Discussion about account security

General discussion and socializing.

Discussion about account security

Postby VikingWarrior » Fri Jun 17, 2016 11:50 pm

Hello, right now i am on a account which is not mine. [This one i'm posting with right now] I didn't know it was so freaking simple to hack a account on this website haha. Now, the way i did it boys and girls was with "Sentry mba" Look it up if you are wondering what kind of program it is.

Here are the information about the account.

Username:VikingWarrior Password:youbeenhacked

Village name: Asylium [Which it was part of]
Last edited by Granger on Tue Jun 21, 2016 6:30 am, edited 2 times in total.
Reason: Title changed to reflect the contents
VikingWarrior
 
Posts: 43
Joined: Fri Dec 30, 2011 1:31 am

Re: I have hacked this account! <3

Postby shubla » Fri Jun 17, 2016 11:54 pm

I am not surprised that security of HnH is not the best..
But how did you get him password? Did you actually get it through some cool haxor ways or did you just "scam" it?
Or maybea the account was originally yours.
Image
I'm not sure that I have a strong argument against sketch colors - Jorb, November 2019
http://i.imgur.com/CRrirds.png?1
Join the moderated unofficial discord for the game! https://discord.gg/2TAbGj2
Purus Pasta, The Best Client
User avatar
shubla
 
Posts: 13041
Joined: Sun Nov 03, 2013 11:26 am
Location: Finland

Re: I have hacked this account! <3

Postby sabinati » Sat Jun 18, 2016 12:05 am

Credential stuffing is the automated injection of breached username/password pairs in order to fraudulently gain access to user accounts. This is a subset of the brute force attack category: large numbers of spilled credentials are automatically entered into websites until they are potentially matched to an existing account, which the attacker can then hijack for their own purposes.
User avatar
sabinati
 
Posts: 15513
Joined: Mon Jul 13, 2009 4:25 am
Location: View active topics

Re: I have hacked this account! <3

Postby shubla » Sat Jun 18, 2016 12:09 am

sabinati wrote:Credential stuffing is the automated injection of breached username/password pairs in order to fraudulently gain access to user accounts. This is a subset of the brute force attack category: large numbers of spilled credentials are automatically entered into websites until they are potentially matched to an existing account, which the attacker can then hijack for their own purposes.

Devs should really do something to security such as:
Changing password or email should be made impossible without confirmation from current mail.
Also somekind of "maxium of 5 logon attempts in x amount of time". Maybe evenCAPTCHAS. Of course some may say that captchas are not helping, because theres lot of services that will solve them for few pennies. But some captcha is better than no captcha. It would perhaps reduce the amount of attempts. Maybe re captcha could be required on each logon attempt. In my user side experience they arent much of a hassle. Of course something like that would have to be implemented in client as well..
Captchas would atleast make people feel a bit safer.
Image
I'm not sure that I have a strong argument against sketch colors - Jorb, November 2019
http://i.imgur.com/CRrirds.png?1
Join the moderated unofficial discord for the game! https://discord.gg/2TAbGj2
Purus Pasta, The Best Client
User avatar
shubla
 
Posts: 13041
Joined: Sun Nov 03, 2013 11:26 am
Location: Finland

Re: I have hacked this account! <3

Postby sabinati » Sat Jun 18, 2016 12:16 am

the main point is don't use the same account name and password on multiple sites, at least for this method of attack.
User avatar
sabinati
 
Posts: 15513
Joined: Mon Jul 13, 2009 4:25 am
Location: View active topics

Re: I have hacked this account! <3

Postby loftar » Sat Jun 18, 2016 12:21 am

VikingWarrior wrote:Sentry mba

So what you're saying is that you got his username and password via external means? Not sure what you'd expect this website to do against that.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9051
Joined: Fri Apr 03, 2009 7:05 am

Re: I have hacked this account! <3

Postby shubla » Sat Jun 18, 2016 12:21 am

loftar wrote: Not sure what you'd expect this website to do against that.

Please add some more security on changing password/email atleast.
Image
I'm not sure that I have a strong argument against sketch colors - Jorb, November 2019
http://i.imgur.com/CRrirds.png?1
Join the moderated unofficial discord for the game! https://discord.gg/2TAbGj2
Purus Pasta, The Best Client
User avatar
shubla
 
Posts: 13041
Joined: Sun Nov 03, 2013 11:26 am
Location: Finland

Re: I have hacked this account! <3

Postby loftar » Sat Jun 18, 2016 12:24 am

shubla wrote:Changing password or email should be made impossible without confirmation from current mail.

This makes you lose your Haven account if you lose your e-mail account.

shubla wrote:Also somekind of "maxium of 5 logon attempts in x amount of time".

There were no failed login attempts; he knew the password from the outset.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9051
Joined: Fri Apr 03, 2009 7:05 am

Re: I have hacked this account! <3

Postby The_Blode » Sat Jun 18, 2016 12:24 am

shubla wrote:
loftar wrote: Not sure what you'd expect this website to do against that.

Please add some more security on changing password/email atleast.


if they add too much it becomes easy to get locked out of your own stuff. Extra security is great until you find yourself on the outside looking in wistfully at your account.
User avatar
The_Blode
 
Posts: 511
Joined: Sat Oct 08, 2011 7:51 am
Location: Location: Location

Re: I have hacked this account! <3

Postby bananza » Sat Jun 18, 2016 12:41 am

apx again..... omg..........


i hope you dont hack me becuase this account is a key to my ironic memes vault
Warning to mods: This post is mirror protected, so giving a warning/ or ban means you will be warned/banned by redirection.

GEX
User avatar
bananza
 
Posts: 203
Joined: Wed Sep 02, 2015 12:21 am
Location: GEX Headquarters

Next

Return to The Inn of Brodgar

Who is online

Users browsing this forum: Claude [Bot], Yandex [Bot] and 50 guests