AionSource.com - Powered by the Tower of Eternity: WTF? Security issues on NCSoft's website? - AionSource.com - Powered by the Tower of Eternity

Jump to content

  • (6 Pages)
  • +
  • 1
  • 2
  • 3
  • Last »
  • You cannot start a new topic
  • You cannot reply to this topic

WTF? Security issues on NCSoft's website? Rate Topic: -----

#1 User is offline   Allah Icon

  • Star Officer
  • PipPipPip
  • View blog
  • Group: Members
  • Posts: 353
  • Joined: 18-September 09
  • Legion:Auxium

Posted 17 December 2009 - 11:38 AM

I dont know if this has been brought up before but I just logged into my NCSoft master account, and when i pressed submit, the page refreshed and I was logged into ANOTHER account that wasn't mine............ I had full control over the account and could do as I please.. wtf is up with that?? lol.. I just logged out and logged into my account again but that was pretty freaking weird o.O
0

#2 User is offline   Ville Icon

  • Officer
  • PipPipPip
  • View blog
  • Group: Members
  • Posts: 135
  • Joined: 23-November 09
  • Character:Ville
  • Legion:None

Posted 17 December 2009 - 11:56 AM

Zhenocnra said:

Edited


I understand, or at least hope, you are being sarcastic but seriously man. Why would someone wanna do that? I love loser people that when they go to a library and see someone accidentally forgot to sign out of their e-mail go and send I hate you messages to everyone in their contact list.

Are there no people that can just do the right thing anymore?

This post has been edited by Celystine: 20 December 2009 - 05:37 AM

~~"I am fairly sure that if they took porn off the internet, there would only be one website left and it would be called bring back the porn.."
Dr. Cox
0

#3 User is offline   SirNiko Icon

  • Lieutenant
  • PipPipPipPip
  • Group: Members
  • Posts: 546
  • Joined: 28-October 09

Posted 17 December 2009 - 12:00 PM

This has been an issue for months.

This is a shame, too, because I find the ability to check legion status, view profiles, and check on mail from the browser to be tremendously helpful. I don't feel like I need to be logged into the game constantly to check on everything.

What browser are you using? I'm hitting it with Chrome. Perhaps it's not designed for other browsers?

-SirNiko
0

#4 User is offline   Malackai Icon

  • Officer
  • PipPipPip
  • View blog
  • Group: Members
  • Posts: 183
  • Joined: 22-April 08
  • Character:Mezra
  • Legion:Pwnage
  • Race :Asmodians
  • Server:Telemachus

Posted 17 December 2009 - 12:41 PM

I had the same a week back
i logged in on my account to check mail and broker status and after i logged there was a completely different character name that i dint own but after refreshing my page my own character appeared pretty creepy if you ask me ><
0

#5 User is offline   Zhenocnra Icon

  • General
  • PipPipPipPipPip
  • View blog
  • Group: Members
  • Posts: 990
  • Joined: 21-January 09

Posted 17 December 2009 - 12:43 PM

Malackai said:

I had the same a week back
i logged in on my account to check mail and broker status and after i logged there was a completely different character name that i dint own but after refreshing my page my own character appeared pretty creepy if you ask me ><


Pending MMORPG disaster.
Straight guys using homophobic insults to strengthen their masculinity.
[SIGPIC][/SIGPIC]
US Military at their finest... not; LOL!
0

#6 User is offline   Malackai Icon

  • Officer
  • PipPipPip
  • View blog
  • Group: Members
  • Posts: 183
  • Joined: 22-April 08
  • Character:Mezra
  • Legion:Pwnage
  • Race :Asmodians
  • Server:Telemachus

Posted 17 December 2009 - 12:44 PM

Zhenocnra said:

Pending MMORPG disaster.


