[READ]SRO Account Hacks: How it's done and how to stop it.

Here you can post guides and tutorials you have written for Silkroad Online. If submitting a guide from another forum, please post credit to the author.
User avatar
SuicideGrl
Retired Admin
Posts: 8004
Joined: Fri Jan 27, 2006 4:17 pm
Location: World of Warcraft

Post by SuicideGrl »

draquish wrote:I refuse to call this hacking.

it's not hacking. it's what the SRO community generally refers to as hacking though. i'd hazard to guess that 9/10 of so-called "ZOMG WTF H4x0rED" threads originated in actions like what was described here, and ver few are actually "hacks" by the textbook definition.
Image
Thx IceCrash for my awesome sig :)
SRF Name Change Policy
Having trouble accessing SRF?

dom wrote:
RuYi wrote:Are you from outer space or something?
He's from Jersey. Close enough.

User avatar
Draquish
Elite Member
Posts: 6423
Joined: Wed Mar 15, 2006 10:25 pm
Quick Reply: Yes
Location: ____

Post by Draquish »

@ Lizard boy: Yes :)

@ SG: Exactly. Fake emails work wonders :P

User avatar
judaiskariot
Regular Member
Posts: 309
Joined: Sun Jan 14, 2007 1:59 am
Quick Reply: Yes
Location: Croatia

Post by judaiskariot »

The funiest thing is: lots of people that play SRO are not native english speakers and 80% of them have their scret answer, username, email etc. in english (human stupidity - question in english = answer in english). :)

Isn't it more secure if u have everything in your native language (lot of dictionarys to find and use), and noone is asking you to answer truthfully on secret question (for ex. what's my pets name = idontrealyownapet or something but in urdu or siux or what ever)..

And another thing: i dont get it - how can people be so desperate to ask a complete stranger in game to buy him silk, gives him his ID and PW, and then logs off (cause scammer told him he must). And we are not talking here about lvl 1-20 chars but lvl 60+++...
Babel:
lvl 64 Bow hybrid (hacked / retired)
Zeus:
lvl 90 Bow hybrid (fu.fa.)
lvl 76 Cleric/warlock (on hold)

User avatar
IguanaRampage
Advanced Member
Posts: 2483
Joined: Fri Jul 14, 2006 1:37 am
Quick Reply: Yes
Location: Changing

Post by IguanaRampage »

draquish wrote:@ Lizard boy: Yes :)

@ SG: Exactly. Fake emails work wonders :P

lmao :D :D
McCain, he (Barack Obama) said, will soon "be accusing me of being a secret communist because I shared my toys in kindergarten."

User avatar
XuChu
Advanced Member
Posts: 2429
Joined: Thu Apr 20, 2006 9:30 am
Quick Reply: Yes
Location: here

Re: [READ]SRO Account Hacks: How it's done and how to stop i

Post by XuChu »

whpwnage wrote:I've noticed a rash of hackers running about SRO - and truthfully, it pisses me off. I was confronted by one in-game, warning me to "watch out and don't try to offend the wrong people."


rofl, some nerd acting tough "yo n00bz i w1ll hax0r j00 w1th m31n 1337 hax0rz $k1llz, dul\l ..... w1t m3"

User avatar
timtam
Loyal Member
Posts: 1779
Joined: Fri Nov 17, 2006 10:09 am
Quick Reply: Yes
Location: Warcraft 3: The frozen throne

Post by timtam »

Nice ^.^

I just changed my sro password (old one was timtam =0)

That helped me alot, thanks man.
Us west (lordaeon)
ign: karanadon

User avatar
sloweredmangyang
Active Member
Posts: 605
Joined: Wed Jul 19, 2006 12:12 am
Quick Reply: Yes
Location: alps

Post by sloweredmangyang »

i dont get it how would you get someones username? (hackers should die i got hacked when i was a noob :banghead: ) and 1/2 the time the secret question is BS.
Highest Lvl:43
Image
Image
Image

User avatar
IguanaRampage
Advanced Member
Posts: 2483
Joined: Fri Jul 14, 2006 1:37 am
Quick Reply: Yes
Location: Changing

Post by IguanaRampage »

if

SRF handle = username

or

You posted on official forums when you could quote people

and probably some other ways too. :)
McCain, he (Barack Obama) said, will soon "be accusing me of being a secret communist because I shared my toys in kindergarten."

User avatar
PR0METHEUS
Senior Member
Posts: 4093
Joined: Tue Aug 22, 2006 7:30 pm
Quick Reply: Yes
Location: Earth
Contact:

Post by PR0METHEUS »

J3FFz128 wrote:wouldn't you need their password to be able to login into silkroadonline.net and get there email addrress?


