Page 5 of 14 FirstFirst ... 3 4 5 6 7 ... LastLast
Results 41 to 50 of 132
  1. #41
    Player
    One_Time's Avatar
    Join Date
    Sep 2013
    Posts
    91
    Character
    The Gibbs
    World
    Famfrit
    Main Class
    Goldsmith Lv 84
    Excellent info. I will begin work on a new application with this information you provided.
    (0)

  2. #42
    Player
    Join Date
    Mar 2011
    Posts
    4,948
    Ask Reinhart just how much more gets posted in the JP threads from the devs than the English ones, looking over everything he's translated we get about 1 post for every 3 they get even though we have the exact same topics over here(some of which are just as high profile to all countries and not just Japan).
    That's just because the devs speak japanese, so it's much easier for them to communicate. That does NOT however mean that stuff doesn't get read on the NA forums nor does it mean that our excellent community reps don't communicate any of our concerns to them.
    (4)

  3. #43
    Player
    Ebon_Drake's Avatar
    Join Date
    Sep 2013
    Posts
    179
    Character
    Ebon Drake
    World
    Zalera
    Main Class
    Archer Lv 50
    Why hack anyone? Just look at your session ID and then using some common sense write an application that generates random session IDs and tests them against the server for validity reporting back which ones are good.

    Seems apple got into trouble with this a while back and whomever discovered it got in a load of trouble if I recall.

    SE Fix this please.
    (3)

  4. #44
    Player
    TaranTatsuuchi's Avatar
    Join Date
    Oct 2011
    Posts
    1,462
    Character
    Aryn Tatsuuchi
    World
    Balmung
    Main Class
    Samurai Lv 90
    Wow, Yeah gotta agree, this needs fixed fast.

    Quote Originally Posted by Eekiki View Post
    Was not expecting to see a link to my post in here... XD
    (2)

  5. #45
    Player
    Ladon's Avatar
    Join Date
    Aug 2012
    Posts
    570
    Character
    Resa Nome
    World
    Hyperion
    Main Class
    Paladin Lv 90
    Quote Originally Posted by Ebon_Drake View Post
    Why hack anyone? Just look at your session ID and then using some common sense write an application that generates random session IDs and tests them against the server for validity reporting back which ones are good.

    Seems apple got into trouble with this a while back and whomever discovered it got in a load of trouble if I recall.

    SE Fix this please.
    Because session IDs are 32 hex digit GUIDs with 2^128 possible combinations. Good luck finding an active one especially since the server isn't going to let you check them at any kind of reasonable rate.
    (0)

  6. #46
    Player
    Ebon_Drake's Avatar
    Join Date
    Sep 2013
    Posts
    179
    Character
    Ebon Drake
    World
    Zalera
    Main Class
    Archer Lv 50
    Quote Originally Posted by Ladon View Post
    Because session IDs are 32 hex digit GUIDs with 2^128 possible combinations. Good luck finding an active one especially since the server isn't going to let you check them at any kind of reasonable rate.
    my point is it's not impossible.

    How long does it take 20 people, 50 people, 100 people trying this method from as many computers before hitting on 1 valid ID that doesn't belong to them. Are you suggesting that since it took so long to get one ID that it's ok? Is it fair to the person whose account they stole?

    It shouldn't be possible at all.
    (2)

  7. #47
    Player
    Ladon's Avatar
    Join Date
    Aug 2012
    Posts
    570
    Character
    Resa Nome
    World
    Hyperion
    Main Class
    Paladin Lv 90
    Quote Originally Posted by Ebon_Drake View Post
    my point is it's not impossible.

    How long does it take 20 people, 50 people, 100 people trying this method from as many computers before hitting on 1 valid ID that doesn't belong to them. Are you suggesting that since it took so long to get one ID that it's ok? Is it fair to the person whose account they stole?

    It shouldn't be possible at all.
    How long? Uh, many, many years. I don't think you realize the magnitude of the probability we are talking about here. Do you realize how many of the 2^128 GUIDs are actually active at the moment? What a million at the very very most? That's a .000000000000001% chance you are going to hit an active GUID.

    Social engineering people into giving you their credentials is going to be far more successful then trying to brute force a 32 digit HEX GUID.
    (2)

  8. #48
    Player
    Ebon_Drake's Avatar
    Join Date
    Sep 2013
    Posts
    179
    Character
    Ebon Drake
    World
    Zalera
    Main Class
    Archer Lv 50
    Quote Originally Posted by Ladon View Post
    How long? Uh, many, many years. I don't think you realize the magnitude of the probability we are talking about here. Do you realize how many of the 2^128 GUIDs are actually active at the moment? What a million at the very very most? That's a .000000000000001% chance you are going to hit an active GUID.

    Social engineering people into giving you their credentials is going to be far more successful then trying to brute force a 32 digit HEX GUID.
    Well I guess we're safe then, whew.. That's a load of my back.
    (0)

  9. #49
    Player
    Fahzewn's Avatar
    Join Date
    Aug 2013
    Posts
    42
    Character
    Fahzewn Jukuren
    World
    Adamantoise
    Main Class
    Lancer Lv 58
    Quote Originally Posted by Livilda View Post
    Twelvedamn. I can't really think of any other game with such a huge security hole. I'll have to try playing around with this myself when I get home.
    Rift was bad for the first month or so. Same thing like this one...a player found it and explained it. They were bypassing the Log-In screen pretty much as well.
    (2)
    ...and it's a fact, that the ones actually fighting, are never perceived as being tainted.

  10. #50
    Player
    Tsukki's Avatar
    Join Date
    Feb 2012
    Location
    Uldah
    Posts
    21
    Character
    Tsukki Zakki
    World
    Sargatanas
    Main Class
    Conjurer Lv 50
    wow....... yeah this is bad... very bad... This needs to be sorted out asap, like right now! *bump*
    (0)

Page 5 of 14 FirstFirst ... 3 4 5 6 7 ... LastLast