didnt believe me about OE bug? Read this thread.

General Discussion Started Last reply 138 posts
http://www.mmorpg.com/discussion2.cfm/thread/88746/page/2

If something like this can happen, it proves that L2 isn't 100% perfect code. Loopholes are always there. Remember that.

And before someone is idiotic enough to say, why then isn't there anyone with +65000 weapons? Uh DUH? Why not advertise your a cheater? If you are going to hide an OE bug, you are going to be discreet so you dont invite suspicion. You know its called using your head.
You're like a religeous fanatic about this whole OE bug, aren't you?
LOL hey if you wanna believe in your ignorance than its fine by me. But now I have shown you proof of it. Believe what you like.
I haven't show proof of anything beyond my observation that you act like a religeous fanatic. But I'll admit, I'm skeptical about such an exploit existing for at least 7-8 months, when C4 was introduced to the PTS, without being identified or at least investigated until now. You have used the fact that to your knowledge, a +10 SoM has yet to have exist until now, though people have since explained that your key reasoning behind your truthfulness may actually mean just the opposite. +10 SoMs are rare, and very hard to create. This is common knowledge. If there are a few popping up, especially within a narrow time frame, then you may have grounds for an investigation. But this is ONE incident. ONE +10 SoM.

Accept the fact that some lucky bastard probably got lucky. He has it, and you don't. And neither do I. *cries*
uh, maybe the guy just found out how to do it recently? That thought ever cross your mind? Also, I'm not the one making that up on that other thread. OTHERS have now verified it.

But now I have shown you proof of it. Believe what you like.



I'm not sure how a link to a message board with wild speculation is 'proof'. Even if you did take the word of some random people as gospel, they even admit that it was only a problem on the PTS and couldn't happen on live servers. Hacking a fully supported server and a test server are two completely different projects. There's a reason these events only show during PTS tests of new chronicles.


If you are going to hide an OE bug, you are going to be discreet so you dont invite suspicion.



Cheaters don't have that kind of self control. Granted an intelligent person is going to be careful about things, but a widely known overenchant bug would eventually invite someone to exploit it in a very obvious manner. For example, someone quitting the game is not going to care about being discreet, he's going to go on a rampage with his insane weapon. That we don't see bot groups running around with red weapons every day is proof enough that no exploit exists.

Yes, no code is perfect. However if players know about an exploit you can be sure that NC knows about it as well (companies don't rely on their own forums to gather info). When an exploit is found it is closed, as many were in the early days of L2.
Greetings,


LOL hey if you wanna believe in your ignorance than its fine by me. But now I have shown you proof of it. Believe what you like.



Just such an excellent dinner. Thank you.


I will never beleive in Ignorance. Ignorance is a desease.

I releive Ignorance, for I am teacher. Just like a doctor.

Most of my clients treat me as if I was carrying a * red glow * weapon.

DUDE, it's a surge of enchants coming from the squash event that pushes people into doing stupid things.

*licks fingers*

Have Fun ! ™

BoardPK
Official Board Devil

You got burned by GrandMastaDM.
lol are you that naive to think that movies mimick life? Like I said before, a smart person can manipulate and use an exploit for a long time before anyone suspects something if they can control themselves. Especially if its an exploit that not a lot of people know about and it sure seems like this is one of those exploits.

As for what that other guy said, read it carefully. He said that they were not aware of anything obvious. Like I said power in the grips of clever people who has patience is a very dangerous thing.

Hey like I said before, believe what you like. But as a programmer, you learn pretty quick that code isn't perfect. Theres always lots of loopholes in code...lol

Hey like I said before, believe what you like. But as a programmer, you learn pretty quick that code isn't perfect. Theres always lots of loopholes in code...lol



As a progammer, you extensively test the code (and also get other people to do it for you. I know people that live for that stuff.) and then close every 'loophole' you find. The only program where bugs are common and are still acceptable would be Windows. C4 has been out for quite a while with a team of frenzied Korean developers working on it around the clock (with a playerbase that big, they pretty much have to).

I have about eight professors that would slap me if I ever said, "There's always lots of loopholes in my code."
The exploit on the PTS was not an OE bug, it was a command bug. The hacker gained admin rights and gave himself anything he wanted. Any skill, any stats, you name it. Like running a private server, he had full powers of a GM.

Who do you think invests the most time and money on live servers to gain advantages? Hackers? Players? You're ******ED if you think that is the case. The answer is FARMERS. If a farmer could generate adena, he wouldn't need a bot train. He could spread it across accounts slowly and be completely unnoticable. Adena drops on the ground anyways.

While there are threats to L2 security, that doesn't mean that they are readily exploited. When such things exist, they don't stay hidden long. These types of actions cause NUMEROUS glitches. The C4 PTS had the same hacker and he spawned and dropped weapons in every town. The server went down within an hour, but we got to play around with them before that.

Ready for the shocker? THEY DIDN'T WORK. The SA'd weapons and absurdly overenchanted items would hit for X billion damage and actually do zero or random low numbers. You equipped a health weapon or SA focus and nothing changed.

Sure, there is an exploit possibility. There is ALWAYS an exploit possibility. But look, they caught a POTENTIAL security risk and reset the passwords on every account. The people that know the code best and discover these things are normally the developers. And when one glitch gets exploited, the developers normally solve a dozen others in fixing it.

The fact remains, just because you saw a +10 SOM doesn't make the weapon a cheat nor does it suggest the player exploited. No "investigation" is warranted from one isolated instance. You're flat out jealous and every time you post, your nubile cry to mommy crap just makes most of us laugh. What's next? You going to tell us how no legit players afford A grade anyways? Sit down and let far more intelligent people call out these things. You are wasting everyone's time with your stupidity.

CRY MORE NOOB
Greetings,


You got burned by GrandMastaDM.



By my first course in programming, my professor said this as his first words...

By the half of this course, half of you will have left.

3 people left right then and there.

Man that was hilarious.

Have Fun ! ™

BoardPK
Official Board Devil

Look Silviera you obviously have no clue what your talking about regarding how programs are turned out in a REAL world, business environment. QA only insures you catch loopholes that you DISCOVER. Who ever told you it was foolproof told you lies. If you work in the tech field, this is the first thing you learn as a programmer and a QA tester. No code is 100% perfect. The bigger the project, the more code you have, the more potential for loopholes there are.

Also, again which tells me how little you know about the professional world of programming is that you bash windows blindly like some zealous linux/unix initiates. What you don't know is that Windows IS one of the most QA tested software on the market. Just because it is the most popular and just because its a popular target by hackers to "test" the system. Its one of the most idiotic things to say that windows has loopholes, because ALL programs have them. Especially on a scale of a program such as windows, its actually remarkable how few the loopholes they have found, with millions of people bashing away at it.

and the "professionals" you know sound like they dont make very good programmers.
Are you, in fact, a "professional programmer", BlazerX?

The exploit on the PTS was not an OE bug, it was a command bug. The hacker gained admin rights and gave himself anything he wanted. Any skill, any stats, you name it. Like running a private server, he had full powers of a GM.

Who do you think invests the most time and money on live servers to gain advantages? Hackers? Players? You're ******ED if you think that is the case. The answer is FARMERS. If a farmer could generate adena, he wouldn't need a bot train. He could spread it across accounts slowly and be completely unnoticable. Adena drops on the ground anyways.

While there are threats to L2 security, that doesn't mean that they are readily exploited. When such things exist, they don't stay hidden long. These types of actions cause NUMEROUS glitches. The C4 PTS had the same hacker and he spawned and dropped weapons in every town. The server went down within an hour, but we got to play around with them before that.

Ready for the shocker? THEY DIDN'T WORK. The SA'd weapons and absurdly overenchanted items would hit for X billion damage and actually do zero or random low numbers. You equipped a health weapon or SA focus and nothing changed.

Sure, there is an exploit possibility. There is ALWAYS an exploit possibility. But look, they caught a POTENTIAL security risk and reset the passwords on every account. The people that know the code best and discover these things are normally the developers. And when one glitch gets exploited, the developers normally solve a dozen others in fixing it.

The fact remains, just because you saw a +10 SOM doesn't make the weapon a cheat nor does it suggest the player exploited. No "investigation" is warranted from one isolated instance. You're flat out jealous and every time you post, your nubile cry to mommy crap just makes most of us laugh. What's next? You going to tell us how no legit players afford A grade anyways? Sit down and let far more intelligent people call out these things. You are wasting everyone's time with your stupidity.

CRY MORE NOOB



You sound like you have first hand experience in how this **** worked. HOW THE HELL WOULD YOU KNOW? I mean are you somehow intimate with this hacker or are you guessing? You sound pretty confident in your answers though, so why don't you enlighten us? It seems like you just know it all don't you?



While there are threats to L2 security, that doesn't mean that they are readily exploited. When such things exist, they don't stay hidden long. These types of actions cause NUMEROUS glitches. The C4 PTS had the same hacker and he spawned and dropped weapons in every town. The server went down within an hour, but we got to play around with them before that.



You and some others keep saying this but you don't show any evidence to why you support this theory? You base your whole conclusion that whoever hacked the system is soo impulsive that its inevitable that they somehow screw up and reveal the exploit? Why exactly do you believe this? There is no basis for your analysis.



The exploit on the PTS was not an OE bug, it was a command bug. The hacker gained admin rights and gave himself anything he wanted. Any skill, any stats, you name it. Like running a private server, he had full powers of a GM.

