Go Back   Dreams in Vanadiel - Final Fantasy XI Forum > Dreams in Vana'diel - Main Topics > General FFXI Discussion

Post New Thread Reply
 
LinkBack Thread Tools Display Modes
Old 08-24-2009, 01:54 PM   #1
~ Mama Gamer ~
Golden Star
 
Aksannyi's Avatar
 
Join Date: May 2006
Location: Al'Taieu
Posts: 4,480
Style: Light Theme V7

Thanks: 610
Thanked 880x in 569 Posts
My Mood:
   
New Hackings Begin ... Security Token or Not.

Yeah, that's right, people are getting hacked with the security tokens at work. I understand how it works but not well enough to explain it, so I'll quote BG:

Quote:
Originally Posted by Valient from BG
Did all you guys miss what TummieGaruda said? While SE has strengthened their account security using a token generated password it still isn’t impossible for a hacker to take control over your account while you are logged in. In this case they never even input the password.

Let me demonstrate with my asci skills.
Normally your connection with SE would look like this.

You <----> SE

You get some evil program on your computer that changes your connection to look like this.

You <----> Hacker <----> SE

Hacker now sees everything you are doing in game. They come along back from their nap and see you are connected to the game. They spring into action and cause this to happen.

You <--X--> Hacker <----> SE

You are now D/Cing from your end but the hacker now has full control of your character, more importantly, bypassing all passwords.

As you try to re-login and input your password a couple times the hacker now has obtained that information and used it to change your POL password, if they are fast enough.

I find it very unlikely for a hacker to be actively waiting and watching for you to login. They rather capture that data and use it at their convenience. With the above method they can just hop on anytime they see you connected to the game and take over.

That’s my theory and I’m sticking to it.
EOL
And the thread: The sky is falling: player with token hacked? (lolIE) - Order of the Blue Gartr

Apparently it's been reported on sites like slashdot and a few others (forgot which) that this is a new token exploit for much more secure companies like banks, government agencies, etc., and the RMT have found their new niche.

Awesome.

So yeah, no one's safe anymore. Not that we assumed security tokens were 100% secure, but we sure didn't expect a new hacking method to come about so soon. Apparently there's a stink about it on Alla as well, but I really can't stand to go there anymore to read about it. I'd suggest watching your shit closely.
__________________
~Aksannyi~~Hades~~75WHM~75RDM~75BLM~75SMN~73WAR~67SCH~47BRD~
~Mama Gamer~~Quitted July 2009~~Excellence LS~
~~ ~~ ~~ ~~ ~~ ~~ ~~
Quote:
Originally Posted by Callisto View Post
Aksannyi's Nyzul Advice: "Oh, it's easy, just grab a couple of relic holders and an EBody WAR!"
Quote:
Originally Posted by Feba View Post
amazingly enough, aksannyi beat 16 pages worth of Sev humour in a single post.

Actually, there's nothing amazing about that, I suppose.
Aksannyi is offline   Reply With Quote Button by Aksannyi :)
Old 08-24-2009, 02:02 PM   #2
Senior Veteran
Iron Emblem of Service
 
Mhurron's Avatar
 
Join Date: May 2006
Posts: 5,230
Style: Light Theme V7

Thanks: 145
Thanked 1,896x in 1,096 Posts
Send a message via ICQ to Mhurron Send a message via Yahoo to Mhurron
   
Re: New Hackings Begin ... Security Token or Not.

Quote:
You get some evil program on your computer
Nothing saves users from themselves.
Mhurron is offline   Reply With Quote Button by Aksannyi :)
The Following 15 Users Say Thank You to Mhurron For This Useful Post:
Akashimo (08-25-2009), Armando (08-24-2009), Auron517 (08-30-2009), Feba (08-24-2009), Grizzlebeard (08-25-2009), Jarre (08-25-2009), Kailea (08-24-2009), Kasandaro (09-03-2009), Ketaru (08-25-2009), Losrase (09-03-2009), Malacite (08-24-2009), Omniblast (08-24-2009), Satori (08-25-2009), Wise Donkey (08-24-2009), Yellow Mage (08-25-2009)
Old 08-24-2009, 02:34 PM   #3
The Closer
Super Moderator
Brass Wings of Service
 
TheGrandMom's Avatar
 
Join Date: Nov 2004
Location: In the little corner in my mind
Posts: 6,942
Style: Light Theme V7

Thanks: 306
Thanked 1,111x in 657 Posts
My Mood:
Re: New Hackings Begin ... Security Token or Not.

