Newest hackmethod - fail by joymax..

A place for general discussion about Silkroad Online. Talk about the game or ask questions. Please keep threads Silkroad Online related.
User avatar
Razorhead
Active Member
Posts: 820
Joined: Tue Apr 22, 2008 9:19 pm
Quick Reply: Yes
Location: leagueoflegends

Newest hackmethod - fail by joymax..

Post by Razorhead »

New Joymax Website exploit:
http://supportcp.joymax.com/demo/mail/e ... ardAll.jsp

DO NOT SEND SUPPORT MESSAGE THAT HAVE ACCOUNT NAME AND PASSWORD TO JOYMAX!!!

All the post are public and if you look at rev6 forum, the exploit was found like this: pic1 , pic2. Basically if you send them a message using your account that has a premium, you can from there browse from their website to the admin mailbox without any password with only 3 mouse clicks. Enter any username and password you want, they are all valid...
They better fix it soon, I don't even want to contact Joymax knowing that everyone can view everything...
This is another huge FAILED! for Joymax -_-
Credit goes to _TANGUITO_ for posting it on rev6 forum.

Joymax NEED to fix it as soon as possible before another exploit come out of it (sql injection, cross site scripting exploit etc...)

User avatar
pr0klobster
Frequent Member
Posts: 1427
Joined: Wed Oct 17, 2007 2:28 pm
Quick Reply: Yes
Location: Olympus

Re: Newest hackmethod - fail by joymax..

Post by pr0klobster »

oh boy...yeah, you can just type random characters in that ID and password field, and I see tons of emails in there. Not good!

edit: OH MAN this looks bad...at first, I thought it might be a demo, but I see people in there that I have seen on Olympus...and more that show up on rev6...this appears to be true.
Last edited by pr0klobster on Fri Jan 30, 2009 3:03 pm, edited 1 time in total.
If faith is a crutch, I'm not limping anymore.

User avatar
Razorhead
Active Member
Posts: 820
Joined: Tue Apr 22, 2008 9:19 pm
Quick Reply: Yes
Location: leagueoflegends

Re: Newest hackmethod - fail by joymax..

Post by Razorhead »

Now the proof this isn't a hoax:
Just found my own question in their site :roll:
question support.JPG
question support.JPG (80.04 KiB) Viewed 6923 times

reply jm support.JPG
reply jm support.JPG (70.14 KiB) Viewed 6903 times

User avatar
Strwarrior
Veteran Member
Posts: 3798
Joined: Sat Oct 25, 2008 11:41 am
Quick Reply: Yes
Location: ....

Re: Newest hackmethod - fail by joymax..

Post by Strwarrior »

Yes, the 1st post is true.. i just saw some1 saying about his lvl 90 account.. with id and pw.. omg these guys are crazy.
Image

HUUU MADE THIS SIG?? Amarisa

User avatar
Lowis
Active Member
Posts: 570
Joined: Sun Feb 24, 2008 4:45 pm
Quick Reply: Yes
Location: Trolling

Re: Newest hackmethod - fail by joymax..

Post by Lowis »

Looks like korean people respond using that.
Image

---Playing EchSRO---
http://www.echsro.com

User avatar
hapnz
Valued Member
Posts: 493
Joined: Thu Jan 18, 2007 10:42 pm
Quick Reply: Yes
Location: Arctic Circle

Re: Newest hackmethod - fail by joymax..

Post by hapnz »

lol i bet lots of ppl are already scanning through all the posts

User avatar
aznronin
Frequent Member
Posts: 1393
Joined: Wed Jun 18, 2008 4:39 pm
Quick Reply: Yes
Location: Aege

Re: Newest hackmethod - fail by joymax..

Post by aznronin »

Alright so then, in these emails, everyone who has prem can read it, and if you put personal information you are screwd right?
Man this is serious, joymax seriously screwd people this time, if what i asked is true...

User avatar
pr0klobster
Frequent Member
Posts: 1427
Joined: Wed Oct 17, 2007 2:28 pm
Quick Reply: Yes
Location: Olympus

Re: Newest hackmethod - fail by joymax..

