hack attack?

A place for general discussion about Silkroad Online. Talk about the game or ask questions. Please keep threads Silkroad Online related.
User avatar
xMoDx
Valued Member
Posts: 456
Joined: Tue May 30, 2006 6:50 am
Quick Reply: Yes
Location: Xian
Contact:

Post by xMoDx »

0Kelvin wrote:I'm trying to change my password, but when I enter my details and click "change pw" I get directed to a blank page. Anyone else have this problem? :?


check:

1) Update IE
2) Clear Cache
3) Remove Cookies

Restart Browser

If still blank u need to get your pc a customer support personel

User avatar
PR0METHEUS
Senior Member
Posts: 4093
Joined: Tue Aug 22, 2006 7:30 pm
Quick Reply: Yes
Location: Earth
Contact:

Post by PR0METHEUS »

0Kelvin wrote:I'm trying to change my password, but when I enter my details and click "change pw" I get directed to a blank page. Anyone else have this problem? :?


Are you possibly using Firefox? Silkroad's website is designed for Internet Explorer. Try using IE to change your password. I ran into the same problem myself with Firefox. I assume Opera and others would do the same.

Sorry if someone else already answered this below your post.
Missing the good times in SRO... :love:

SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)

User avatar
Darkangel
Regular Member
Posts: 268
Joined: Sat Sep 30, 2006 9:09 pm
Quick Reply: Yes
Location: babel

Post by Darkangel »

LoL its sad that when u play agame you worry about getting hacked from a simple party invite.
IGN - DarkAngel
Build - Hybrid spear nuker
Guild - BestO7heBest
lvl - 64

RETIRED!! *WoW FtW*

User avatar
PR0METHEUS
Senior Member
Posts: 4093
Joined: Tue Aug 22, 2006 7:30 pm
Quick Reply: Yes
Location: Earth
Contact:

Post by PR0METHEUS »

Karlos Vandango wrote:o could someone find out how many differnt combinations u could have in a 12 number password and a 12 letter password (no numbers)


Well 12 characters is a pretty good length to make a secure password:

- A 12 number password has 10^12 = 1,000,000,000,000 (1 trillian) possible combinations.
- A 12 letter (no numbers) password has 26^12 = 95,428,956,661,682,176 possible combinations.

Yes, a brute forcing program will eventually crack passwords of this length, but it will take some time.
Missing the good times in SRO... :love:

SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)

User avatar
zrabbit
Common Member
Posts: 146
Joined: Fri Nov 03, 2006 7:48 pm
Quick Reply: Yes
Location: Athens

Post by zrabbit »

PR0METHEUS wrote:
Karlos Vandango wrote:o could someone find out how many differnt combinations u could have in a 12 number password and a 12 letter password (no numbers)


Well 12 characters is a pretty good length to make a secure password:

- A 12 number password has 10^12 = 1,000,000,000,000 (1 trillian) possible combinations.
- A 12 letter (no numbers) password has 26^12 = 95,428,956,661,682,176 possible combinations.

Yes, a brute forcing program will eventually crack passwords of this length, but it will take some time.

even at 1000 tries per sec it would take many years to try only a 10% of the posible convinations and i think 1000 per second needs a really heavy pc with a powerfull connection.
im asking myself this after reading the thread, does the silkroad server allows 100 tries without blocking the ip and the account?. if it does... well it proves my theory that joymax is hiring trained monkeys for their network security
(\__/)
(='.'=) This is Bunny. Copy and paste bunny into your
(")_(") signature to help him gain world domination.
and the name of the next joymax game is...:"We apologize for the problems this may have caused."

User avatar
Troo
Valued Member
Posts: 487
Joined: Fri Jun 16, 2006 1:02 pm

Post by Troo »

True.. and llike I said if you combinate numbers+letters it will be 26^12+10^12=36^12 = gl brute force that. What alot forget is that it is usefull to do the same for your secret question.