Ya I think I pretty much reported this issue a while ago when I told how my son was hacked and was using the token. Of course, everyone ignored it and thought I was full of shit.
__________________
Quote:
Originally Posted by Taskmage View Post
I think I'd be happier without mine. I've reproduced; its job is done.
Quote:
Originally Posted by WishMaster3K
The vagina is a magical object.
Quote:
Originally Posted by Balfree
AND, running the game at 2024x2024 resolution, with forced AA and AF... o boy, you can even see that galka's pubes.
Quote:
Originally Posted by Aksannyi View Post
FFXIOnline.com ... "Where women are not constantly begged to show tits or GTFO!"
TheGrandMom is offline   Reply With Quote Button by Aksannyi :)
Old 08-24-2009, 02:38 PM   #4
~ Mama Gamer ~
Golden Star
 
Aksannyi's Avatar
 
Join Date: May 2006
Location: Al'Taieu
Posts: 4,480
Style: Light Theme V7

Thanks: 610
Thanked 880x in 569 Posts
My Mood:
   
Re: New Hackings Begin ... Security Token or Not.

You were one of the first people I thought if when I saw the thread on BG, TGM. I mean we knew it was possible somehow, but hell if I know the way this shit all works. People were clinging to the token as a security blanket, and probably still are. ><

I read you don't really d/c from the game ... you red dot, and when you recover from the red dot, your game is crashed but the hacker remains in control of the character and strips it. So you never even know that your account has been accessed, and when you attempt to log back into FFXI, the hack prevents POL from loading all the way through.

Sophisticated and creepy.
__________________
~Aksannyi~~Hades~~75WHM~75RDM~75BLM~75SMN~73WAR~67SCH~47BRD~
~Mama Gamer~~Quitted July 2009~~Excellence LS~
~~ ~~ ~~ ~~ ~~ ~~ ~~
Quote:
Originally Posted by Callisto View Post
Aksannyi's Nyzul Advice: "Oh, it's easy, just grab a couple of relic holders and an EBody WAR!"
Quote:
Originally Posted by Feba View Post
amazingly enough, aksannyi beat 16 pages worth of Sev humour in a single post.

Actually, there's nothing amazing about that, I suppose.
Aksannyi is offline   Reply With Quote Button by Aksannyi :)
Old 08-24-2009, 03:01 PM   #5
Soldier Tony
Allied Ribbon of Bravery
 
Durahansolo's Avatar
 
Join Date: Oct 2006
Location: Flint, MI
Posts: 1,760
Style: Light Theme V7

Thanks: 398
Thanked 259x in 177 Posts
My Mood:
   
Re: New Hackings Begin ... Security Token or Not.

Crazy, somebody was mentioning that "You <----> Hacker <----> SE" thing possibly happening awhile back on this board. Don't remember where exactly, probably in one of the token discussions lol.
__________________
-----------------------



"There will come a day when the world will realize that Superman can no longer create miracles. If my name was Superman, that day would be today." 4/29/2009 - Me

Quote:
Originally Posted by Aksannyi View Post
"Hello! 100+3 Leathercrafting, your materials, 5k! Mention code LTH74 for a special discount!" - they'd get blisted by everyone they sent that to.
Quote:
Originally Posted by Solymir View Post
What do you have against Ants? Is iVirus some new Apple product?
Durahansolo is offline   Reply With Quote Button by Aksannyi :)
Old 08-24-2009, 03:04 PM   #6
Crime Solving Rank 11 Paladin!
Steelknight Emblem
 
Malacite's Avatar
 
Join Date: May 2006
Location: None of your damn business
Posts: 5,840
Style: Light Theme V7

Thanks: 1,375
Thanked 524x in 365 Posts
My Mood:
   
Re: New Hackings Begin ... Security Token or Not.

