Major Rift Account Security Exploit Found, Fixed menu

User Tag List

Page 1 of 2 12 LastLast
Results 1 to 15 of 18
  1. #1
    argh44z's Avatar Member
    Reputation
    19
    Join Date
    Nov 2007
    Posts
    93
    Thanks G/R
    0/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Major Rift Account Security Exploit Found, Fixed

    Looks like there was a major hole in how Rift authentication worked, which was exploited by many gold sellers, and as a result MANY people got hacked. It basically allowed people to login as any other account w/o knowing password or email details. A guy on the rift forums independently found what the exploit was:
    Account Security Discussion

    (it looks like it was some kind of man in the middle attack)

    Looks the hole was fixed with the emergency client/server update tonight:
    Account Security Discussion
    Account Security Discussion

    Major Rift Account Security Exploit Found, Fixed
  2. #2
    cdmichaelb's Avatar Contributor CoreCoins Purchaser
    Reputation
    119
    Join Date
    Jan 2011
    Posts
    368
    Thanks G/R
    21/5
    Trade Feedback
    7 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    They needed email address to log in basically?

  3. #3
    argh44z's Avatar Member
    Reputation
    19
    Join Date
    Nov 2007
    Posts
    93
    Thanks G/R
    0/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Nope - they didn't need your email OR password. In Rift's authentication method, internally there is a accountID associated with each account (look at C:\Users\<username>\AppData\Local\Temp\tkt*.tmp) that look like random numbers between 1 and a few million. The hackers went through random IDs until they found one that worked, performed the exploit, and were able to be authenticated and clean out the users.

    Good that they fixed it so quickly, it would have probably cost them a lot more accounts if it hadn't been discovered and fixed quickly.

  4. #4
    Deviltry1's Avatar Private
    Reputation
    0
    Join Date
    Feb 2010
    Posts
    5
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    DDDDDDDDDDDD

    And you expect this company to make a worthwile MMO? ) SERIOUSLY!

  5. #5
    akiyar's Avatar Private
    Reputation
    18
    Join Date
    Apr 2010
    Posts
    14
    Thanks G/R
    1/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Deviltry1 View Post
    DDDDDDDDDDDD

    And you expect this company to make a worthwile MMO? ) SERIOUSLY!
    They contacted the guy who found it within an hour and a patch was released that same day to plug the hole AND fix some other issues that can arise if you get hacked. That is pretty damn good if you ask me. It was pretty stupid but it happens and at least they don't try to cover it up and wait to do something about it.

  6. #6
    argh44z's Avatar Member
    Reputation
    19
    Join Date
    Nov 2007
    Posts
    93
    Thanks G/R
    0/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Deviltry1 View Post
    DDDDDDDDDDDD

    And you expect this company to make a worthwile MMO? ) SERIOUSLY!
    They've already made a pretty good one.

    Major banks and even governmental institutions have had breaches like this in the past. Adobe and Microsoft are continually plugging holes in Flash and Windows. Security is tough, and the fact that they fixed this within hours is pretty impressive.

    Hell, the standard of the authenticator industry, RSA SecurID authenticators got recently breached a few days ago:
    http://en.wikipedia.org/wiki/SecurID...tem_Compromise
    Last edited by argh44z; 03-19-2011 at 12:33 PM.

  7. #7
    Narugold's Avatar Sergeant Major

    Reputation
    49
    Join Date
    Apr 2010
    Posts
    143
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Deviltry1 View Post
    DDDDDDDDDDDD

    And you expect this company to make a worthwile MMO? ) SERIOUSLY!

    Remember the whiptail respawn bug?
    Whiptails are still in the 30-70g on my server.
    Economy = Wrecked.

    Nice to see that Blizzard is such a better company

  8. #8
    Deviltry1's Avatar Private
    Reputation
    0
    Join Date
    Feb 2010
    Posts
    5
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Narugold View Post
    Remember the whiptail respawn bug?
    Whiptails are still in the 30-70g on my server.
    Economy = Wrecked.