Post by pr0klobster »

aznronin wrote:Alright so then, in these emails, everyone who has prem can read it, and if you put personal information you are screwd right?
Man this is serious, joymax seriously screwd people this time, if what i asked is true...


so far, that appears to be the case from what we can see :(

Although, I am unsure of the premium thing because I'm at work, how would they know? I'm just putting in garbage characters for ID and password.
If faith is a crutch, I'm not limping anymore.

User avatar
Razorhead
Active Member
Posts: 820
Joined: Tue Apr 22, 2008 9:19 pm
Quick Reply: Yes
Location: leagueoflegends

Re: Newest hackmethod - fail by joymax..

Post by Razorhead »

pr0klobster wrote:
aznronin wrote:Alright so then, in these emails, everyone who has prem can read it, and if you put personal information you are screwd right?
Man this is serious, joymax seriously screwd people this time, if what i asked is true...


so far, that appears to be the case from what we can see :(

Although, I am unsure of the premium thing because I'm at work, how would they know? I'm just putting in garbage characters for ID and password.

U don't need prem or even silk.
Just tested it with a acc without silk.
Login to joymax portal, go to sro Q&A history; then on the "home" sign
Then on that inbox image & start reading.

Found already 2 acc id & pw; both blocked for chargeback ><

User avatar
YangKang
Active Member
Posts: 838
Joined: Wed Dec 13, 2006 4:26 pm
Quick Reply: Yes
Location: Uranus

Re: Newest hackmethod - fail by joymax..

Post by YangKang »

Ive got a lvl 90 force glaive o_o to bad he has only a lvl 24 glaive left.
Image

User avatar
aznronin
Frequent Member
Posts: 1393
Joined: Wed Jun 18, 2008 4:39 pm
Quick Reply: Yes
Location: Aege

Re: Newest hackmethod - fail by joymax..

Post by aznronin »

YangKang wrote:Ive got a lvl 90 force glaive o_o to bad he has only a lvl 24 glaive left.


are you serious?

User avatar
pr0klobster
Frequent Member
Posts: 1427
Joined: Wed Oct 17, 2007 2:28 pm
Quick Reply: Yes
Location: Olympus

Re: Newest hackmethod - fail by joymax..

Post by pr0klobster »

Razorhead wrote:
pr0klobster wrote:
aznronin wrote:Alright so then, in these emails, everyone who has prem can read it, and if you put personal information you are screwd right?
Man this is serious, joymax seriously screwd people this time, if what i asked is true...


so far, that appears to be the case from what we can see :(

Although, I am unsure of the premium thing because I'm at work, how would they know? I'm just putting in garbage characters for ID and password.

U don't need prem or even silk.
Just tested it with a acc without silk.
Login to joymax portal, go to sro Q&A history; then on the "home" sign
Then on that inbox image & start reading.

Found already 2 acc id & pw; both blocked for chargeback ><


What I'm saying is that I haven't logged on to the Joymax portal from work. There is no way to refer to my account from this computer. It's more wide open than we think. ANYONE can see this. People don't even need SRO accounts.
If faith is a crutch, I'm not limping anymore.

User avatar
YangKang
Active Member
Posts: 838
Joined: Wed Dec 13, 2006 4:26 pm
Quick Reply: Yes
Location: Uranus

Re: Newest hackmethod - fail by joymax..

Post by YangKang »

aznronin wrote:
YangKang wrote:Ive got a lvl 90 force glaive o_o to bad he has only a lvl 24 glaive left.


are you serious?


http://www.rev6.com/player.asp?id=627612

That guy posted his ID&PW
Image

User avatar
Rush4Life
Valued Member
Posts: 408
Joined: Wed Jan 09, 2008 9:42 am
Quick Reply: Yes
Location: Persia

Re: Newest hackmethod - fail by joymax..

Post by Rush4Life »

IGN: _H_
Level: 54
Status:Inactive
Server:Persia
Image

User avatar
YangKang
Active Member
Posts: 838
Joined: Wed Dec 13, 2006 4:26 pm
Quick Reply: Yes
Location: Uranus

Re: Newest hackmethod - fail by joymax..

Post by YangKang »

Rush4Life wrote:This guy too: http://www.rev6.com/player.asp?id=493218


I want that one :p Might doing a exchange haha?
Image

User avatar
pr0klobster
Frequent Member
Posts: 1427
Joined: Wed Oct 17, 2007 2:28 pm
Quick Reply: Yes
Location: Olympus

Re: Newest hackmethod - fail by joymax..

