i think nearly everyone on the kain server has been getting pms at night around 2-3am, i'm not sure this is just what i've been hearing, and its from a character named "xx1122" and its just a blank (or what appears to be a blank 3 times almost instantly) its completely server wide, it hits nearly everyone connected to the server, can we get some official word from NCSoft if this is some bot detection tool, or if its a computer geek who found out how to mass pm the server.
Same happened on Sieghardt over the weekend or towards the back end of last week from a toon named "ee78". Apparently the message is in Chinese but looks blank because the NA client doesn't support the character set.
It's a bit concerning if someone has found out how to check which toons are online at any one time across the entire server and mass PM them. What's next?
3rd party program user who has set a wrong option in his software? (like one guy here at work who wanted to send a very private message to his gf in the company via a windows popup message and accidentally sent it to the whole Windows domain)
Farmers communicating server wide to set prices for mats, or maybe they are planning a server takeover?
Trojan viruses, once planted, often broadcast their presence to the person who planted them. I'm going to throw a punch in the dark and say that a malicious script kiddie has infected one of our much loved 3rd party crapplications [sic] with such a tool. Upon connecting to the server it then broadcasts to everyone in its visible range in the hope that the person who planted the Trojan is nearby ready to send a "special code" in reply. It continues to broadcast (keeping track so as not to message the same person twice) until it finally finds its master. Then... well, it could do many things - trade all of the items, hand over the account/password. All it would take for this to happen is for someone to submit a "cracked super special" version of one of these applications which would "wow" and "awe" people into downloading it.
Another suggestion is that the 3rd party applications are compiling a list of characters over time and are getting ready for a mass illegal site advertising campaign. Wouldn't take much... sit a toon or two in every village and have it log everyone who passes through. The farmers then compile a list of names and when they're ready, initiate a server-wide advertising spree. And what you're seeing at the minute is possible a test to see if the tool is working. This is pretty much the same way advertising companies do in real life.
If either of these are true, maybe NC should implement a limit on chat where you can't PM more than 5 people in 10 seconds (or there abouts). It would make sense, because unless you were extremely popular and a very fast typer, a normal person won't be PMing more than 5 people in such a short period of time.
Lionna as well. Last night it was 4445, tonight it was 2245, I believe.
According to one of our heroes (no validation on my part, so take it for what you will), several accounts that replied to the PM were stripped today. Unlikely, but check yourself for keyloggers, all the same.
According to one of our heroes (no validation on my part, so take it for what you will), several accounts that replied to the PM were stripped today. Unlikely, but check yourself for keyloggers, all the same.
If thats true, then I say let it continue to happen. Replying to a pm would not magically send your login/password. Being stupid enough to run some "special program" or botting software that was infected by a virus would. You deserve to lose your stuff if you think you sould get an unfair advantage over other players by running something you believed would give you said advantage. For those stupid enough to get infected by a keylogger, well, you'r better off to stay off the internet entirely for your own sake.
i also received a triple empty message from someone 44455 or something like that.
imo, to being checked by a gm through random messages is not a solution. i hate to find my dwarf banned cause he is just selling my stuff overnight while im sleeping
Alyra, I petitioned last night right away after that guy, aaaa22 pmed my character with some numbers. [That happened in Gustin, btw.] In my petition I wrote, "I got a pm from aaaa22 with that message [I forget the numbers] and weird thing the whole server is getting the same message at the same time. Please investigate."
I got back a "canned" response about using a third party program.
I didn't reply that pm and proceeded with blocking the user.
You'll always get an auto response when you send in a petition. That's just to let you know we received your petition. :) Most everything else is done behind the scenes.
Also got similar message on Erica. majority of the server is receiving them. Mostly gibberish too. aadd123 sends me a tell saying ddghfhsg. At firsti thought it was a friend fooling around.
How is this possible using the l2 client software. Oh right, sorry we won't get into that. I wonder if it can fake the sender name. On erica I think the name was aadd12 or aadd123. Two days in a row now.
