Page 1 of 1
"Trade or Party Hack", REAL?
Posted: Tue Dec 18, 2007 7:45 am
by fReDdArZ
Direct Hack
Commonly known as "Trade or Party Hack" in SRO, this is when hackers, using some sort of loophole in Joy Max's coding have access to all your account information when you accept a trade or party invitation from them. With those few seconds they can get the information they need to take over your account.
Possible Prevention
Although there is no definite way to prevent this, the best way to protect yourself is to simply never accept any trade invitations or random party invitations, do all your selling through stalls and only get into parties with people who your truly trust. But remember, "Greed can overcome even the noblest of people".
http://www.gkclan.com/forums/showthread.php?t=129170
______________________________________________________
I have a friend saying he got hack with this way. I dunno if its real, we are still observing his character for about 2 weeks now, nothing lost.
I searched the internet and saw this thread about this "Direct Hack" on SRO.
The only thing I know about being victim of hacking are keyloggers or telling/showing ur password. As a precaution, we all turned off our party/trade settings just to be sure.
And we dont wanna spend anymore if we will only get hacked.
Please confirm, anyone? if this is in existence.
Posted: Tue Dec 18, 2007 7:48 am
by mypride
is already been confirm..not possible.
Posted: Tue Dec 18, 2007 7:55 am
by fReDdArZ
what about the thing they say "BRUTE FORCE"?
Brute Force In cryptanalysis, a brute force attack is a method of defeating a cryptographic scheme by trying a large number of possibilities; for example, exhaustively working through all possible keys in order to decrypt a message, which basically means that a program will try for days even weeks all possible types of passwords until it finally matches one with your Username.
Posted: Tue Dec 18, 2007 7:58 am
by BuLLeTz
no such thing.
Posted: Tue Dec 18, 2007 8:02 am
by fReDdArZ
My friend, hope you see these guys telling us that it's not in existence in SRO. So why quit? Anyone, who sees this in different way?
Posted: Tue Dec 18, 2007 8:04 am
by Silver0
yeah its BS its ppl who visit those free gold sites gave out there ID and plain out scammed who get there shit taken Or extremely Easy ID
Posted: Tue Dec 18, 2007 8:08 am
by fReDdArZ
So this is really possible?

Posted: Tue Dec 18, 2007 8:13 am
by sama98b
BuLLeTz wrote:no such thing.
+1
fReDdArZ wrote:So this is really possible?

So you understand it:
Not possible
If you still don't get it:

Posted: Tue Dec 18, 2007 8:19 am
by fReDdArZ
sama98b wrote:BuLLeTz wrote:no such thing.
+1
fReDdArZ wrote:So this is really possible?

So you understand it:
Not possibleIf you still don't get it:

Silvero just said it, it is possible. Call me an idiot or noob, i just need to show this to my friend and convince him that he was not hacked. Like i said, "The only thing I know about being victim of hacking are keyloggers or telling/showing ur password." 1st post.
Posted: Tue Dec 18, 2007 8:40 am
by sama98b
fReDdArZ wrote:sama98b wrote:BuLLeTz wrote:no such thing.
+1
fReDdArZ wrote:So this is really possible?

So you understand it:
Not possibleIf you still don't get it:

