Yarr The Pirate! https://w.yarrthepirate.com/phpbb3/ |
|
Server Hack (11/08/2013) https://w.yarrthepirate.com/phpbb3/viewtopic.php?f=79&t=14355 |
Page 1 of 1 |
Author: | Ketrebu [ Fri Nov 08, 2013 9:20 am ] |
Post subject: | Server Hack (11/08/2013) |
For those not keeping tabs, SE did an emergency shutdown of the server late last night. If you were online, and in a zone with a market ward, you may have been hacked. Supposedly some people found out how to trick the server into making OTHER PEOPLE buy things from the ward. I.e.: - Seller puts bone chip up for 1 million gil. - Seller uses hack. - You, who happen to be in the zone, "buy" the bone chip with your money without knowing about it. - Seller has stolen 1 million gil from you. When you log on, make absolutely certain you still have your gil. SE have stated they will not be doing character rollbacks (this is open to exploits unless they rollback the entire server), however they will be reimbursing players on a case by case basis. Quote: This is Producer/Director Yoshida. This is just a preliminary report on the situation, but allow me to explain about current and future countermeasures. Firstly, we’ve been receiving numerous questions and reports over the last few hours and confirmed unauthorised activity from third parties impersonating legitimate players, who have targeted a portion of the market place. We don’t currently have many reports of users affected but, in order to nip this in the bud, we are going to conduct emergency maintenance. Please accept my sincerest apologies for the inconvenience caused to many of our players. We are verifying the data and promise that everything will be kept secure. This issue can only be seen in a small portion of Worlds, Zones and certain situations, so it will not affect players that were not logged in. Once we resolve this issue, confirm security and recover the game, we will take action against the external fraud source and take further security countermeasures. Again, we apologize for the inconvenience that this may have caused. Quote: We are not planning to perform any sizable character data roll backs at the current time. However, we will arrange proper assistance for players whose data was affected. We have obtained information on the route and IP address of the source and are proceeding with legal action against the party responsible. Quote: This is Producer/Director Yoshida.
Please note that we will not be posting more detailed information on this issue as this could potentially assist similar fraudulent activities or attacks. Also, there are several posts in this thread and some users could get lost in the text, so we’ve put together a basic explanation on the emergency shutdown below. Current Status No. of affected cases: Approximately 200 Prerequisite: Those who were logged in. Affected Locations: Parts of certain worlds only Affected Area: Only portions of zones players were in Only affected those who possessed more than several hundred thousand gil (Excluding gil deposited with retainers) Only those who fulfill these conditions and have been targeted by fraudulent third parties have been affected. Review policy: No large-scale roll backs/Each case will be individually addressed by the operations team. Details on the Emergency World Shutdown This current emergency maintenance seems to have been confused with the other recent scheduled maintenances. Please accept our apologies for the confusion this may have caused. Immediately after the escalation of this incident reached me, the operations team proceeded to announce the shutdown procedure as a ‘scheduled emergency maintenance”. This was going to notify players of the shutdown in advance. However, as this was an external attack, and so much more urgent, we decided that a world shutdown notification in this case could have actually increased the frequency of third party attacks and initiated an emergency world shutdown. As this is an urgent matter, we will post further announcements on this thread and on the NEWS, and we have prepared an emergency flow. Thank you for your patience and understanding. |
Author: | Ridere [ Fri Nov 08, 2013 10:40 am ] |
Post subject: | Re: Server Hack (11/08/2013) |
I read about this. Pretty scary stuff. I stayed logged in last night, but in Wineport. Risata is chilling in front of the market wards, but if they steal his 1.2k gil, then whatever. hah. Hopefully no one in our group got targetted, though. |