XD

you think :plshelp:
0

#7 User is offline   Trublood Icon

  • Officer
  • PipPipPip
  • View blog
  • Group: Members
  • Posts: 117
  • Joined: 07-December 09
  • LocationFlorida
  • Character:Trueblood
  • Legion:The Grey Feather
  • Race :Elyos
  • Server:Lumiel

Posted 17 December 2009 - 12:47 PM

Same thing happened to me yesterday. Multiple times. It kept taking me to some Elyos Sorceror's page that was from the same server. I could access broker & post info and everything. I was like wtf??
FFXI-Ashleyflowers - Midgardsormr - 75 BLM BRD BLU WAR SAM


Aion - Trueblood - Lumiel Server
0

#8 User is offline   Senses Nonsense Icon

  • Soldier
  • PipPip
  • View blog
  • Group: Members
  • Posts: 75
  • Joined: 18-September 09

Posted 17 December 2009 - 12:59 PM

Zhenocnra said:

2.) It's not about people not doing the correct thing. It's about an MMORPG company having to deal with a problem like this on a continent-wide scale. It's about the curiosity of how NCSoft would react and countermeasure their problems they've created related to customer accounts.

Imagine if half if not more of World of Warcraft accounts in North America was lost/damaged beyond repair/stolen/blanket banned. I would assume every gaming site would be on their backs and they just might have a little press coverage.



So if I understand...

You want Aion to get bad press on a massive scale, and you're willing for thousands of people to have their accounts and playtime adversely affected just so that happens?

Really?
Sense & Nonsense
The Pretend Heroes
Igraine * Sargeras * Gareth * Iron Rock * Vaizel
0

#9 User is offline   Silvervain Icon

  • Star Officer
  • PipPipPip
  • View blog
  • Group: Members
  • Posts: 341
  • Joined: 20-August 08
  • Character:Zeba
  • Legion:Elysium

Posted 17 December 2009 - 01:28 PM

so this is how they are hacking accounts.

Liv said:

Everyone at the NCsoft West HQ pronounces it "eye-on"
0

#10 User is offline   Abraxus Icon

  • Officer
  • PipPipPip
  • View blog
  • Group: Members
  • Posts: 164
  • Joined: 14-October 08
  • Character:Abraxus
  • Legion:DemonLegion

Posted 17 December 2009 - 03:47 PM

HA! Notice how no one wants to post under "so this is how they are hacking accounts".

Maybe you're on to something...
0

#11 User is offline   Kyande Icon

  • Soldier
  • PipPip
  • View blog
  • Group: Members
  • Posts: 89
  • Joined: 12-October 09
  • Character:Kyande
  • Legion:Sedition

Posted 17 December 2009 - 03:56 PM

I've had that happen to me a couple of times. I back right out of whatever account I'm in and try again. Usually just one relog does it, but I've gotten stuck in some weird loop once.
0

#12 User is offline   Slang Icon

  • Officer
  • PipPipPip
  • View blog
  • Group: Members
  • Posts: 198
  • Joined: 12-September 09

Posted 17 December 2009 - 04:12 PM

I have noticed this multiple times, NCSoft really needs to fix this. No corporation should ever have a security flaw on their site. Most companies would have had this fixed the NEXT DAY if they knew about it. Very very poor management going on over there.
0

#13 User is offline   Zhenocnra Icon

  • General
  • PipPipPipPipPip
  • View blog
  • Group: Members
  • Posts: 990
  • Joined: 21-January 09

Posted 17 December 2009 - 04:15 PM

Slang said:

I have noticed this multiple times, NCSoft really needs to fix this. No corporation should ever have a security flaw on their site. Most companies would have had this fixed the NEXT DAY if they knew about it. Very very poor management going on over there.


Exactly. :skip::skip::skip:
Straight guys using homophobic insults to strengthen their masculinity.
[SIGPIC][/SIGPIC]
US Military at their finest... not; LOL!
0

#14 User is offline   Twilight Sky Icon

  • Great General
  • PipPipPipPipPipPip
  • View blog
  • Group: Members
  • Posts: 1452
  • Joined: 20-September 09
  • Server:Undecided

Posted 17 December 2009 - 04:18 PM

Yeah so, Ayase/Tiamat should look into this I guess.
0

#15 User is offline   Arwydd Icon

  • Officer
  • PipPipPip
  • View blog
  • Group: Members
  • Posts: 273
  • Joined: 23-November 09
  • Character:Vedu