Not necessarily. That's why he suggested to use an email address you don't use anywhere else.
Missing the good times in SRO... :love:

SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)

User avatar
judaiskariot
Regular Member
Posts: 309
Joined: Sun Jan 14, 2007 1:59 am
Quick Reply: Yes
Location: Croatia

Post by judaiskariot »

hahahhhaahhha Caio, good one..
Babel:
lvl 64 Bow hybrid (hacked / retired)
Zeus:
lvl 90 Bow hybrid (fu.fa.)
lvl 76 Cleric/warlock (on hold)

User avatar
IguanaRampage
Advanced Member
Posts: 2483
Joined: Fri Jul 14, 2006 1:37 am
Quick Reply: Yes
Location: Changing

Post by IguanaRampage »

Caio wrote:Thanks for the information m8, I'll give it a try.

seeing as you are the botter, there's another, much easier way to hack you you know...
McCain, he (Barack Obama) said, will soon "be accusing me of being a secret communist because I shared my toys in kindergarten."

User avatar
Nuklear
Veteran Member
Posts: 3272
Joined: Fri Jun 16, 2006 7:46 pm
Quick Reply: Yes
Location: off topic

Post by Nuklear »

MastaChiefX wrote:This REALLY got a sticky? Wow general discussion has really gone down

I believe this was posted for the computer newbs and sro newbs to get knowledge from, not us smart people.:P
Image
No government?!?! Oh, noes! Total chaos! Or would it be? http://freekeene.com/free-audiobook/

User avatar
linange
Regular Member
Posts: 345
Joined: Sun Feb 04, 2007 2:29 pm
Quick Reply: Yes
Location: World of P0121\10

Post by linange »

thx for such a great work~

btw, i shall add one more thing.......

DON"T USE unreliable bots........ :P

User avatar
PR0METHEUS
Senior Member
Posts: 4093
Joined: Tue Aug 22, 2006 7:30 pm
Quick Reply: Yes
Location: Earth
Contact:

Post by PR0METHEUS »

linange wrote:thx for such a great work~

btw, i shall add one more thing.......

DON"T USE unreliable bots........ :P


I believe you meant "DON'T USE bots...." at least I hope.
Missing the good times in SRO... :love:

SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)

User avatar
PR-Solja
Regular Member
Posts: 203
Joined: Thu Nov 02, 2006 1:22 pm
Quick Reply: Yes
Location: Tibet

Post by PR-Solja »

I have a question when you make up a new email addy for your SRO account does it have to be an active account. lets say I changed my email addy to 25OP90YU@gmail.com, now my question is does SRO accept that as a valid email adress if it doesn't exist at all?
If Knowledge Is Power, Then To Be Unknown Is To Be Unconquerable.

User avatar
JackB4u3r
Frequent Member
Posts: 1115
Joined: Sat Jun 10, 2006 9:08 pm
Quick Reply: Yes
Location: Sarajevo

Post by JackB4u3r »

PR-Solja wrote:I have a question when you make up a new email addy for your SRO account does it have to be an active account. lets say I changed my email addy to 25OP90YU@gmail.com, now my question is does SRO accept that as a valid email adress if it doesn't exist at all?


Probably... yes. Because they sure don't check your e-mail address the only thing why you need it for, is to recover you pass, and activate a new account.

About the topic:
Great! Some users have known this, the one who have already experienced hacking and similar in other games, but most don't know how to protect an account completely. As he said:

- random e-mail
- random user name
- random pass
- random secret answer

Write everything down on a paper and, you are safe & set to play the game :D
Stopped playing SRO a long time ago; still pr0.

User avatar
CrazyAztec
Valued Member
Posts: 419
Joined: Fri Jan 19, 2007 3:55 am
Quick Reply: Yes
Location: RED SEA

Post by CrazyAztec »

I, too, REfuse to call this hacking!!!

ok. One of my friend is a hacker. Elite hacker and crack NASA's database and even goes face to face with the FBI!!! lol...can u see that. He hacked paypal and lots more idk what. To tell you the truth, he doesnt need any white hat tricks at all!!! simply just ..programming. oh yeah btw he even teach me a lil about hacking lol...send them a keylogger :twisted:

im not pro-hax and pro-bots just interested on the both side of the community in SRo..or the NetWArriors!! hehe :D
Image
I wanna wrote:i love fonts is size 24 and bold

User avatar
judaiskariot
Regular Member
Posts: 309
Joined: Sun Jan 14, 2007 1:59 am
Quick Reply: Yes
Location: Croatia

Post by judaiskariot »

Elite hacker and crack NASA's database and even goes face to face with the FBI!!!

hahahah very funny
Babel:
lvl 64 Bow hybrid (hacked / retired)
Zeus:
lvl 90 Bow hybrid (fu.fa.)
lvl 76 Cleric/warlock (on hold)

oktaytheazer
Frequent Member
Posts: 1123
Joined: Mon Nov 06, 2006 12:16 pm
Quick Reply: Yes

Post by oktaytheazer »

sweet.

another advise for sro users, read srf.

