You are not logged in.

Applications: [GameMaster: OPEN] | [Volunteer Testers: OPEN]


This forum will be permanently shut down on Friday 13.07.2018
Please copy or save all important information from old forum before they will be deactivated
We have moved to new board. https://forum.runesofmagic.gameforge.com/Come join us.

21

Wednesday, March 21st 2012, 10:11am

Since they downgraded the forum, you can't view who's online anymore to track down a GM easy. I would have gone to the EU forum and got someone to take care of this.

myraged

Trainee

Posts: 128

Location: Whattttttt ?????????????????????????????????????????????????????????????????????????????????????????

  • Send private message

22

Wednesday, March 21st 2012, 10:23am

Got the screenshot to show the GM case during sw figured id post it for everyone to see before it gets removed :s
Kinda crazy there able to get into accounts so easy maybe frogster should implement a new IP system of some type that if its a IP outta your normal state or diff from the normal string logging into your account in the past month they blocked them from getting in http://imageshack.us/photo/my-images/808…2031822093.png/

23

Wednesday, March 21st 2012, 10:41am

Another high level character hacked and spamming world shout now. This is getting a little freaky.

myraged

Trainee

Posts: 128

Location: Whattttttt ?????????????????????????????????????????????????????????????????????????????????????????

  • Send private message

24

Wednesday, March 21st 2012, 10:50am

ya kinda sucks for these players most likely having all there dias spent/gear stolen then dumb people that will report them for spam like its not enough they will have there toon banned then

Kefkai

Professional

Posts: 907

Location: Pulling my own puppet strings

Occupation: Jerk

  • Send private message

25

Wednesday, March 21st 2012, 11:08am

So we're up to a minimum of 5 players who have been 'hacked' at this point, I personally am going to change my password on a secure computer due to paranoia, I'd suggest the same to anyone who feels uncomfortable with this situation.

It'd be one thing if this were an isolated incidence, but it's not.

Can we just list the character names of the people who have had their accounts compromised? It'd be easier to be able to tell people here so they know what happened.

26

Wednesday, March 21st 2012, 11:38am

Add ANOTHER level 70 to the list.

27

Wednesday, March 21st 2012, 1:01pm

My account was acting weird last night and I couldn't log on...can anyone just list out the character names. In this instance I don't think it would be violating forum rules, since there is no implication that the players are doing anything wrong.

regentego

Professional

Posts: 1,686

Location: AZ

Occupation: Manager

  • Send private message

28

Wednesday, March 21st 2012, 1:01pm

Yeah I think we're past the point of a coincidence. I thought there already were mechanics that did not allow you to log from a different state or country?

29

Wednesday, March 21st 2012, 1:03pm

Quoted from "Droodetoo;518909"

My account was acting weird last night and I couldn't log on...can anyone just list out the character names. In this instance I don't think it would be violating forum rules, since there is no implication that the players are doing anything wrong.


Forum rules prohibit me from saying any of the toons names, but your main toon wasn't one of them :)

Kefkai

Professional

Posts: 907

Location: Pulling my own puppet strings

Occupation: Jerk

  • Send private message

30

Wednesday, March 21st 2012, 1:21pm

Quoted from "UncleMart;518911"

Forum rules prohibit me from saying any of the toons names, but your main toon wasn't one of them :)


I sent a pm to Droode with a list of names of everyone who has been hacked so far, if anyone else is interested they can PM me as well or ask in here.

Btw, the safest you can make your account is whenever you log in, go to another secure computer and change your password unless there's a security leak at Frogster there's no way that your account can be 'hacked' if you change your password after you log in (assuming the password you change it to you don't use anywhere else).

31

Wednesday, March 21st 2012, 1:31pm

As far as I know, Artemis is the only server affected, and it affected enough to see a one-server only pattern. That likely means that the server itself has been compromised. Changing password would only work if the breach was one time and has been plugged; otherwise your new password is as vulnerable as your old one.

And, good luck to good people at Artemis. Hope this is contained now.
-- Rustyx --- 92R / 92S / 92M on Reni (Guild KnightShift). Yes, running the new FOTM R/M, cause I am not elf enough to be WD/S.

Oh, and people who have more than 3 classes are clinically insane.


