rev6 is *******

A place for general discussion about Silkroad Online. Talk about the game or ask questions. Please keep threads Silkroad Online related.
Sylhana
Veteran Member
Posts: 3467
Joined: Tue Mar 06, 2007 8:05 am
Quick Reply: Yes
Location: Babel

Post by Sylhana »

_SomeOne_ wrote:well remeber the expliot alll u needed is the ID and SQ right... so if u knew the ID and u find out the SQ and if ur SQ is easy then ur .....?


Before joymax.com, you needed to know the account's email before you could input a secret answer. But still, getting this wasnt always impossible.

darkmaster21 wrote:Same here, everyone in going crazy for no reason. Any website reveals the Secret Question...how else would you know what to answer to obtain your password you forgot?


Exactly :).

Unless this is exploitable, I wouldnt worry much. Hopefully JM would get their act together to prevent future exploits on they site.
<<banned from SRF for bot support. -SG>>

User avatar
h33r0yuy
Common Member
Posts: 133
Joined: Mon Mar 12, 2007 9:54 am
Quick Reply: Yes
Location: Venice

Post by h33r0yuy »

oh yeah, another thing. rev6 just links to the same java function on jm's site that fetches the secret question. they didnt even use their own method/code. the point of that link in rev6 completely escapes me.


edit:

so they added some text to it. whoever that guy is says that he doesnt like that you can now get the question with only the id, instead of needing both id and email.

i somewhat agree, it'd be nice to need the email address to see the question, just as an added layer of security, but i dont see at all why its necessary.

i think im just gonna shut up now.
Last edited by h33r0yuy on Thu Dec 20, 2007 7:08 am, edited 1 time in total.
Image
I'll need to update this someday ^

User avatar
sama98b
Frequent Member
Posts: 1428
Joined: Thu Feb 22, 2007 2:32 am
Quick Reply: Yes
Location: Aege

Post by sama98b »

I think you all missing the point here.

Does rev6 do the account name/secret question in real time from jm website.

Code: Select all

<p>
<form method="post" action="https://portalcp.joymax.com/member/getSecretQuestion.jmx">
  <font color=red><b>Silkroad Account name</b></font> <input type="text" name="userID" value="morningdew">

  <input type="submit" value="Find This Account Secret Question">
</form>
</p>


OR
Already had a database with all the account names.

If it has all the account names then it has a database Account Name -> Character name, linked to them.

They got a big database there and a lot of time on their hands.
Since it updating automatically, no work to do with it most time.

My best guess:

Rev6 staff = JoymaxFanClub

ps.:
Rev6 is hosted in the usa.

United States Orem Bluehost Inc
RAbuseHandle: NOC2320-ARIN
RAbuseName: Network Operations Center
RAbusePhone: +1-801-765-9400
RAbuseEmail: abuse@bluehost.com

Rev6 should read up on the new patriot act b4 setting up server and locating in the usa ...

So if you get pissed on rev6 you know where to mail ^^
Be straight be proud of it, don't end up like them:
Image

User avatar
h33r0yuy
Common Member
Posts: 133
Joined: Mon Mar 12, 2007 9:54 am
Quick Reply: Yes
Location: Venice

Post by h33r0yuy »

if you use something to view the page info, you'll see that the button simply links to joymax's retrieval function. rev6 has no database of acct names.

Image
Image
I'll need to update this someday ^

User avatar
sama98b
Frequent Member
Posts: 1428
Joined: Thu Feb 22, 2007 2:32 am
Quick Reply: Yes
Location: Aege

Post by sama98b »

Yes but are they hiding something else with that ?
Be straight be proud of it, don't end up like them:
Image

User avatar
h33r0yuy
Common Member
Posts: 133
Joined: Mon Mar 12, 2007 9:54 am
Quick Reply: Yes
Location: Venice

Post by h33r0yuy »

no, you showed the code yourself, its just a link. goes straight to jm's site.

if it linked to some rev6 or other url id say it wasnt safe. im still not going to use it....

but still. all he did was link to the function on jm's site.
Image
I'll need to update this someday ^

User avatar
phulshof
Frequent Member
Posts: 1137
Joined: Fri Apr 21, 2006 10:36 am
Quick Reply: Yes
Location: Troy
Contact:

Post by phulshof »

h33r0yuy wrote:
_SomeOne_ wrote:well remeber the expliot alll u needed is the ID and SQ right... so if u knew the ID and u find out the SQ and if ur SQ is easy then ur .....?


a. the exploit doesnt work anymore.

b. you need the ANSWER, not the question. youve been able to know a SQ for years if you knew the id...