And this is why I never use 3rd party software regardless.

Also, Microsoft Onecare FTW.
__________________


My Dream Samurai Gear
Malacite is offline   Reply With Quote Button by Aksannyi :)
Old 08-24-2009, 03:17 PM   #7
Dark Arts Master
Bronze Ribbon of Service
 
Takelli's Avatar
 
Join Date: Sep 2008
Location: Conneticut
Posts: 994
Style: Light Theme V7

Thanks: 41
Thanked 28x in 20 Posts
My Mood:
Send a message via AIM to Takelli Send a message via MSN to Takelli
   
Re: New Hackings Begin ... Security Token or Not.

Dang. That really sucks. Just don't download any files or open any emails that you don't trust. Thats the only real way to prevent hacking. Even then, you can still get hacked. Even having the most up to date fire wall, anti virus, and anti spyware. Hell, if my account gets hacked I'd be pissed, but I'll be quitting soon enough anyways, so it wont matter all that much to me. (FFXIV!)
__________________
Quote:
Originally Posted by hexx View Post
A subjob is like sex, shouldn't have it till you're 18, but if you don't have it by 21, people laugh at you."
~The guide to the n00bs~

http://www.ffxionline.com/forums/ffx...00b-guide.html
Quote:
Originally Posted by FFXIV
Quote:
Originally Posted by Raydeus View Post
Never! I'll roleplay as a Slider if I have to but I will never stop calling Tarus Tarus!
Quote:
Originally Posted by Raydeus View Post
anyone who uses the FFXI race names in FFXIV will end up looking like a noob.
Takelli is offline   Reply With Quote Button by Aksannyi :)
Old 08-24-2009, 03:39 PM   #8
Expert Chocobo Cook
 
hexx's Avatar
 
Join Date: Jul 2006
Location: El Paso, TX
Posts: 458
Style: Light Theme V7

Thanks: 145
Thanked 36x in 26 Posts
My Mood:
Send a message via AIM to hexx Send a message via Yahoo to hexx
   
Re: New Hackings Begin ... Security Token or Not.

This is why i play on a console ^^b
__________________
Quote:
Originally Posted by Van Wilder
Worrying is like a rocking chair, gives you something to do, but doesnt get you anywhere
Quote:
Originally Posted by Taskmage View Post
No matter how far an ass travels he will never be a horse. Some people are just bad players and no amount of tools you give them will change that.


Hexx of Quetzalcoatl - 75PLD, 75NIN, 75WAR, 75SAM, 75BLU
hexx is offline   Reply With Quote Button by Aksannyi :)
Old 08-24-2009, 03:52 PM   #9
Dark Arts Master
Bronze Ribbon of Service
 
Takelli's Avatar
 
Join Date: Sep 2008
Location: Conneticut
Posts: 994
Style: Light Theme V7

Thanks: 41
Thanked 28x in 20 Posts
My Mood:
Send a message via AIM to Takelli Send a message via MSN to Takelli
   
Re: New Hackings Begin ... Security Token or Not.

Quote:
Originally Posted by hexx View Post
This is why i play on a console ^^b
Well... With the way technology is getting now. Even using a console wont be safe soon. A PS3 is what? A computer bassically, and it has internet. Phones are being hacked now, so I don't doubt that a system can't be hacked with a keylogger if you hooked it up to your main PC and you had a kew logger on it.
__________________
Quote:
Originally Posted by hexx View Post
A subjob is like sex, shouldn't have it till you're 18, but if you don't have it by 21, people laugh at you."
~The guide to the n00bs~

http://www.ffxionline.com/forums/ffx...00b-guide.html
Quote:
Originally Posted by FFXIV
Quote:
Originally Posted by Raydeus View Post
Never! I'll roleplay as a Slider if I have to but I will never stop calling Tarus Tarus!
Quote:
Originally Posted by Raydeus View Post
anyone who uses the FFXI race names in FFXIV will end up looking like a noob.
Takelli is offline   Reply With Quote Button by Aksannyi :)
Old 08-24-2009, 04:04 PM   #10
~ Mama Gamer ~
Golden Star
 
Aksannyi's Avatar
 
Join Date: May 2006
Location: Al'Taieu
Posts: 4,480
Style: Light Theme V7

Thanks: 610
Thanked 880x in 569 Posts
My Mood:
   
Re: New Hackings Begin ... Security Token or Not.