32

Wednesday, March 21st 2012, 1:34pm

Guessing you just added the new one that popped up to your list Kefkai? ;)

For the record, thats ANOTHER level 70 from a very well known Artemis guild.

There is without doubt a security hole or leak somewhere. Be VERY careful guys, change your passwords, check your systems for virus.

To Frogster : I've seen this happen before, you need to get a tech to inspect your security asap. Please dont dismiss this as if you do, and you have a security problem the fallout will be way beyond anything you can control.

Drakkarsdad

Professional

Posts: 599

Location: In a house

Occupation: CSR

  • Send private message

33

Wednesday, March 21st 2012, 1:36pm

Gm needed in game on all servers around the clock until this is dealt with. A guildy is being hacked as i type this. Amadrim on artemis server

Kefkai

Professional

Posts: 907

Location: Pulling my own puppet strings

Occupation: Jerk

  • Send private message

34

Wednesday, March 21st 2012, 1:36pm

Quoted from "vfwiffo;518915"

As far as I know, Artemis is the only server affected, and it affected enough to see a one-server only pattern. That likely means that the server itself has been compromised. Changing password would only work if the breach was one time and has been plugged; otherwise your new password is as vulnerable as your old one.

And, good luck to good people at Artemis. Hope this is contained now.


Yeah that was the bit about "unless there's a security leak at Frogster", in the case that there is we're all screwed.

I'm not really sure to be honest why there's only a problem with Artemis though since accounts aren't limited to one server (only secondary passwords are).

If they bypassed authentication on Artemis that'd be another issue, but then if they did, they wouldn't need passwords regardless.

35

Wednesday, March 21st 2012, 1:47pm

Well, the way (most) mmo's work is they have a gateway/login server which will authenticate people, once they're authenticated they get redirected with a security certificate to the actual game server.

A certain other well known MMO game had a serious security hole where they could totally bypass the actual sending of the login/password and just use a player # (randomly picked) which would allow them to login to any account, they just didn't know which one. This went on for a couple weeks till a very smart player (who actually worked in computer security) managed to find the security hole and let the company know. A few hours later the patch was rolled out and there were no more hackings.

The problem with this story is that the game company just kept on saying "You shouldn't give you details to other people" and "You shouldn't use hacks or third party programs". Me and my girlfriend BOTH got hacked and we both had major security (I've also worked in computer security) and I knew the whole time that the problem was on the games end.

Personally, my opinion on this is that Frogster has had their database compromised or someone has managed to find a security hole. These accounts are almost ALL level 70, all have megaphones. They're being identified by details. The only way someone could do this is by either going through accounts till one fits the purpose or someone has access to the actual database details and can flick through until they see a level 70.

This is very worrying indeed though.

The only fix I can think of for now is that you give you login name (NOT YOUR PASSWORD) to a close friend who plays and if your friend see's you login and start doing this to attempt to login with the wrong password. This will have the effect of blocking the account for 30 minutes, which might just save them.

This does however need urgent attention as player can potentially stand to lose items/gold/diamonds or even real life money.

36

Wednesday, March 21st 2012, 2:18pm

Quoted from "UncleMart;518924"

Personally, my opinion on this is that Frogster has had their database compromised or someone has managed to find a security hole. These accounts are almost ALL level 70, all have megaphones. They're being identified by details. The only way someone could do this is by either going through accounts till one fits the purpose or someone has access to the actual database details and can flick through until they see a level 70.


Just as likely, other accounts could be accessed but do not serve the purpose. Either they

Quoted

The only fix I can think of for now is that you give you login name (NOT YOUR PASSWORD) to a close friend who plays and if your friend see's you login and start doing this to attempt to login with the wrong password. This will have the effect of blocking the account for 30 minutes, which might just save them.

This does however need urgent attention as player can potentially stand to lose items/gold/diamonds or even real life money.


That likely wont work. The lockout almost certainly happens on the login server. If the perp can either bypass or spoof authentication that goes from login server to Artemis, lockout on login server wont do any good.