Actually, no.. you needed the id AND the account's email before you would get the secret question. It may not be exploitable at this moment, but people can start to gather a rather large database of information that may be used with the next exploit.
[88] Vivace
Pure INT Bard/Cleric, Bard 88, Cleric 88

[83] Pinokkio
Pure INT Force Nuker, Force 83, Cold 83, Lightning 83, Fire 60

[81] Sybian
Pure INT KD Nuker, Bicheon 81, Cold 81, Lightning 81, Fire 60

User avatar
h33r0yuy
Common Member
Posts: 133
Joined: Mon Mar 12, 2007 9:54 am
Quick Reply: Yes
Location: Venice

Post by h33r0yuy »

ur right, i remember now. i wouldnt say theres much if any risk here though. it'd be nice if they hid the answer till the email addy was put in though.
Image
I'll need to update this someday ^

User avatar
MrBow
Ex-Staff
Posts: 2979
Joined: Sun Jan 07, 2007 9:57 am
Quick Reply: Yes
Location: Playin' Talkin'

Post by MrBow »

lol i entered just a random asnwer when i created my acc, i don't even know my secret answer :P [size=0]yes i know i'm farked when i forget my pw :wink: [/size]
Image


Niyoke wrote:err i know ium soudning weird but .. Mr Bow is my p.e teacher .. ARE YOU MR BOW? LMAO ?

User avatar
dizzie38
Common Member
Posts: 127
Joined: Fri Aug 31, 2007 1:23 pm
Quick Reply: Yes
Location: london

Post by dizzie38 »

lol morning dues secret question is ur birthplace

User avatar
iGod
Veteran Member
Posts: 3728
Joined: Wed Oct 11, 2006 11:22 pm
Quick Reply: Yes
Location: Off Topic

Post by iGod »

h33r0yuy wrote:https://www.joymax.com/portal/Joymax_Front.jmx?workURL=https://portalcp.joymax.com/member/member_find_idpw.jmx&returnURL=http://www.joymax.com/portal/Joymax_Front.jmx?workURL=http://portalcp.joymax.com/

go here. type any id you want, click ok!, and it shows the question.



rev6 isnt providing any info that you cant find from jm's site with that feature.

however, i dont get why that exists if you can do the same thing from jm's site.


You type in your id just to try it out...they get your id :/

User avatar
DrWicked
Common Member
Posts: 184
Joined: Sat Dec 01, 2007 3:15 pm
Quick Reply: Yes
Location: Xian

Post by DrWicked »

Now you need secret answer and email so dont worry guys no more hacking i think.
xaxaaaxa

User avatar
Casey613
Addicted Member
Posts: 2926
Joined: Thu Jul 26, 2007 6:36 pm
Quick Reply: Yes
Location: Somewhereee

Post by Casey613 »

Rev is now being retarded..
<<Puff, bye>>

User avatar
NuclearSilo
Forum God
Posts: 8834
Joined: Mon Aug 21, 2006 12:00 pm
Quick Reply: Yes
Location: Age of Wushu

Post by NuclearSilo »

iGod wrote:
h33r0yuy wrote:https://www.joymax.com/portal/Joymax_Front.jmx?workURL=https://portalcp.joymax.com/member/member_find_idpw.jmx&returnURL=http://www.joymax.com/portal/Joymax_Front.jmx?workURL=http://portalcp.joymax.com/

go here. type any id you want, click ok!, and it shows the question.



rev6 isnt providing any info that you cant find from jm's site with that feature.

however, i dont get why that exists if you can do the same thing from jm's site.


You type in your id just to try it out...they get your id :/

Type your ID there, then it will be secretly stored in their website :S

Oh shit ~ i typed my ID :shock: :banghead:

Dont blame anyone if u get hacked that way. :D
Playing Age of Wushu, dota IMBA

User avatar
shoto
Frequent Member
Posts: 1459
Joined: Sun Oct 08, 2006 10:54 pm
Quick Reply: Yes
Location: Alps
Contact:

Post by shoto »

what?

i don't see how this compromises your account. At the point where they know your secret question, you're already f*ked (i.e. they must know your username)
Image

Mysterious Death Desert
Mysterious desert that causes mysterious deaths

User avatar
darkmaster21
Ex-Staff
Posts: 2156
Joined: Sun Jul 15, 2007 3:11 am
Quick Reply: Yes
Location: Off Topic

Post by darkmaster21 »

NuclearSilo wrote:
iGod wrote:
h33r0yuy wrote:https://www.joymax.com/portal/Joymax_Front.jmx?workURL=https://portalcp.joymax.com/member/member_find_idpw.jmx&returnURL=http://www.joymax.com/portal/Joymax_Front.jmx?workURL=http://portalcp.joymax.com/

go here. type any id you want, click ok!, and it shows the question.



rev6 isnt providing any info that you cant find from jm's site with that feature.

however, i dont get why that exists if you can do the same thing from jm's site.