Oh, also, it seems that the person would log off after sending the pm. After getting the PM I would try to send one back but the user was offline. Then I'd hear from someone else later that they just got a pm from the person and when trying to pm the person again, they would be logged off.
On erica:
aadd11 pmed everyone I believe
aadd22 only PMed two of my accounts but he was much spammier sending 9 messages instead of only 2 (858, 888, 999, 333, 2222, 555, tons of p, tons of p again, tons of o and tons of i)
And yeah, in both cases I tried replying and the person was offline too. Kinda makes me wonder if they found a way to send PMs without logging on?
They're planning something; it's a conspiracy. If they're checking for certain users, then I'm pretty sure they're looking for an infected client (3rdp) to respond to it so they can steal the acc/items.
it would be funny if there was a back door programed into the "bot" programs, only ppl to get striped are the ppl who bot :P prepare for the rebirth of l2, free of bots :P
They're planning something; it's a conspiracy. If they're checking for certain users, then I'm pretty sure they're looking for an infected client (3rdp) to respond to it so they can steal the acc/items.
We'll see.
I wouldn't go that far. I won't claim to know what they're up to, but this is exactly how other "gold spammers" function in other games. I don't know how it works, but sending a petition in with the name will help us catch whoever is doing it.
I wouldn't go that far. I won't claim to know what they're up to, but this is exactly how other "gold spammers" function in other games. I don't know how it works, but sending a petition in with the name will help us catch whoever is doing it.
Why not? It's exactly what has happened in the past. From my experience of internet security there are many trojan horses which broadcast their activation/presence globally so as not to incite any person(s) as the perpetrator.
Does anyone remember NetBus or Sub7. They used to broadcast globally.
I was trying to rip off from one of the south park shows related to WoW
"How do you kill that which has no life"
I'm familare with the engine used for l2, and the logging system, anything at all said, done, accessed, is logged.
However, i also know that logs can be confusing when For no apparent reason at all due to glitch/bug, (exploit that is unknown), a user could be disconnected from the server, yet make abrupt connections, quick enough possibly to send messages.... Although i think the number of connection attempts per second would be insane, i'd think the server would consider it a DOS attack of sort and ban the connecting ip emediately. no?
Either way, i've seen some pretty strange things. While the server game engine may not provide logs the explain all that much, i'm sure it could be easily tide to server side logs (outside the game server) that would. ;)
I wouldn't go that far. I won't claim to know what they're up to, but this is exactly how other "gold spammers" function in other games. I don't know how it works, but sending a petition in with the name will help us catch whoever is doing it.
Why not? It's exactly what has happened in the past. From my experience of internet security there are many trojan horses which broadcast their activation/presence globally so as not to incite any person(s) as the perpetrator.
Does anyone remember NetBus or Sub7. They used to broadcast globally.
I don't think it would be the first time a game would/could be used to distribute or "call home"...
My friend got a mysterious nonsensical PM too. I told him to change his password right away. I told him to go to the forums to ask about it but he couldn't be bothered. e_e
Same happened on Sieghardt over the weekend or towards the back end of last week from a toon named "ee78". Apparently the message is in Chinese but looks blank because the NA client doesn't support the character set.
It's a bit concerning if someone has found out how to check which toons are online at any one time across the entire server and mass PM them. What's next?
So that's what that was! I tried to respond with a simple "hi", not knowing what was going on. But it said the player was "not on-line".
Strange, messages have been sent across franz too. 80% of the people i know recived one, "xuxu" "sunsun13", there have been ones advertising adena selling websites.
Sending a trojan / keylogeed through PM's is impossible, thats just dumb. Login / password maybe, could be to do with 3rd party program responding to there pm's for people who use them, Strange...
