. my pass for sro was qwertyu for a long long time... never got hacked...
_________________
|
|
Top |
|
 |
omier
|
Post subject: Re: Joymax Major Security Issue Database Leak Still On Going iss Posted: Wed Feb 22, 2012 2:07 pm |
|
Elite Member |
 |
 |
Joined: Aug 2006 Posts: 5985 Location: ...
|
NuclearSilo wrote: Quote: Nobody should know the secret answer on those account, even those that created the account must of forgotten the secret answer by then. I didn't forget mine. If someone created an account, it's his property. It is JoyMax's property actually.
_________________
|
|
Top |
|
 |
BuDo
|
Post subject: Re: Joymax Major Security Issue Database Leak Still On Going iss Posted: Wed Feb 22, 2012 3:41 pm |
|
Senior Member |
 |
 |
Joined: Dec 2008 Posts: 4714 Location:
|
Sanktum wrote: NuclearSilo wrote: Quote: Nobody should know the secret answer on those account, even those that created the account must of forgotten the secret answer by then. I didn't forget mine. If someone created an account, it's his property. It is JoyMax's property actually. +1
If joymax's weak security cause my account to get stolen then that is it for me. I'll be quitting for good. Not that they care anyways about who gets hacked. It simply means for them you can start over which works out for their financial benefit. I wont give them that satisfaction.
I might even wager they will intentionally not care for that exact same reason (unless it gets out of hand with every account). They've been claiming for years that they're doing their best to prevent botting. Whats to stop them from claiming the same bullshit when it comes to improving their security? Anything is possible with joymax.
_________________
_________________________________________________ BOW Full STR Fire level 102 -- ON A LONG BREAK..POSSIBLY FOREVER
|
|
Top |
|
 |
Majorharper
|
Post subject: Re: Joymax Major Security Issue Database Leak Still On Going iss Posted: Thu Feb 23, 2012 3:00 am |
|
Site Contributor |
 |
 |
Joined: Apr 2007 Posts: 2079 Location: Looking for my signature....
|
I have been sro-free for a few months now no remorse, iSro I havent touched in over 1 year! woop! (BF3 took sro's place) 
_________________
|
|
Top |
|
 |
BuDo
|
Post subject: Re: Joymax Major Security Issue Database Leak Still On Going iss Posted: Thu Feb 23, 2012 7:24 am |
|
Senior Member |
 |
 |
Joined: Dec 2008 Posts: 4714 Location:
|
I haven't played in about a month. I think I'm due for another long break from SRO......maybe even not returning at all this time....I was so bored I wasted 20 days worth of premium ticket...The appeal is dwindling again........
I need to find a game where less emphasis is placed on grinding and more on just enjoying the game....I find that type of enjoyment when playing first person shooters because you immediately start to have fun without waiting to reach higher levels...If only I could find an MMORPG like that..
_________________
_________________________________________________ BOW Full STR Fire level 102 -- ON A LONG BREAK..POSSIBLY FOREVER
|
|
Top |
|
 |
_Dutchy_
|
Post subject: Re: Joymax Major Security Issue Database Leak Still On Going iss Posted: Thu Feb 23, 2012 11:14 am |
|
Frequent Member |
 |
 |
Joined: Apr 2008 Posts: 1347 Location: Netherlands
|
BuDo wrote: I haven't played in about a month. I think I'm due for another long break from SRO......maybe even not returning at all this time....I was so bored I wasted 20 days worth of premium ticket...The appeal is dwindling again........
I need to find a game where less emphasis is placed on grinding and more on just enjoying the game....I find that type of enjoyment when playing first person shooters because you immediately start to have fun without waiting to reach higher levels...If only I could find an MMORPG like that.. You should Try SRO-Salvation ( If you haven't already )Light grinding enough PVP and PVE stuff to do!
_________________
|
|
Top |
|
 |
heroo
|
Post subject: Re: Joymax Major Security Issue Database Leak Still On Going iss Posted: Thu Feb 23, 2012 11:18 am |
|
Forum Legend |
 |
 |
Joined: Sep 2006 Posts: 6618 Location:
|
BuDo wrote: I haven't played in about a month. I think I'm due for another long break from SRO......maybe even not returning at all this time....I was so bored I wasted 20 days worth of premium ticket...The appeal is dwindling again........
I need to find a game where less emphasis is placed on grinding and more on just enjoying the game....I find that type of enjoyment when playing first person shooters because you immediately start to have fun without waiting to reach higher levels...If only I could find an MMORPG like that.. The only reason I started playing SRO again is because Modern Warfare 3 scks ballz. FPS FTW. Imma keep playing SRO until the new COD comes out which will be a sequel to Black Ops which we all know is the best COD of all after oldschool Call Of Duty 2.
_________________
''When I die, make sure they bury me upside down, so that the world can kiss my ass.''
|
|
Top |
|
 |
|
Page 1 of 1
|
[ 15 posts ] |
|
Who is online |
Users browsing this forum: No registered users and 7 guests |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot post attachments in this forum
|
|