Hackers In Nexon Database
thread starter xbowman22222 Sep 16 2010
+ PM | QUOTE | PERMALINK | REPORT
| Hey Basil, As many of you know, people are saying that the nexon database has been breached by some hackers. and so when you change your password or login you could be hacked. and i have been a victim of this ); haha i was just wondering if they still have access to the database? and seeing if i can start my bucc again and not be hacked Lol |
My Characters: LetsPee - 123 Windia Buccaneer
Knox 09/16/10
+ PM | QUOTE | PERMALINK | REPORT
| ive beeen going on the website like 10 times and been charging cash and i've havent been hacked ._. |
My Characters: FlashJin - 72 Bera Dragon Knight
Piymonk 09/16/10
+ PM | QUOTE | PERMALINK | REPORT
| I'm guessing these are rumors. Nexon claims that even they do not have access to your information, as it is encrypted. The question is, "How hard to crack is their encryption?" |
My Characters: TheFrozenSky - 51 Broa Aran in Memory
Cinos11
+ PM | QUOTE | PERMALINK | REPORT
| [quote] myrdrex : I mean this with no disrespect, but that makes no sense whatsoever from a technical perspective. "Breeching a database" is completely unrelated to someone changing their PIN/PW. A database stores data. If they have access to this, they would know what everyone's PW/PIN is right now! In fact, changing your PW/PIN woud be the safest thing you could possibly do (assuming it was a 1 time breech). Go ahead and use a packet sniffer and look at the traffic that is exchanged between your browser and Nexon's servers when you issue a password reset request. It's all going to nexon.net, there's no 3rd party involved. If you're somehow implying that some professional hacker has DNS-spoofed a childrens game, that's insane. And that's the only thing that would explain a PW/PIN reset giving someone access- not some silly "Database breech". [/quote] Well, that's not entirely true. Most database administrators code a form of encryption to encrypt the passwords within the database. So, the password, pic, and so on can not be unencrypted unless you have the original password which is used to unencrypt, then verify that there the same words. |
My Characters: Cinos11 - 122 Scania Night Lord
kanyewest95 09/16/10
+ PM | QUOTE | PERMALINK | REPORT
| Just befriend me on maple and ill loan you a white fangz to get back on your feet :o |
My Characters: TheBig21 - 108 Windia Marauder
xbowman22222 09/16/10
+ PM | QUOTE | PERMALINK | REPORT
| [quote] Knox : ive beeen going on the website like 10 times and been charging cash and i've havent been hacked ._. [/quote] are there items worth taking on your account? |
My Characters: LetsPee - 123 Windia Buccaneer
mochaalatte 09/16/10
+ PM | QUOTE | PERMALINK | REPORT
| I recently changed my pass AND pin, so if it is true, they thought my account was worthless or missed me. So they probably don't exist. |
My Characters: sirotherguy - 40 Bellocan Gunslinger
DrBrandy 09/16/10
+ PM | QUOTE | PERMALINK | REPORT
| I've never heard of this, but it's pretty scary sounding. |
Cinos11 09/16/10
+ PM | QUOTE | PERMALINK | REPORT
| [quote] xbowman22222 : are there items worth taking on your account? [/quote] By the way, you do realize. That by changing your password, and you have a keylogger. You will get hacked. (This is another theoretical likely situation) |
My Characters: Cinos11 - 122 Scania Night Lord
jokston 09/16/10
+ PM | QUOTE | PERMALINK | REPORT
 | danger danger mr robinson. danger . the database had been breeched! danger |
My Characters: SinusAttck - 25 Broa Aran Awakened
myrdrex
+ PM | QUOTE | PERMALINK | REPORT
| [quote] Cinos11 : Well, that's not entirely true. Most database administrators code a form of encryption to encrypt the passwords within the database. So, the password, pic, and so on can not be unencrypted unless you have the original password which is used to unencrypt, then verify that there the same words. [/quote] Regardless of whether you're using a salted hash or not, access to a DB is irrelevant, since we're talking about them still needing access to capture the traffic (username/PW) the user types at nexon.net. That's not happening. Just fire up your favorite tool like charles, fiddler, or dozens of others. Look at the traffic as you enter and change your password. It's nothing to anything except Nexon.net. If someone's successfully spoofed Nexon.net on the worlds leading domain controllers, they are far too professional to waste their time with a silly kids game. The real answer is that people were keylogged through malware on their machine, not by Nexon, but by their own unfortunate actions. |
My Characters: ulgarbosnot - 50 Scania Aran in Memory
Taichikara 09/16/10
+ PM | QUOTE | PERMALINK | REPORT
| Heard too many stories about this happening. Suffice it to say... I'm not changing my pw until it gets fixed. o.o; |
My Characters: Hatunave - 160 Windia Evan 1st Growth
KayFour 09/16/10
+ PM | QUOTE | PERMALINK | REPORT
| If they had db access, no need to take stuff from others when you could give to yourself. Think about what you are posting before you post it. |
My Characters: LaKaynu - 77 Windia Blade Specialist
xbowman22222 09/16/10
+ PM | QUOTE | PERMALINK | REPORT
| [quote] kanyewest95 : Just befriend me on maple and ill loan you a white fangz to get back on your feet :o [/quote] Thankss but ive been mercahnting and got some equips i could use(; and theres no way i could of gotten keylogged i dont go on sketchy websitess and i just got a new hp mini |
My Characters: LetsPee - 123 Windia Buccaneer
kanyewest95 09/16/10
+ PM | QUOTE | PERMALINK | REPORT
| xbowman22222 oho i see u could still bl me xD |
My Characters: TheBig21 - 108 Windia Marauder
Cinos11 09/16/10
+ PM | QUOTE | PERMALINK | REPORT
| [quote] myrdrex : Regardless of whether you're using a salted hash or not, access to a DB is irrelevant, since we're talking about them still needing access to capture the traffic (username/PW) the user types at nexon.net. That's not happening. Just fire up your favorite tool like charles, fiddler, or dozens of others. Look at the traffic as you enter and change your password. It's nothing to anything except Nexon.net. If someone's successfully spoofed Nexon.net on the worlds leading domain controllers, they are far too professional to waste their time with a silly kids game. The real answer is that people were keylogged through malware on their machine, not by Nexon, but by their own unfortunate actions. [/quote] I know, I'm just replying to the "If you access the DB you get the pic/passwords immediately" which is false. As for the keylogger/malware, i already stated that above as another theoretical possibility for being hacked. |
My Characters: Cinos11 - 122 Scania Night Lord
BasilMarket is Copyright 2004-2008 BasilMarket.com (archive reconstruction). Data recovered from the Internet Archive Wayback Machine for the Classic MapleStory community.