Wamphyri
Hi, I'm New Here
Posts: 1
Joined: Tue Feb 13, 2007 1:08 pm

Post by Wamphyri »

CrazyAztec wrote:I, too, REfuse to call this hacking!!!

ok. One of my friend is a hacker. Elite hacker and crack NASA's database and even goes face to face with the FBI!!! lol...can u see that. He hacked paypal and lots more idk what. To tell you the truth, he doesnt need any white hat tricks at all!!! simply just ..programming. oh yeah btw he even teach me a lil about hacking lol...send them a keylogger :twisted:

im not pro-hax and pro-bots just interested on the both side of the community in SRo..or the NetWArriors!! hehe :D


i don't know what drives peopel to make comments like this?

bruteforcing and dictionary attack are a style, i repeat "STYLE" of hacking

reffering to your "programming" aspect what do you think drives these attack, oh crap. programs

anyways for anyone who has been around since the b.b.s. days understand what this guys has said and is trying to do thank you very much for the descriptive information as the password adding ascii shift - #'s is an added bonus as well as numbers and characters longer the better as it take bruteforcing longer to run through all the combined keystrokes avalable

oh and one more thing so how long is your elite hacker buddy in jail for? using a metal spoon to drug yourself outta federal prison doesn't constitute as hacking nor does having big bubba for a cell mate lol

User avatar
bugy92
Regular Member
Posts: 294
Joined: Sat Oct 28, 2006 5:33 pm
Quick Reply: Yes
Location: Greece

Post by bugy92 »

hey.....If they know your id and e-mail, your account isn`t theirs.....they steal need to know the secret question, who is difficolt to find out....how can you know someone`s secret question?? I forgot my own secret answer...It`s dificult to find secret answer...how can you???
Name:_Akon_
LvL:86
Guild:Romanasii
Build:Full str archer(fire/light).
Pet:HarryPotter(lvl 82)

Romanasii...Can`t live with them, can`t live without them...

98% of the teenagers will try or has tried smoking pot.If you're one of the 2% who hasn't, copy & paste this into your signature.

themeatwagon
Hi, I'm New Here
Posts: 1
Joined: Thu Sep 14, 2006 10:32 am

funny

Post by themeatwagon »

It's funny how naive some people can be, alls it take is someone with a properly worded sentence and no knowledge of the computer language of SQL to convince people that hacking silkroad can't be done. Hacking Silkroad is possible and it's done through blind SQL injection. Every website on the internet is suseptible to at least one form of SQL injection but some site like silkroad are....easier than others.

Beleive what you want doesn't hurt me in the least :roll:
IGN-The_Ruiner
Build-Hybrid int spear
Lvl-75

User avatar
FuryAngle
Regular Member
Posts: 253
Joined: Wed Feb 14, 2007 5:46 pm

Post by FuryAngle »

This is far from hacking, this is just research and cracking and taking an educated guess at somebodys answer. It obviously doesnt work 100% and it doesnt even work 20%of the time, I would have to say you got lucky with the 5accounts that you tried. Aswell its much easier just to gain acces to the acctual host of sro.net, after all its just html, and if you take notice to the actual silkroadonline.net website, you will notice they are not security certified(if your are certified[protected] you have a little lock in the corner of the screen) this indicated all data is in code. Ie: if your id is idiot it would be stored in a code format and not in actual leters which can be read. sro.net is although certified by SSL (verisign secured) This is a company with very poor fire wall and defenses, their certificates can be easily intercepted and resent to sro.net, if i remeber right, it was 128 bit encryption/SSL encryption. If you gained even one certificate you could gain acces to their homepage, you can edit minor data this way, such as the incident when there was a notice on main page. I wonder who did that :roll: :roll: BTW They also have data stored in .txt format which just scares me. Well good thing for some people, bad thing for others :)

-And for gods sake, Can these noobs not register on SRF with their real ID and E-Mail that is used for SRO? SRF would take less than a day to data wipe
>Had to remove my Signature because idiots kept begging for accounts<

Z0mbs
New Member
Posts: 33
Joined: Thu Feb 01, 2007 5:41 pm

Post by Z0mbs »

I suggest you scan all files you download at http://www.virustotal.com and use SpyBot Search & Destroy before you install anything. To install SpyBot S&D first download and install WinRar and use the trial version forever. It seems like a lot of work but it's worth it to protect yourself.