Who do you think invests the most time and money on live servers to gain advantages? Hackers? Players? You're ******ED if you think that is the case. The answer is FARMERS. If a farmer could generate adena, he wouldn't need a bot train. He could spread it across accounts slowly and be completely unnoticable. Adena drops on the ground anyways.




LOL, if you've done QA before you'll know that the version of the application usually on the BETA server IS the real FULL application that is undergoing "tests". That's the whole point of QA if you don't get it. QA is to test the software before it goes LIVE. Understand that principle? Therefore, any bugs or errors you don't catch on the BETA or PTS server is bound to show up on LIVE after it gets released. Thats the WHOLE POINT of PTS or BETA servers. To test for LAST MINUTE bugs or errors. Since this error didn't get caught until NOW, one can only assume that it existed all the way from Prelude or at whatever point in the chronicle series that the GM module was introduced.



Sure, there is an exploit possibility. There is ALWAYS an exploit possibility. But look, they caught a POTENTIAL security risk and reset the passwords on every account. The people that know the code best and discover these things are normally the developers. And when one glitch gets exploited, the developers normally solve a dozen others in fixing it.

The fact remains, just because you saw a +10 SOM doesn't make the weapon a cheat nor does it suggest the player exploited. No "investigation" is warranted from one isolated instance. You're flat out jealous and every time you post, your nubile cry to mommy crap just makes most of us laugh. What's next? You going to tell us how no legit players afford A grade anyways? Sit down and let far more intelligent people call out these things. You are wasting everyone's time with your stupidity.




That's right an exploit DID exist. You've already proven my point. There's really nothing more to say.

Are you, in fact, a "professional programmer", BlazerX?



Why yes, yes I am.
Greetings,



As a progammer, you extensively test the code (and also get other people to do it for you.



You get OTHER people to test your code, because of the God syndrome.

When you create you cannot accept flaw. So you need The Devil, whether you like it or not.

It is the way if the IT expert. The thing I love most is the look on their faces when I show them I I stole their money.

People who target L2 accounts are n00bZ, bar none. Try hacking an account and stripping 500K from it. Then you can be a hacker.

Be carefull at challenging a Master at arms. (http://en.wikipedia.org/wiki/Master_at_arms) I am deadly.

Have Fun ! ™

BoardPK
Official Board Devil



Are you, in fact, a "professional programmer", BlazerX?



Why yes, yes I am.



Even though emotion is hard to derive from words, you have shown me, and hopefully a few others more of your personality and character by replying.

EDIT:

Since this error didn't get caught until C4, one can only assume that it existed all the way from Prelude or at whatever point in the chronicle series that the GM module was introduced.



I think you're a little confused here. That could have been the case, yes. But, what I think (notice that is an estimation, and an opinion, so don't try to pick it apart saying I'm meddling with the truth by stating false facts) is that the code for the GM module may have been altered a little bit, or information used in the module (they had to add the codes for the S grade items, didn't they?) changed as of C4. Because of this change the hacker was able to work its way through a loophole in the module and do what the hacker did.

Yes, I admited and everyone else admits that such an exploit or loophole existed in the C4 PTS. But it was FIXED!!!11one
66% doest have 'grade' racisim.

if there are +10 d grade there will be +10 a grade eventually.

duh




OE'ing is a money sink, but some ppl get lucky. stop whining!
Take it easy there, I said one line about Windows. It's a popular program with errors and thus I used it to make a point. That people accept the constant errors and crashes in such a popular program is worthy of notice. They don't periodically patch Windows because it's working fine.

No, it is not acceptable to have bugs in any professional program. Yes, it is possible to have a 100% functional program without errors (I could send you a calculator that gives 2+2=4 every time). While it's true that many programs don't meet this, you're not going to find a programmer that says "My program has bugs and I don't intend to fix them." The fact is that L2 has a dedicated development team, bugs that survive the initial launch are dealt with later. If a program isn't at 100%, it's your job to get it there.

Game Design is very different from your average programming project, and MMOs are handled differently than normal games as well. L2 currently has more than one million volunteer testers (ie: players), most of which do not want other players having an unfair advantage due to exploits. The idea that some tiny group of players has discovered an overenchant bug in such a massive game and are using it only to create a handful of +10 weapons while keeping the method fully secret is insanity. Not to mention your assumption that such an overenchanting cult has existed since Prelude.



Are you, in fact, a "professional programmer", BlazerX?



Why yes, yes I am.



Even though emotion is hard to derive from words, you have shown me, and hopefully a few others more of your personality and character by replying.



This sounds pretty cryptic? lol whatever it means I hope it answerd your question.

Take it easy there, I said one line about Windows. It's a popular program with errors and thus I used it to make a point. That people accept the constant errors and crashes in such a popular program is worthy of notice. They don't periodically patch Windows because it's working fine.

No, it is not acceptable to have bugs in any professional program. Yes, it is possible to have a 100% functional program without errors (I could send you a calculator that gives 2+2=4 every time). While it's true that many programs don't meet this, you're not going to find a programmer that says "My program has bugs and I don't intend to fix them." The fact is that L2 has a dedicated development team, bugs that survive the initial launch are dealt with later. If a program isn't at 100%, it's your job to get it there.

Game Design is very different from your average programming project, and MMOs are handled differently than normal games as well. L2 currently has more than one million volunteer testers (ie: players), most of which do not want other players having an unfair advantage due to exploits. The idea that some tiny group of players has discovered an overenchant bug in such a massive game and are using it only to create a handful of +10 weapons while keeping the method fully secret is insanity.



I'm sorry but this is why you won't make a very good programmer. Good luck though if you decide to persue this profession.
Greetings,





Are you, in fact, a "professional programmer", BlazerX?



Why yes, yes I am.



Even though emotion is hard to derive from words, you have shown me, and hopefully a few others more of your personality and character by replying.



This sounds pretty cryptic? lol whatever it means I hope it answerd your question.



Well this has shown your elders what you are worth as a programmer.

Remember, young one, there is always a cat stronger than you.

Can't act this stupid and hope to get away with it.

Have Fun ! ™

BoardPK
Official Board Devil


I'm sorry but this is why you won't make a very good programmer. Good luck though if you decide to persue this profession.



I'm having difficulty understanding this. You're saying my drive to create a perfect program, the acceptance of its flaws and the desire to correct problems as they pop up from extensive testing (with aid of users) makes me a bad programmer?

My intent is to become a Game Designer, which as I said is a completely different profession in terms of programming. All I need to do is make a game fun, even if bugs pop up if I've done my job correctly people will still play. I don't profess to be skilled at my job yet, but I wouldn't call myself a failure either.

Greetings,





Are you, in fact, a "professional programmer", BlazerX?



Why yes, yes I am.



Even though emotion is hard to derive from words, you have shown me, and hopefully a few others more of your personality and character by replying.



This sounds pretty cryptic? lol whatever it means I hope it answerd your question.



Well this has shown your elders what you are worth as a programmer.

Remember, young one, there is always a cat stronger than you.

Can't act this stupid and hope to get away with it.

Have Fun ! ™

BoardPK
Official Board Devil





Senior to what exactly? As far as I know I've kept my end of the conversation civil. It seems its YOU young ones that are breaking at the seams.

Senior to what exactly? As far as I know I've kept my end of the conversation civil. It seems its YOU young ones that are breaking at the seams.



Your may have kept yourself civil, but your manner still portrays yourself as an "I R BETTER3R THAN YOU!!!" kind of personality. You come off as overzealous and overconfident that no matter what opinions we express or facts we provide in rebuttal to your theory, you are and always will be right.


I'm sorry but this is why you won't make a very good programmer. Good luck though if you decide to persue this profession.



I'm having difficulty understanding this. You're saying my drive to create a perfect program, the acceptance of its flaws and the desire to correct problems as they pop up from extensive testing (with aid of users) makes me a bad programmer?




Unfortunately yes. You'll burn yourself out too quick to stay anywhere very long.



My intent is to become a Game Designer, which as I said is a completely different profession in terms of programming. All I need to do is make a game fun, even if bugs pop up if I've done my job correctly people will still play. I don't profess to be skilled at my job yet, but I wouldn't call myself a failure either.



Designing in some ways takes a lot more effort and employs the analytical mind of the programmer. I'm afraid your in the "day-dreaming" phase of game development. You will be surprised how much analyzing, planning and project management is required to be a designer. Its not all about "fun", although its part of it.
Greetings,


Senior to what exactly?



Senior to your computer skills.

I was programming a while before you while you didn't know what the HELL an Internet was.

Hell you weren't even born probably.

You a bit too mouthy and a bit less tech wise for claiming such things.

Now go back and play in the kids yard...

Have Fun ! ™

BoardPK
Official Board Devil


You will be surprised how much analyzing, planning and project management is required to be a designer. Its not all about "fun", although its part of it.



Who's to say that isn't fun to some?

As far as I know I've kept my end of the conversation civil.




And before someone is idiotic enough to say
LOL hey if you wanna believe in your ignorance than its fine by me
lol are you that naive to think that movies mimick life?
Its one of the most idiotic things to say that windows has loopholes, because ALL programs have them.
HOW THE HELL WOULD YOU KNOW?
It seems its YOU young ones that are breaking at the seams.



Your own words speak for themselves. If as a professional you have some proof that such a bug exists, I will gladly accept defeat in this argument. Speculation and third hand information does little to waver my stance on the matter.