Posted 17 December 2009 - 04:22 PM

They should. And yet they're utterly silent...
0

#16 User is offline   Lemons Icon

  • Officer
  • PipPipPip
  • View blog
  • Group: Members
  • Posts: 172
  • Joined: 17-September 08

Posted 17 December 2009 - 04:32 PM

Allah said:

I dont know if this has been brought up before but I just logged into my NCSoft master account, and when i pressed submit, the page refreshed and I was logged into ANOTHER account that wasn't mine............ I had full control over the account and could do as I please.. wtf is up with that?? lol.. I just logged out and logged into my account again but that was pretty freaking weird o.O


Hah, yeah I know what you mean. I recently logged in to add some CE items to my mess around alt and I was logged in under someone named like Juneberry or something, I forget. I could do anything I wanted, sorta weird but I just logged out and logged back in.
If god gives you lemons...
You find a new god.

Posted Image

Thanks for the spacer Cynic!!!1
0

#17 User is offline   Pluxus Icon

  • Officer
  • PipPipPip
  • Group: Members
  • Posts: 136
  • Joined: 14-October 09

Posted 17 December 2009 - 05:19 PM

I'm assuming with NCSoft master account you mean the one where you can completely control the account, like change password and cancel the sub and so on?

I got logged into a wrong aion acc on the aion-site just a few days ago, but the worst damage you can do there is sneak peak others mail and broker status, it's still seriously bad... but seriously, it happens with the master accounts also?! What kind of clowns do they have running this show?
It's simply unacceptable, any half-serious company, hell, **** that, even halfassed small community, completely free forums wouldn't allow bugs like that on their site for more than a hour after detection. Unfortunately, this would explain how accs of mmo/internet veterans that know how to protect their accounts and computers got hacked in the recent threads, since you can just change password on the master account site, they don't ask you for your old password when changing.

So get the bug, change password, voila, account taken over... if this is true that is. For NCSofts sake I hope it's not.
0

#18 User is offline   Vaelithian Icon

  • Soldier
  • PipPip
  • View blog
  • Group: Members
  • Posts: 64
  • Joined: 15-November 09

Posted 17 December 2009 - 07:52 PM

wow this is an incredibly volatile dilemma, having read threads and comments about recent accounts being hacked this would appear to be one of the more key sources of such an issue.

as an aside:

"Zenocnra said:

Edited.


no it is not. The distinction, useful for ethical considerations, would be between necessary and sufficient conditions. For this scenario it would be necessary for a person to leave the email open, but that alone would not suffice. The undue intent of another is necessary for misuse or untoward behaviour. The condition for learning the "most rewarding" way is (according to reasons given) ultimately dependent on understanding why something is a mistake, as such the hardest way is not strictly necessary either.

Quote

2.) It's not about people not doing the correct thing. It's about an MMORPG company having to deal with a problem like this on a continent-wide scale. It's about the curiosity of how NCSoft would react and countermeasure their problems they've created related to customer accounts.


for the issues and reasons given it is about NCSoft and individual responsibility. No need to dichotomise at the unnecessary expensive of others.

This post has been edited by Celystine: 20 December 2009 - 05:42 AM

0

#19 User is offline   Noriega Icon

  • Great General
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1570
  • Joined: 17-February 09
  • Character:Noriega
  • Legion:SiN (probably)
  • Server:Undecided

Posted 17 December 2009 - 08:17 PM

I thought they fixed that already.
0

#20 User is offline   Serefina Icon

  • Human
  • Pip
  • View blog
  • Group: Newbies
  • Posts: 2
  • Joined: 27-August 09
  • Character:Serefina

Posted 17 December 2009 - 11:10 PM

Had this happen to me as well. Logged in to Aion website, only to find that I was logged into someone's account. Also, they don't even encrypt the sign in. When you go to sign in, it's on an http site not an https. This is something that really needs fixed, and fast especially if this is also true of the NCSoft master account page.
0

  • (6 Pages)
  • +
  • 1
  • 2
  • 3
  • Last »
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users