rev6 is *******

A place for general discussion about Silkroad Online. Talk about the game or ask questions. Please keep threads Silkroad Online related.
User avatar
_SomeOne_
Active Member
Posts: 735
Joined: Mon Sep 17, 2007 1:41 pm
Quick Reply: Yes
Location: Troy

rev6 is *******

Post by _SomeOne_ »

rev6 is ..... dumb...
they just added secret questions.... to ACCs
they try to make joymax fix that bug...
and now they are helping hackers...
wtf?
keke

Image <---me

User avatar
h33r0yuy
Common Member
Posts: 133
Joined: Mon Mar 12, 2007 9:54 am
Quick Reply: Yes
Location: Venice

Post by h33r0yuy »

questions, not answers... if you knew the acct you could go click forgot password and it'd ask you the question anyway.
Last edited by h33r0yuy on Thu Dec 20, 2007 6:03 am, edited 1 time in total.
Image
I'll need to update this someday ^

User avatar
Wu
Addicted Member
Posts: 2521
Joined: Wed Apr 04, 2007 2:48 am
Quick Reply: Yes
Location: Around.

Post by Wu »

holy crap you're right
Image

User avatar
_SomeOne_
Active Member
Posts: 735
Joined: Mon Sep 17, 2007 1:41 pm
Quick Reply: Yes
Location: Troy

Post by _SomeOne_ »

h33r0yuy wrote:questions, not answers... if you knew the acct you could go click forgot password and it'd ask you the question anyway.

yea thats what i said..... secret questions.. not secret answer........
keke

Image <---me

User avatar
_SomeOne_
Active Member
Posts: 735
Joined: Mon Sep 17, 2007 1:41 pm
Quick Reply: Yes
Location: Troy

Post by _SomeOne_ »

ppl can type in random ids... like nick silkroad123 happyme ect,,
and get the SQ
Last edited by _SomeOne_ on Thu Dec 20, 2007 6:06 am, edited 1 time in total.
keke

Image <---me

SpInKsTaR
Valued Member
Posts: 412
Joined: Fri Oct 19, 2007 4:45 pm
Quick Reply: Yes
Location: Pacific
Contact:

Post by SpInKsTaR »

MAGICAL.....
It works :banghead:
<<banned from SRF for bot admission. -SG>>

User avatar
Crumpets
Forum Legend
Posts: 7800
Joined: Mon Aug 14, 2006 4:58 pm
Quick Reply: Yes
Location:         

Post by Crumpets »

Even if it's just the answer, rev6 is now raiding people's privacy.

**** Nimble seriously.
<< banned for being a constant problem. -cin >>

Wheres Waldo?
New Member
Posts: 25
Joined: Thu Dec 20, 2007 5:58 am

Post by Wheres Waldo? »

Just dont go there? =/

User avatar
h33r0yuy
Common Member
Posts: 133
Joined: Mon Mar 12, 2007 9:54 am
Quick Reply: Yes
Location: Venice

Post by h33r0yuy »

https://www.joymax.com/portal/Joymax_Fr ... oymax.com/

go here. type any id you want, click ok!, and it shows the question.



rev6 isnt providing any info that you cant find from jm's site with that feature.

however, i dont get why that exists if you can do the same thing from jm's site.
Last edited by h33r0yuy on Thu Dec 20, 2007 6:10 am, edited 1 time in total.
Image
I'll need to update this someday ^

User avatar
_SomeOne_
Active Member
Posts: 735
Joined: Mon Sep 17, 2007 1:41 pm
Quick Reply: Yes
Location: Troy

Post by _SomeOne_ »

Wheres Waldo? wrote:Just dont go there? =/

they take it from ingame... not from the site
keke

Image <---me

SpInKsTaR
Valued Member
Posts: 412
Joined: Fri Oct 19, 2007 4:45 pm
Quick Reply: Yes
Location: Pacific
Contact:

Post by SpInKsTaR »

Image

Yeah....uhh wtf....
Why would Joymax do that....You just put in the username and it comes up with the "SECRET" Question...

