[READ]SRO Account Hacks: How it's done and how to stop it.

Here you can post guides and tutorials you have written for Silkroad Online. If submitting a guide from another forum, please post credit to the author.
User avatar
SuicideNz
Regular Member
Posts: 221
Joined: Fri Dec 01, 2006 7:13 am
Quick Reply: Yes
Location: Tibet

Post by SuicideNz »

hey i appreciate wat ur trying to do but can ppl stop making these hacking posts

it is showing ppl how easy it is, so then more ppl go and try it out.

i got hacked and i was hoping it was u but no email came up so i wasnt so lucky.
Nick: SuicidalNz
Build: Fire, Str, Bow
Guild: Mushroom
Image

User avatar
PR0METHEUS
Senior Member
Posts: 4093
Joined: Tue Aug 22, 2006 7:30 pm
Quick Reply: Yes
Location: Earth
Contact:

Post by PR0METHEUS »

SuicideNz wrote:hey i appreciate wat ur trying to do but can ppl stop making these hacking posts

it is showing ppl how easy it is, so then more ppl go and try it out.

i got hacked and i was hoping it was u but no email came up so i wasnt so lucky.


I think it's good to share these things with everyone. The more people know about these techniques, the better prepared they'll be to prevent them. It's just like with vulnerabilities in software. Microsoft releases security bulletins all the time informing users of various vulnerabilities, and how to protect themselves from being exploited. Of course Microsoft has plenty of security problems themselves, but just an example.

It's better than just keeping users in the dark and unable to protect themselves.
Missing the good times in SRO... :love:

SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)

User avatar
exality
Loyal Member
Posts: 1802
Joined: Wed Mar 07, 2007 6:31 am
Quick Reply: Yes
Location: **** if i know

Post by exality »

see if you can catch me! dont repost the info tho pm it to me to see if your right

User avatar
Dark0Archer0
Regular Member
Posts: 342
Joined: Fri Feb 16, 2007 6:58 am
Quick Reply: Yes
Location: Oasis

Post by Dark0Archer0 »

Posting this topic actually would give more potential hackers the information they need to be able to hack accounts successfully than help players keep their accounts safe. Legit players who don't hack would be less inclined to read this topic than someone who wants to learn.

Thankyou for broadening the hacker community, greatly appreciated.
Image

SOS Pie FTW!!!

User avatar
PR0METHEUS
Senior Member
Posts: 4093
Joined: Tue Aug 22, 2006 7:30 pm
Quick Reply: Yes
Location: Earth
Contact:

Post by PR0METHEUS »

Dark0Archer0 wrote:Posting this topic actually would give more potential hackers the information they need to be able to hack accounts successfully than help players keep their accounts safe. Legit players who don't hack would be less inclined to read this topic than someone who wants to learn.

Thankyou for broadening the hacker community, greatly appreciated.


True, but with all the "OMG I got hacked" threads that we see here, we can just point that user to this thread so he/she can learn ways to help prevent it from happening in the future. This information is already out there in the hacker community, and anyone that wants to hack will find it whether this thread exists or not.
Missing the good times in SRO... :love:

SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)

SazerX
Hi, I'm New Here
Posts: 10
Joined: Wed Mar 14, 2007 1:37 am

Post by SazerX »

ok well since i dont have any other way to put this... u cannot stop hacking of accounts, there will always be an exploit in silkroad database, there is no possible way to completely kill all exploits in silkroad database, im sorry but there is no possible way to shut it all off, hackings will always occur its harsh but true, hopefully suicide dont ban me again, im just speaking my mind on the subject

User avatar
PR0METHEUS
Senior Member
Posts: 4093
Joined: Tue Aug 22, 2006 7:30 pm
Quick Reply: Yes
Location: Earth
Contact:

Post by PR0METHEUS »

SazerX wrote:ok well since i dont have any other way to put this... u cannot stop hacking of accounts, there will always be an exploit in silkroad database, there is no possible way to completely kill all exploits in silkroad database, im sorry but there is no possible way to shut it all off, hackings will always occur its harsh but true, hopefully suicide dont ban me again, im just speaking my mind on the subject


Any logical person would agree with you. Of course there will always be vulnerabilities in ANY piece of software. Efforts should still be made to identify and close as many vulnerabilities as possible. For the ones that can't be closed, compensating controls need to be put in place. Any residual risk from what's left just needs to be accepted. It's a constant battle. It's like that in any area of IT security.

*goes back to writing up security plans*
Missing the good times in SRO... :love:

SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)

User avatar
FuryAngle
Regular Member
Posts: 253
Joined: Wed Feb 14, 2007 5:46 pm

Post by FuryAngle »

Theoreticaly you can "hack" into sro, by SQL injections or using their SSL certificates. But 99.99%of hacked accounts are not hacked, but rather cracked. it, email+id then generate the answer.