There have been some console users reporting hacks on Alla. So yeah, not exactly sure how, but it seems nothing is safe. If they're hijacking your online internet session (which it was what it sounds like) then they may have some way to track your console on your network and figure out how to un-encrypt the data sent to the server or something.

Hell if I know if that even makes any sense. But with this new session hijack thing people are talking about on BG, I wouldn't be too surprised.
__________________
~Aksannyi~~Hades~~75WHM~75RDM~75BLM~75SMN~73WAR~67SCH~47BRD~
~Mama Gamer~~Quitted July 2009~~Excellence LS~
~~ ~~ ~~ ~~ ~~ ~~ ~~
Quote:
Originally Posted by Callisto View Post
Aksannyi's Nyzul Advice: "Oh, it's easy, just grab a couple of relic holders and an EBody WAR!"
Quote:
Originally Posted by Feba View Post
amazingly enough, aksannyi beat 16 pages worth of Sev humour in a single post.

Actually, there's nothing amazing about that, I suppose.
Aksannyi is offline   Reply With Quote Button by Aksannyi :)
Old 08-24-2009, 04:17 PM   #11
Expert Chocobo Cook
 
hexx's Avatar
 
Join Date: Jul 2006
Location: El Paso, TX
Posts: 458
Style: Light Theme V7

Thanks: 145
Thanked 36x in 26 Posts
My Mood:
Send a message via AIM to hexx Send a message via Yahoo to hexx
   
Re: New Hackings Begin ... Security Token or Not.

Quote:
Originally Posted by Takelli View Post
Well... With the way technology is getting now. Even using a console wont be safe soon. A PS3 is what? A computer bassically, and it has internet. Phones are being hacked now, so I don't doubt that a system can't be hacked with a keylogger if you hooked it up to your main PC and you had a kew logger on it.

And that is also why I do not link my consoles to computers. Besides, to be able to access my consoles, they would have to be parked outside my house, within range of my wireless network, to be able to intercept it, if at all with all the security I have attached to mine. Never the less, I'll be keeping a close eye on it just in case.
__________________
Quote:
Originally Posted by Van Wilder
Worrying is like a rocking chair, gives you something to do, but doesnt get you anywhere
Quote:
Originally Posted by Taskmage View Post
No matter how far an ass travels he will never be a horse. Some people are just bad players and no amount of tools you give them will change that.


Hexx of Quetzalcoatl - 75PLD, 75NIN, 75WAR, 75SAM, 75BLU
hexx is offline   Reply With Quote Button by Aksannyi :)
Old 08-24-2009, 05:03 PM   #12
Junior Member
 
Join Date: Dec 2008
Posts: 81
Style: Light Theme V7

Thanks: 76
Thanked 0x in 0 Posts
My Mood:
   
Re: New Hackings Begin ... Security Token or Not.

Its probably because Playonline is a crappy online medium and SE just needs to develop something better and more secure for customers to use.
Aylmer is offline   Reply With Quote Button by Aksannyi :)
Old 08-24-2009, 05:08 PM   #13
Sticky Paws
Sterling Star
 
IfritnoItazura's Avatar
 
Join Date: May 2006
Location: Southern California
Posts: 3,201
Style: Light Theme V7

Thanks: 256
Thanked 678x in 434 Posts
My Mood:
   
Re: New Hackings Begin ... Security Token or Not.

hmm. This reminds me of the descriptions for the "packet sniffer" third party apps. (BTW, "packet sniffer" is the wrong term; more like "packet-intercept-modify-generate" programs, but I digress.) Wonder where these thieves cut their computing-fu teeth at. lol.

Hack FFXI for fun and in-game profit -> write bots and tools for RL $$$ while 'helping' other players -> hijack FFXI accounts for gil to sell to poor FFXI players who 'need' more in-game money. Interesting career path there. The next step would be finding horrific systemic weaknesses to exploit, and blackmail SE into paying "protection money" if the company doesn't want the FFXI cash cow to croak.

