Be Wary, Champion


AngieB

 

Posted

I know this has been brought up in other parts of the City of Heroes forums, but I also know a lot of people don't pay attention to those other parts, so I thought I'd bring it up here.

A very serious bug has been discovered with NCSoft's web site that allows anyone to randomly access someone else's account.

Quote:
It started as a surprise. Guild Wars players reported suddenly finding themselves hacked, their accounts cleaned out, no indication of what could have caused the problem. NCsoft and ArenaNet offered suggestions, security safeguards, new measures being taken, hints that the problem lay in a popular third-party website with an undisclosed name. But with the recent rash of problems that Aion players have been having regarding security, new facts have begun coming to light, and they paint a picture that isn't pretty.

Specifically, some players seem to be finding that it doesn't take any skill to wind up hacking someone's account accidentally. And all it takes is a few log-in attempts to find yourself with access to someone's account name, password, and billing information for all of a player's NCsoft games.

Aion fans first began reporting that they were finding themselves getting accidentally logged in to the master accounts of other players. It didn't take long to put two and two together -- after all, an unscrupulous player or two could easily exploit this to drain Guild Wars accounts dry without ever being detectable. Poster Erys Vasburg on the Guild Wars Guru forum wrote a lengthy post detailing many of the pieces of evidence suggesting that the source of the much-feared hacks have been just that, despite repeated statements from Support Liason Gaile Gray to the contrary.
Yep, if you reload the NCSoft master account page enough times, you'll eventually find yourself logged into another random player's account, and can easily change his or her's master account's email address and passwords.

lol, NCSoft security.


@Celestial Lord and @Celestial Lord Too

 

Posted

I didn't catch that before; thanks for this post.

That is scary as hell.




-Star


 

Posted

Oy! Hope they do something with this, pronto. Heck, I wouldn't mind if they shut things down until it gets fixed. There are just too many bad possibilities if this is true, and simple as it sounds.

edit: Tested this out, and so far no other accounts showing up. Just my own, thankfully. What browsers were used in testing this?


 

Posted

I've been trying this all day but so far only got my own account or some guy name Stryker. He didn't have anything interesting so I just moved on.


(Hey, just kidding on the hack in case anyone didn't get the joke.)


Current favs: Champ: Frau Schmeterling-22 MM 50s: NOTW-Blaster, Cat-Girl Commando-corr, Queen of the Dawn-PB, NOTW-Def, Peterbilt-Brute, IcedTNA-Tank, Archilies-scrap, Mann Eater-stalk, Redemptive Soul-toller, Mt Fuji of A-Team-Tank, Hot Stuff Vale-Dom
My MiniCity

 

Posted

Quote:
Originally Posted by Seldom View Post
Oy! Hope they do something with this, pronto. Heck, I wouldn't mind if they shut things down until it gets fixed. There are just too many bad possibilities if this is true, and simple as it sounds.

edit: Tested this out, and so far no other accounts showing up. Just my own, thankfully. What browsers were used in testing this?
From what I've read, it's random. It could happen after a few tries, or it could occur after several thousand tries. It wouldn't be difficult for someone to write up a script to constantly refresh a web site until it loads up a different account, if they're so inclined.


@Celestial Lord and @Celestial Lord Too

 

Posted

Hm. I've tried a good many times, and was pleased to see that my account is stubbornly secure as of yet. Can anyone confirm the wrong account problem? (I was using chrome/IE 7)


 

Posted

I've had this happend a lot on the Aion website. not so much as the ncsoft master account but the Aiononline.com website.

I didn't understand at the time why i'd get the name and item of someone else and thought it was just a hickup of the database not linking correctly.

At least from that website one can't control the account.


 

Posted

Quote:
Originally Posted by Ashcraft View Post
Oooh, I'm gonna try and log in as Cobalt! Finally get Operation: Pink Walrus underway!
LOL. Good things I wasnt drinking, I would have had to clean my desk and head back to AAA for bubbles in the nose adiction.


Lead Squirrel at Dr. E Spider robotic site #643

Nothing saids its your spot like an ourob. Portal dropped on the ground.

 

Posted

Quote:
Originally Posted by Ashcraft View Post
Oooh, I'm gonna try and log in as Cobalt! Finally get Operation: Pink Walrus underway!
Anyways.


"Champion (the Community Server... or GTFO) is like a small town where everyone knows each other's names, for better or worse." -kojirodensetsu.
"If all you have is a hammer, everything looks like a nail." - Maslow's Hammer

 

Posted

HA! Not BMT Cobalt, you're powers of Anyways will not detour the randomness.


 

Posted

Quote:
Originally Posted by Darzer View Post
HA! Not BMT Cobalt, you're powers of Anyways will not detour the randomness.
No, it's just my account...


"Champion (the Community Server... or GTFO) is like a small town where everyone knows each other's names, for better or worse." -kojirodensetsu.
"If all you have is a hammer, everything looks like a nail." - Maslow's Hammer

 

Posted

There was a period when these new boards went up where you'd be logged into some random name, until you logged out and back in again, but I've never seen that issue with the game itself, or the NCSoft page.


Loose --> not tight.
Lose --> Did not win, misplace, cannot find, subtract.
One extra 'o' makes a big difference.

 

Posted

ahh ha! so thats how i keep ending up in the bmt randomness thread.. some ahole hacked my account and has been playin on my toons! yes yes! thats it!


 

Posted

So if Golden Girl opens a thread about how Villains are superior then we know someone got her huh? lol

:P


 

Posted

Quote:
Originally Posted by _Cherry_ View Post
ahh ha! so thats how i keep ending up in the bmt randomness thread.. some ahole hacked my account and has been playin on my toons! yes yes! thats it!
This? This is funny.


: )




-Star


 

Posted

No Cherry. Honey we KNOW that's you. We ALWAYS know.


@AngieB & @Angie B
Ms. Paragon City 2009
"The ingenuity of game players is a formidable force that, if properly directed, can be used to solve a wide range of scientific problems." - Firas Khatib

 

Posted

After having seen so many stories on Guild Wars Guru, this doesn't surprise me in the least.


Elsegame: Champions Online: @BellaStrega ||| Battle.net: Ashleigh#1834 ||| Bioware Social Network: BellaStrega ||| EA Origin: Bella_Strega ||| Steam: BellaStrega ||| The first Guild Wars: Kali Magdalene ||| The Secret World: BelleStarr (Arcadia)

 

Posted

I've gotten a few emails that went straight to my junk folder from "NCSoft Support". Except the grammar/spelling was always a little off and while the link looked kosher in the email, mousing over it would reveal it would actually take me to sacuar-ncsoft or something.

Nice try, Zarflax!


Support Guides for all Corruptor secondaries and Fortunatas
The Melee Teaming Guide for Melee Mans