BTW SuicideNz i remeber you when I was level 21, you recruited me for your guild. Same with my friend. we got to 26 then switched servers :roll: Is your guild dead?
>Had to remove my Signature because idiots kept begging for accounts<

User avatar
Dr_Etsh
Hi, I'm New Here
Posts: 24
Joined: Fri Dec 29, 2006 5:22 pm

Post by Dr_Etsh »

I heared that there's a virus (may be a trojan or a worm) that can steal ur login info :shock:

is that true? and if it was can that virus steal it from the game login screen or only the web? :?
IGN: ????, lvl 4x Blader, server:Greece ---Stopped till Greece return as it was be4
IGN: ????, lvl6x Glavier, server:Eldorado --- boOored
IGN:????, lvl 3x glavier, Server:Pacific---making friends ;)
IGN:????, lvl 3x nuker, server:sparta---falling in love <3
IGN:???? lvl 4x nuker, server:Zeus---fixing my keyboard :D

User avatar
Pan_Raider(`_´)
Senior Member
Posts: 4737
Joined: Fri Jul 28, 2006 11:20 am
Quick Reply: Yes
Location: Athens

Post by Pan_Raider(`_´) »

There might be a trojan. But then it is acquired from some hacker source.
Trojans steal all you info about everything u do, the hacker gets all he needs to snuff you out.
Image

User avatar
lolster
Regular Member
Posts: 318
Joined: Wed Mar 21, 2007 12:57 am

ahhh

Post by lolster »

what kind of idiot would do that it so simple >.> :? lol :P

User avatar
Stress
Ex-Staff
Posts: 4599
Joined: Thu Oct 26, 2006 7:42 am
Quick Reply: Yes
Location: Studying Computer Science, Vienna

Post by Stress »

I've had a bloddy 12-letter number+word password, a 11 letter username and a long e-mail address, but I still got hacked.... :( Now, my info is so tight, not even I know all of it, unless I read it from a paper. Learned my lesson *sighs*
Carry your cross, and I'll carry mine.

User avatar
JackB4u3r
Frequent Member
Posts: 1115
Joined: Sat Jun 10, 2006 9:08 pm
Quick Reply: Yes
Location: Sarajevo

Post by JackB4u3r »

tiglari51 wrote:I've had a bloddy 12-letter number+word password, a 11 letter username and a long e-mail address, but I still got hacked.... :( Now, my info is so tight, not even I know all of it, unless I read it from a paper. Learned my lesson *sighs*


On my new account i needed about 5 days of constant logging in, in order to remember my user and pass xD.

It's better to have a dam long pass and user name with combined letters and number that you can't remember, then a short pass and user name that is easy to remember.
Stopped playing SRO a long time ago; still pr0.

User avatar
scorpius59
Hi, I'm New Here
Posts: 16
Joined: Sun Mar 11, 2007 4:00 pm

Post by scorpius59 »

yeh it's common sense stuff we've been warned about for years but hearing someone tell how EASY it is exposes the fact of how MANY are probably capable, mean, and bored enough to do it! And all over a friggin game account no less! Is there no place you can get away from this crap...
LiuKain

User avatar
immortalkillerz
Hi, I'm New Here
Posts: 20
Joined: Sun Mar 11, 2007 5:21 pm
Quick Reply: Yes
Location: meh shi ka

Post by immortalkillerz »

Why would you waste your time flaming him, he has probabally helped those who didnt know how to prevent hacking well...

Thanks for the guide.....

o.0

-]sKuLLz[-$phYnX
Casual Member
Posts: 72
Joined: Mon Mar 26, 2007 2:11 pm

Post by -]sKuLLz[-$phYnX »

This isnt hacking. This is cracking.

It's easy all you need is a program H*d** [Not saying the name]. Get the IP to both server's and login. pick a username and wait. heres what the program looks like using CMD.

Please Note: This isn't on SRO.

Image

User avatar
pineapples
Common Member
Posts: 108
Joined: Fri Oct 27, 2006 3:23 am
Quick Reply: Yes
Location: Jon's tummy.

Post by pineapples »

Wow. Nice. Thanks. :)
Image


I'M PEACEFUL


+ I borrowed this account from the old pineapples.
shhhhhh!

JajaAmnem
Hi, I'm New Here
Posts: 6
Joined: Sun Apr 29, 2007 12:15 pm

Post by JajaAmnem »

wait so its based ont he question. i dont even know what question i picked and i know the answer i put was so random like it didnt even make sense. tyhat sucks if i lose my pw theres no way im gettin it back. lol

dyn3x
Hi, I'm New Here
Posts: 5
Joined: Thu May 03, 2007 5:05 pm
Quick Reply: Yes
Location: Sparta
Contact:

Post by dyn3x »

,.....

User avatar
truez
Frequent Member
Posts: 1288
Joined: Mon Jan 15, 2007 9:36 pm
Quick Reply: Yes
Location: Greece

Post by truez »

JajaAmnem wrote:wait so its based ont he question. i dont even know what question i picked and i know the answer i put was so random like it didnt even make sense. tyhat sucks if i lose my pw theres no way im gettin it back. lol

Well its not just wit SRO .. even u email accounts or ur bank accounts have questions ...
So tink abt it :roll:

Next time make sure u save it up somewhere with the answers.
Cheers,
Truez
Zero_Doom wrote:Quick Easy Fix Turn off your computer, beat it with a hammer. If it turns back on when prompted, turn it back off and do again until it doesn't come on again. Once that is taken care of, go get a book and learn about computers.