Basically, until you can describe the method in which weapons are overenchanted through an exploit I do not believe that it exists. If you told me back in Prelude that such a bug existed, perhaps I would have believed you (in fact one did, though it was nothing like the bug you describe). However at the dawn of C5 in a game that's been around for over two years, a handful of overenchanted weapons and people claiming of a bug with no information as to how it works does nothing for me.
Holy crap, I've never seen someone so bitter over failing an OE. This thread is awesome.


As far as I know I've kept my end of the conversation civil.




And before someone is idiotic enough to say
LOL hey if you wanna believe in your ignorance than its fine by me
lol are you that naive to think that movies mimick life?
Its one of the most idiotic things to say that windows has loopholes, because ALL programs have them.
HOW THE HELL WOULD YOU KNOW?
It seems its YOU young ones that are breaking at the seams.



Your own words speak for themselves. If as a professional you have some proof that such a bug exists, I will gladly accept defeat in this argument. Speculation and third hand information does little to waver my stance on the matter.

Basically, until you can describe the method in which weapons are overenchanted through an exploit I do not believe that it exists. If you told me back in Prelude that such a bug existed, perhaps I would have believed you (in fact one did, though it was nothing like the bug you describe). However at the dawn of C5 in a game that's been around for over two years, a handful of overenchanted weapons and people claiming of a bug with no information as to how it works does nothing for me.



That is your choice in the matter, nor can I force you to believe it. I've simply defended my conclusion of the matter with backup from others who share the same conclusion as I have come to. In much the same way, you cannot enforce your belief that there is no exploit. It seems though at the moment I have the upper hand. At least I have presented a catalyst to my conclusion.

Holy crap, I've never seen someone so bitter over failing an OE. This thread is awesome.



Failing an OE? Where did this come out of? I've never enchanted since c1. I have several OE weapons at my disposal that are greater than +14 that I've bought with money I legitimately raised playing the market. Who said anything about failing an OE?



As far as I know I've kept my end of the conversation civil.




And before someone is idiotic enough to say
LOL hey if you wanna believe in your ignorance than its fine by me
lol are you that naive to think that movies mimick life?
Its one of the most idiotic things to say that windows has loopholes, because ALL programs have them.
HOW THE HELL WOULD YOU KNOW?
It seems its YOU young ones that are breaking at the seams.



Your own words speak for themselves. If as a professional you have some proof that such a bug exists, I will gladly accept defeat in this argument. Speculation and third hand information does little to waver my stance on the matter.

Basically, until you can describe the method in which weapons are overenchanted through an exploit I do not believe that it exists. If you told me back in Prelude that such a bug existed, perhaps I would have believed you (in fact one did, though it was nothing like the bug you describe). However at the dawn of C5 in a game that's been around for over two years, a handful of overenchanted weapons and people claiming of a bug with no information as to how it works does nothing for me.



That is your choice in the matter, nor can I force you to believe it. I've simply defended my conclusion of the matter with backup from others who share the same conclusion as I have come to. In much the same way, you cannot enforce your belief that there is no exploit. It seems though at the moment I have the upper hand. At least I have presented a catalyst to my conclusion.



You have your multitudes of L2blah posters who believe that such an exploit exists because they themselves cannot get a +10 SoM, and Silvera has us on the official forums who, for the most part so far, have been civil and forgiving in allowing you to rant on about this "exploit".

Right now, it just seems like this is a battle between the [Censored] and the rational thinkers.
Greetings,


Right now, it just seems like this is a battle between the [Censored] and the rational thinkers.



1 million adena on the rational thinkers.

Tell me who won tomorrow, I'm going to sleep.

Have Fun ! ™

BoardPK
Official Board Devil


Designing in some ways takes a lot more effort and employs the analytical mind of the programmer. I'm afraid your in the "day-dreaming" phase of game development. You will be surprised how much analyzing, planning and project management is required to be a designer. Its not all about "fun", although its part of it.



To clarify, I'm not such a newbie that I've never programmed a game before. Analyzing, planning, and project management are all considered fun to me. In many ways a game is much more fun in the development stages before you're hit with the reality of budget, time, and creative restrictions. I'm well aware of all the work that goes into a successful game, and I also know enough that I will never be doing all of these things alone in a project.


In much the same way, you cannot enforce your belief that there is no exploit. It seems though at the moment I have the upper hand.



I'm having trouble finding someone that agrees with your point of view. Even in the thread you point to in your OP the posters are clearly talking about a completely different issue.

In manners of accusations without proof, the defender will always have the upper hand. I could claim there is a bug in L2 that allows people to fly. There would be a person somewhere that would jump in saying "My friend saw some guy do that!", but that doesn't make the claim any more valid.
ah thanks it really is hard to argue the rational point. Good to know its appreciated!


Designing in some ways takes a lot more effort and employs the analytical mind of the programmer. I'm afraid your in the "day-dreaming" phase of game development. You will be surprised how much analyzing, planning and project management is required to be a designer. Its not all about "fun", although its part of it.



To clarify, I'm not such a newbie that I've never programmed a game before. Analyzing, planning, and project management are all considered fun to me. In many ways a game is much more fun in the development stages before you're hit with the reality of budget, time, and creative restrictions. I'm well aware of all the work that goes into a successful game, and I also know enough that I will never be doing all of these things alone in a project.


In much the same way, you cannot enforce your belief that there is no exploit. It seems though at the moment I have the upper hand.



I'm having trouble finding someone that agrees with your point of view. Even in the thread you point to in your OP the posters are clearly talking about a completely different issue.

In manners of accusations without proof, the defender will always have the upper hand. I could claim there is a bug in L2 that allows people to fly. There would be a person somewhere that would jump in saying "My friend saw some guy do that!", but that doesn't make the claim any more valid.



Isn't that the sad truth? But hey who said anyone ever won a war with defense? To the victor goes the spoils! Hurrah!

Ah well I'll take my que from the old devil. I'm sure he needs his beauty nap these days and so do I. But of course after I use the toilet to appreciate his gift!

adieu
ok kids, there is a goof amongst us, can you tell who it is?

Isn't that the sad truth? But hey who said anyone ever won a war with defense? To the victor goes the spoils! Hurrah!



That is true, but one must win the war to share in the spoils.


But of course after I use the toilet to appreciate his gift!



I'm sorry, but comments like that discredit almost anything you say.
The first thing a programmer should ever realize:

No well written and thoroughly tested program, ever survives contact with the users.

It can't be done because users tend to do weird things thye really shouldnt be doing. When I did my stint as a programmer I even discoverd bugs in the programming language themselves. In a program as complicated as a mmorpg there are bound to be hundreds of bugs yet to be found.
Nobody denies that there will be bugs, especially when thousands of people are actively trying to break the code. It should still be one's goal to work towards no bugs, because that's the only way you're going to minimise them.

As for an overenchant exploit? One existed in Prelude and C1, it was fixed. One might still exist, but there are too many people who overenchant excessively and break things. If people were to exploit overenchanting, they would probably up not the things that draw suspicion (and reports) from their fellow players, but the alternatives, like armour and jewellery.

An exploit is sooner or later always found out by the one idiot who gets caught - it's just as impossible to keep it hushed up forever as it is to avoid putting it into the game in the first place.

What happened on the PTS had nothing to do with live servers. There might or there might not be an overenchanting exploit, but the simple assumption that there must be one because of what happened on the PTS or because there are weapons you say you "know" are harder to enchant, although by your own admission, you are not actually active in overenchanting and thus have absolutely no reliable data, is ridiculous.

No well written and thoroughly tested program, ever survives contact with the users.



This is very true. However, L2 is not some fresh game that just hit the market. It had a lot more bugs back in Prelude than it does today.

In MMOs and in any program, you target specific areas when testing for bugs. Hundreds of small bugs such as text and clipping errors amount to nothing next to a large game breaking bug such as an overenchant exploit. That's why even at Prelude you didn't see things like infinite exp bugs. The overenchant exploit that existed back then didn't actually give people the ability to enchant their weapons higher than normal (it was really a lack of foresight by the designers, not some weird occurence), and when the bug was discovered it was fixed. You can bet both cheaters and NC programmers have worked tirelessly trying to find some way to exploit enchants, so the idea that a bug has been present since Prelude yet remains some well kept secret is ridiculous in a game with over one million players.

In the end, a well designed program may crash if a user clicks 'back' while holding down QWERTY and the middle mouse button while running Windows on a Mac as they chant a demonic incantation. However if you program a calculator that turns out 2+2=17, you've made a bad program.

Bugs pop up, but no self respecting programmer releases their work without having key elements undergo rigorous black box testing. Things may slip past now and then, but after two years there's no excuse for game breaking bugs.

This is all a moot point however, as there's really no issue when there's no proof.
If I'm reading the 3rd picture in that posted thread correctly, the character Fade hits the character Amilda for 1,823,925 damage yet she is not dead.
It is a private server, isnt that pretty obvious?
On private servers, weapons above 30 simply disappear or have a glow issue (doesnt glow, has discolored color, or no smoke effect). So a +65000 weap...LOL. And where in the hell would someone get that many enchant scrolls O.O
Does the look change at all between 16 and 30?

It is a private server, isnt that pretty obvious?



Not to me. Though I've never been on a private server. Perhaps I misunderstood the context of the picture. I thought that this was a picture taken on the PTS. I suppose not.
She was probably ressed. But, I don't remember if you get a message on the chat window, for being ressurected.

If that 1.8million damage was a normal hit, I wonder how much a Crit would do...wouldn't want to be on the receiving end of that.

http://www.mmorpg.com/discussion2.cfm/thread/88746/page/2

If something like this can happen, it proves that L2 isn't 100% perfect code. Loopholes are always there. Remember that.