Silvero just said it, it is possible. Call me an idiot or noob, i just need to show this to my friend and convince him that he was not hacked. Like i said, "The only thing I know about being victim of hacking are keyloggers or telling/showing ur password." 1st post.
Learn to read.
Silver0 wrote:yeah its BS its ppl who visit those free gold sites gave out there ID and plain out scammed who get there shit taken Or extremely Easy ID
Should I translate ?
"Yes it is bull shit, only nobs who visit the sites from the game spammers getting hacked that way who give out login id and password free willingly"
ps.:
By the way what you are talking mainly is packet catching from party/chat/trade/pvp/just looking at a char.
Nothing new rev6 doing that for age long.
It doesn't show password, just account/id/stats/hp/clothes/equipment....
Posted: Tue Dec 18, 2007 8:42 am
by Cerus
Its been confirmed that Trade Hack is possible.
But its limited to Botters only.
If you are using a bot, theres a script that allow hacker to gather your info thru trade.
If you are not using an altered client then do not worry.
Posted: Tue Dec 18, 2007 8:43 am
by Kawaii
Silver0 wrote:yeah its BS its ppl who visit those free gold sites gave out there ID and plain out scammed who get there shit taken Or extremely Easy ID
He obviously did not say that it's true. BS means it's not real. He is also saying that the people who get their passwords stolen are gold buyers, scammers, and people with really simple passwords.
Posted: Tue Dec 18, 2007 8:45 am
by sama98b
If it would be possible rev6 owners would have emptied all the characters on all the servers already ..
They using this security hole for ages as I wrote b4.
Atm. there is no security hole that would enable to take over or strip characters/accounts.
Other then some ppl stupidity to give out info by free will, alias scammed.
Posted: Tue Dec 18, 2007 8:52 am
by skandal
I just love it when idiots blaime JM loopholes for everything that happens, then this anonymous bastard comes and copy-pastes definitions from google to show us he's right...why don't u just die and leave us alone ?xD
Posted: Tue Dec 18, 2007 9:15 am
by Tribe_Rock
it`s real and possible although a very old hack, it was spread in whole union past ago
my first account (my best 2) was hacked 1 year ago with this hack and same happened to my 2 stall account, while they have unique different pw/secret answer
they all have been hacked with whole information while i have never used legal/illegal programs for sro nor accepting files from unknown ppl, i have a good security with daily updated anti virus/spy ware and firewall and i have never shared my id/pw with anyone
you can ask XMAT, Soulreaper and ZombieGirl who were playing at greece server for this exploit, i hope reaper still posting here to explain
GUYS GAME EXPLOITS STILL EXIST
Posted: Wed Dec 19, 2007 7:03 pm
by Blasjr
Love to hear all your comments. If you want to be safe and you have gear you dont want to lose, Create a mule account, tell no one, transfer your shit to it everynight, and you'll be safe. I warn you, regardless of what any1 tells you, it's still happening, packets are being sent thru Game (the same way that rev6 does it), to you Character. You will get a BOX with scribbles in either Korean, or arabic writing and an OK box. Without login off from game, go to JM main site and change your PW without exiting game immediately. Once PW change confirmation is received, shut down game and re-open, you are safe. The moment this BOX appears you are being sent a packet, that will send info to the hacker. You're warned. I keep posting this info everytime I read a post on this subject. Think of it this way: Microsoft has security patches very often to protect itself from loopholes which hackers exploit. Do you think a petty Co. like JM doesn't have security flaws? The bigger problem is when they send out to independent Co's to work on their sites, programs,servers,etc. The programers know the code. Ever heard of disgrunteled employees?
Peace and best of luck
Re: GUYS GAME EXPLOITS STILL EXIST
Posted: Wed Dec 19, 2007 7:28 pm
by mafa
Blasjr wrote:Love to hear all your comments. If you want to be safe and you have gear you dont want to lose, Create a mule account, tell no one, transfer your shit to it everynight, and you'll be safe. I warn you, regardless of what any1 tells you, it's still happening, packets are being sent thru Game (the same way that rev6 does it), to you Character. You will get a BOX with scribbles in either Korean, or arabic writing and an OK box. Without login off from game, go to JM main site and change your PW without exiting game immediately. Once PW change confirmation is received, shut down game and re-open, you are safe. The moment this BOX appears you are being sent a packet, that will send info to the hacker. You're warned. I keep posting this info everytime I read a post on this subject. Think of it this way: Microsoft has security patches very often to protect itself from loopholes which hackers exploit. Do you think a petty Co. like JM doesn't have security flaws? The bigger problem is when they send out to independent Co's to work on their sites, programs,servers,etc. The programers know the code. Ever heard of disgrunteled employees?
Peace and best of luck
Iv had box with some wierd korean text in it and OK buttom and after i pres ok, i get two more boxes and everything continues normally

Posted: Wed Dec 19, 2007 10:37 pm
by djpatje
brute force is possible or WAS
Posted: Thu Dec 20, 2007 4:12 am
by SkyNight
3 passwords/15 minutes would take ages for brute force to succeed.
Posted: Thu Dec 20, 2007 4:34 am
by _SomeOne_
dont b a dumb ass..
Posted: Thu Dec 20, 2007 4:34 am
by Aby
NO!@!!!!
This was a LONG TIME AGOOO
Posted: Thu Dec 20, 2007 4:35 am
by Naigasakis_Rebirth
Cerus wrote:Its been confirmed that Trade Hack is possible.
But its limited to Botters only.
If you are using a bot, theres a script that allow hacker to gather your info thru trade.
If you are not using an altered client then do not worry.
LOL at you. I hate bots also but I dont make lame excuses to scare people out of using them
Posted: Thu Dec 20, 2007 1:27 pm
by Cerus
Naigasakis_Rebirth wrote:LOL at you. I hate bots also but I dont make lame excuses to scare people out of using them
lol, im not making this up.
I am merely telling what i know.
Y do u care? U bot?