Silkroad Online Forums

A community forum for the free online game Silkroad Online. Discuss Silkroad Online, read up on guides, and build your character and skills.

Faq Search Members Chat  Register Profile Login

All times are UTC




Post new topic Reply to topic  [ 62 posts ]  Go to page 1, 2, 3  Next
Author Message
 Post subject: SRO base hacked - all accounts in danger ????
PostPosted: Tue Sep 26, 2006 10:24 pm 
Regular Member
User avatar
Offline

Joined: Apr 2006
Posts: 293
Location:
Babel
I just read globals from our server official helper saying that all people in game need change their pw,and to not trader with exchange syste cuz theres some global hack that can make u send ur info to other people even if u dont want to.


Any one got any clue whats going on ???

Im going to change my pw but this is so strange!

_________________
Image
1st = 67 / STR blade/fire/ice
2nd = 29 / INT spear/fire/light

QUIT Silkroad forever -


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 26, 2006 10:36 pm 
Common Member
User avatar
Offline

Joined: Mar 2006
Posts: 165
A polish web-site is hosting 47 pages of login/name/character/servers/e-mail/country etc... that were obtained using the trade hack.

So yea... change your PW if you traded a Pol in the last month.

_________________
Image
SILKROAD ALCHEMIST - we will never fall
Drink less HATERADE


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 26, 2006 10:41 pm 
Advanced Member
User avatar
Offline

Joined: Apr 2006
Posts: 2429
Location: here
..... im scared now,i clicked on the link =((((


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 26, 2006 10:45 pm 
Loyal Member
Offline

Joined: Apr 2006
Posts: 1950
This is bad. Another flaw once again. Good going Joymax!

_________________
<<banned from SRF for rules violations. -SG>>


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 26, 2006 10:56 pm 
Frequent Member
User avatar
Offline

Joined: Jun 2006
Posts: 1115
Location: Sarajevo
So you mean, if you have done trades using the Exchange, you can get hacked?

Whatever happend i changed my pass.


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 26, 2006 11:14 pm 
Frequent Member
User avatar
Offline

Joined: Jun 2006
Posts: 1346
Location:
Oasis
whaaaa?!? are you serious? But i havent traded in the last month.

_________________
Image


Top
 Profile  
 
 Post subject:
PostPosted: Tue Sep 26, 2006 11:23 pm 
Hi, I'm New Here
Offline

Joined: Sep 2006
Posts: 2
Location:
Tibet
Bullshit.
There is one golden rule for programmers in any given MMO out there: Create as few internet traffic as possible as it costs the company money. So why give out account information during an intertoon trade?

Second Bullshit.
People get alarmed when there seems to be something called a security breach. They suddenly want to change their password, get a cookie, anything just to be safe.
On second thought, they want to talk about it, discuss it, and by making their fears public, they make themselves vulnerable.

Third Bullshit.
If you really believe SRO has been hacked to such an extent, think about the consequences. There would be no chance the servers would be up and working tomorrow, as it would throw the whole game system into disarray. Just wait and see.

Last Bullshit for tonight:
Yeah, server helpers, Silkies, whatever. Just compare the amount of authority and regulation in the SRO chat channels - let's say only global chat which could be monitored by one person easily for all our servers - to any other major MMORPG out there.

G'night pals from Tibet.


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 12:53 am 
Banned User
Offline

Joined: Feb 2006
Posts: 4561
Location: aeratadfer
Flaps wrote:
Bullshit.
There is one golden rule for programmers in any given MMO out there: Create as few internet traffic as possible as it costs the company money. So why give out account information during an intertoon trade?

Second Bullshit.
People get alarmed when there seems to be something called a security breach. They suddenly want to change their password, get a cookie, anything just to be safe.
On second thought, they want to talk about it, discuss it, and by making their fears public, they make themselves vulnerable.

Third Bullshit.
If you really believe SRO has been hacked to such an extent, think about the consequences. There would be no chance the servers would be up and working tomorrow, as it would throw the whole game system into disarray. Just wait and see.