You type in your id just to try it out...they get your id :/

Type your ID there, then it will be secretly stored in their website :S

Oh shit ~ i typed my ID :shock: :banghead:

Dont blame anyone if u get hacked that way. :D


Look what I posted on the first page:

darkmaster21 wrote:I'm not entering my ID in there, they might have a log of all the ID's entered. Then bruteforce the account.


:banghead:
Image

cSRO / Division 2 / Pure STR Bow / Lv 65

User avatar
ScZz
Common Member
Posts: 141
Joined: Fri Mar 23, 2007 1:27 pm
Quick Reply: Yes
Location: somewhere over the rainbow

Post by ScZz »

joymax is looking more retarded from day to day.. no wait , they already are overretarded :banghead:
Tibet

Blasjr
Common Member
Posts: 182
Joined: Wed Oct 24, 2007 6:21 pm

phulshof ....

Post by Blasjr »

Actually, no.. you needed the id AND the account's email before you would get the secret question. It may not be exploitable at this moment, but people can start to gather a rather large database of information that may be used with the next exploit.

phulshof, you're the only one that got it right! :-)

U guys dont get it, Do you? Hackers have the exploits cause they're either disgrunteled employees, or JM entrusted their Website Code to ppl who need to work for them (out sourcing), to upgrade, add, delete functions, etc etc. I for one (and think the rest of you should as well), feel a bit uncorfortable, knowing that any site REV6 particularly, can have access and post my gear, wep. etc. Its meant to be secret, why else would they do it, unless is to set you up? Exploits are not done, look at Microsoft and their constant patchings to XP (all of them!), you cant stop it.

Right now hackers are looking for the next exploit, to wipe you out. Make a mule account transfer your shit to it every night. Remember REV6 only shows you the gear, wep. you wear. A mule account cant wear it! Its safe

Peace

User avatar
heroo
Forum Legend
Posts: 6618
Joined: Sat Sep 30, 2006 12:56 pm
Quick Reply: Yes
Location: Off Topic

Post by heroo »

don't blame rev6.

blame JOYMAX
''When I die, make sure they bury me upside down, so that the world can kiss my ass.''

User avatar
ArchYourFace
Active Member
Posts: 638
Joined: Tue Oct 09, 2007 2:11 pm
Quick Reply: Yes
Location: Venus

HELLO!

Post by ArchYourFace »

:!: :!: :!: :!: :!: :!: :!: :!: :!: :!: :!: :!:
Um ok, you remember the method rev6 said was used to aquire usernames in the first place, in order that they may be hacked?

If not ill reittereate: go to the forum and type anything in, and any random password. Then it would say one of 2 things. It would say, not an account, would you like to make one(and buy silk please), or wrong password try again douche.

Same concept here. If you type in a random user name, it can be confirmed that it IS infact a valid user name via this method. Its exactly the same. The email addy SHOULD be required. Wrap your head around that for a minute.


thats why whats his face up there was like "i think i know your id, can i guess?" cuase he found a valid username via this method.
:!: :!: :!: :!: :!: :!: :!: :!: :!: :!: :!: :!:

User avatar
BalkanFanaticS
Active Member
Posts: 768
Joined: Fri Nov 02, 2007 10:54 pm
Quick Reply: Yes
Location: Greece

Post by BalkanFanaticS »

h33r0yuy wrote:ie why i didnt stick my id into rev6, lol

NuclearSilo wrote:Type your ID there, then it will be secretly stored in their website :S

Oh shit ~ i typed my ID :shock: :banghead:

Dont blame anyone if u get hacked that way. :D



too bad nymble(rev6) already has a copy of the full id database back from a year due to an old forum bug(blame joymax) .

sure he rly needs YOUR id :wink:
<< banned for selling characters. -cin >>

/Pi
Senior Member
Posts: 4590
Joined: Fri May 18, 2007 3:49 am
Quick Reply: Yes
Location: Off Topic

Post by /Pi »

You guys are retarded. Hundreds of websites do this - even the popular ones like Gmail.

Chillax. Just follow the best instruction here: don't even bother going to Rev6.