We don't walk up and loot the lying on the ground unconscious players for gil in FFXI--we go to the web and buy the gil taken from the kidnapped and then horribly butchered characters instead. Well, the gil buyers do; the rest of us just tolerate their dealings with the body snatching mobsters.

Edit:
Quote:
Originally Posted by Aylmer View Post
Its probably because Playonline is a crappy online medium and SE just needs to develop something better and more secure for customers to use.
"Medium"? Strange choice of the word.

Faults with POL client's security or lack of aside, there's not much the application developers can do when facing compromised network stack and computers infected by rootkits without going through extraordinary measures (which probably wouldn't withstand hack attempts for long anyway). Like Mhurron says, nothing saves the users from themselves.

If you don't know how to protect your lousy PC from at least the worst of the attacks, it's your fault for being ignorant and lazy.
__________________
I’m in pain, but I’m happy.
It hurts, but I can smile.
That’s why I can tell you from the depths of my being…

Last edited by IfritnoItazura; 08-24-2009 at 05:15 PM.
IfritnoItazura is offline   Reply With Quote Button by Aksannyi :)
Old 08-24-2009, 05:50 PM   #14
Altanaの戦士
Golden Star
 
Raydeus's Avatar
 
Join Date: May 2006
Location: Fenrir Server
Posts: 4,100
Style: Light Theme V6

Thanks: 228
Thanked 500x in 322 Posts
   
Re: New Hackings Begin ... Security Token or Not.

Quote:
Originally Posted by Mhurron View Post
Nothing saves users from themselves.
Death is salvation.








...what? <_<;

Ok, ok, I've been watching The Lost Canvas.
__________________
Sanctuary of Zi'tah!

"In this world, the one who has the most fun is the winner!" C.B.

Prishe's Knight since 2004.

その目だれの目。
Raydeus is offline   Reply With Quote Button by Aksannyi :)
Old 08-25-2009, 12:30 AM   #15
Raidou Kuzunoha Vs. Demi-Fiend
Brass Wings of Service
 
Omgwtfbbqkitten's Avatar
 
Join Date: May 2006
Location: Windurst
Posts: 6,798
Style: Light Theme V7

Thanks: 208
Thanked 2,097x in 1,142 Posts
My Mood:
Send a message via Skype™ to Omgwtfbbqkitten
   
Re: New Hackings Begin ... Security Token or Not.

You mean if I download all these crazy plug-ins for Windower that I don't know are trustworthy or not, I might get session hacked? Shit, I'll delete all that stuff right now.

Oh, wait, I play on PS2.

Each new security scare is always the same, someone got "hacked" when in reality they didn't secure their PC well or trust the wrong people with their information. And its always SE's fault, never the user's fault.

Because this is the internet, where everyone is always right.
__________________


Sig by Ragman of the LBR Fan Art Forum
Omgwtfbbqkitten is offline   Reply With Quote Button by Aksannyi :)
The Following 6 Users Say Thank You to Omgwtfbbqkitten For This Useful Post:
AngelX (09-02-2009), Auron517 (08-30-2009), Electricity Gone Human (09-07-2009), Kailea (08-25-2009), Ketaru (08-25-2009), Yellow Mage (08-25-2009)
Post New Thread Reply

Tags
begin, hackings, security, token

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -8. The time now is 11:53 AM.
Site Powered by: vBulletin Version 3.8.1 Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.0 RC2
©2001-2009 SQUARE ENIX CO., LTD. All Rights Reserved. Title Design by Yoshitaka Amano.
FINAL FANTASY and VANA'DIEL are registered trademarks of Square Enix Co., Ltd. SQUARE ENIX, PLAYONLINE and the PlayOnline logo are trademarks of Square Enix Co., Ltd.
Comments and posts are property of their authors. All the rest, including video, articles, compiled game data, and sections, unless otherwise noted, are
©2002-2009 FFXIOnline.com: Dreams in Vana'diel. All rights reserved.

no new posts
Page generated in 0.53840 seconds with 25 queries