Last Bullshit for tonight:
Yeah, server helpers, Silkies, whatever. Just compare the amount of authority and regulation in the SRO chat channels - let's say only global chat which could be monitored by one person easily for all our servers - to any other major MMORPG out there.

G'night pals from Tibet.

Bullshit of all time:
Your post. It makes no sense.

_________________
<<banned from SRF for rules violations. -SG>>


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 1:14 am 
Common Member
Offline

Joined: Apr 2006
Posts: 138
Location:
Alps
If thats true Silkroad is Screwed.

_________________
Lvl - 4x
Str Blader
_____________
Image


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 1:32 am 
Loyal Member
User avatar
Offline

Joined: Jun 2006
Posts: 1764
Location:
Xian
Th0m@$ wrote:
If thats true Silkroad is Screwed.
Just as i predicted....The SRO apocolypse....

_________________
DECEASED
Image


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 2:15 am 
Frequent Member
User avatar
Offline

Joined: Jun 2006
Posts: 1346
Location:
Oasis
lolz this is GunZ all over again.

_________________
Image


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 2:17 am 
Loyal Member
User avatar
Offline

Joined: Jun 2006
Posts: 1764
Location:
Xian
wow....gunz....never knew u guys heard of that game

_________________
DECEASED
Image


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 2:22 am 
Frequent Member
User avatar
Offline

Joined: Jun 2006
Posts: 1346
Location:
Oasis
SHOORE BUDDAY..

i knew about GunZ before i started SRO. i gotz to like 10-20(cant remember maybe 21) then the haX0rz wiped my account.

_________________
Image


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 2:33 am 
Casual Member
User avatar
Offline

Joined: May 2006
Posts: 78
Location:
Babel
Prevention:
1. dun accept random trades and parties
-no proof yet (theoretically possible if gameguard is not present, since GG are so easy to by-pass, i will advice to believe it to prevent account theft)
2. dun buy stuff using trades
-still on testing
3. dun simply use the silkroadonline.net official site
-proven, but temporary solved by joymax. It was first hack by indonesian hacker who hack for fun. He inform joymax and joymax reply him kindly.

original post (no link provided to avoid any further problems)
Kelemahan pada http://www.silkroadonline.net
(The weakness of silkroadonline.net)

Dear all friends and enemies,

Selain meniliti sedikit mengenai friendster, saya juga sempat meneliti mengenai http://www.silkroadonline.net website yang meruapakan official site untuk game online sRO (SilkRoadOnline) milik korea yang dapat dimainkan secara International. Kalau saya perhatikan game ini, juga sudah mulai mendapat cukup banyak perhatian dari para gamer Indonesia.
(After analyzing more detail on friendster, i have my chance to know more about silkroadonline.net. An official website for SRO, korean international online game. I realise this game have a lot of attention from indonesian gamers.)

Pada kesempatan kali ini, saya kembali ingin memberikan video tutorial berkenaan dengan celah keamanan berupa Cross-site Scripting pada situs game tersebut. Dan hal ini memungkinkan adanya Semi-Offensive Phising Attack yang mengatas namakan website tersebut.
(I would like to take this chance to show a tutorial by using cross site scripting on the official site. It will probably launch an Semi-offensive phising attack on the official site itself.)

Berikut adalah video-nya:.
(this is the video)
http://www.hellgeeks.org/SilkRoadOnline.rar (down link : dun worry)

Mungkin tidak terlalu penting dikarenakan data yang dapat di-gain hanyalah berupa data online pada website dan game tersebut saja, akan tetapi kita tidak bisa hanya melihat dari sebelah mata dikarenakan gamingpun sekarang ini sudah benar benar menjadi salah satu Industry besar di dunia IT, dan kemungkinan bahwa game bisa menghasilkan uang juga merupakan suatu hal yang perlu digaris bawahi berkenaan dengan kelemahan pada situs situs gaming international.
(May be it is not that important because the data obtain is an online data for the game and website only, but from the other point of view, gaming industry is becoming overwhelm in the global world of IT and may be it is important to raise awareness on the weaknesses of all international gaming site.)