NVDIA Drivers
BSOD
Download anything for FREE

austinwolfclaw
Hi, I'm New Here
Posts: 11
Joined: Sun Sep 17, 2006 6:37 am
Quick Reply: Yes
Location: Alps
Contact:

Post by austinwolfclaw »

You know, a long long long time ago, someone gave me some usernames and passwords to try out ((i wanted to sic a bunch of tigers on a high lvl person)) only one username/password worked, however the character was a murderer, and it wasnt worth playing. so i left it behind, never to be touched again :P

User avatar
DeathBeforeDishonor
Active Member
Posts: 990
Joined: Sun Jun 10, 2007 1:05 am
Quick Reply: Yes
Location: Sitting at my computer?

Post by DeathBeforeDishonor »

Very Nice

User avatar
hootsh
Active Member
Posts: 541
Joined: Wed Jun 13, 2007 9:15 am
Quick Reply: Yes
Location: Cairo, Egypt

Post by hootsh »

Thanks for the email tip..i could have easily fallen for that i'm a pretty social person ingame :p

There doesnt seem to be lots of friendly users around lol so i havent had a chance to spread my email around thank God, now i changed it :P

shadowman20875

Post by shadowman20875 »

First, whoever moved this to Guides I really think it should go back on general, as it is a must read, and most people go to general first.

Second, for your SRO password and username, ADD A CAPITAL LETTER. Helps A LOT with brutes.

austinwolfclaw
Hi, I'm New Here
Posts: 11
Joined: Sun Sep 17, 2006 6:37 am
Quick Reply: Yes
Location: Alps
Contact:

Post by austinwolfclaw »

shadowman20875 wrote:First, whoever moved this to Guides I really think it should go back on general, as it is a must read, and most people go to general first.

Second, for your SRO password and username, ADD A CAPITAL LETTER. Helps A LOT with brutes.


Last i checked you could only use lowercase letters.....
Lvl 21 Swordie
Alps Server

WhiteSun
Hi, I'm New Here
Posts: 2
Joined: Tue Jun 19, 2007 3:00 pm

Post by WhiteSun »

this guide came to late for me :(

User avatar
leetest
Hi, I'm New Here
Posts: 16
Joined: Wed Jun 27, 2007 3:16 pm

Post by leetest »

for some reason, when i try to find the pw of my friend using the "forget ur id and password" link on the homepage, it doesn't work

is it just me?

User avatar
PR0METHEUS
Senior Member
Posts: 4093
Joined: Tue Aug 22, 2006 7:30 pm
Quick Reply: Yes
Location: Earth
Contact:

Post by PR0METHEUS »

leetest wrote:for some reason, when i try to find the pw of my friend using the "forget ur id and password" link on the homepage, it doesn't work

is it just me?


Last I checked, that link only works in Internet Explorer.

Btw, stop trying to break into your friend's account! :P :P
Missing the good times in SRO... :love:

SRO:
1x, STR Blader (Thebes)
54, STR blader (Venice)
0x, INT wizard (Venice)
19, INT spear (Venice)
34, STR rogue/bard (Venus)
0x, STR blader (Venus)
8x, INT bard/cleric (Gaia)

User avatar
yesyes
Common Member
Posts: 163
Joined: Tue Jul 24, 2007 4:51 pm
Quick Reply: Yes
Location: Red Sea

Re: [READ]SRO Account Hacks: How it's done and how to stop i

Post by yesyes »

whpwnage wrote: I dug up his secret question, I prepared a dictionary attack.

A dictoionary attack? I htought you don't use programs. Or is that a dictionary attack when you open a dictionary and write in all the words from A to Z?
Image

User avatar
GeoHolyhart
Hi, I'm New Here
Posts: 9
Joined: Fri Aug 03, 2007 10:10 am
Quick Reply: Yes
Location: The Moon
Contact:

Post by GeoHolyhart »

What amazes me, is why Joymax continues to let this happen. They could do the following to completely stop this form of account stealing.

1. Never allow e-mails to be publicized
2. Don't allow users to create characters with names similar to there account name.
3. Require passwords be numbers and letters over 8 characters.
4. Secret hints should be treated as a 2nd passwords, so instead of using something as dumb as "Birthplace: California" something like "Birthplace:southcali85".

This topic may seem to provoke more account crackers, which is true, but it gives the poor souls who don't know these kind of things a fighting chance as well, since they're the first ones targeted. Still I stand by my comment, that this should be Joymax's priority not ours. I know they're making pretty good money with the shear amount of silk people buy, so instead of constantly opening servers, they should try strengthening there security. Even though what I mentioned above costs nothing.
Image
Image

Post Reply

Return to “Guides and Tutorials”