Post by pr0klobster »

I went way back through the emails...several people have emailed much more information than they should have :( (like phone numbers, cc#, etc)
If faith is a crutch, I'm not limping anymore.

User avatar
BloodyBlade
Elite Member
Posts: 5219
Joined: Wed Nov 14, 2007 8:32 pm
Quick Reply: Yes
Location: Attending your mothers sexual needs :)

Re: Newest hackmethod - fail by joymax..

Post by BloodyBlade »

Get this message to popular game sites & everybody will know this.
This will mean nobody will play sro anymore, so no silk buyers anymore :roll:
My sig died

User avatar
aznronin
Frequent Member
Posts: 1393
Joined: Wed Jun 18, 2008 4:39 pm
Quick Reply: Yes
Location: Aege

Re: Newest hackmethod - fail by joymax..

Post by aznronin »

I'm started to get worried...
Last edited by aznronin on Fri Jan 30, 2009 5:24 pm, edited 1 time in total.

User avatar
Swindler
Forum God
Posts: 11256
Joined: Tue Apr 10, 2007 7:49 am
Quick Reply: Yes
Location: Pimpas Paradise.

Re: Newest hackmethod - fail by joymax..

Post by Swindler »

Question

soooo support the damn fking sever are ALL FULL can you make the fking server higher taht more people can connect



Answer:

Dear Valued Customer,
Greetings from Joymax Customer Support Team!

We received your email regarding the server traffic problem that you are experiencing. We are sorry for the inconvenience that this may have caused you.

We suggest that you should try our Premium Gold Time Plus (4 weeks) were you can have a special bonus of preferred game access to the game that users can log into the game during server traffic hours.


*Also, please try to check your PC specification, get a faster connection that utilizes ADSL, VDSL, T3 lines, a faster computer faster/more efficient CPU, graphic card, or RAM.

Thank you for emailing Joymax Customer Support.

For further details and support, kindly visit our website at http://www.joymax.com/silkroad.


Sincerely yours,

Joymax Customer Support Team


HAHHAHAHA

User avatar
aznronin
Frequent Member
Posts: 1393
Joined: Wed Jun 18, 2008 4:39 pm
Quick Reply: Yes
Location: Aege

Re: Newest hackmethod - fail by joymax..

Post by aznronin »

HejsaN wrote:
Question

soooo support the damn fking sever are ALL FULL can you make the fking server higher taht more people can connect



Answer:

Dear Valued Customer,
Greetings from Joymax Customer Support Team!

We received your email regarding the server traffic problem that you are experiencing. We are sorry for the inconvenience that this may have caused you.

We suggest that you should try our Premium Gold Time Plus (4 weeks) were you can have a special bonus of preferred game access to the game that users can log into the game during server traffic hours.


*Also, please try to check your PC specification, get a faster connection that utilizes ADSL, VDSL, T3 lines, a faster computer faster/more efficient CPU, graphic card, or RAM.

Thank you for emailing Joymax Customer Support.

For further details and support, kindly visit our website at http://www.joymax.com/silkroad.


Sincerely yours,

Joymax Customer Support Team


HAHHAHAHA


So I guess this is the end for us guys?

User avatar
DarkJackal
Elite Member
Posts: 6119
Joined: Mon Feb 20, 2006 7:23 pm
Quick Reply: Yes
Location: A den~
Contact:

Re: Newest hackmethod - fail by joymax..

Post by DarkJackal »

aznronin wrote:Alright so then, in these emails, everyone who has prem can read it, and if you put personal information you are screwd right?
Man this is serious, joymax seriously screwd people again, if what i asked is true...
Image

User avatar
Lowis
Active Member
Posts: 570
Joined: Sun Feb 24, 2008 4:45 pm
Quick Reply: Yes
Location: Trolling

Re: Newest hackmethod - fail by joymax..

Post by Lowis »

Bets that they'll cover it up just like the Joymax portal exploit. :D
Image

---Playing EchSRO---
http://www.echsro.com

User avatar
OTG
Frequent Member
Posts: 1060
Joined: Tue Oct 21, 2008 6:15 am
Quick Reply: Yes
Location: Off Topic

Re: Newest hackmethod - fail by joymax..

