[READ]SRO Account Hacks: How it's done and how to stop it.
- PR0METHEUS
- Senior Member
- Posts: 4093
- Joined: Tue Aug 22, 2006 7:30 pm
- Quick Reply: Yes
- Location: Earth
- Contact:
SuicideNz wrote:hey i appreciate wat ur trying to do but can ppl stop making these hacking posts
it is showing ppl how easy it is, so then more ppl go and try it out.
i got hacked and i was hoping it was u but no email came up so i wasnt so lucky.
I think it's good to share these things with everyone. The more people know about these techniques, the better prepared they'll be to prevent them. It's just like with vulnerabilities in software. Microsoft releases security bulletins all the time informing users of various vulnerabilities, and how to protect themselves from being exploited. Of course Microsoft has plenty of security problems themselves, but just an example.
It's better than just keeping users in the dark and unable to protect themselves.
Missing the good times in SRO... 
SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)
SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)
- Dark0Archer0
- Regular Member
- Posts: 342
- Joined: Fri Feb 16, 2007 6:58 am
- Quick Reply: Yes
- Location: Oasis
Posting this topic actually would give more potential hackers the information they need to be able to hack accounts successfully than help players keep their accounts safe. Legit players who don't hack would be less inclined to read this topic than someone who wants to learn.
Thankyou for broadening the hacker community, greatly appreciated.
Thankyou for broadening the hacker community, greatly appreciated.
SOS Pie FTW!!!
- PR0METHEUS
- Senior Member
- Posts: 4093
- Joined: Tue Aug 22, 2006 7:30 pm
- Quick Reply: Yes
- Location: Earth
- Contact:
Dark0Archer0 wrote:Posting this topic actually would give more potential hackers the information they need to be able to hack accounts successfully than help players keep their accounts safe. Legit players who don't hack would be less inclined to read this topic than someone who wants to learn.
Thankyou for broadening the hacker community, greatly appreciated.
True, but with all the "OMG I got hacked" threads that we see here, we can just point that user to this thread so he/she can learn ways to help prevent it from happening in the future. This information is already out there in the hacker community, and anyone that wants to hack will find it whether this thread exists or not.
Missing the good times in SRO... 
SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)
SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)
ok well since i dont have any other way to put this... u cannot stop hacking of accounts, there will always be an exploit in silkroad database, there is no possible way to completely kill all exploits in silkroad database, im sorry but there is no possible way to shut it all off, hackings will always occur its harsh but true, hopefully suicide dont ban me again, im just speaking my mind on the subject
- PR0METHEUS
- Senior Member
- Posts: 4093
- Joined: Tue Aug 22, 2006 7:30 pm
- Quick Reply: Yes
- Location: Earth
- Contact:
SazerX wrote:ok well since i dont have any other way to put this... u cannot stop hacking of accounts, there will always be an exploit in silkroad database, there is no possible way to completely kill all exploits in silkroad database, im sorry but there is no possible way to shut it all off, hackings will always occur its harsh but true, hopefully suicide dont ban me again, im just speaking my mind on the subject
Any logical person would agree with you. Of course there will always be vulnerabilities in ANY piece of software. Efforts should still be made to identify and close as many vulnerabilities as possible. For the ones that can't be closed, compensating controls need to be put in place. Any residual risk from what's left just needs to be accepted. It's a constant battle. It's like that in any area of IT security.
*goes back to writing up security plans*
Missing the good times in SRO... 
SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)
SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)
Theoreticaly you can "hack" into sro, by SQL injections or using their SSL certificates. But 99.99%of hacked accounts are not hacked, but rather cracked. it, email+id then generate the answer.
BTW SuicideNz i remeber you when I was level 21, you recruited me for your guild. Same with my friend. we got to 26 then switched servers
Is your guild dead?
BTW SuicideNz i remeber you when I was level 21, you recruited me for your guild. Same with my friend. we got to 26 then switched servers
>Had to remove my Signature because idiots kept begging for accounts<
I heared that there's a virus (may be a trojan or a worm) that can steal ur login info
is that true? and if it was can that virus steal it from the game login screen or only the web?
is that true? and if it was can that virus steal it from the game login screen or only the web?
IGN: ????, lvl 4x Blader, server:Greece ---Stopped till Greece return as it was be4
IGN: ????, lvl6x Glavier, server:Eldorado --- boOored
IGN:????, lvl 3x glavier, Server:Pacific---making friends
IGN:????, lvl 3x nuker, server:sparta---falling in love <3
IGN:???? lvl 4x nuker, server:Zeus---fixing my keyboard
IGN: ????, lvl6x Glavier, server:Eldorado --- boOored
IGN:????, lvl 3x glavier, Server:Pacific---making friends
IGN:????, lvl 3x nuker, server:sparta---falling in love <3
IGN:???? lvl 4x nuker, server:Zeus---fixing my keyboard
- Pan_Raider(`_´)
- Senior Member
- Posts: 4737
- Joined: Fri Jul 28, 2006 11:20 am
- Quick Reply: Yes
- Location: Athens
- JackB4u3r
- Frequent Member
- Posts: 1115
- Joined: Sat Jun 10, 2006 9:08 pm
- Quick Reply: Yes
- Location: Sarajevo
tiglari51 wrote:I've had a bloddy 12-letter number+word password, a 11 letter username and a long e-mail address, but I still got hacked....Now, my info is so tight, not even I know all of it, unless I read it from a paper. Learned my lesson *sighs*
On my new account i needed about 5 days of constant logging in, in order to remember my user and pass xD.
