rev6 is *******
rev6 is *******
rev6 is ..... dumb...
they just added secret questions.... to ACCs
they try to make joymax fix that bug...
and now they are helping hackers...
wtf?
they just added secret questions.... to ACCs
they try to make joymax fix that bug...
and now they are helping hackers...
wtf?
keke
<---me
<---me- h33r0yuy
- Common Member
- Posts: 133
- Joined: Mon Mar 12, 2007 9:54 am
- Quick Reply: Yes
- Location: Venice
questions, not answers... if you knew the acct you could go click forgot password and it'd ask you the question anyway.
Last edited by h33r0yuy on Thu Dec 20, 2007 6:03 am, edited 1 time in total.

I'll need to update this someday ^
- h33r0yuy
- Common Member
- Posts: 133
- Joined: Mon Mar 12, 2007 9:54 am
- Quick Reply: Yes
- Location: Venice
https://www.joymax.com/portal/Joymax_Fr ... oymax.com/
go here. type any id you want, click ok!, and it shows the question.
rev6 isnt providing any info that you cant find from jm's site with that feature.
however, i dont get why that exists if you can do the same thing from jm's site.
go here. type any id you want, click ok!, and it shows the question.
rev6 isnt providing any info that you cant find from jm's site with that feature.
however, i dont get why that exists if you can do the same thing from jm's site.
Last edited by h33r0yuy on Thu Dec 20, 2007 6:10 am, edited 1 time in total.

I'll need to update this someday ^
_SomeOne_ wrote:h33r0yuy wrote:the question isnt secret, the answer is. the purpose of the question is to ask it to anyone who wants to access your account password, to make sure its you.
the question was never hidden...
then tell me ur question.. lol thought so
My answer is never related to the question in anyway whats so ever so doesn't matter
- h33r0yuy
- Common Member
- Posts: 133
- Joined: Mon Mar 12, 2007 9:54 am
- Quick Reply: Yes
- Location: Venice
_SomeOne_ wrote:h33r0yuy wrote:my question is "your high school"
reason i can say that is simply that, in order for you to hack my account, you would need my account id. if you had my account id, you could get my question anyway. dont need to bother hiding it, now do i?
u sure its not birthplace .. lol
im sure.

I'll need to update this someday ^
h33r0yuy wrote:_SomeOne_ wrote:h33r0yuy wrote:my question is "your high school"
reason i can say that is simply that, in order for you to hack my account, you would need my account id. if you had my account id, you could get my question anyway. dont need to bother hiding it, now do i?
u sure its not birthplace .. lol
im sure.
i think i no ur id lol
keke
<---me
<---me- h33r0yuy
- Common Member
- Posts: 133
- Joined: Mon Mar 12, 2007 9:54 am
- Quick Reply: Yes
- Location: Venice
oh, and just for fun...
go to http://www.worldofwarcraft.com/loginsup ... sword.html, put in anyone's wow id, and it tells you their secret question.
that would be the purpose of the question........
go to http://www.worldofwarcraft.com/loginsup ... sword.html, put in anyone's wow id, and it tells you their secret question.
that would be the purpose of the question........

I'll need to update this someday ^
- darkmaster21
- Ex-Staff
- Posts: 2156
- Joined: Sun Jul 15, 2007 3:11 am
- Quick Reply: Yes
- Location: Off Topic
- h33r0yuy
- Common Member
- Posts: 133
- Joined: Mon Mar 12, 2007 9:54 am
- Quick Reply: Yes
- Location: Venice
seriously guys, why is it dumb for a site to use the secret question for its intended purpose?
the secret question is used in this way: if you forget your password, you put in your id, it asks a question. once you put in the answer to the question (and a lot of places that use secret questions/answers also ask for email address), it sends you an email to change your password.
if it didnt ask the question when provided the acct id, how would that system work?
id rather the topic of guessing my id stop before it starts, thx.
in case you didnt know, this same system has been in use by lots of sites and games for years... how is it suddenly that some 3rd party site is providing info you can get in 10 seconds suddenly makes it a security breach?
fyi: im not defending rev6, im defending jm (yes, i would) because this is a totally ridiculous argument saying that its a security hole of any sort...
the secret question is used in this way: if you forget your password, you put in your id, it asks a question. once you put in the answer to the question (and a lot of places that use secret questions/answers also ask for email address), it sends you an email to change your password.
if it didnt ask the question when provided the acct id, how would that system work?
_SomeOne_ wrote:h33r0yuy wrote:ie why i didnt stick my id into rev6, lol
can i guess ur ID on here?
id rather the topic of guessing my id stop before it starts, thx.
in case you didnt know, this same system has been in use by lots of sites and games for years... how is it suddenly that some 3rd party site is providing info you can get in 10 seconds suddenly makes it a security breach?
fyi: im not defending rev6, im defending jm (yes, i would) because this is a totally ridiculous argument saying that its a security hole of any sort...
Last edited by h33r0yuy on Thu Dec 20, 2007 6:33 am, edited 1 time in total.

I'll need to update this someday ^
- darkmaster21
- Ex-Staff
- Posts: 2156
- Joined: Sun Jul 15, 2007 3:11 am
- Quick Reply: Yes
- Location: Off Topic
Sylhana wrote:As long as your secret answer is not revealed, I fail to see how this would be much of a security flaw.
Same here, everyone in going crazy for no reason. Any website reveals the Secret Question...how else would you know what to answer to obtain your password you forgot?

cSRO / Division 2 / Pure STR Bow / Lv 65
-
Wheres Waldo?
- New Member
- Posts: 25
- Joined: Thu Dec 20, 2007 5:58 am
- h33r0yuy
- Common Member
- Posts: 133
- Joined: Mon Mar 12, 2007 9:54 am
- Quick Reply: Yes
- Location: Venice
_SomeOne_ wrote:well remeber the expliot alll u needed is the ID and SQ right... so if u knew the ID and u find out the SQ and if ur SQ is easy then ur .....?
a. the exploit doesnt work anymore.
b. you need the ANSWER, not the question. youve been able to know a SQ for years if you knew the id...

I'll need to update this someday ^