Joymax is extremely strange :S
<<banned from SRF for bot admission. -SG>>

User avatar
h33r0yuy
Common Member
Posts: 133
Joined: Mon Mar 12, 2007 9:54 am
Quick Reply: Yes
Location: Venice

Post by h33r0yuy »

the question isnt secret, the answer is. the purpose of the question is to ask it to anyone who wants to access your account password, to make sure its you.

the question was never hidden...
Image
I'll need to update this someday ^

User avatar
_SomeOne_
Active Member
Posts: 735
Joined: Mon Sep 17, 2007 1:41 pm
Quick Reply: Yes
Location: Troy

Post by _SomeOne_ »

h33r0yuy wrote:the question isnt secret, the answer is. the purpose of the question is to ask it to anyone who wants to access your account password, to make sure its you.

the question was never hidden...

then tell me ur question.. lol thought so
keke

Image <---me

User avatar
h33r0yuy
Common Member
Posts: 133
Joined: Mon Mar 12, 2007 9:54 am
Quick Reply: Yes
Location: Venice

Post by h33r0yuy »

my question is "your high school"

reason i can say that is simply that, in order for you to hack my account, you would need my account id. if you had my account id, you could get my question anyway. dont need to bother hiding it, now do i?
Image
I'll need to update this someday ^

User avatar
_SomeOne_
Active Member
Posts: 735
Joined: Mon Sep 17, 2007 1:41 pm
Quick Reply: Yes
Location: Troy

Post by _SomeOne_ »

h33r0yuy wrote:my question is "your high school"

reason i can say that is simply that, in order for you to hack my account, you would need my account id. if you had my account id, you could get my question anyway. dont need to bother hiding it, now do i?

u sure its not birthplace .. lol
keke

Image <---me

User avatar
Nyte
Regular Member
Posts: 226
Joined: Sun Aug 05, 2007 7:45 am

Post by Nyte »

_SomeOne_ wrote:
h33r0yuy wrote:the question isnt secret, the answer is. the purpose of the question is to ask it to anyone who wants to access your account password, to make sure its you.

the question was never hidden...

then tell me ur question.. lol thought so


My answer is never related to the question in anyway whats so ever so doesn't matter :) Who ever does put a real related answer to their question is plain stupid.
Image

User avatar
h33r0yuy
Common Member
Posts: 133
Joined: Mon Mar 12, 2007 9:54 am
Quick Reply: Yes
Location: Venice

Post by h33r0yuy »

_SomeOne_ wrote:
h33r0yuy wrote:my question is "your high school"

reason i can say that is simply that, in order for you to hack my account, you would need my account id. if you had my account id, you could get my question anyway. dont need to bother hiding it, now do i?

u sure its not birthplace .. lol


im sure.
Image
I'll need to update this someday ^

User avatar
_SomeOne_
Active Member
Posts: 735
Joined: Mon Sep 17, 2007 1:41 pm
Quick Reply: Yes
Location: Troy

Post by _SomeOne_ »

h33r0yuy wrote:
_SomeOne_ wrote:
h33r0yuy wrote:my question is "your high school"

reason i can say that is simply that, in order for you to hack my account, you would need my account id. if you had my account id, you could get my question anyway. dont need to bother hiding it, now do i?

u sure its not birthplace .. lol


im sure.

i think i no ur id lol
keke

Image <---me

User avatar
h33r0yuy
Common Member
Posts: 133
Joined: Mon Mar 12, 2007 9:54 am
Quick Reply: Yes
Location: Venice

Post by h33r0yuy »

oh, and just for fun...


go to http://www.worldofwarcraft.com/loginsup ... sword.html, put in anyone's wow id, and it tells you their secret question.


that would be the purpose of the question........
Image
I'll need to update this someday ^

User avatar
darkmaster21
Ex-Staff
Posts: 2156
Joined: Sun Jul 15, 2007 3:11 am
Quick Reply: Yes
Location: Off Topic

Post by darkmaster21 »

I'm not entering my ID in there, they might have a log of all the ID's entered. Then bruteforce the account.
Image

cSRO / Division 2 / Pure STR Bow / Lv 65

User avatar
h33r0yuy
Common Member
Posts: 133
Joined: Mon Mar 12, 2007 9:54 am
Quick Reply: Yes
Location: Venice