And before someone is idiotic enough to say, why then isn't there anyone with +65000 weapons? Uh DUH? Why not advertise your a cheater? If you are going to hide an OE bug, you are going to be discreet so you dont invite suspicion. You know its called using your head.


Okay, again for those with very short memories. These shots were from C4 PTS. Someone (from Russia, I believe) gained access to GM commands and created a bunch of highly OE'ed weapons. I remember someone posting these exact same screenshots.

This was not live. This never happened on live. Blazer is still upset that someone has better gear than him.
wtb saber
lol this thread is funny, anything to do with private servers has nothing to do with retail
Okay there, Dexter. All I read on there was that there was an exploit on the PTS that allowed for someone to gain GM powers and OE gear. Your original whining post about OE weapons was on the Live servers (ie the oe'd SOM on bartz). I bet you scoured the google search engine trying to prove your point, didnt you? Didn't work. So you have evidence that the PTS was hacked...we have yet to see evidence that the live servers had the same thing done.
Everyone knows about this, its was a bug on the PTS that NCSOFT didnt secure. It CANNOT happen on live servers.
It truly surprises me that little kids on these forums have no clue what a software development cycle is. I guess its not surprising because they are little kids and have no experience in a real world software test environment. Just because its on the PTS doesnt mean its not on LIVE. Since applications are test first on PTS and then put up to LIVE, its not a big leap in logic, for anyone for that matter, to see how if its not caught on the PTS the same bugs appear on live. PTS is a test site to make last minute changes to the software/application, in this case the game Lineage2, before it goes to LIVE. I guess its kinda useless to talk to kids about what a professional who have been in the field would instantly recognize. Go figure.
18 years in the I.T. industry in software development as a lead. You?
Senior Developer at a major Telco. So what of it?
You could hardly call me a kid and your arguments don't hold water.
Then you don't have a clue what your talking about and call your supposed experience BS. Did you work for the state all this time? LOL
Just a correction, while BlazerX is wrong about just about everything, there has been 3 Overenchant exploits in Lineage 2 history, they've all been long patched and not all that many weapons survived to today.

Also people need to remember that just because there's an exploit they were never easy, so noone could squirt out +16 weapons with it.
Some people just have a LOT of Adena, they buy some weapons and try to overenchant, simple as that.
After C3, where weapons glow, everyone want a overenchanted weapon, people try, and thats what happen.
I Expended a lot of Adena trying to overenchant things, i even created a +14 weapon, all u need is try, if u lucky, there u go.
BlazerX, the thing can't happen on Live because of the NPCs involved - if there is no access to appropriate NPCs, this particular exploit can not be reproduced; those NPCs do not appear on live, and that was pretty much it already.

Chaos, whenabouts were the two exploits unrelated to announced server downtime? I never heard about those.
OMG, BlazerX, you are so high on yourself, does it hurt to have a head so big? so swollen? i'll admit, you do have some knowledge in what you say, but you must admit defeat, there is NO exploit bug, and if there was you can't hold it against ONE +10 SOM, I have seen +18 duals, so how hard is it to get a +10 SOM if you have the funds? Just cry to your mommy some more until your daddy comes in to reassure you that ur not loseing your mind and that ppl actualy do like your babble.

Look, another thread that should be locked and/or deleted, along with a message sent to the OP saying he will be banned if he keeps this up because he is just wasteing everyones time, or we could all just ignore him, wait, maybe something is missing in his life. Hey BlazerX, go get yourself a date ;)
I'm not privy to the details of this **** so based on what you said here about needing access to specific NPCs, lets taket his scenario as an example. If someone like this Russian guy can modify their client L2 and make those specified NPCs show up on his client alone and not the server's, if he interacts with said NPCs on his client side and said NPCs then relay that information as it would normally back to the server....even if those NPCs on the server side are not graphically active, if the functions and procedure or class module is active an the server end and it has not been patched to stop receiving information passed on from the client side, it is theoretically and highly possible to "interact" with said NPCs even though it may not be graphically active on the server side. As long as the class modules are exposed and active on ther server L2 code, it is still listening for feedback and a hacker can exploit this vulnerability. But again this would be a theoretical scenario.

OMG, BlazerX, you are so high on yourself, does it hurt to have a head so big? so swollen? i'll admit, you do have some knowledge in what you say, but you must admit defeat, there is NO exploit bug, and if there was you can't hold it against ONE +10 SOM, I have seen +18 duals, so how hard is it to get a +10 SOM if you have the funds? Just cry to your mommy some more until your daddy comes in to reassure you that ur not loseing your mind and that ppl actualy do like your babble.

Look, another thread that should be locked and/or deleted, along with a message sent to the OP saying he will be banned if he keeps this up because he is just wasteing everyones time, or we could all just ignore him, wait, maybe something is missing in his life. Hey BlazerX, go get yourself a date ;)



haha thanks for the concern but I'm a married man. I don't think my wife would like the idea of me having a mistress or two.

Like I said before, you can believe what you want but never rule out the possibility that an OE bug could exist. So far you've seen me show you an thread from someone telling you that it can be done as close as c4 or up til now and another person in this thread, saying there has been 3 OE bugs thus far. Seems like OE bugs are spilling out all over the place.
How would you make the server believe there are extra NPCs just because your characters tell him to? If this was possible, do you think he or she would have stopped after the cats were removed from PTS?
They are simply not there on the live server, there's nothing on the server to exploit in that manner.

Not to mention the PTS is set up differently too, which allows for some exploiting.
if the code base for PTS is the same for L2, it is naive to think that for some reason you can exploit on PTS and not LIVE.

Server -> Client application work in this manner. You download all the graphics and interface modules onto your client. The basic of information is passed between your client and the server maybe in an xml format, who knows how they did that. But it would not be a stretch to make this assumption.

Said server that is triggered by the information that it is passed from the client process information based on where said information came from.

This russian dude modified his client code and inserted his own special routine (class module, procedure or function, whatever) to send specific information to the server Lineage 2 and probably through trial and error (99% of the cases of how hackers **** systems, unless its from the inside) figured out what type of commands or even the commands themselves to do what he wanted through the modified interface.

Having said such, it is highly possible that if the server's listening class module has vulnerabilities or is too generic in what it accepts as feedback from the client, it is very possible to "****" it. Of course this will take time and effort but hey, hackers thrive on that stuff.

Most hackers do it because they want to do something never done before. This russian dude probably did it for the challege. After a challenge is met and accomplished, the hacker usually looses interest and moves on towards wanting acknowledgement for his/her conquest so to speak. Most hackers do it for the "fame" or notoriety than anything else.

omg, I just read the 2 new posts on that thread I posted. ARE FRIGGIN KIDDING ME? Your telling me its a SQL **** that the russian dude did? Tell the dumb *** programmers in NCSOFT or wherever that set up the SQL server to first have better secure login/passwords. Use paramaterized SQL statements, using the **** command module. Also I hope to god that they do not put any SQL query statements on the client side of the L2 applications. This is really unacceptable. I really hope that no one figures out the login/pass for the SQL servers on LIVE. Can't believe this is a friggin SQL **** of all sh*t. You guys are really starting to disappoint me NCSOFT.

You guys seriously better hope that your SQL server on the LIVE site IS secure. For the love of god, talk about really being self-destructive! How the hell do you guys allow people to **** into your database? Thank god it was only on PTS then. I really hope you guys weren't stupid or cheap enough to put your billing information and all that stuff on the same SQL server as LIVE. I really hope are using a totally separate SQL server for the billing stuff. Be **** sure your LIVE SQL SERVER is secure and that a customers billing or personal info is secure. I don't like to over-react but seriously What are you guys doing? self-destructive indeed.

Read up on SQL Injection attacks because this is exactly the very simple method that the russian dude used to **** your sql server.


OMG, BlazerX, you are so high on yourself, does it hurt to have a head so big? so swollen? i'll admit, you do have some knowledge in what you say, but you must admit defeat, there is NO exploit bug, and if there was you can't hold it against ONE +10 SOM, I have seen +18 duals, so how hard is it to get a +10 SOM if you have the funds? Just cry to your mommy some more until your daddy comes in to reassure you that ur not loseing your mind and that ppl actualy do like your babble.

Look, another thread that should be locked and/or deleted, along with a message sent to the OP saying he will be banned if he keeps this up because he is just wasteing everyones time, or we could all just ignore him, wait, maybe something is missing in his life. Hey BlazerX, go get yourself a date ;)



haha thanks for the concern but I'm a married man. I don't think my wife would like the idea of me having a mistress or two.

Like I said before, you can believe what you want but never rule out the possibility that an OE bug could exist. So far you've seen me show you an thread from someone telling you that it can be done as close as c4 or up til now and another person in this thread, saying there has been 3 OE bugs thus far. Seems like OE bugs are spilling out all over the place.



As impressed as i am of the level of your maturity, even after my post, i will now suggest you not discuss this on the boards, but perhaps if you really are concerned with this, make a petition to NC as that is all you can do,. crying to other gamers will never solve anything, most will happen is thread lock due to trashing NC's game

and just think, all this time monitoring this topic, you could have lvl'd ot attempted to make a +10 SOM yourself have you had said adena to try it out. Trust me, if you have the funds, anything is possible

if the code base for PTS is the same for L2, it is naive to think that for some reason you can exploit on PTS and not LIVE.



It's not, I'll save you some trouble. Rates are different, and NPCs are present at the server startup without GM intervention. This is very clear evidence that the PTS does not use the exact same code as live. Not to mention it has less support and probably few people watching for irregularities in the server.