Terima kasih~
(Thank you)

Shout to: KidChameleon, 8th-Heaven, Creepy, and Super_Babi
And also special words for Her

Salam,
(regards)
Th0R

Note: I'm not indonesian but i understand (a little bit of) their language.


Last edited by radeon on Wed Sep 27, 2006 2:41 am, edited 1 time in total.

Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 2:37 am 
Frequent Member
User avatar
Offline

Joined: Jun 2006
Posts: 1346
Location:
Oasis
ummmm.......yeah... :?

_________________
Image


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 5:33 am 
Veteran Member
User avatar
Offline

Joined: Jul 2006
Posts: 3132
Sory but i didnt get the "Mungkin tidak" part(along with the rest of the post)


Top
 Profile  
 
 Post subject: Re: SRO base hacked - all accounts in danger ????
PostPosted: Wed Sep 27, 2006 5:43 am 
Frequent Member
User avatar
Offline

Joined: Apr 2006
Posts: 1137
Location:
Troy
Winston wrote:
I just read globals from our server official helper saying that all people in game need change their pw,and to not trader with exchange syste cuz theres some global hack that can make u send ur info to other people even if u dont want to.


Any one got any clue whats going on ???

Im going to change my pw but this is so strange!


I don't believe a word of it. There's no sense to sending account information within the system during a trade, so I can't imagine why the GMs would have programmed something like that. More likely that some people with easy to guess passwords or perhaps a brute force password attempt got hacked. I don't think people like Athena_vn would still have their full SOS 8th degree SOS sets if it was that easy to hack the SRO database.

_________________
[88] Vivace
Pure INT Bard/Cleric, Bard 88, Cleric 88

[83] Pinokkio
Pure INT Force Nuker, Force 83, Cold 83, Lightning 83, Fire 60

[81] Sybian
Pure INT KD Nuker, Bicheon 81, Cold 81, Lightning 81, Fire 60


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 5:52 am 
Casual Member
User avatar
Offline

Joined: May 2006
Posts: 78
Location:
Babel
Megalomaniac wrote:
Sory but i didnt get the "Mungkin tidak" part(along with the rest of the post)


i did try my best to translate... =) cos i'm not that familiar with some of the words..

[quote="phulshof"]
I don't believe a word of it. quote]

not directly from the database. GameGuard suppose to do their job but a lot of elite out there know how to by pass it can release to public resulted a lot of hacking tool can be used which lead to the problem u mention.


Last edited by radeon on Wed Sep 27, 2006 5:56 am, edited 1 time in total.

Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 5:56 am 
Common Member
User avatar
Offline

Joined: Sep 2006
Posts: 116
Location:
Babel
This thread was started in response to the Globals i sent out on Babel today. I have asked other SA's on the other servers to do the same thing. I have received reports, over the last two weeks, very slowly at first, of a trade hack.

This type of hack was present in the last mmo that I played in - we were expecting it to arrive on SRO, and in fact it took longer than I would have thought. The "big talkers" above may say all they please. The fact is, there is a hack, and it began 2 weeks ago when the opportunity in the coding presented itself. (hopefully the little grey cells will start to stimulate here lolz)

The best defense to this is yes, change your password. Unless you can remember if you accepted a random invite to a party from a stranger or not, and are sure you haven't purchased anything via trading another character...then just err on the side of caution. Do not trade with another character, and do not accept those spammed party invites that we are receiving in Hotan atm.

I presented all of the information that I have to Gargamel the moment he rolled on to MSN today lol. I think it was 6 a.m in Korea - nice wake up call xD. They are investigating, but sadly are a little doubtful atm. If you have been hacked via this method, or know more about it please leave me a message here or pm me ingame on Babel. IF you have been hacked by this manner you *must* fill out a bug report, it's imperative. Hope this helps.

