In this thread people who can't potato.

In this thread people who can't potato.
What I don't understand is this part..
I was able to give only an old, supposed to be expired, session ID to a friend and they were able to log into my account and characters from an entirely different location in the world. I did not provide an account name, password, or one time password.
How exactly did his friend log into the account without account name and password?
the session id is tied to the account, so if you have the session ID, it thinks you're the other person.What I don't understand is this part..
I was able to give only an old, supposed to be expired, session ID to a friend and they were able to log into my account and characters from an entirely different location in the world. I did not provide an account name, password, or one time password.
How exactly did his friend log into the account without account name and password?
Using the session ID & the command line, you login without the launcher, thus no password, account name or token needed- just the session ID.
http://forum.square-enix.com/ffxiv/t...=1#post1390622
That is where the session ID comes into play. The launcher invokes the game client by executing ffxiv.exe with extra command line parameters. It appends DEV.TestSID=xxxx, where xxx is the session ID, to the launch command. Here is the issue with that. That session ID is now plainly visible with any basic process inspector such as Microsoft's Process Explorer. This means it is incredibly easy for any virus that is on the computer to obtain the information. This also means it is possible to bypass the launcher to load the game client by just repeating the same command at the command line.
An interesting thing I noticed since the latest patch is that now I am getting a 90k error followed by "authentification failed" one, forcing me to close the client. I seem to not be the only one, see discussion thread here.
The reason why I'm posting here is, does anyone think they might have implemented a session ID timeout but it's not working as intended? The timespan between those kicks seems to be around 4 hours for me. Maybe the session expires despite having a valid connection?
[ AMD Phenom II X4 970BE@4GHz | 12GB DDR3-RAM@CL7 | nVidia GeForce 260GTX OC | Crucial m4 SSD ]

SE you need to fix this. This is a freaking security hole.
Yeah, good luck with getting an official support response. All I ever see are Forum Moderators apologizing for their ineptitude.
|
|
![]() |
![]() |
![]() |
|
|
Cookie Policy
This website uses cookies. If you do not wish us to set cookies on your device, please do not use the website. Please read the Square Enix cookies policy for more information. Your use of the website is also subject to the terms in the Square Enix website terms of use and privacy policy and by using the website you are accepting those terms. The Square Enix terms of use, privacy policy and cookies policy can also be found through links at the bottom of the page.
Reply With Quote









