On sieghardt a bunch of people have been hacked or have had attempted hackings from a proxy IP of 74.132.216.39
A few friends have had in the neighboorhood of over 3,000 password reset attempts in a few short minutes. Therefore, this person is using a bruteforce method to **** accounts. PlayNC should really really think about putting in a limit to failures on an attempt to crack a pw before locking people out. This person has got alot of people already. Why let him have more?
I have to agree, there needs to be some kind of confirmation such as having the password sent to your email account rather than being allowed to simply change it on the website.
With infinite attempts and no real security system in place, all a hacker needs to know is your account name before they can brute force their way into it. There needs to be soemthing like a 5 try limit, but even that won't protect users completely thus a confirmation outside of NC's website is also needed.
One of my clan mates on kain had his account hacked
someone has to do something, if a clan lord get hacked? ahh man.
well i know if it happens again, me and 140 other players are leaving the game. theres other online roleplays out there. i like this one but to lose 2 years of everything because a company wont do anything about it.......wait a second.....wth do we pay a subscription for if they dont offer security?
someone of importance please lay it down for me.
we pay 16 a month to lose everything we ever worked for in this fantasy world..........
somethings wrong with this picture
One of my clan mates on kain had his account hacked
someone has to do something, if a clan lord get hacked? ahh man.
well i know if it happens again, me and 140 other players are leaving the game. theres other online roleplays out there. i like this one but to lose 2 years of everything because a company wont do anything about it.......wait a second.....wth do we pay a subscription for if they dont offer security?
someone of importance please lay it down for me.
we pay 16 a month to lose everything we ever worked for in this fantasy world..........
somethings wrong with this picture
You do know that hacking happens in every game, right?
I've always been concerned about it as well. I cant believe how easy it is to reset a PW. I really wish they would do something about it as well, even more then just a limit. They know how hard it is to make it in this game. If i lost it all to some lazy [censored] i would be beyond ******.
It's true that hacking does happen in every game, but most of the time it's due to the failures of the users rather than the company. Account security is extremely weak on this website as the account name is the only thing that a hacker needs to know.
It would be nice to have tighter security to put people's mind at ease, and so they would only have themselves to blame when they are hacked.
according to ncsoft there is not one single case of an account being 'hacked'. Either people give away personal information such as names, email addresses or account information such as usernames but there is no confirmed 'hacking' of an account without prior information.
If you dont have someones username, password or email address you arent going to be able to get anything.
In computer security, hacker refers to a type of computer hacker who is involved in programming and computer insecurity and is able to exploit systems or gain unauthorized access through skills, tactics and detailed knowledge.
In the most narrow use of the word, no, NC has never had its security breached by a malicious intruder. There have been countless reports of people having their user accounts taken over however, and any hacker that has any idea what he's doing can accomplish this easily by knowing the person's username.
Some people actually use their username as their forum account (bad idea), or use a name of something they like and might accidentally mention. There are plenty of ways for clever people to discover usernames without directly asking, and additional security on NC's part can only be a good thing for the players.
I'v to sign that.
Yesterday I'v received "13" mails saying that someone was trying to reset the password of my account. All saying that it failed, but still strange. Happened on an old account that I used for some beta applications. Never used it tho :/
One of my clan mates on kain had his account hacked
someone has to do something, if a clan lord get hacked? ahh man.
well i know if it happens again, me and 140 other players are leaving the game. theres other online roleplays out there. i like this one but to lose 2 years of everything because a company wont do anything about it.......wait a second.....wth do we pay a subscription for if they dont offer security?
someone of importance please lay it down for me.
we pay 16 a month to lose everything we ever worked for in this fantasy world..........
somethings wrong with this picture
You do know that hacking happens in every game, right?
Especially of those using questionable software. :eek:
Four more people were hacked by brute force today. Some of them had more than 2,000 emails of failed attempts at getting into their accounts... NC has to be registering these emails being sent out. This needs to be dealt with A.S.A.P
I plead with NC to look at this thread. Multiple IP's from a Proxy are attempting to **** peoples accounts. If you need to take down the servers for two days in order to assure security please do. ALOT of people are losing their gear... =(
were thinking of moving to city of heroes,wow or something ewlse...once we find a game, if city of heroes, itd be ok ...the game has no economy so the only thing someone could really do is run around on our chars,
in this game when someone gets into the database , or emulates your password, you lose real world cash, time and what not.
Maybe they can implement a bank pin setting so it will be harder to **** once they enter your account and you dont lose "everything", or maybe an inventory lock sytem with a password to it or, maybe both!...just some ideas =P
If this the same ip, it time to bring the authorities in.
If if you get the email saying it failed, please send it to support.
Maybe they will do something when lot of l2 community get the email in there boxes saying the ip tryed to get into there account.
the bank pin thing i saw that in ryl, a similiar roleplay game.
basically you could reset the password at anytime. you went to the warehouse it asked for a code, you put it in, you got your stuff. i don't know if it had a set time to put the psswd in , say the third time it would lock it, not sure if it did that. but it'd be nice to see that.
you said failed attempts? Doesn't that mean NC is already doing it's job?
Not at all.Thats just means that "hacker" tryed wrong password.Problem is that he can try over and over and over untill he succedes.There is no limit on failed attempts(most of message boards for example has 5 attempts limmit and after 5 incorect passwords you have to wait 12 hours to try again).There is no email confirmation on password resset , you just get notification that your password has been resseted.
In short - even some message board administred by 15 year old boy has better acc security.
