The gil was on my character when it happened. Happened at Limsa Lominsa Lower Decks - Hawker Alley. My retainers were unaffected.
Here's my screenshots. (I'm the person in post #12)
Here I am, trying to run to my retainer to save my remaining gil. (And you can see the "Insufficient Gil" message on top)
Here's the history I saw after trying to save remaining gil. Couldn't find the retainer who sold the Antidote but I found the retainer selling the Allagan Tin pieces.
I sent in-game reports / gm-calls and there have been no responses so far. I can send them the original screenshots with chat (timestamps included) from the time I logged in. I was actually busy melding the gear I was supposed to spiritbond while chatting with friend so I didn't notice the purchase message. Only noticed its when I opened my inventory and saw the Allagan tin piece go in I immediately looked at my gil and was like ... !@#$@ .
My theory is packet sniffing for Buyer IDs and other details, followed by Buyer ID spoofing for the sales. Limsa seems to be the main target for this, simply because the Aetherye being in the same zone as the Market Board provides a large amount of traffic that can be caught.
www.eikon-guild.com
Not trying to be smart or something, but i think this exploit happened due to the way the packet sent to the server is structured.
A packet to purchase an item off the board could contain the following
- Buyer ID
- Seller ID
- Item ID
If the hacker could edit the data within the Buyer ID before sending it to the server, I think the server would perceive it as the victim himself who sent the packet to the server to purchase the items instead. Hence, the player purchased the items automatically without even being near the market board.
Wtf is going on? This is madness!
http://www.animeotakus.org/image/anime/1404/because-skill-brings-knife-gun-fight-wins-anyway-blade-and-s-anime-otakus-1398098083.jpg
Login to share my experience.
Insufficient Gil keeps appearing on my screen while I am crafting near the "Market board". It happened maybe 2 hrs before.
Luckily that.. I have all my gil on retainers
this just happened to me as well, was chatting with a friend in limsa while crafting
Time: Between 11:00 - 11:39 am (PST)
Frequency: Once
World name: Behemoth
Character name: Cass Tristesse
NPC name: Market Board
Area and coordinates: Limsa Lominsa Lower Decks 12x 13y
Steps:
1. was crafting some armorsmith, then a friend came by and we chatted
2. during the conversation was seeing "insufficient gil" msg on my screen, didnt know what it was
3. went to summoner's bell to get some materials to make some stuff for my friend
4. then went back and got this msg that i bought a braised pipira
5. looked at the market board and saw my history that i bought it for 1 million gil =(, I was nowhere near the marketboard.
Goal: hopefully to recover my lost 1 million gil
However, if my theory is right, then nobody is safe in the server as long as the hacker has your ID. Logging out would be the safest option.Not trying to be smart or something, but i think this exploit happened due to the way the packet sent to the server is structured.
A packet to purchase an item off the board could contain the following
- Buyer ID
- Seller ID
- Item ID
If the hacker could edit the data within the Buyer ID before sending it to the server, I think the server would perceive it as the victim himself who sent the packet to the server to purchase the items instead. Hence, the player purchased the items automatically without even being near the market board.
Cookie Policy
This website uses cookies. If you do not wish us to set cookies on your device, please do not use the website. Please read the Square Enix cookies policy for more information. Your use of the website is also subject to the terms in the Square Enix website terms of use and privacy policy and by using the website you are accepting those terms. The Square Enix terms of use, privacy policy and cookies policy can also be found through links at the bottom of the page.