My guess is that it is either backdoor emergency access that a lot of systems have to allow administrators access when system is having issues; or it is spoofing. If someone managed to be able to monitor traffic between login server and Artemis, captured enough of it to analyze and then is able to spoof login messages as if they are coming from login server, they can do lots of damage. Also would explain why only one server looks to be compromised.
-- Rustyx --- 92R / 92S / 92M on Reni (Guild KnightShift). Yes, running the new FOTM R/M, cause I am not elf enough to be WD/S.

Oh, and people who have more than 3 classes are clinically insane.


Kefkai

Professional

Posts: 907

Location: Pulling my own puppet strings

Occupation: Jerk

  • Send private message

37

Wednesday, March 21st 2012, 2:19pm

Quoted from "UncleMart;518924"

Well, the way (most) mmo's work is they have a gateway/login server which will authenticate people, once they're authenticated they get redirected with a security certificate to the actual game server.

A certain other well known MMO game had a serious security hole where they could totally bypass the actual sending of the login/password and just use a player # (randomly picked) which would allow them to login to any account, they just didn't know which one. This went on for a couple weeks till a very smart player (who actually worked in computer security) managed to find the security hole and let the company know. A few hours later the patch was rolled out and there were no more hackings.

The problem with this story is that the game company just kept on saying "You shouldn't give you details to other people" and "You shouldn't use hacks or third party programs". Me and my girlfriend BOTH got hacked and we both had major security (I've also worked in computer security) and I knew the whole time that the problem was on the games end.

Personally, my opinion on this is that Frogster has had their database compromised or someone has managed to find a security hole. These accounts are almost ALL level 70, all have megaphones. They're being identified by details. The only way someone could do this is by either going through accounts till one fits the purpose or someone has access to the actual database details and can flick through until they see a level 70.

This is very worrying indeed though.

The only fix I can think of for now is that you give you login name (NOT YOUR PASSWORD) to a close friend who plays and if your friend see's you login and start doing this to attempt to login with the wrong password. This will have the effect of blocking the account for 30 minutes, which might just save them.

This does however need urgent attention as player can potentially stand to lose items/gold/diamonds or even real life money.


The one thing I have noticed with this so far is that all of the people who have been 'hacked' have not been online at the time, it could be the time of day, but it may also be a relevant detail.

Typically there are 3 servers, a login, a character and a map/game server, they have inter-server connection.

If they're somehow skipping past the login server, it may mean that the login server is the one that sends a d/c command to the character server which then sends it to the map server.

Staying online may be preventative, but at this point it's just all guessing.

There has been a certain delay between them logging into accounts though which does suggest they may be logging into a bunch of accounts, there has to be a common thread between all these people.

Oh, and one of them was 67, not 70 anyways.

I really miss administrating game servers sometimes, dealing with this sort of stuff was fun, though generally you make sure this sort of thing doesn't happen.

38

Wednesday, March 21st 2012, 2:46pm

This sucks for those who have been hacked...keep all your info changed hourly if necessary and do check your PC for any funny stuff and get it removed fast.

Quoted from "UncleMart;518894"

Since they downgraded the forum, you can't view who's online anymore to track down a GM easy. I would have gone to the EU forum and got someone to take care of this.



You can view which CM/GM/FM is online.

Do the following:

- Go to main forum page
- In sub menu click Quick Links > View Forum Leaders
(if there is a green dot next to their name, they are online)

Also as what was mentioned, go to the EU forums and do the same if none of ours are online.

This is how i contacted a Frogster representative when we had our login servers down for 8 hours a while back.

Good luck all

39

Wednesday, March 21st 2012, 2:47pm

By the way just curious... to the people that where hacked did they take your gear?
Berec [PPK]
Class: R/S/K 72/72/72
Server: Artemis

40

Wednesday, March 21st 2012, 3:01pm

Quoted from "Craigers;518932"

This sucks for those who have been hacked...keep all your info changed hourly if necessary and do check your PC for any funny stuff and get it removed fast.




You can view which CM/GM/FM is online.

Do the following:

- Go to main forum page
- In sub menu click Quick Links > View Forum Leaders
(if there is a green dot next to their name, they are online)

Also as what was mentioned, go to the EU forums and do the same if none of ours are online.

This is how i contacted a Frogster representative when we had our login servers down for 8 hours a while back.

Good luck all


Awesome, didn't know that :) thanks :)

Cronrs, guild member of mine got hit and they used all his megas and stole all his gold.