Edit: BTW we found some of the hacks on the internet - forgot to mention that :p - so if you still doubt it exists...go trade a noob or accept a party invite ^^

_________________
Lvl 70 Nuker Babel
Silk Assistant Extraordinaire


Last edited by Sutaseyu on Wed Sep 27, 2006 6:08 am, edited 1 time in total.

Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 6:01 am 
Advanced Member
User avatar
Offline

Joined: Apr 2006
Posts: 2429
Location: here
dam betta n0t d3lay "maconha hunt"


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 10:57 am 
Regular Member
User avatar
Offline

Joined: Apr 2006
Posts: 218
Location:
Babel
JM policy has always been to ignore any complaints about hacked character. Will they revise their position if the problem comes from a security breach due to them ?

Second question : is there a risk with stall ?

BTW Suta, thanks for information. please do come back if you know more

_________________
Ezeckiel Lvl5x - hybrid 2:1 INT Fire Sword
_____________________________________

Image


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 11:30 am 
Hi, I'm New Here
Offline

Joined: Apr 2006
Posts: 9
Ezeckiel wrote:
JM policy has always been to ignore any complaints about hacked character. Will they revise their position if the problem comes from a security breach due to them ?

Second question : is there a risk with stall ?

BTW Suta, thanks for information. please do come back if you know more

There isn't a risk with stalling. Suta learned the info from someone else.


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 11:45 am 
Frequent Member
Offline

Joined: Apr 2006
Posts: 1468
I changed my pw now, and can log in to them game. Says the id or pw are wrong. :shock: I can log in on site, but not on game. :(


edit: i loged in, guess i made pw to long :D

_________________
<<banned from SRF for bot admission. -SG>>


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 1:32 pm 
Regular Member
Offline

Joined: Jul 2006
Posts: 203
Sutaseyu wrote:

Edit: BTW we found some of the hacks on the internet - forgot to mention that :p - so if you still doubt it exists...go trade a noob or accept a party invite ^^



Your claims are full of shit, no such info gets sent in any type of exchange, party invite, stall, etc, etc. I play on Athens, i have 80m banked and 52 SoS Message me privately in this forum we will set up a time and place on Athens server i'll do any type of exchange, party you want, if you can hack my account you can have the damn thing. Until then shut up or put up. False claims like this need to be a bannable offense.


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 1:40 pm 
Loyal Member
Offline

Joined: Apr 2006
Posts: 1950
Sroge wrote:
Sutaseyu wrote:

Edit: BTW we found some of the hacks on the internet - forgot to mention that :p - so if you still doubt it exists...go trade a noob or accept a party invite ^^



Your claims are full of shit, no such info gets sent in any type of exchange, party invite, stall, etc, etc. I play on Athens, i have 80m banked and 52 SoS Message me privately in this forum we will set up a time and place on Athens server i'll do any type of exchange, party you want, if you can hack my account you can have the damn thing. Until then shut up or put up. False claims like this need to be a bannable offense.


You realize this is an SA. Suta isnt going to try/doubtful that they know how to do it. The trade hack is where the 48 pages of logins came from. Every time you go to hotan in the past few days there is trade / pt spam.

Come back when you have proof it doesnt exist.

_________________
<<banned from SRF for rules violations. -SG>>


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 1:49 pm 
Common Member
Offline

Joined: Feb 2006
Posts: 159
Location:
Pluto
Sroge wrote:
Sutaseyu wrote:

Edit: BTW we found some of the hacks on the internet - forgot to mention that :p - so if you still doubt it exists...go trade a noob or accept a party invite ^^



Your claims are full of shit, no such info gets sent in any type of exchange, party invite, stall, etc, etc. I play on Athens, i have 80m banked and 52 SoS Message me privately in this forum we will set up a time and place on Athens server i'll do any type of exchange, party you want, if you can hack my account you can have the damn thing. Until then shut up or put up. False claims like this need to be a bannable offense.


yeh you see i kinda doubt the silk road assistant is gonna hack your account even for kicks..