You claim to be a professional yet rely on wild assumptions. When someone casually mentions SQL in another thread (again, no proof, just a rumor of a rumor) you go on a quasi technical rant with absolutely no knowledge of how L2 is set up and call the security unacceptable. The truth of the matter is, unless your job background includes "two years working on L2 security" any arguments you make based on your own knowledge are suspect at best. As for the whole SQL thing, if something like this was present on live it would be trivial for NC to track and shut down the offendor even if they were lacking basic security that is undoubtedly present anyway. Basically if you're going to make accusations about sloppy code, security vulnerabilities, and imaginary bugs (with no experience in overenchanting yourself) you need to have some actual proof or at least logical arguments to back your claims.

Elro was pretty clear that this was in fact an issue on the C4 PTS (not C5), and again the thread in your OP has nothing to do with an overenchant exploit in any way and calling it proof of your point simply hurts your argument in the end. The fact that these crackers appear on the PTS and not live is evidence in of itself, not to mention that when they have appeared even on the PTS server NC has been well aware of their presence and has closed the security vulnerability. If a security vulnerability allowed access to a GM command list then +10 overenchanted weapons would be the least of your worries (not to mention calling it an overenchant bug is ridiculous at that point).
Well, nobody ever claimed L2 was well-thoughtout in any regard ...
Sorry, I stopped reading when I saw "PTS" and hacked GM priviledges.

What is the point of this post? [1] To prove that an exploit currently exists on all of the Live servers? [2] To prove that it is feasable and within the realm of possibility for an exploit to exist in the general sense? Kind of like saying that maybe there is life elsewhere in the universe, it just sounds hard to believe that the obvious is all we have? [3] To prove that every overenchanted weapon ever created was achieved through an exploit? [4] To prove that everyone who has ever overenchanted a weapon not only uses this exploit, but are clearly in collusion with one another? [5] To bring your own brand of McCarthyism to the L2 community? [6] To rant until you yourself have successfully made your own +++++++ weapon?

Please tell us the point of this theory/hypothesis/conjecture/insinuation.

My position is simple: you don't need an exploit to overenchant, even to red glow and beyond. All you need is luck, adena/enchant scrolls and cajones. You may substitute "Beer" for cajones. :)
I stopped reading after the first page, but +1 for me.
hmm i seen people with +17 sud i consider them cheaters as well LOL sinds i cant enchent my duels pass +10????
I think his point is that because some cheaters don't blatantly cheat, it means we can't be aware of it, therefore it must exist. Kinda like the instant strider cheat and instant lvl75 cheat. The only reason we don't know about it is because the ones using it are hiding it well.

Or something.
This is what you don't understand, the SQL is run on a database thats local when its the PTS and when you have that TOGETHER with modded NPCs like the cats, you can inject modified SQL into the server.

But BOTH those things have to be present to do it, neither of these are true on the real servers.

So it can only be done on the PTS or you would have +65000 weapons on the real server too (like you did on the PTS)

This is what you don't understand, the SQL is run on a database thats local when its the PTS and when you have that TOGETHER with modded NPCs like the cats, you can inject modified SQL into the server.

But BOTH those things have to be present to do it, neither of these are true on the real servers.

So it can only be done on the PTS or you would have +65000 weapons on the real server too (like you did on the PTS)



If this is true then there wouldn't have been any reason for the scare on LIVE yes? Then why is it that NCSOFT felt it necessary to take down LIVE servers for 2 days and reset everyone's password? SQL servers do not need to be local to be vulnerable. It doesnt friggin matter if SQL is local or if its remote if you have the right security settings applied to said SQL servers.

Also, I've already explained to you that the modules and programming behind the operation of these cats have been downloaded on your computer. I'm sorry maybe its my fault to try to explain to kids about how client/server programs work and I'll stop after this, but you little kids have a long way to go before you understand software programming.
Nothing happened to the live servers while this same crap happened on the C4 PTS.

Since it was apparently the same exploit used by the same person, I would wager that whatever they were fixing on live was something different.
As Maline said, the PTS issue was different from the one on live. Your entire SQL argument is based on a casual comment in another forum (one with no explanation or sources, the person who put this idea into your head said one line preceded by C4 PTS screenshots that are completely unrelated to the C5 PTS, live, or this issue at all).


Also, I've already explained to you that the modules and programming behind the operation of these cats have been downloaded on your computer. I'm sorry maybe its my fault to try to explain to kids about how client/server programs work and I'll stop after this, but you little kids have a long way to go before you understand software programming.



You seem to be confused about server vs. local operations. You can do whatever you want on your own computer, but that's not going to generate +10,000 weapons on NC's servers. Simply put, no one can generate +10 weapons on live servers and use it because your data is held by NC, any introduction of items would need to be through hacking or oversights in design. If it was as simple as editting a character file we'd have a game economy like D2 on our hands.

You're jumping around issues so often it's difficult to understand what you're actually attempting to argue for. An overenchant exploit, an SQL security vulnerability, and the ability manipulate event cat scripts without cats being present are three completely different and unrelated issues. Trying to argue them all at once but not refuting the counterpoints of anyone is likely why no one understands what you're trying to say. That this whole thread started in an "I told you so" format with you linking to something unrelated to your own issue should've been a clear indication where this thread was heading.

The "I'm a super l33t programmer and you're all kidz even though some of you have worked in the industry for 20 years!" argument doesn't exactly help your case either. Falling back on a techincal background does not serve to make your points any more valid.

Those with true expertise let their arguments, and not their past accomplishments drive the debate. If they truly know what they're talking about and can convey it (turning jargon into laymen's terms is another skill held by some experts), their words will be enough to drive any argument without bringing their personal background into the fray.
What I've gathered from your reasoning is since we do not know if a Exploit exists, we cannot prove that it doesn't exist. That's like saying since we don't know if there aren't Trolls under any bridge in the world, then we cannot prove that there are none.

You make a claim and the burden of proof is on you. We do not have to prove a negative.

Just such an excellent dinner. Thank you.


I will never beleive in Ignorance. Ignorance is a desease.

I releive Ignorance, for I am teacher. Just like a doctor.

Most of my clients treat me as if I was carrying a * red glow * weapon.

DUDE, it's a surge of enchants coming from the squash event that pushes people into doing stupid things.






Greetings,

I after E except after C and whom shall I see for this spellchecker "disease"?

Have Fun!!+1
Board PK
Official Board Devil Spell Checker

did you know if you OE something while in the church it increases the sucess rate :)



Only if you do it while praying to GameGuard. :p
While standing on your hands IRL. You'll have to learn to use the mouse with your feet.
I used an exploit to overenchant my butt, it now glows red in the dark. Great for scaring cardrivers at night. :D
strangely ****
mmmm glowy red butt thingers....


mmmmmm

*chokes a bit*

errrr

*runs*

shonen
Snorfle!
Greetings,


I used an exploit to overenchant my butt, it now glows red in the dark. Great for scaring cardrivers at night. :D



HAHAhahahaahahahahhaahaha !

Dude, Best L2 related RL reference. EVAR !

Have Fun ! ™

BoardPK
Official Board Devil

No matter how valid an argument is, when you present that argument while being a presumptuous ***, doing nothing but insulting those that propose potential counter-arguments and talking down to those that disagree with you in any way, as if their opinion is any less important then your own, then your point loses any weight it might have held. But, let's pretend for a minute that you're right, so what? you would just be an *** with a point, feel fulfilled now? Good, let's move on to a conversation that's a bit less subjective and one sided now, ok?

No matter how valid an argument is, when you present that argument while being a presumptuous ***, doing nothing but insulting those that propose potential counter-arguments and talking down to those that disagree with you in any way, as if their opinion is any less important then your own, then your point loses any weight it might have held. But, let's pretend for a minute that you're right, so what? you would just be an *** with a point, feel fulfilled now? Good, let's move on to a conversation that's a bit less subjective and one sided now, ok?



I'm assuming you intended to reply to BlazerX instead of MalineII
Greetings,


No matter how valid an argument is, when you present that argument while being a presumptuous ***, doing nothing but insulting those that propose potential counter-arguments and talking down to those that disagree with you in any way, as if their opinion is any less important then your own, then your point loses any weight it might have held. But, let's pretend for a minute that you're right, so what? you would just be an *** with a point, feel fulfilled now? Good, let's move on to a conversation that's a bit less subjective and one sided now, ok?



NO ! Perps have to be PK'd. then asked questions.

I am a torture expert, and I tortured this soul to the point he camped his spawn.

My pleasure is not to give you pain, although it is my specialty. I'm an expert at this, so would you prefer a martini of my chamber of torture ?

Have Fun ! ™

BoardPK
Official Board Devil



Read up on SQL Injection attacks because this is exactly the very simple method that the russian dude used to **** your sql server.



Hmm interesting read that SQL Injection attacks.

If that is indeed the problem, then the Live servers are probably as vulnerable as the PTS was. Worse, this means that that all validation of userinput must be done on the server and not on the client which will result in slower response times and more lag.

But if it was that simple, why didnt those writing down all those botting programs use this to their advantage earlier? They have spend more then enough money and time to develop their botting programs in the first place.

This is what you don't understand, the SQL is run on a database thats local when its the PTS and when you have that TOGETHER with modded NPCs like the cats, you can inject modified SQL into the server.

But BOTH those things have to be present to do it, neither of these are true on the real servers.