In the most narrow use of the word, no, NC has never had its security breached by a malicious intruder.
WRONG. Some Russian chick hacked the C4 PTS and could spawn items at will. She brought the whole PTS down for more than 1 day.
Malicious intuders are everywhere.
Brute force is hardly the way of a good hacker. That's a n00b, and his IP is known.
On the other hand, a known pirate showing his IP is an invitation to hackers. I still haven't suffered any attacks. Most hackers with experience don't use "broadcasting" as a method of attack. They use finesse, and you never see them act.
Client : So, how was your test ?
Dark : I stole 10 thousand dollars from your security flaws.
Client : So where is the money ?
Dark : *Throws 10K on the desk*. I got it from your clerk less than 10 minutes ago, if you'd like to review the replay.
Client : That's ok. Your check is in my secretary's hand. Just go see her.
Dark : A pleasure doing business with you.
It is worrying that there is not a limit of failed logins on the account page, I always thought there was, I guess I just assumed that would be common sense.
I strongly advise NCSoft to add a limit of 3 or 5 failed logins in a 12hour period to PlayNC. This effects everyone from all of your games NC, it's a worthwhile change to protect your customers.
WRONG. Some Russian chick hacked the C4 PTS and could spawn items at will. She brought the whole PTS down for more than 1 day.
I stand corrected, I suppose that's what I get for missing nearly a year.
Brute force is hardly the way of a good hacker. That's a n00b, and his IP is known.
This is very true, and that is why it is so easy to defend against. A policy to prevent brute force hacking is the most basic defense that any company employs; the most common example being a limit on password change attempts.
Because of idiotic gameguard, I have to type my password in very very very very very slowly, otherwise it jumbles up the order (same thing with my ID, if I type at a normal speed it jumbles it). I sometimes get my own password wrong 10 times in a row. I am a very good typist. I NEVER have any problems entering my own passwords in all of the systems I am required to log onto at work.
Locking an account after x number of failed attempts would SUCK as long as we have gameguard.
Because of idiotic gameguard, I have to type my password in very very very very very slowly, otherwise it jumbles up the order (same thing with my ID, if I type at a normal speed it jumbles it). I sometimes get my own password wrong 10 times in a row. I am a very good typist. I NEVER have any problems entering my own passwords in all of the systems I am required to log onto at work.
Locking an account after x number of failed attempts would SUCK as long as we have gameguard.
Because of idiotic gameguard, I have to type my password in very very very very very slowly, otherwise it jumbles up the order (same thing with my ID, if I type at a normal speed it jumbles it). I sometimes get my own password wrong 10 times in a row. I am a very good typist. I NEVER have any problems entering my own passwords in all of the systems I am required to log onto at work.
Locking an account after x number of failed attempts would SUCK as long as we have gameguard.
I have this same problem as well. :(
It's almost (and always has been) non-existant on PTS.
Have you tried it while listening to music? It freezes the computer with each keypress.
i think it's [censored]
i dont think it's posable for noob hacker to **** someone's account of lineage2 or webpage account
a real hacker it's useless to **** into a x-player account for his "stuff" just a waste of time and risk
real hackers are people that gives the creeps to banks and things so it's all bull**** people clam his/her account is hacked dont belive it
NCSoft has a strict write off policy on anything that most users would consider as helping their users.
Case in point:
Thank you for contacting us regarding this matter. Dealing with a hacked account is terribly frustrating, and can leave a victim with a feeling of sincere vulnerability and loss. We have constructed this document to help players get through this situation, as well as to empower you to take action on the individual(s) responsible.
Please understand that NCsoft only considers a "hacked" account to be the unauthorized access of an account resulting from the criminal act of distributing and propagating a keylogger, Trojan, or other computer virus. We do not recognize a "hacked" account to be the theft of items resulting from any sort of account sharing, trading, or selling. Please remember that the integrity, security and interactions of characters on an account are the sole responsibility of the account owner, and not NCsoft's. Additionally, we do not return any items that are missing as a result of hacked/stolen accounts or having been accessed by another person. Owners are responsible for maintaining the confidentiality of their password and security of their account at all times.
The act of writing and distributing malicious code is a criminal act, one that the police will often investigate. A victim will need to contact their local authorities in order to report this activity. Because the actual crime was committed on the user's system, and not a system owned by NCsoft, we cannot file such the report on behalf of the user.
During the investigation, police will likely need to contact us with a subpoena request to identify and track down the perpetrators. This can be done by writing or faxing NCsoft at the contact below:
NC Interactive, Inc.
Account Administration Department
6801 North Capitol of Texas Highway
Austin, Texas 78731
Fax Number: 512-498-4099
Once we receive this information, we will then proceed to review the account history and pursue the individuals responsible. If there are any additional questions or concerns, or if there is anything else that we may be able to assist with, please let us know and we will help as soon as possible.
Thank you,
They expect US to provide litigation instead of looking into the matter themselves.
This, is rediculious
I can write you a PHP program, that will put a serial number behind any name you want and use that as E-Mail Adress to send 3000 different mails in one go ;)
Unfortunately that would be considered spamming by most providers.
I have passed this thread along to the appropriate teams. Please ask anyone who has received messages about reset attempts to contact the Support team (http://support.lineage2.com) to report the attempts. Thank you!
ok from what my friend was telling me, I maybe getting the explination wrong, he believes he went to some website , and the website may have downloaded an emulater to randomly pick passwords off of his computer.
I may of not explained this correctly, but maybe someone has a similiar explination?