EDIT: ahh chaud i didnt see your post when i made mine :)

_________________
CharacteR: Thoth (Pluto Server)
LeveL: 50
JoB:Trader (4)
GuilD: Dark_Legion(lv4)
BuilD:Pure INT Wizard/Bard


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 2:02 pm 
Active Member
User avatar
Offline

Joined: Feb 2006
Posts: 670
Location: Hell
Aaigt ! Can sum1 plz post or PM me the site with all the logins ? Cuz I don't belive this BS until I've seen it. Ppl just talk about stuff and don't show any proof of sum sort :roll:

And like sum1 said, if Joymax would've known/knows (cut the "SAs" already know :roll: ) the problem don't u think they would do sumthing against it like do another inspection or sumthing ? :?

They haven't even mentioned it on the official site :roll: --> these assumptions = shit :wink: :P

_________________
link 2 my sig :P
old sig
Quote: Life sux....but it's got hella good grafix :P
---For a completely new experience of music visit http://www.pandra.com :D
Quit SRO


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 2:23 pm 
Regular Member
Offline

Joined: Jul 2006
Posts: 203
chaud wrote:
Sroge wrote:
Sutaseyu wrote:

Edit: BTW we found some of the hacks on the internet - forgot to mention that :p - so if you still doubt it exists...go trade a noob or accept a party invite ^^



Your claims are full of shit, no such info gets sent in any type of exchange, party invite, stall, etc, etc. I play on Athens, i have 80m banked and 52 SoS Message me privately in this forum we will set up a time and place on Athens server i'll do any type of exchange, party you want, if you can hack my account you can have the damn thing. Until then shut up or put up. False claims like this need to be a bannable offense.


You realize this is an SA. Suta isnt going to try/doubtful that they know how to do it. The trade hack is where the 48 pages of logins came from. Every time you go to hotan in the past few days there is trade / pt spam.

Come back when you have proof it doesnt exist.



48 pages of logins came from a keylogger. Thats not hard to figure out =). Like i said before, i'm willing to put my account on the line. If you or anyone else think they can hack it over a trade or party invite let me know i'll meet you in game.


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 2:36 pm 
Common Member
User avatar
Offline

Joined: Sep 2006
Posts: 116
Location:
Babel
Well as utterly "valiant" as your ignoramousnosity appears, your lack of attention to the printed word is stunning. Let's go through a couple of things. A) Yes, it took us less than two minutes searching to find both a list, and the information on how the hack works and is being used. B) only an utter MORON would install anything from a hack site on their computer C) i am not an utter moron D) henceforth, the hack is not installed on my computer E) I found the final proof of this hack and an absolutely new one out at 5 a.m. KST and waited for Gargamel to wake up (which was approximately 6:15 AM KST) and immediately reported and E) SRO has *never* once posted one of the scams, hacks and issues we have found. They have always been just quietly corrected.

While everyone absolutely has the right to be wary of things they read, bear in mind what this post is asking you to do. Is it asking you to share your user/pass? Or email your pass to Bulgaria? Or drink Iced Tea upside down on a rollercoaster? No? The failsafe from this point is to do 3 things: change your pwd, disable trade/party requests, and stop accepting random party/trade requests.

You may and should do whatever you please. That is absolutely your right. But resist flaming just so that you can be party to the post, should you have nothing of real substance to ask. And as a final note, one of your SA's on Troy is naked atm. If you think it can't happen to you... ask your SA. He's a great, helpful, hard working guy who has been absolutely cleaned out. Nuff said yah?

_________________
Lvl 70 Nuker Babel
Silk Assistant Extraordinaire


Top
 Profile  
 
 Post subject:
PostPosted: Wed Sep 27, 2006 2:55 pm 
Regular Member
Offline

Joined: Jul 2006
Posts: 203
Honestly, i'm not flamming or trying to argue. All i am saying is no type of account info is sent while your in game. By that i mean account ID or password.

If someone downloads a 3rd party program then yes their info can be stolen by the 3rd party program. People cannot hack your character while your in game by any type of action.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 62 posts ]  Go to page 1, 2, 3  Next

All times are UTC


Who is online

Users browsing this forum: No registered users and 15 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group