So it can only be done on the PTS or you would have +65000 weapons on the real server too (like you did on the PTS)



Sorry but I don't understand this. In his aformentioned method of SQL injection it should not matter if the database is running on another server then the PTS. Becasue you acces the database from your(modified) client. So why should that not work?
Greetings,

If you're lost, just ask BlazerX.

Where are you now, programmer ?

You're a mouse to me.

Have Fun ! ™

BoardPK
Official Board Devil


Hmm interesting read that SQL Injection attacks.



SQL Injection Attacks are old news, and as I said the entire claim was based on a casual comment in a thread accompanied by no proof (and again, this was also supposition only for the C4 PTS, not current C5 events). That it was once a popular method of intrusion means that a wide variety of defenses were developed.

The first step would be implementing stored procedures at the database layer to filter user input and only allow applications access to stored procedures and not the base tables. This is an incredibly basic defense, and for such a widely known intrusion method you can bet NC is using it.

All you need to do for added security is to make sure that parameters passed to each stored procedure are validated. Another addition would be to only allow input to be included in a specific format, and ignore commands entered in a different pattern. SQL databases have common functions, but if you create your own functions for each method then a person who has access isn't going to be able to do anything(require the second letter to be context sensitive and you'll really confuse people). There are a multitude of other widely known defenses for different levels of security, and the fact that this game isn't hacked every day is evidence that they are there.

How such an attack would be connected to an overenchant exploit, and only an overenchant exploit, I would never know. Thus it does little to aid the original argument.
Any programmer bragging about his skills isn't a good programmer. My god, I do not even want to think about the mess it would create having such an individual in a project. How about cutting down on the "my skills are better then yours" and just leave it at the "there’s no OE exploit until actually having some strong arguments favour of the theory"? I have yet to see any good argument. The PTS one isn't one. Claiming software has loopholes hardly validates as an argument to accommodate the OE **** theory.

Even if the chance of getting a +10 SoM would be less then the official 2/3 chance per OE, theoretically you could still get a +10 SoM first try. Welcome to statistics.

omg, I just read the 2 new posts on that thread I posted. ARE FRIGGIN KIDDING ME? Your telling me its a SQL **** that the russian dude did? Tell the dumb *** programmers in NCSOFT or wherever that set up the SQL server to first have better secure login/passwords. Use paramaterized SQL statements, using the **** command module. Also I hope to god that they do not put any SQL query statements on the client side of the L2 applications. This is really unacceptable. I really hope that no one figures out the login/pass for the SQL servers on LIVE. Can't believe this is a friggin SQL **** of all sh*t. You guys are really starting to disappoint me NCSOFT.




From what I have read, one part of the problem was that the SQL server on the PTS is on the same machine, making some exploits possible which simply would not work if - as is with 100% certainty the case for the live servers, simply for performance reasons - the SQL server was NOT on the same physical machine. Just think of e.g. paths. So saying "it works on PTS, so it will work on live servers, too" does not always hold true.

The exploit on the PTS was not an OE bug, it was a command bug. The hacker gained admin rights and gave himself anything he wanted. Any skill, any stats, you name it. Like running a private server, he had full powers of a GM.

Who do you think invests the most time and money on live servers to gain advantages? Hackers? Players? You're ******ED if you think that is the case. The answer is FARMERS. If a farmer could generate adena, he wouldn't need a bot train. He could spread it across accounts slowly and be completely unnoticable. Adena drops on the ground anyways.

While there are threats to L2 security, that doesn't mean that they are readily exploited. When such things exist, they don't stay hidden long. These types of actions cause NUMEROUS glitches. The C4 PTS had the same hacker and he spawned and dropped weapons in every town. The server went down within an hour, but we got to play around with them before that.

Ready for the shocker? THEY DIDN'T WORK. The SA'd weapons and absurdly overenchanted items would hit for X billion damage and actually do zero or random low numbers. You equipped a health weapon or SA focus and nothing changed.

Sure, there is an exploit possibility. There is ALWAYS an exploit possibility. But look, they caught a POTENTIAL security risk and reset the passwords on every account. The people that know the code best and discover these things are normally the developers. And when one glitch gets exploited, the developers normally solve a dozen others in fixing it.

The fact remains, just because you saw a +10 SOM doesn't make the weapon a cheat nor does it suggest the player exploited. No "investigation" is warranted from one isolated instance. You're flat out jealous and every time you post, your nubile cry to mommy crap just makes most of us laugh. What's next? You going to tell us how no legit players afford A grade anyways? Sit down and let far more intelligent people call out these things. You are wasting everyone's time with your stupidity.

CRY MORE NOOB



For future reference, once you about +99 on D grade you would be able to one shot everything in game. Besides, if you see an overenchant above 20, you should know it doesn't work, and that it's a cheat, because it isn't enabled over 16 that we've seen, and that the probability would bottom out after a certain number. The probability that you would be able to overenchant that high that is. I can't remember what it is at +16, but it's extremely difficult to get it that high, without being a server administrator of course.
like I said before its useless to talk to about a bunch of kids about programming basics, which is obviously to someone who's been in the industry for awhile. SQL injection attacks are simple but its used widely by a lot of people to try and **** into bank or financial institutions to get at your account info. Remember when NC Korea has issues with identity theft? It could be that they lost those identity because of these SQL injection attacks. Maybe they've done more patching since then? who knows. But it seems "holes" still exist.

Its actually idiotic to continue debathing with kids who "think" they know it all when they don't have a clue what they are talking about. It shows how ignorant they are and how much of a lack of programming experience they have in such matters as this. So I'll stop.
Your bragging about your years of experience would look better if you did a little research.

No data was lost through NCSoft during that incident, it was just that a lot of people played with identities stolen from elsewhere (farmers).

You've not bothered trying to explain anything, and have been stacking unreferenced opinions as facts sky high.
THIS IS PROOF!1!11!!1!!1!

lol.
I have no clue/proof/opinion about the claim of the OP. I just believe he brings poor evidence.

But if Maline disagree then BlazerX is probably right.

A word about a 'fact' taken for granted :
'no data was lost' ; cool and how would you know if so ? You are responsible for their db ?

Then one can't complain that he hasn't explained. He did. He said 'SQL injections'. Every Google on earth can explain you that.

But to sum it up, sql injections are not about deleting data... They are about reading and writing in a db you're not supposed to access in such a way.
With this technique it is technically possible to write in a db that your bow is a +65254, or even -254. The 'mechanics' of the game which prevent you from enchanting do not apply when accessing a db provided you respect its data structure.

So a hole in the game would allow a guy to execute sql code to manipulate the db and his toons/inventory stats.
That's the hypotesis. ANd it's logically and technically possible IF the hole exists AND you are not the casual geek.

The casual geek will just use that technique to deface boards in php/mysql (like phpbb phpnuke, ubb, mambo...) and pretend he's god while he's just using other's people proofs of concept.
And it's the reason why no one should post his account info in private messages on ANY boards... ad who knows, perhaps also the reason of the last Official Boards downtime. Ppl snd their account info in pms, the boards are compromised, leading NC to reset the pws that were in the pms and explaining why the pws were compromised and not PlayNC's dbs...


Your bragging about your years of experience would look better if you did a little research.

No data was lost through NCSoft during that incident, it was just that a lot of people played with identities stolen from elsewhere (farmers).

You've not bothered trying to explain anything, and have been stacking unreferenced opinions as facts sky high.




THis is friggin hilarous. A little kid like yourself is telling a professional like me about "bragging" about my experience. LOL, why not first find out what the hell your talking about before you open your mouth? Research? bwahhahaha and what would YOU know about it?

You should stop right now Maline, because everyone who has been in the Software industry and knows about SQL Injection attacks know how absurd and inexperienced you sound. Your only hurting your own credibility. Remember Google is your friend. Use it.
BlazerX, thanks you for the interesting subject for me to read about. I hardly call myself well versed in security issues here and had never ehard about SQL injections. Then again, I am out of the porgramming scene for a few years.

But, don't you think you are overdoing your act a bit? Calling people names is not a good way to prove your point.
yeah I'm just frustrated is all. I love the game but its just sad that its going down the tubes in this way. very very sad.
And imo its people like you that makes it go down the tubes. People with no social skills running around screaming like a **** zelot. Yes the game has problems. But you wont change one thing insolting people and their inteligense, that makes you the little kid imo.
Miz....

You can keep it civil as well of course.

I suggest everybody try to bring forth some arguments why he is wrong so Blazer can use counterarguments. I believe there were some interesting pointers by lordofchaos for example that I like to see adressed.

Ps. I normally don't play the mediator but as I got a birthday cake.

Miz....

You can keep it civil as well of course.

I suggest everybody try to bring forth some arguments why he is wrong so Blazer can use counterarguments. I believe there were some interesting pointers by lordofchaos for example that I like to see adressed.


I have GM powers on live servers. Prove me wrong.

People have tried to be reasonable and he just calls us "kids". He is screaming so loudly that he knows more than anyone else here that he's deaf to any kind of rational discussion. Plus, he's said several times that he was done here. He lied about that as well.

Watch how this is done, Blazer: I'm done here.


Miz....

You can keep it civil as well of course.

I suggest everybody try to bring forth some arguments why he is wrong so Blazer can use counterarguments. I believe there were some interesting pointers by lordofchaos for example that I like to see adressed.


I have GM powers on live servers. Prove me wrong.

People have tried to be reasonable and he just calls us "kids". He is screaming so loudly that he knows more than anyone else here that he's deaf to any kind of rational discussion. Plus, he's said several times that he was done here. He lied about that as well.

Watch how this is done, Blazer: I'm done here.