And ofcourse, get a good anti-virus program.. and an 'ok' firewall and you should be pretty save. Ofcourse no-one can garantee it.. but neither can anyone that the world won't get hit by a meteor tomorrow. Just take the needed precousions and have fun. After all that is where this game is all about.
Do not write stupid,when somebody loses.l lik the game myself but my 6jears old kid,who like to play games so much,has refuse to play,bcos of that word.Pls write something abit funny.l hope you consider my suggestion.Thank you and God bless you.
lol

User avatar
PR0METHEUS
Senior Member
Posts: 4093
Joined: Tue Aug 22, 2006 7:30 pm
Quick Reply: Yes
Location: Earth
Contact:

Post by PR0METHEUS »

zrabbit wrote:im asking myself this after reading the thread, does the silkroad server allows 100 tries without blocking the ip and the account?. if it does... well it proves my theory that joymax is hiring trained monkeys for their network security


Well, block the offending IP, don't block the account. Otherwise if you wanted to get someone banned, just brute force their account. I don't know what Joymax's policy is, but I doubt they'd block an account because someone tried to brute force it.
Missing the good times in SRO... :love:

SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)

User avatar
PR0METHEUS
Senior Member
Posts: 4093
Joined: Tue Aug 22, 2006 7:30 pm
Quick Reply: Yes
Location: Earth
Contact:

Post by PR0METHEUS »

Troo wrote:True.. and llike I said if you combinate numbers+letters it will be 26^12+10^12=36^12 = gl brute force that. What alot forget is that it is usefull to do the same for your secret question.

And ofcourse, get a good anti-virus program.. and an 'ok' firewall and you should be pretty save. Ofcourse no-one can garantee it.. but neither can anyone that the world won't get hit by a meteor tomorrow. Just take the needed precousions and have fun. After all that is where this game is all about.


Good idea, I never thought of that for the secret question.
Missing the good times in SRO... :love:

SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)

User avatar
Ishagmuro
Regular Member
Posts: 230
Joined: Fri Oct 27, 2006 3:56 pm
Quick Reply: Yes
Location: Athens

Post by Ishagmuro »

Just... Don`t give your username or password to anybody

That`s all , then , use a very very nice and updated antivus, and check your PC often.

And, care with your friends when they use your PC 8)

User avatar
zrabbit
Common Member
Posts: 146
Joined: Fri Nov 03, 2006 7:48 pm
Quick Reply: Yes
Location: Athens

Post by zrabbit »

PR0METHEUS wrote:
zrabbit wrote:im asking myself this after reading the thread, does the silkroad server allows 100 tries without blocking the ip and the account?. if it does... well it proves my theory that joymax is hiring trained monkeys for their network security


Well, block the offending IP, don't block the account. Otherwise if you wanted to get someone banned, just brute force their account. I don't know what Joymax's policy is, but I doubt they'd block an account because someone tried to brute force it.

the problem with blocking the ip its that most of the brute programs use proxys (if not all (i know this cause i used some to try to enter porn sites with them a long time ago)). i know yahoo and many other sites block the account temporaly and ask the users to change their password. its true, if someone wants to block an account can use this as an exploit... i dont know if theres another solution running around for this kind of problem
ps.: i never could enter to a porn site with those programs. for 3 reassons mainly: 1.: luck of discipline, 2.: crappy conection (in those days i used to have dial up), 3.: luck of pc power (my lil pentium wasnt brute enought to get that stuff running right)
(\__/)
(='.'=) This is Bunny. Copy and paste bunny into your
(")_(") signature to help him gain world domination.
and the name of the next joymax game is...:"We apologize for the problems this may have caused."

User avatar
Manowar
Ex-Staff
Posts: 2150
Joined: Fri Sep 08, 2006 9:30 pm
Location: にニニコ
Contact:

Post by Manowar »

Jay wrote:Well, someone from my clan got hacked he neither used this forum or the official one, never botted, din't have a wea kpassword or had any spyware on his computer, he just got hacked, like the post above me said theres no safety in sro. What annoy's me even more is that joymax doesn't even do anything about acc's getting hacked, you loose it it's gone, at least it was just a person who just stripped him and din't actualy change the details so he got it back, but still..