It's better to have a dam long pass and user name with combined letters and number that you can't remember, then a short pass and user name that is easy to remember.
Stopped playing SRO a long time ago; still pr0.
- scorpius59
- Hi, I'm New Here
- Posts: 16
- Joined: Sun Mar 11, 2007 4:00 pm
- immortalkillerz
- Hi, I'm New Here
- Posts: 20
- Joined: Sun Mar 11, 2007 5:21 pm
- Quick Reply: Yes
- Location: meh shi ka
-
-]sKuLLz[-$phYnX
- Casual Member
- Posts: 72
- Joined: Mon Mar 26, 2007 2:11 pm
- pineapples
- Common Member
- Posts: 108
- Joined: Fri Oct 27, 2006 3:23 am
- Quick Reply: Yes
- Location: Jon's tummy.
- truez
- Frequent Member
- Posts: 1288
- Joined: Mon Jan 15, 2007 9:36 pm
- Quick Reply: Yes
- Location: Greece
JajaAmnem wrote:wait so its based ont he question. i dont even know what question i picked and i know the answer i put was so random like it didnt even make sense. tyhat sucks if i lose my pw theres no way im gettin it back. lol
Well its not just wit SRO .. even u email accounts or ur bank accounts have questions ...
So tink abt it
Next time make sure u save it up somewhere with the answers.
Cheers,
Truez
NVDIA Drivers
BSOD
Download anything for FREE
Truez
Zero_Doom wrote:Quick Easy Fix Turn off your computer, beat it with a hammer. If it turns back on when prompted, turn it back off and do again until it doesn't come on again. Once that is taken care of, go get a book and learn about computers.
NVDIA Drivers
BSOD
Download anything for FREE
-
austinwolfclaw
- Hi, I'm New Here
- Posts: 11
- Joined: Sun Sep 17, 2006 6:37 am
- Quick Reply: Yes
- Location: Alps
- Contact:
- DeathBeforeDishonor
- Active Member
- Posts: 990
- Joined: Sun Jun 10, 2007 1:05 am
- Quick Reply: Yes
- Location: Sitting at my computer?
-
shadowman20875
-
austinwolfclaw
- Hi, I'm New Here
- Posts: 11
- Joined: Sun Sep 17, 2006 6:37 am
- Quick Reply: Yes
- Location: Alps
- Contact:
shadowman20875 wrote:First, whoever moved this to Guides I really think it should go back on general, as it is a must read, and most people go to general first.
Second, for your SRO password and username, ADD A CAPITAL LETTER. Helps A LOT with brutes.
Last i checked you could only use lowercase letters.....
Lvl 21 Swordie
Alps Server
Alps Server
- PR0METHEUS
- Senior Member
- Posts: 4093
- Joined: Tue Aug 22, 2006 7:30 pm
- Quick Reply: Yes
- Location: Earth
- Contact:
leetest wrote:for some reason, when i try to find the pw of my friend using the "forget ur id and password" link on the homepage, it doesn't work
is it just me?
Last I checked, that link only works in Internet Explorer.
Btw, stop trying to break into your friend's account!
Missing the good times in SRO... 
SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)
SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)
Re: [READ]SRO Account Hacks: How it's done and how to stop i
whpwnage wrote: I dug up his secret question, I prepared a dictionary attack.
A dictoionary attack? I htought you don't use programs. Or is that a dictionary attack when you open a dictionary and write in all the words from A to Z?

- GeoHolyhart
- Hi, I'm New Here
- Posts: 9
- Joined: Fri Aug 03, 2007 10:10 am
- Quick Reply: Yes
- Location: The Moon
- Contact:
What amazes me, is why Joymax continues to let this happen. They could do the following to completely stop this form of account stealing.
1. Never allow e-mails to be publicized
2. Don't allow users to create characters with names similar to there account name.
3. Require passwords be numbers and letters over 8 characters.
4. Secret hints should be treated as a 2nd passwords, so instead of using something as dumb as "Birthplace: California" something like "Birthplace:southcali85".
This topic may seem to provoke more account crackers, which is true, but it gives the poor souls who don't know these kind of things a fighting chance as well, since they're the first ones targeted. Still I stand by my comment, that this should be Joymax's priority not ours. I know they're making pretty good money with the shear amount of silk people buy, so instead of constantly opening servers, they should try strengthening there security. Even though what I mentioned above costs nothing.
1. Never allow e-mails to be publicized
2. Don't allow users to create characters with names similar to there account name.
3. Require passwords be numbers and letters over 8 characters.
4. Secret hints should be treated as a 2nd passwords, so instead of using something as dumb as "Birthplace: California" something like "Birthplace:southcali85".
This topic may seem to provoke more account crackers, which is true, but it gives the poor souls who don't know these kind of things a fighting chance as well, since they're the first ones targeted. Still I stand by my comment, that this should be Joymax's priority not ours. I know they're making pretty good money with the shear amount of silk people buy, so instead of constantly opening servers, they should try strengthening there security. Even though what I mentioned above costs nothing.