    Nice to see that Blizzard is such a better company
    At least they have real raids, real PvP content, real quests, real class designs.

    Valor in PvP doesn't work, Armor in PvP doesn't work (at least for warriors, which are the main physical damage source in warfronts at 50), grey weapon or epic weapon - scaling doesn't work, strength basicly useless for warriors - intended plate wearing and str stacking doesn't work.

    But what do we have? Crappy BG design where you go 10+ vs 10+ most of the time - no skill, just a zergfest, as you cannot track that much cooldowns, you just go in blindly and hope for the ebst - check.
    Great talent system, where you AGAIN go blindly, take EVERY GOD DAMN TALENT IN THE TREE and KICK ASS - check.
    and so on

  9. #9
    cdmichaelb's Avatar Contributor CoreCoins Purchaser
    Reputation
    119
    Join Date
    Jan 2011
    Posts
    368
    Thanks G/R
    21/5
    Trade Feedback
    7 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Are you seriously crying about warrior? The most powerful class when it comes to pvp or pve?

    Obviously you don't know the game rift at all, probably played it to level 7 with a retarded spec and soul combination and decided it sucked and logged off.
    Last edited by cdmichaelb; 03-20-2011 at 06:48 AM.

  10. #10
    argh44z's Avatar Member
    Reputation
    19
    Join Date
    Nov 2007
    Posts
    93
    Thanks G/R
    0/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Deviltry1 View Post
    At least they have real raids, real PvP content, real quests, real class designs.
    I disagree with you that Rift doesn't have all those things. However, I played WoW since beta (it started losing its luster for me in early wotlk and I've been cancelling/resubbing on and off since). Rift at the moment is far far far better than WoW was at this point in it's history. It's a new game, and a promising one at that.

  11. #11
    Esset's Avatar Member
    Reputation
    8
    Join Date
    Mar 2007
    Posts
    285
    Thanks G/R
    1/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Deviltry1 View Post
    Crappy BG design where you go 10+ vs 10+ most of the time - no skill, just a zergfest
    ^ This, can't stop laughing! Tell me one BG in WoW that ain't a zergfest, I beg you!

  12. #12
    cl3ver's Avatar Site Donator
    Reputation
    2
    Join Date
    Sep 2006
    Posts
    27
    Thanks G/R
    1/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Rift Launch > WoW launch

    Go back to the WoW forums Deviltry.

  13. #13
    sol82's Avatar Banned
    Reputation
    20
    Join Date
    Feb 2007
    Posts
    428
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Rift is better than WoW, Deviltry. Get over it. Besides, every single thing you said was completely wrong.

    Wait...you're from Lotham, aren't you...

  14. #14
    zubzero's Avatar Member
    Reputation
    3
    Join Date
    Dec 2007
    Posts
    28
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    These are 2 different games some people like rift some still like wow.. thats it.

    You dont have to fight for "ur" game.. its stupid.

  15. #15
    StupidDog's Avatar Private
    Reputation
    1
    Join Date
    Mar 2011
    Posts
    13
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Pay no attention guys, he's just pissed because there are only 4 people left in wow for him to play with.

Page 1 of 2 12 LastLast

Similar Threads

  1. Mount Hyjal 1st boss Exploit found, or is it ?
    By Evilcookie in forum World of Warcraft Exploits
    Replies: 24
    Last Post: 04-15-2008, 11:49 PM
  2. A very interesting account scam I found, but I want the program!
    By kemalraik in forum WoW Scam Prevention
    Replies: 13
    Last Post: 01-18-2008, 12:16 AM
  3. Account Security
    By PerplexityAoS in forum World of Warcraft General
    Replies: 1
    Last Post: 12-27-2007, 11:59 AM
  4. WSG exploit alliance fix
    By 0mats0 in forum World of Warcraft Exploits
    Replies: 3
    Last Post: 12-28-2006, 02:36 PM
All times are GMT -5. The time now is 08:19 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search