SkyNight wrote:
blutrausch wrote:
obviously fake
not even joymax would transmit users password hashes in packets
would have been already discovered by 0x33 otherwise
On the contrary, i remember 0x33 warning users about the security vulnerability of sroa WHILE ago. They made a simple program that could search for players online. They could get account info basically...this was after Gameguard was disactivated i think
JM did fix that specific issue of the password and account name being stored in plaintext in the client at a static address. I haven't search though to see if it was actually fixed or simply "looks" like it's fixed, but I do know for sure it's not how it was.