Post by OTG »

LOL another FailMax. I suggest you all quit! :twisted:

User avatar
lopasas
Active Member
Posts: 733
Joined: Sat Nov 29, 2008 8:51 am
Quick Reply: Yes
Location: Troy

Re: Newest hackmethod - fail by joymax..

Post by lopasas »

ok now i get it
like i ever send e-mails to joymax, geez worthless topic...
<< banned for proof of botting. -cin >>

User avatar
SwordCloud
Active Member
Posts: 837
Joined: Tue May 13, 2008 7:40 pm
Quick Reply: Yes
Location: Nice question O,O

Re: Newest hackmethod - fail by joymax..

Post by SwordCloud »

Omg that sogay how ppl can be naives.............
plz plz my account plz id: dzdsd
pw:dsdsds
cc:1212121323
lol i'm sure some of them are turk.(sorry im not racism but they have a lack
of languages understanding).

@lopas1:
People are now able to read all message sent to the customer support,
and 80% people give their id and pw and much more sometime.
Sword d12:
Spoiler!

User avatar
asusi
Veteran Member
Posts: 3223
Joined: Tue Jul 08, 2008 7:04 pm
Quick Reply: Yes
Location: Off topic
Contact:

Re: Newest hackmethod - fail by joymax..

Post by asusi »

OTG wrote:LOL another FailMax. I suggest you all quit! :twisted:

:? wtf are you talking about go quit your self
glad i never mailed them :roll:
Spoiler!

User avatar
AnarChaos
Active Member
Posts: 572
Joined: Wed Jan 30, 2008 8:59 am
Quick Reply: Yes
Location: SILKROAD SALVATION
Contact:

Re: Newest hackmethod - fail by joymax..

Post by AnarChaos »

ROFL read this:
--------------------
Dear Valued Customer,



Greetings from Joymax Customer Support Team!



Thank you for emailing Joymax Customer Support. Sorry for the inconvenience that caused you by experiencing hacking on your account. We do understand your state. However, we regret to inform you that we will not offer services regarding account theft/hacking for the time being for the purpose of providing better service in the future as what our policy declares. Users are responsible for maintaining the confidentiality of their own accounts and all relevant responsibilities attached to their accounts to keep away from hacker and any malicious circumstance. Same as email verification, if your registered email address is already verified using our new email verification service you cannot change it. Please check the email address before use, and please take care of your email address and password information if you verify your email.



For further details and support, kindly visit our website at http://www.joymax.com/silkroad





Thank you for your understanding.



Sincerely yours,

Joymax Customer Support Team






고객님이 문의하신 사항은 아래와 같습니다
Hello, I have the following problem which I hacked into my account can not change pw wiel the verification email to mail is because hackers.
I ask for help.
------------------------------------------------

They will not help you even if your account was hacked because of this fcking exploit!

User avatar
Mousetrap
Active Member
Posts: 817
Joined: Mon Mar 31, 2008 5:07 pm
Quick Reply: Yes
Location: Oasis

Re: Newest hackmethod - fail by joymax..

Post by Mousetrap »

Who the f.uck gives their ID and password out, especially CC # in a JM support email.
At any rate.. I've never used the support thing, so meh.

@YangKang, hope you get forums banned scammer.

User avatar
DotCom
Valued Member
Posts: 497
Joined: Thu Jul 20, 2006 1:44 am
Quick Reply: Yes
Location: Alexander

Re: Newest hackmethod - fail by joymax..

Post by DotCom »

Its Joymax who asks for server, char name and ID for verification purposes. But those who included more info than that are screwed.
Server: Alexander

-=IMPERIAL FOREVER=-

[Quit]

User avatar
StacE
Active Member
Posts: 502
Joined: Wed Aug 29, 2007 7:08 am
Quick Reply: Yes
Location: Athens

Re: Newest hackmethod - fail by joymax..

Post by StacE »

BAHAHAHA

quit now.
Crusher - 78 Hybrid Int S/S.
Anurin - 80 Pure Int Cleric/Bard.

Post Reply

Return to “Silkroad General Discussion”