I think this might have happened on Erica too? I got it around 2-3 am as well, something with the name aadd12 (something like that) and all it said was random numbers and then "ppppppp" "iiiiii"
I'll tell you what this is, they're setting up spam wars.... My friend was tellin me about ppl that did this in WOW, whats gonna happen is, instead of the 11xxzz guy that pm'd me the random things u guys are talking about, are now going to be pming you website addresses to buy adena and stuff from. Like what Valkyrie was sayin, simple as that..
Trial accounts IMO, the mass PM system will be used later to spam people with Adena and stuff selling pages. Trial accounts can not trade or drop stuff in inventory and cannot shout, but still can PM.
I think EQ2 has this system where trial accounts can only PM people who have added them to their buddy list. I don't see why something similar shouldn't work in L2, assuming this is what it will come to.
Gold seller spam is some of the most annoying 923 there is in mmo's these days. I'm currently playing eve and you can't get by for more than a couple of hours before you get some dude named Sgakjfha joining your channel and repeating his ad as fast as the spam-filter allows him. Not to mention the in-game mails.
Just ignore them don't listen to anything you say so you can keep playing and not have you computer on fire by an onslaught of viruses with additional pop-up ads that come at such a mass quantity that it fries your harddrive and as I stated before sets your computeron fire which gives them enough time to get your bank account # and your passwords and stuff,
or they're just trying to annoy people serverwide, best not to take chances though
I'm sure it's a packet injection.
With the proper packet injection, you can make up names on the fly, randomize them, and then send all these messages off.
All these names, but one account, and none of them show the name that actually sent the PM's.
Makes it harder to trace to the source, and the output could be rather large.
Well, they can no longer use trials to farm adena, so they are now learning how to use trials for advertising.
I don`t think that`s a trojan in 3rd party software, i have absolutely no such software on my PC, got Kerio fw and KAV, and I still got same pm`s.
If you read my posts correctly you will see that I'm not inciting that everyone who gets the PM has a 3rd party application but more along the lines that they're sending out a broadcast to either;
1. Make the person(s) who planted them aware of their presence.
2. Search for an infected client which would, in turn, reply to the original PM.
I'm beginning to think this isn't the case and more like someone trying to generate a database of active character names for a future advertising spree.
I figured the other 8 went someplace else. He/she didn't specifically say the others went to WoA. I'm just providing an alternate possibility before anyone burns anyone on the stake ;)
Wanna know whats really scary? The person who did this had access to some sort of database with every character name on that server.
No they didn't... they probably just sat a toon in each town for a period of time and logged the coming and goings of everyone. I could probably write something to do that; but I'd have to break the EULA to do so :p
Wanna know whats really scary? The person who did this had access to some sort of database with every character name on that server.
No they didn't... they probably just sat a toon in each town for a period of time and logged the coming and goings of everyone. I could probably write something to do that; but I'd have to break the EULA to do so :p
I wouldn't go that far. I won't claim to know what they're up to, but this is exactly how other "gold spammers" function in other games. I don't know how it works, but sending a petition in with the name will help us catch whoever is doing it.
Why not? It's exactly what has happened in the past. From my experience of internet security there are many trojan horses which broadcast their activation/presence globally so as not to incite any person(s) as the perpetrator.
Does anyone remember NetBus or Sub7. They used to broadcast globally.
mIRC on the MSN Chat network :) Flood bots > L2 bots.
We need to chat... pm me lol :P
I wouldn't go that far. I won't claim to know what they're up to, but this is exactly how other "gold spammers" function in other games. I don't know how it works, but sending a petition in with the name will help us catch whoever is doing it.
Why not? It's exactly what has happened in the past. From my experience of internet security there are many trojan horses which broadcast their activation/presence globally so as not to incite any person(s) as the perpetrator.
Does anyone remember NetBus or Sub7. They used to broadcast globally.
Like I said, toons sitting in towns logging character names to a database. All you have to do is come within x-distance and BAM, you're on their database. No such thing as Ex-Directory in L2 ;)
That doesn't explain how they where able to pm a Character I created 5 minutes before I was messaged?