Author: | Shiroken [ Fri Nov 08, 2013 10:48 am ] |
Post subject: | Re: Server Hack (11/08/2013) |
I keep most of my gil in retainers to keep myself from spending it anyways. But really whats the point? its not like its 1. Hard to make gil 2. It hardly serves a purpose outside of how absurdly expensive food is. |
Author: | Dustdevil [ Fri Nov 08, 2013 11:01 am ] |
Post subject: | Re: Server Hack (11/08/2013) |
AFK'ED OUT IN ULDAH MARKET WARD, NO CLUE AS TO HOW LONG I WAS ON, LORD OF ONZOZO!!!!!!! WHY MUST I HAVE TO STAY AT WORK AND BE TORTURED NOT KNOWING!!!!!! |
Author: | Shiroken [ Fri Nov 08, 2013 11:05 am ] |
Post subject: | Re: Server Hack (11/08/2013) |
Dustdevil wrote: AFK'ED OUT IN ULDAH MARKET WARD, NO CLUE AS TO HOW LONG I WAS ON, LORD OF ONZOZO!!!!!!! WHY MUST I HAVE TO STAY AT WORK AND BE TORTURED NOT KNOWING!!!!!! Just have rush log you in, careful though or he will end up getting you a new relic. |
Author: | Rushal [ Fri Nov 08, 2013 11:10 am ] |
Post subject: | Re: Server Hack (11/08/2013) |
rofl... Dust will never live that one down and all I did was kill Titan... |
Author: | Dustdevil [ Fri Nov 08, 2013 11:45 am ] |
Post subject: | Re: Server Hack (11/08/2013) |
ill have to look myself, knowing and being at work would be even worse than not knowing lol |
Author: | Kluya [ Fri Nov 08, 2013 11:54 am ] |
Post subject: | Re: Server Hack (11/08/2013) |
Shiroken wrote: Dustdevil wrote: AFK'ED OUT IN ULDAH MARKET WARD, NO CLUE AS TO HOW LONG I WAS ON, LORD OF ONZOZO!!!!!!! WHY MUST I HAVE TO STAY AT WORK AND BE TORTURED NOT KNOWING!!!!!! Just have rush log you in, careful though or he will end up getting you a new relic. hahahahhaha |
Author: | Kioko [ Fri Nov 08, 2013 11:57 am ] |
Post subject: | Re: Server Hack (11/08/2013) |
random guy on reddit posted possible explanation, " The old exploit basically involved a ridiculously trusting server which would accept an inventory update (or pretty much anything, really) from the client-side. You could grab the packet along the wire when you earn an item from a quest, and just modify it and resend it over and over to get yourself more of it. Basically the worst possible communication protocol design possible. This seems similar; an attacker replaces their ID with other players' in a packet requesting a market purchase, and the server never checks to make sure it came from the correct session. " |
Author: | Athel [ Fri Nov 08, 2013 12:35 pm ] |
Post subject: | Re: Server Hack (11/08/2013) |
That's scary! |
Author: | Kluya [ Fri Nov 08, 2013 2:37 pm ] |
Post subject: | Re: Server Hack (11/08/2013) |
Yeah it's pretty crazy. I logged in at lunch to make sure I isn't broke. They didn't get me! I try to keep gil on retainers, but I stop spending once my chacater's $$ falls below a certain threshold. I have to retrieve $$ from the retainers when that happens lol. |
Author: | Shiroken [ Fri Nov 08, 2013 3:17 pm ] |
Post subject: | Re: Server Hack (11/08/2013) |
If I lost the 50k I didn't have in retainers its probably less time consuming and less of hassle to just go farm for it back haha |
Author: | Ridere [ Fri Nov 08, 2013 3:43 pm ] |
Post subject: | Re: Server Hack (11/08/2013) |
You know... Whenever I hit a certain "new milestone" of gil, I generally make a rule to myself that I won't dip below that amount. I should probably just start keeping it on my retainer now. Out of sight, out of mind kind of thing. |
Author: | Kluya [ Fri Nov 08, 2013 3:55 pm ] |
Post subject: | Re: Server Hack (11/08/2013) |
I think i'm gonna do the same lol. It's like keeping it in a savings account irl. Every new milestone, just dump that $$ on a retainer and keep 50-100k on your main for teleports and other b.s. |
Author: | Ketrebu [ Sat Nov 09, 2013 8:50 am ] |
Post subject: | Re: Server Hack (11/08/2013) |
FYI, don't know how legit it is, but there are reports (and screenshots) of a variant of this hack still working. Something to do with the hacker opening a trade window with you (which you can't block), probably to obtain your player/session ID or something. It's not safe to be carrying gil or be in a zone with a market board. Put your gil on a retainer. |
Author: | Yarr [ Sat Nov 09, 2013 9:32 am ] |
Post subject: | Re: Server Hack (11/08/2013) |
Sounds good, im only going to carry 100k gil on me... |
Page 1 of 1 | All times are UTC - 5 hours |
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group http://www.phpbb.com/ |