Ive had guildmates that got hacked the same way. If its the member i think you're talking about, i only recently heard of how she got hacked which really suks.
Image
Image

User avatar
BoyrIIng
Casual Member
Posts: 50
Joined: Mon Nov 13, 2006 4:04 am
Quick Reply: Yes
Location: Troy

Post by BoyrIIng »

change ur pass.
Server: Troy
ID: hotair
lvl: 6X.. 11.53 %
Build: Pure STR
Guild: DIVINITY.. lvl5
Job: Thief & Trader

User avatar
Manowar
Ex-Staff
Posts: 2150
Joined: Fri Sep 08, 2006 9:30 pm
Location: にニニコ
Contact:

Post by Manowar »

BoyrIIng wrote:change ur pass.


I said guildmates. I change mine on a 5-7 day basis.
Image
Image

tyfly
Active Member
Posts: 826
Joined: Fri Jul 21, 2006 11:29 pm
Quick Reply: Yes
Location: Troy
Contact:

Post by tyfly »

but wouldn't you rather be safe than sorry?
<<banned from SRF for bot admission. -SG>>

User avatar
PR0METHEUS
Senior Member
Posts: 4093
Joined: Tue Aug 22, 2006 7:30 pm
Quick Reply: Yes
Location: Earth
Contact:

Post by PR0METHEUS »

Sazer wrote:
Aya wrote:did you accept any party or echange from a stranger recently?


i hate to tell you Aya but that stranger party and exchange thing is a load of shit...how are you gonna get hacked by training in a dis party with other ppl...it dont make sense but w/e and secondly ive traded to sell weapon elixers MILLIONS OF TIMES and look im still 69 and UNHACKED >.> jeez ppl


Well it does seem suspicious when I can log into the game and immediately, even before I can see any player models (including myself), I get either a party invite or an exchange request window.

Maybe the party/exchange hacking thing is false, but I can see it as a possibility at least. If an attacker is able to access Joymax's database and read records as an exchange attempt is happening between the attacker and you, he/she could possibly see your username and possibly other info to use against you.

Of course, a hacker isn't going to be able to see your password by reading records in a database (the GMs I'm sure can't even determine your password -- 1-way encryption) but there could be other information that would be useful.

Then again, if you get access to the database, you shouldn't really need to actively interact with the player you want to hack anyway. So who knows.
Missing the good times in SRO... :love:

SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)

User avatar
Musaboru
Common Member
Posts: 139
Joined: Wed Oct 25, 2006 5:56 pm
Quick Reply: Yes
Location: Oasis

Post by Musaboru »

Troo wrote:True.. and llike I said if you combinate numbers+letters it will be 26^12+10^12=36^12 = gl brute force that. What alot forget is that it is usefull to do the same for your secret question.

And ofcourse, get a good anti-virus program.. and an 'ok' firewall and you should be pretty save. Ofcourse no-one can garantee it.. but neither can anyone that the world won't get hit by a meteor tomorrow. Just take the needed precousions and have fun. After all that is where this game is all about.


I can imagine all those answers to the pet name questions: Spike, Fifi, Tofu, Buster, Buddy and even Puppy or Kitty.
Hehe.

User avatar
Demarthl
Advanced Member
Posts: 2296
Joined: Mon Jan 02, 2006 8:33 pm

Post by Demarthl »

yes, most of the site features don't like firefox, my girlfriend can't even register through linux+FF, she gets directed to a page saying 'use IE!' and she stabs it with a thousand wooden spoons of hate.

oh and hehe! dana scully, wow, someone an x-files fan? :3 cute

edit: x_X the post was deleted quickly/... weird
<<banned from SRF for disrespect of the mod team and rules violations. -SG>>

Tallrik
Common Member
Posts: 182
Joined: Sun Oct 22, 2006 4:09 pm

Post by Tallrik »

0Kelvin wrote:I'm trying to change my password, but when I enter my details and click "change pw" I get directed to a blank page. Anyone else have this problem? :?


The password can only be changed with Internet Explorer.
<<banned from SRF for rules violations. -SG>>

Post Reply

Return to “Silkroad General Discussion”