What: Many game accounts were hacked and robbed since GoD. There could be many reasons, and I believe NCSoft tech.support will find the real one, and help people. However, for now, I will tell you how the Path of Awakening or Forums or Market could be dangerous, and how to avoid that treat.
How: The cross-site cookie theft. Some malicious code, located on some webpage (away from lineage2.com) could contain ****, that gains access to the cookies of same browser process. When you log in to the lineage2.com your login/password is stored in cookies (read http://en.wikipedia.org/wiki/HTTP_cookie). Theoretically, Cookies could be read only by same website that created them. But there is a cross-site cookie theft (http://en.wikipedia.org/wiki/HTTP_cookie#Cross-site_scripting_.E2.80.93_cookie_theft). Thus, your computer is free from trojans or viruses, still your login and password could be stolen.
What do to: Do not open lineage2.com and 3rd party related websites in same browser. Do not open in same browser with lineage2.com websites like unofficial item databases, unofficial guides, forums, walkthrough for quests, etc, etc. Actually I suggest to open lineage2.com website in new browser and never open anything in other tabs of this browser. Ever.
So, if you plan to log in lineage2.com forums, Path, Marketplace, or your master account - make sure you are using new browser window without any tabs open.
What else. Some browsers are protected from cross-site cookie theft. Chrome and Opera opens each tab in fresh new process, like if you open new window for it. But still, be careful.
As far as I know, the username and password aren't stored in cookies here, its not allowed to be remembered in password remembering programs either. This is why you have to log in fresh every time you get logged out.
As far as I know, the username and password aren't stored in cookies here, its not allowed to be remembered in password remembering programs either. This is why you have to log in fresh every time you get logged out.
This.
Cookies are not meant to keep important data.
The normal way a login happens is with sessions.
You login,the server create a big hashed series of numbers/letters and it stores this into a cookie. But even if you know this you can't get the password .
Ofc there is a chance that NC's site stores passwords on a cookie but this could be kinda imposible considering they are proffesionals.
This.
Cookies are not meant to keep important data.
The normal way a login happens is with sessions.
You login,the server create a big hashed series of numbers/letters and it stores this into a cookie. But even if you know this you can't get the password .
Ofc there is a chance that NC's site stores passwords on a cookie but this could be kinda imposible considering they are proffesionals.
Wouldn't be first time having security breaches on big companies.
wouldn't be the first time ncsoft has a breach in security.
if breaches didn't exist, private server with stolen files of L2 wouldn't exist.
We can imagine that psw can be stolen also.
ncsoft would never admit their breaches in security, it would be too difficult to manage the consequences.
So, people hacked, like me are victim twice : once by the hacker, a second by ncsoft.
Case by case, said sace. They send you a copy of answer, same for everyone, and they don't do anything.
You are in town, with nothing to sell, and no adena for ss nor port. They even don't give arrows for the archers!
A guy, after 7 years paying each month, who lost 7 billion, received a bound gear! even not safe enchanted.
Are you kinding ncsoft?
They don't care because, anyway, there is too many people on the servers. SO, hacked persons leave and give one more slot for bot and hacker/spammers RMT.
Actually, storing information in cookies is just a matter of encoding/encrypting. And some cookies remain active even after the session is closed. Facebook, in fact, is being investigated because their cookies contain tracker information for the next 50-100 sites you visit after you close/log out of Facebook and then relay that information to Facebook's server next time you log into the site or visit a site with a Facebook-share button on it. And Facebook only started doing this after they hired a top-notch hacker who broke into their security and was offered a job.
Having this happen on any other site is not far fetched in the least. Simplest option is to download say Firefox. It has an option to 'Start Private Browsing', which does not save any cookies, history, or login information of any type, as well as flushes the RAM for the firefox task after said private session is closed.
NCSOFT giving bound gear to people who have lost billions is a complete joke
If you look at blizzards protocol for WoW, you report your account as hacked and someone contacts you within 10 minutes. They then go through the procedure of restoring EVERY SINGLE ITEM that was taken from your account and aim to do so within 12hours.
Even if NCSOFT review the logs and found someone from half way across the world logged your account and took all your stuff, you still get nothing back from them... they seriously need to review their system because they should be ashamed of that kindof support and then expect our money in return
wouldn't be the first time ncsoft has a breach in security.
if breaches didn't exist, private server with stolen files of L2 wouldn't exist.
We can imagine that psw can be stolen also.
True..i can give one clear example, on the old l2 launcher, rarely you would get server-side files downloaded into ur PC, it happened nevertheless and the user didn't do anything but click start/update button.