Nah you can't, you got no cake. You will be back.
Want a slice of this lovely virtual chocolate apple cake with loads of whipcream? Guaranteed non fatening.

Miz....

You can keep it civil as well of course.



Wasn't I ? When ? In the tubes post ? it was meant to remove pressure... and calm down people by having a laugh at Ted Stevens on YouTube...



I suggest everybody try to bring forth some arguments why he is wrong so Blazer can use counterarguments. I believe there were some interesting pointers by lordofchaos for example that I like to see adressed.



LC is often pinpoint on topic. But so was I a few posts ago... SQL injections are a risk. Even if in this case I tend to think about a boards vulnerability leading to mess in game due to accounts disclosure.


Ps. I normally don't play the mediator but as I got a birthday cake.


lol @ bringing the birthday cake security hole in a security thread...

And imo its people like you that makes it go down the tubes. People with no social skills running around screaming like a **** zelot. Yes the game has problems. But you wont change one thing insolting people and their inteligense, that makes you the little kid imo.



lol and it people like you that make the games die out. People like you who are not smart enough nor have the brains enough to recognize problems and give feedback when appropriate. People like you that sit back and watch the world fall apart and then wonder why when everything goes to hell in a handbasket. People like are the worst of the lot because you dont do a **** thing to try and change the system when you should be doing it.

I call them lemmings. When one drops off the cliff, every others like you follow.


Miz....

You can keep it civil as well of course.

I suggest everybody try to bring forth some arguments why he is wrong so Blazer can use counterarguments. I believe there were some interesting pointers by lordofchaos for example that I like to see adressed.


I have GM powers on live servers. Prove me wrong.

People have tried to be reasonable and he just calls us "kids". He is screaming so loudly that he knows more than anyone else here that he's deaf to any kind of rational discussion. Plus, he's said several times that he was done here. He lied about that as well.

Watch how this is done, Blazer: I'm done here.



well you are *kids* aren't you? So far I've shown threads and others have responded that there have been OE bugs in the past, more than 1. As recently as just now. I've shown proof for my conclusions. What have you others done except scream at me like little kids so far telling me that can't be because??? why? You haven't provided the WHY. I have.
Actually I see several people posting here that are well above 28...
So for the "kids".... I see some too.

You haven't provided the WHY. I have.



Again, I reference the fact that you cite your OP as proof even though it's completely unrelated to your 'overenchant bug'. At this point it seems as though you've lost sight of the issue entirely (whatever it may have been) and are simply trying to argue that you are correct in all things.

If you are trying to convince us of an overenchant exploit, then show us some evidence.


So far I've shown threads and others have responded that there have been OE bugs in the past, more than 1



When these existed, we discovered how they worked (believe it or not, when there's a bug people talk about it on unofficial channels) and reported them to NC describing the method in detail. The problem was solved. You have no method or even case examples. The threads you link to are completely unrelated and also as unofficial as your own opinions. Your case isn't weak, it's not even there.

If you want to convince us of an SQL vulnerability, then demonstrate that NC has suffered such an attack. And no, a link to a message board post preceded by C4 screenshots is not valid proof. Not to mention that if an SQL Injection Attack was being performed, overenchanted weapons would be the least of your worries.

If you believe that people are running event cat scripts without the cats being present, then explain why this is happening and more importatly how that relates to an overenchant bug when the cats are incapable of creating more than +0 equipment.

Why I continue to argue this I have no idea, as you've yet to refute one point in any of the posts I've made.


Wasn't I ? When ? In the tubes post ? it was meant to remove pressure... and calm down people by having a laugh at Ted Stevens on YouTube...




Well you know how good intentions travel on a forum where emoticons are needed to bring the message true.



LC is often pinpoint on topic. But so was I a few posts ago... SQL injections are a risk. Even if in this case I tend to think about a boards vulnerability leading to mess in game due to accounts disclosure.




Yeah, the method they choose seems to be a bit messy. But I hope they know what they are doing. ANd indeed i found the remark of LC interesting as well. I still like to know why according to him this Security issue could happen on the PTS and not on the Live server. After all, the PTS is supposed to be a beta test of the program they intend to bring live. Both client and server wise. It would be a dangerous thing to have much differences between the PTS and the live servers as that canl influence the test itself.


lol @ bringing the birthday cake security hole in a security thread...



Uh oh, you think that people knowing I was born on 6-8-06 is bad?



Uh oh, you think that people knowing I was born on 6-8-06 is bad?



Only if your PlayNC username is Woodsman ;)
And don't use 'What is the internet' as a secret question. Because now we all know ' it's a series of tubes (http://www.youtube.com/watch?v=Prtwd85YqAM) '.

(And I quite agreed on all the rest ;) )
Im not here to compare IQ, number of years in the IT biz or the number of years working with programing or SQL or w/e it is you are trying to do here. Yeas there is some big problems with the game, no one is saying anyhting else. But making up evidence for it and trying to call everyone that dont agree with you stupid, uninteligent etc is not the way to go. Maybe you should use some of that superior intelect you aparently think you have to learn how to deal with people. Then you can try again.


/Eriot
a brainless lemming with 10 years of database experience and probobly more brains then you will ever have.
The guy did not find out how to do it recently or anything. He's had that SoM for some time now. (I assume you're speaking about Vanosh) He's also a very cool guy and does not use any cheats in the game. Please quit crying about someone who has an OE weapon, you sound like a baby.
!WTS +18 SoM cheap!

Im not here to compare IQ, number of years in the IT biz or the number of years working with programing or SQL or w/e it is you are trying to do here. Yeas there is some big problems with the game, no one is saying anyhting else. But making up evidence for it and trying to call everyone that dont agree with you stupid, uninteligent etc is not the way to go. Maybe you should use some of that superior intelect you aparently think you have to learn how to deal with people. Then you can try again.


/Eriot
a brainless lemming with 10 years of database experience and probobly more brains then you will ever have.



First you start off with your statement that you are not trying to compare IQs above and at the conclusion you say this :"more brains then you will ever have". Is it that you really don't know how to debate or do you just like to shoot yourself in the foot or stick it in your mouth?

As for me making evidence up...how do you figure? I guess in your paranoid point of view, I must have assumed all the identities in that other thread I linked and "made all that stuff up" by posting as different individuals? Or maybe I'm really LordChaos?

I'm sorry but debating with you is like lecturing a little child. As for 10 years of database experience...how full of sh*t can you be really? You don't even know what SQL injection attacks are or what I'm getting at when I describe the vulnerability such a **** can cause if its not properly addressed.

10 years of database experience doing data entry into an excel sheet is NOT in any form or any way a "database". Nor does programming in Access make you a database or applications programmer. Pfft. Sorry but I honestly do think you don't have a clue what your talking about.

'no data was lost' ; cool and how would you know if so ?



Basic reading comprehension?


Apparently, hundreds of thousands of "Lineage" accounts were created using stolen IDs. South Korean police are investigating an NCSoft executive for not doing enough to prevent users from signing up with the pinched IDs.



source (http://news.com.com/2061-10797_3-6091898.html)

All reports universally contain the same information - stolen IDs were used to create accounts in Lineage/Lineage2, and NCSoft did not appropriately verify that the person whose ID was being used was really the one signing up. That has nothing to do with losing your customer info; it's like somone faking your real life name and address when signing up.

If you'd done a bit of research when this came up (or just knew a bit about how most Korean games deal with this), you would also know that most Korean games require an ID unique to each Korean, a sort of Korean social security number. You would further know that many western players use generators of these when they sign up to open betas and similar things, which is, in fact, the kind of identity theft which is very likely talked about here.

PS: Miz, if, and I'm not saying this is the case, one of us can say "is usually wrong when the other agrees," it's most certainly not you, and you know that. This is likely what Woodsman referred to as civil also, although of course I can't see into his head.

As for me making evidence up...how do you figure? I guess in your paranoid point of view, I must have assumed all the identities in that other thread I linked and "made all that stuff up" by posting as different individuals? Or maybe I'm really LordChaos?



You do realize that message board posts are not evidence, do you not? Especially when none of the posts you reference are in fact agreeing with you. Not to mention if you actually read the post which you reference as gospel, you'll see that the posters are all arguing about what actually occured (and are also simply flaunting wild opinions with no proof). All the posters there also fail to understand what is actually going on (for example they don't realize that a +65,000 weapon would not function correctly).


'no data was lost' ; cool and how would you know if so ?



Basic reading comprehension?



That's exactly what I was waiting you to answer ty.
SO you don't KNOW, you just BELIEVE what NC said, a company well used to transform facts due to PR and marketing thoughts...ty.
These are articles not written by NCSoft based on what people were going to sue about. They were sueing about NCSoft allowing people to use their stolen identities. There was never any, even the softest, complaint about NCSoft losing identities in this context.

God, you're desperate. And wrong - so save yourself the public embarrassment.

Or are you going to explain that sign-up procedures that do not appropriately verify the new customer's real life identity are somehow related to getting hacked or losing your customers' information?

This is likely what Woodsman referred to as civil also, although of course I can't see into his head.



Another fact taken out of the blue I imagine ?

What I say is you don't have a semi clue about SQL and still you hit him hard with your 'facts' which as we've just seen are none others than misinformed opinions. No data was lost... How would you know if a sql querry had inserted something in the game db?