User avatar
F-22
Active Member
Posts: 755
Joined: Fri Aug 10, 2007 2:31 pm
Quick Reply: Yes
Location: Making out with Crystal Liu Yi Fei

Post by F-22 »

if you guys really want to make your account safer then make an email address that does not exist. That way no one can trace your email address, if something do no exist then it can not be found. Most of the people who got hacked are people who share accounts and give out their email addresses to friends, and people who buy other people's character online.
Image
Guild: KnightsofTyr
Build: Pure Kickass
Occupations: Hunter and Guild Master
HUNTER FOR LIFE

User avatar
PileOfMush
Valued Member
Posts: 456
Joined: Mon Jun 04, 2007 8:55 pm
Quick Reply: Yes
Location: Venus

Post by PileOfMush »

F-22 wrote:if you guys really want to make your account safer then make an email address that does not exist. That way no one can trace your email address, if something do no exist then it can not be found. Most of the people who got hacked are people who share accounts and give out their email addresses to friends, and people who buy other people's character online.


Before this new joymax.com/portal site came to be, I'd have agreed with you, but now this ISN'T the best way. Joymax keeps changing things, and one day you're going to be locked out of your own account because they suddenly decide you can ONLY change your password if you have access to the email account you gave them.

They should have just taken the time to get this whole account security thing right from the beginning and it wouldn't be such a big mess. Designing secure web forms and pages that provide secure dynamic content is not exactly simple and obvious, but that's why e-commerce companies (which I'd say JMax is because they take e-payments for a product) hire experienced developers and don't just throw something together that barely works.
Venus: Crush
Oasis: BuryMe

User avatar
Genocide
Regular Member
Posts: 219
Joined: Sun Mar 18, 2007 1:40 am
Quick Reply: Yes
Location: ROME

..

Post by Genocide »

i got my account hacked before and i know the id and secret question and answer but not the email is there anyway i can get my account back??????

User avatar
thAi
Active Member
Posts: 891
Joined: Thu May 10, 2007 3:24 am
Quick Reply: Yes
Location: Off Topic

Post by thAi »

We Are Doomed
Image

User avatar
magisuns
Veteran Member
Posts: 3303
Joined: Mon Apr 09, 2007 12:33 am
Location: パズドラ

Post by magisuns »

MAUHAAHAHAHAHAHAH MUHAAHAHAHAHAHAH I'M NOT DOOMED xD AHAHAHAHAAAHAH ^^ I LOVE U JM SOOOO MUCH =)
THEY PUT MY ID UNDER A DIFFERENT NAME xD ie if my id wuz... idk.. citrus.. jm is showing ctiirus xD gotta love their oddness cuz now apparently thats my id :P evenn though u cant log in with it... hackers are pwn from my acc (^^)V ... did this happen 2 n e one else?

User avatar
Braka
Frequent Member
Posts: 1369
Joined: Fri Oct 12, 2007 11:45 am
Quick Reply: Yes
Location: AEGE

Post by Braka »

Stop being paranoid and go play the game jeez , its like ur preying for someone to hack ur account so u can leave the game :x

Blasjr
Common Member
Posts: 182
Joined: Wed Oct 24, 2007 6:21 pm

I have 1 more idea

Post by Blasjr »

Lets go https: :banghead: JM.COM goes https in order to protect your info plus paypal acc. Incorporates safety, by doing all checks: Verification Code to your email address, your secret answer (to your not so secret Question), and entering your Current PW. Im surprised no 1 has thought about hacking paypal thru the JM website...ummmm maybe they're working on it! Possibly cause paypal is encrypted, they cant get in? Move to have JM do same! 8)

Be honest w you, I think they want ppl to get hacked so you can buy more silk in rebuilding! I did the opposite, I'm hurting them. Just remember, 1 day Blizzard/'Activision, releases a new supped up MMORP game (Starcraft II), or WoW IV (for free w/Credit buy system like Trickster), you know what happens to JM? Goes belly up, lost all your Pixels. Think about this, each server is maxed out daily by GOLD BOTS not real players, its their busines right? Well JM is in business to make KRW's frnds, never has nor will take care of the Legit players. No Corporate responsibility to the real guys. What for? To lose money? Ha...
I saw it first hand. I don't respect Company that doesn't respect my privacy as a player and my security of what I'm paying for.

Peace

User avatar
Swindler
Forum God
Posts: 11256
Joined: Tue Apr 10, 2007 7:49 am
Quick Reply: Yes
Location: Pimpas Paradise.

Post by Swindler »

never trusted rev6...

Post Reply

Return to “Silkroad General Discussion”