New Hacker Found...

Langues: JP EN DE FR
users online
Forum » FFXI » General » New hacker found...
New hacker found...
 Carbuncle.Axle
Offline
Serveur: Carbuncle
Game: FFXI
user: Zephin
Posts: 742
By Carbuncle.Axle 2010-03-11 16:44:17
Link | Citer | R
 
Caitsith.Iphone said:
Carbuncle.Xandor said:
Caitsith.Iphone said:
I was too cheap to spend 10$ on a token, and now I'm justifying that by calling everyone who did buy one stupid

Nice fix on the quote there, I'm by no means calling anyone stupid who bought a Token. All I'm saying is it's not needed at all.

You've never been hacked i guess.
 Shiva.Weewoo
Offline
Serveur: Shiva
Game: FFXI
Posts: 3323
By Shiva.Weewoo 2010-03-11 16:47:42
Link | Citer | R
 
Some peace of mind and a mog satchel is worth $10 to me.
[+]
 Carbuncle.Axle
Offline
Serveur: Carbuncle
Game: FFXI
user: Zephin
Posts: 742
By Carbuncle.Axle 2010-03-11 16:52:15
Link | Citer | R
 
How long till other MMO's follow ffxi with security tokens.
 Ragnarok.Doluka
Offline
Serveur: Ragnarok
Game: FFXI
user: Doluka
Posts: 252
By Ragnarok.Doluka 2010-03-11 16:52:55
Link | Citer | R
 
Shiva.Weewoo said:
Some peace of mind and a mog satchel is worth $10 to me.
[+]
 Garuda.Hypnotizd
Offline
Serveur: Garuda
Game: FFXI
user: hypnotizd
Posts: 2400
By Garuda.Hypnotizd 2010-03-11 17:15:03
Link | Citer | R
 
Carbuncle.Axle said:
How long till other MMO's follow ffxi with security tokens.
FFXI followed other MMOs in getting them.
http://en.wikipedia.org/wiki/World_of_warcraft#Security_concerns said:
In June 2008, Blizzard announced the Blizzard Authenticator, a hardware security token that provides two factor security. The token generates a one-time password based code that the player supplies when logging on. The password is only valid for a limited time, thus providing extra security against keylogging malware.[86]

SE got theirs April 6, 2009
 Gilgamesh.Minusseven
Offline
Serveur: Gilgamesh
Game: FFXI
Posts: 1096
By Gilgamesh.Minusseven 2010-03-11 18:24:46
Link | Citer | R
 
Garuda.Hypnotizd said:
Carbuncle.Axle said:
How long till other MMO's follow ffxi with security tokens.
FFXI followed other MMOs in getting them.
http://en.wikipedia.org/wiki/World_of_warcraft#Security_concerns said:
In June 2008, Blizzard announced the Blizzard Authenticator, a hardware security token that provides two factor security. The token generates a one-time password based code that the player supplies when logging on. The password is only valid for a limited time, thus providing extra security against keylogging malware.[86]
SE got theirs April 6, 2009
I paid for one about 6-7 months ago, never got it.
 Odin.Zicdeh
Offline
Serveur: Odin
Game: FFXI
Posts: 6558
By Odin.Zicdeh 2010-03-11 18:40:15
Link | Citer | R
 
Lakshmi.Holman said:
Ramuh.Kalyna said:
Holman: did they deactivate the token so they don't have to use it to log in? (which is a dumb-as hell idea) i know ppl who do that and only got the token for the statchel.
Nope, the token code stays registered for 15 Min's I think. If a hacker has that trojan that records real time key strokes, then yea it's possible for them to get in.


Edit: This Se token isn't like the corporate one many folks have. The old code stays registered on the sytem for a while.

The real way to hack a security token is to implant a trojan that is essentially a fake login screen. You enter the token code, and even if right, it will say it's wrong. The Receiving hacker then has the POL password and the Token password, and can immediately log in. That's just a broad stroke of how the token hacking goes. It's a lot more intricate than that, at least in the details. World of Warcraft security tokened accounts get hacked all the time through that means. It's very hard, but very possible.

 Asura.Nkai
Offline
Serveur: Asura
Game: FFXI
user: Nkai
Posts: 7
By Asura.Nkai 2010-03-11 19:19:50
Link | Citer | R
 
Gilgamesh.Minusseven said:
Garuda.Hypnotizd said:
Carbuncle.Axle said:
How long till other MMO's follow ffxi with security tokens.
FFXI followed other MMOs in getting them.
http://en.wikipedia.org/wiki/World_of_warcraft#Security_concerns said:
In June 2008, Blizzard announced the Blizzard Authenticator, a hardware security token that provides two factor security. The token generates a one-time password based code that the player supplies when logging on. The password is only valid for a limited time, thus providing extra security against keylogging malware.[86]
SE got theirs April 6, 2009
I paid for one about 6-7 months ago, never got it.

Same problem here. Called them (finally) and they claimed that they were unable to deliver it(for some unknown reason) and said they would resend our token. 3 months later, repeat process. 1 month after that, repeat with a different address(apparently UPS says my home doesnt exist so we gave them the address to a UPS store in town). 3 weeks later.... same thing. We called them up and they had some bizaar address listed for us. *bangs head on wall* On to attempt 5. Makes me wonder if they have some of those RMT working in their sales center. 'www.Br8.... (8=0)' morons....