And I also say that when you bash on someone like that it's generally cos you have poor arguments and try to 'win' by being the most vocal... that's just how you do.
maline being vocal = trigger = the guy is probably right. See? Easy.
Sorry, please quote the misinformed opinion, I don't know what you're referring to - and while you're at it, quote the passage that proves it was wrong, because I do think I would have noticed if an actual fact had been poked at anything (except the count of exploits, which is what I did notice, but wasn't the main point) I said - so far I've just seen BlazerX's possibly correct but totally unfounded-on-arguementation accusations.

Let me grab some quotes before I reply to the second half here.

PS:

Remember when NC Korea has issues with identity theft?




No data was lost through NCSoft during that incident



This is the incident I was referring to. This incident had nothing to do with SQL queries or anything of the like. If you're talking about another cry of public outrage of identity theft than we are, then kindly inform me which one so I can say what I have to think about it - although I can't guaranttee it will be the same as above, as I'm refering to that particular incident there.

My arguements are rarely poor, and almost always poorly arguemented. There's a big difference.

PPS: I get vocal when I feel I'm definitely right and people - like you - are ignoring coherently built and sound arguements. ^_^ I bet you're going to claim I made up that I was talking about that one incident which actually got press attention and discussions at the time now, but I'll point you at the fact that this is exactly the one I went looking for a quote on, too, and that I already outlined what happened in the first post in which I mentioned it.


This is likely what Woodsman referred to as civil also, although of course I can't see into his head.



Another fact taken out of the blue I imagine ?

What I say is you don't have a semi clue about SQL and still you hit him hard with your 'facts' which as we've just seen are none others than misinformed opinions. No data was lost... How would you know if a sql querry had inserted something in the game db?

And I also say that when you bash on someone like that it's generally cos you have poor arguments and try to 'win' by being the most vocal... that's just how you do.
maline being vocal = trigger = the guy is probably right. See? Easy.



What I hope to achieve is to read some good argumentative threads. In which one side makes a statement. Another person chalenges that statement and then get a counterargument form the OP.

Good arguments include things like: pointing about a flaw in the argument and why it is flawed. If you can bring sources to back for your arguments, even the better.

Bad arguments include things like: You are stupid, I have an higher IQ then you, I worked with databases for 10 years (this is not an argument, but it can help to give you more credibility).

For example:
Argument
I believe that this **** was done by people using technique X, I came to this conclusion because of circumstance Y and Z.

Counterargument
I think you are wrong here, because circumstance Y is not valid for services rendered this way. See also: include source.

Counter that counterargument:
Good catch. If we consider that Circumstance Y is not valid (I will come back to that after reading your source) that leaves us still with circumstance Z. Hence my original conclusion still stands.

etc.

(this way, we the readers can hope to learn a bit as well)
Greetings,

Dude, don't expect people to be logical here.

That's like to have Ice cream in HELL.

:)


Have Fun ! ™

BoardPK
Official Board Devil


Greetings,

Dude, don't expect people to be logical here.

That's like to have Ice cream in HELL.

:)


Have Fun ! ™

BoardPK
Official Board Devil





Still woodsman's guide deserves a sticky...

And Maline you can't KNOW that no data was lost you can just BELIEVE it. Quoting "no data was lost" till the end of the world won't turn that belief into a fact. Like ppl having faith in god won't have their faith having any influence on his existence. Act of faith >< logic.
No, in all actuality, I can know that during the context of that incident no data was lost; because that incident had nothing to do with data loss. Your saying they lost customer data during that would be like saying "By the way, in the context of our password resets, identity theft likely took place with NCNA."

While without a doubt, someone signed up with the wrong name, address and birthday during the whole mess (because people do this all the time), and that might even have been the data of a different person altogether, I'm sure you would agree that what that person was doing had nothing to do with the password resets.

The same goes for that incident: It wasn't a ****, it was NCSoft's lax signup procedures. If hacking took place during that time and customer data was lost, it was still totally unrelated - and that's all I'm saying.

To put it into simpler words: "That incident has nothing to do with what we are discussing here, BlazerX."

Coincidentally, we haven't heard about NCKR losing massive amounts of customer data, and the last time that happened to the operator of an MMORPG I played (Gravity Corp, Ragnarok Online), it was definitely all over the place.
Mizwisfist...
You still believe that your government uses your taxes to make your life better (social stuff and streets and something like that)...
Get the truth right here: They use it for their own private pleasure and are doing orgies with it!
There's no need for me to prove this, everyone is corrupt, that's well known, so prove me wrong or your taxes are lost to the Devil!!!!
You can't KNOW that they don't use it for fun you can just BELIEVE it.

So what's that argumentation about? Cowpoo anyway...

Back to the original topic:
What's so hard to believe in ther COULD be an OE-exploit on life too? There COULD be, I don't BELIEVE in there is one, but I don't KNOW either.
There COULD be a loophole, but there also COULD be no loophole to exploit.
Noone KNOWS and noone can PROVE it right or wrong.

So I just go as usual: not guilty until guiltness is proven.

Period.
Of course there could be one, but no exploit is ever kept well hidden for all that long. The basis of assumption for there to be an OE exploit right now that we have isn't that there could be one, but that one of the many idiots producing A Crystals daily got lucky and didn't blow up his SoM when it went +10.


'no data was lost' ; cool and how would you know if so ?



Basic reading comprehension?


Apparently, hundreds of thousands of "Lineage" accounts were created using stolen IDs. South Korean police are investigating an NCSoft executive for not doing enough to prevent users from signing up with the pinched IDs.



source (http://news.com.com/2061-10797_3-6091898.html)

All reports universally contain the same information - stolen IDs were used to create accounts in Lineage/Lineage2, and NCSoft did not appropriately verify that the person whose ID was being used was really the one signing up. That has nothing to do with losing your customer info; it's like somone faking your real life name and address when signing up.

If you'd done a bit of research when this came up (or just knew a bit about how most Korean games deal with this), you would also know that most Korean games require an ID unique to each Korean, a sort of Korean social security number. You would further know that many western players use generators of these when they sign up to open betas and similar things, which is, in fact, the kind of identity theft which is very likely talked about here.

PS: Miz, if, and I'm not saying this is the case, one of us can say "is usually wrong when the other agrees," it's most certainly not you, and you know that. This is likely what Woodsman referred to as civil also, although of course I can't see into his head.



Look Maline, I'm gonna respond to you one last time and then stop posting in this thread altogether. I"m tired of talking to you and the other "kids" on this thread who understand jack sh*t about software development and the IT industry in general and try to make yourselves sound smart with useless prattle about things you have no clue about. Its clearly obvious to a professional that when it comes down to software development, wether that involves databases, application/software programming, you and your compatriots are all talk and no substance.

IDs, login info, CCs and a whole lot of other information are stored in databases. ALL of it and more. In regards to CC information, most smart companies let companies like Verisign and some othe financial instititutions keep that data for them and use an admin interface to get at the data that are stored on their servers because of issues such as privacy and legality, via a reporting system. But if an enterprise level company has the resources to secure this sensitive data and keep it in-house, they do it to save on cost. In NCSOFT's case they have it in-house since they seem to have a custom billing system that they are able to pull from a data source and modify on their terms..which is easiest done if they have access to a localized or internal billings SQL server or some such. I doubt that Verisign or any other 3rd party financial institution out there will willingly expose their senstive SQL or Oracle database data for companies to use on their own whim, because again of legality and privacy issues.

Therefore, when NCSOFT reset YOUR password and everyone elses' there is a valid concern that somehow that information was leaked from their SQL server, otherwise they wouldn't need to have reset the password and make you redo the whole thing all over again. Now IF you cannot acknowledge nor grasp this simple principle of using a data storage system as a backend in software development to house data for almost everything, then just forget it. Forget about every **** piece of knowledge you THINK you have in how software or database systems work ok? I'm tired of explaining to you and other kids about how real systems work out here in the real world because you don't have the slightest clue nor the experience even to know what I'm talking about.

My only hope is that someone in NCSOFT does know what I'm getting at and makes **** sure a security leak like this doesnt happen again or they will seriously be facing several lawsuits, if not already.

Also, I'm pretty sure that someone in NCSOFTs knows **** well that if their login/passwords were vulnerable, other parts of their database was also vulnerable and they should have a dedicated team right now going through the integrity of their database and make **** sure nothing else was comprised, not to mention analyze the data for anamolies where someone could have hacked in and manipulated their stats such as OE weapons.

Good Night.
I know you aren't going to post in this thread anymore, but I have to ask...

What does the recent fiasco with the passwords have to do with an OE bug?
My statement that no data was lost clearly referred to this:


Remember when NC Korea has issues with identity theft?



Which, as I explained above, had nothing to do with a hacking but something with NCSoft's lax sign-up procedures.

I totally agree that the password reset raised valid concerns about the security of the data stored with NCSoft, there was never any denying that. There's no reason for such a drastic measure if security wasn't compromised.

Gildran, BlazerX is trying to relate Archangela's "work" on the PTS to an OE exploit on live. He or she used an exploit which was known on live and since (supposedly) patched there, which operates through the cats, to gain access to GM commands to procure items, levels, skills etc.

It's doubtful that this same exploit works on live, because Archangela obviously feels very comfortable with performing it in public to show off. If he could do it on live, I think he would.
Hey guys,

So I have one simple question. Who's balls turned out to be the biggest?

And to SirElroHir,

I'm jealous you have better equipment than me, and WTB AN ORCISH POLEAXE.

Sorry for the turrette's syndrome, i spent all day yesterday looking for an Orcish poleaxe, and then I got so frustrated I had to buy the dreaded +5tsu*sls and this morning I OE'd to +6 and then wet myself.

Qais