This is an example of virustotal, scanning SpyBot Search & Destroy.
Image
Last edited by Z0mbs on Sun Feb 18, 2007 2:23 am, edited 2 times in total.

User avatar
PR0METHEUS
Senior Member
Posts: 4093
Joined: Tue Aug 22, 2006 7:30 pm
Quick Reply: Yes
Location: Earth
Contact:

Re: funny

Post by PR0METHEUS »

themeatwagon wrote:It's funny how naive some people can be, alls it take is someone with a properly worded sentence and no knowledge of the computer language of SQL to convince people that hacking silkroad can't be done. Hacking Silkroad is possible and it's done through blind SQL injection. Every website on the internet is suseptible to at least one form of SQL injection but some site like silkroad are....easier than others.

Beleive what you want doesn't hurt me in the least :roll:


That's why Joymax needs a company like the one I work for to monitor them for attacks like these....
Missing the good times in SRO... :love:

SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)

Nave47
Frequent Member
Posts: 1038
Joined: Sat Oct 21, 2006 11:15 pm
Quick Reply: Yes
Location: Inside your Mind

Re: funny

Post by Nave47 »

PR0METHEUS wrote:
themeatwagon wrote:It's funny how naive some people can be, alls it take is someone with a properly worded sentence and no knowledge of the computer language of SQL to convince people that hacking silkroad can't be done. Hacking Silkroad is possible and it's done through blind SQL injection. Every website on the internet is suseptible to at least one form of SQL injection but some site like silkroad are....easier than others.

Beleive what you want doesn't hurt me in the least :roll:


That's why Joymax needs a company like the one I work for to monitor them for attacks like these....


And what company is it?
Image
Bakemaster wrote:... Now I have to spam up about 30 more posts tonight so I can go delete some of Nave47's posts.

User avatar
Sponge
New Member
Posts: 48
Joined: Sat Feb 17, 2007 6:04 pm
Quick Reply: Yes
Location: Oasis

Post by Sponge »

BRAVO! thank you so much for ur help! i never got hacked before in any game and now ill be insinsible (not) muhahahahaha! thx alot! :D
IGN: Lormex | Level: 3X | Guild: GuardianZ | Build: Glaive Hybird | Wolf: 2X
Image
~~~>>>Gone to the "Cool" side 2Moons<<<~~~

User avatar
Slayer007
Casual Member
Posts: 80
Joined: Wed Dec 06, 2006 4:41 am
Quick Reply: Yes
Location: Tibet

Post by Slayer007 »

u dont like hacking but yet u hack like 10 ppl and prolly alot more ? wow u must have no life u hipicrit
Image
THANKS Ol3N for my sig
Level:66
Build: Pure STR Glavie
Guild: Armageddon
[CENTER]ImageTake the Magic: The Gathering 'What Color Are You?' Quiz.[/CENTER]

Zeb
Hi, I'm New Here
Posts: 22
Joined: Sat Feb 10, 2007 3:59 am

Post by Zeb »

I just searched all my info. I got 4 results for my login name, 0 results for my email and ~100 results for my password (not going to give the exact word). The weird thing is that my password is something I completely made up a few years ago based off of a swear sensor from a website I used to go to. None of the google results had anything to do with me though, all coincidental. Usually appearing on blogs where people were trying to be random.

My login name unfortunately is similar to my in-game name but I guess there's nothing to be done about that.

User avatar
PR0METHEUS
Senior Member
Posts: 4093
Joined: Tue Aug 22, 2006 7:30 pm
Quick Reply: Yes
Location: Earth
Contact:

Re: funny

Post by PR0METHEUS »

Nave47 wrote:
PR0METHEUS wrote:
themeatwagon wrote:It's funny how naive some people can be, alls it take is someone with a properly worded sentence and no knowledge of the computer language of SQL to convince people that hacking silkroad can't be done. Hacking Silkroad is possible and it's done through blind SQL injection. Every website on the internet is suseptible to at least one form of SQL injection but some site like silkroad are....easier than others.

Beleive what you want doesn't hurt me in the least :roll:


That's why Joymax needs a company like the one I work for to monitor them for attacks like these....


And what company is it?


An IT security company in the tri-state area.
Missing the good times in SRO... :love:

SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)

Post Reply

Return to “Guides and Tutorials”