Excellent info. I will begin work on a new application with this information you provided.
Excellent info. I will begin work on a new application with this information you provided.
That's just because the devs speak japanese, so it's much easier for them to communicate. That does NOT however mean that stuff doesn't get read on the NA forums nor does it mean that our excellent community reps don't communicate any of our concerns to them.Ask Reinhart just how much more gets posted in the JP threads from the devs than the English ones, looking over everything he's translated we get about 1 post for every 3 they get even though we have the exact same topics over here(some of which are just as high profile to all countries and not just Japan).
Why hack anyone? Just look at your session ID and then using some common sense write an application that generates random session IDs and tests them against the server for validity reporting back which ones are good.
Seems apple got into trouble with this a while back and whomever discovered it got in a load of trouble if I recall.
SE Fix this please.
Wow, Yeah gotta agree, this needs fixed fast.
Was not expecting to see a link to my post in here... XDHard not to when I've seen it with my own eyes.
Because session IDs are 32 hex digit GUIDs with 2^128 possible combinations. Good luck finding an active one especially since the server isn't going to let you check them at any kind of reasonable rate.Why hack anyone? Just look at your session ID and then using some common sense write an application that generates random session IDs and tests them against the server for validity reporting back which ones are good.
Seems apple got into trouble with this a while back and whomever discovered it got in a load of trouble if I recall.
SE Fix this please.
my point is it's not impossible.
How long does it take 20 people, 50 people, 100 people trying this method from as many computers before hitting on 1 valid ID that doesn't belong to them. Are you suggesting that since it took so long to get one ID that it's ok? Is it fair to the person whose account they stole?
It shouldn't be possible at all.
How long? Uh, many, many years. I don't think you realize the magnitude of the probability we are talking about here. Do you realize how many of the 2^128 GUIDs are actually active at the moment? What a million at the very very most? That's a .000000000000001% chance you are going to hit an active GUID.my point is it's not impossible.
How long does it take 20 people, 50 people, 100 people trying this method from as many computers before hitting on 1 valid ID that doesn't belong to them. Are you suggesting that since it took so long to get one ID that it's ok? Is it fair to the person whose account they stole?
It shouldn't be possible at all.
Social engineering people into giving you their credentials is going to be far more successful then trying to brute force a 32 digit HEX GUID.
Well I guess we're safe then, whew.. That's a load of my back.How long? Uh, many, many years. I don't think you realize the magnitude of the probability we are talking about here. Do you realize how many of the 2^128 GUIDs are actually active at the moment? What a million at the very very most? That's a .000000000000001% chance you are going to hit an active GUID.
Social engineering people into giving you their credentials is going to be far more successful then trying to brute force a 32 digit HEX GUID.

Rift was bad for the first month or so. Same thing like this one...a player found it and explained it. They were bypassing the Log-In screen pretty much as well.
...and it's a fact, that the ones actually fighting, are never perceived as being tainted.

wow....... yeah this is bad... very bad... This needs to be sorted out asap, like right now! *bump*
|
|
![]() |
![]() |
![]() |
|
|
Cookie Policy
This website uses cookies. If you do not wish us to set cookies on your device, please do not use the website. Please read the Square Enix cookies policy for more information. Your use of the website is also subject to the terms in the Square Enix website terms of use and privacy policy and by using the website you are accepting those terms. The Square Enix terms of use, privacy policy and cookies policy can also be found through links at the bottom of the page.

Reply With Quote