Keep bugging em, if they are un-helpful, request to speak to someone higher up. Complain... alot. Be polite but make its understood that they charged you for a product you never received. (we were charged for ours months before they ever tried to ship it, which is pretty illegal if i remember correctly >.> )

Hopefully this time we actually get it, tho im not holding my breath.

 Caitsith.Iphone
Offline
Serveur: Caitsith
Game: FFXI
user: Imola
Posts: 32
By Caitsith.Iphone 2010-03-11 20:25:51
Link | Citer | R
 
Idk buying a token that gives a bit more security + 80 more inventory space defeats the whole purpose of paying for a monthly MMO game.

It's just like playing one of those free MMO games you can play it, level it, but life is a lot more easier if you buy form their online store hence "more invetory space, sure give us $10 USD and there you go.

If anything SE should have just given Tokens to all players with accounts to tighten up their security. I'm telling you it's just to get your money even a measly $10 can add up to a alot. Mind you there's still a good +1000 playing per server lets just say each baught one that's $10,000 and lets say they did make them for $1 each so they just gained a whopping $9,000. That's not even including people that baught more than 1, and that's just for one server. Think about it.
 Diabolos.Torazalinto
Offline
Serveur: Diabolos
Game: FFXI
Posts: 90
By Diabolos.Torazalinto 2010-03-12 00:31:37
Link | Citer | R
 
EDIT: Quote didn't work. >_>

I think you misunderstood me. I was saying that the idea that a single password ONCE ENTERED is active for 15 minutes is absolutely ludicrous and would make the tokens a sham. Every number is good for 60 seconds. The tokens are valuable and I use them. I wasn't saying that they were a sham I was telling the person ahead of me that what he said was ridiculous.

 Ragnarok.Doluka
Offline
Serveur: Ragnarok
Game: FFXI
user: Doluka
Posts: 252
By Ragnarok.Doluka 2010-03-12 09:31:16
Link | Citer | R
 
Square Enix is a huge corporation...9 or 10 thousand dollars to them is chump change >.>
 Garuda.Hypnotizd
Offline
Serveur: Garuda
Game: FFXI
user: hypnotizd
Posts: 2400
By Garuda.Hypnotizd 2010-03-12 10:15:11
Link | Citer | R
 
Diabolos.Torazalinto said:
EDIT: Quote didn't work. >_>

I think you misunderstood me. I was saying that the idea that a single password ONCE ENTERED is active for 15 minutes is absolutely ludicrous and would make the tokens a sham. Every number is good for 60 seconds. The tokens are valuable and I use them. I wasn't saying that they were a sham I was telling the person ahead of me that what he said was ridiculous.
I reread what the person you quoted said. He said it correctly. The numbers on the token do change every 30 seconds to a new value, but the previous numbers it has generated are still good for up to 15 minutes after it has been displayed. Once you enter that code it and all previous codes before it can no longer be used.

Edit: I still think I read somewhere it was 30 minutes, though. I'll have to try it some time.
 Diabolos.Torazalinto
Offline
Serveur: Diabolos
Game: FFXI
Posts: 90
By Diabolos.Torazalinto 2010-03-13 00:49:58
Link | Citer | R
 
I highly doubt that they're good for up to 15 minutes since I've entered a number after the 60 second mark and it wouldn't log me in.
 Carbuncle.Zanno
Offline
Serveur: Carbuncle
Game: FFXI
user: zanno
Posts: 2849
By Carbuncle.Zanno 2010-03-13 13:13:15
Link | Citer | R
 
Carbuncle.Zanno said:

I've never given out my info to anyone, but I've had ppl giving their info to me.

ops, I lied. I have given my mule account to lots of ppl, probably like 10 different ppl lol. I only have a RDM 75 and a few 100k on that account anyway, so it wouldnt be a big deal if i lost it. I've let several ppl use that account how ever they wanted in order to see if they were intrested enough in the game to start playing.
 Caitsith.Neonracer
Offline
Serveur: Caitsith
Game: FFXI
user: Neonracer
Posts: 2748
By Caitsith.Neonracer 2010-03-13 13:27:42
Link | Citer | R
 
Just don't surf weird sites, and be pre " Oldskool " about your surf habits..

Token or not... same thing above applies... just watch your surfing habits and don't pass info to friends.

and make sure your anti virus programs are legit or real, meaning you didnt DL a copy from Bit torrent and said you got it free..


Sometimes Free, can get land you into trouble with added spyware...

/comfort.. just be careful.
[+]
 Asura.Ericka
Offline
Serveur: Asura
Game: FFXI
user: foxxie
Posts: 703
By Asura.Ericka 2010-03-13 13:52:50
Link | Citer | R
 
having a complex PW helps too. a lot of ppl that play this game and others have VERY easy PWs. an Alpha-numeric password helps also. a PW that's not associated with your real name POL ID or anything related to you works well.



Not giving out your PW and info always work best.
[+]
Log in to post.