Post by h33r0yuy »

ie why i didnt stick my id into rev6, lol
Image
I'll need to update this someday ^

User avatar
_SomeOne_
Active Member
Posts: 735
Joined: Mon Sep 17, 2007 1:41 pm
Quick Reply: Yes
Location: Troy

Post by _SomeOne_ »

nvm.... joymax.com has the same thing...
JM is dumb aswell
keke

Image <---me

User avatar
_SomeOne_
Active Member
Posts: 735
Joined: Mon Sep 17, 2007 1:41 pm
Quick Reply: Yes
Location: Troy

Post by _SomeOne_ »

h33r0yuy wrote:ie why i didnt stick my id into rev6, lol

can i guess ur ID on here?
keke

Image <---me

BryaN
Advanced Member
Posts: 2264
Joined: Thu Apr 27, 2006 7:47 pm

Post by BryaN »

Lol you still neeed ID but joymax omg comeon...!!!
<<banned from SRF for bot admission. -SG>>

User avatar
h33r0yuy
Common Member
Posts: 133
Joined: Mon Mar 12, 2007 9:54 am
Quick Reply: Yes
Location: Venice

Post by h33r0yuy »

seriously guys, why is it dumb for a site to use the secret question for its intended purpose?


the secret question is used in this way: if you forget your password, you put in your id, it asks a question. once you put in the answer to the question (and a lot of places that use secret questions/answers also ask for email address), it sends you an email to change your password.

if it didnt ask the question when provided the acct id, how would that system work?

_SomeOne_ wrote:
h33r0yuy wrote:ie why i didnt stick my id into rev6, lol

can i guess ur ID on here?


id rather the topic of guessing my id stop before it starts, thx.


in case you didnt know, this same system has been in use by lots of sites and games for years... how is it suddenly that some 3rd party site is providing info you can get in 10 seconds suddenly makes it a security breach?

fyi: im not defending rev6, im defending jm (yes, i would) because this is a totally ridiculous argument saying that its a security hole of any sort...
Last edited by h33r0yuy on Thu Dec 20, 2007 6:33 am, edited 1 time in total.
Image
I'll need to update this someday ^

Sylhana
Veteran Member
Posts: 3467
Joined: Tue Mar 06, 2007 8:05 am
Quick Reply: Yes
Location: Babel

Post by Sylhana »

As long as your secret answer is not revealed, I fail to see how this would be much of a security flaw.
<<banned from SRF for bot support. -SG>>

User avatar
darkmaster21
Ex-Staff
Posts: 2156
Joined: Sun Jul 15, 2007 3:11 am
Quick Reply: Yes
Location: Off Topic

Post by darkmaster21 »

Sylhana wrote:As long as your secret answer is not revealed, I fail to see how this would be much of a security flaw.


Same here, everyone in going crazy for no reason. Any website reveals the Secret Question...how else would you know what to answer to obtain your password you forgot?
Image

cSRO / Division 2 / Pure STR Bow / Lv 65

User avatar
_SomeOne_
Active Member
Posts: 735
Joined: Mon Sep 17, 2007 1:41 pm
Quick Reply: Yes
Location: Troy

Post by _SomeOne_ »

well remeber the expliot alll u needed is the ID and SQ right... so if u knew the ID and u find out the SQ and if ur SQ is easy then ur .....?
keke

Image <---me

Wheres Waldo?
New Member
Posts: 25
Joined: Thu Dec 20, 2007 5:58 am

Post by Wheres Waldo? »

U guys get paranoid to easy..... its a security thing... chill out :)


~~~~ Magni

User avatar
h33r0yuy
Common Member
Posts: 133
Joined: Mon Mar 12, 2007 9:54 am
Quick Reply: Yes
Location: Venice

Post by h33r0yuy »

_SomeOne_ wrote:well remeber the expliot alll u needed is the ID and SQ right... so if u knew the ID and u find out the SQ and if ur SQ is easy then ur .....?


a. the exploit doesnt work anymore.

b. you need the ANSWER, not the question. youve been able to know a SQ for years if you knew the id...
Image
I'll need to update this someday ^

Post Reply

Return to “Silkroad General Discussion”