Graal Forums

Graal Forums (https://forums.graalonline.com/forums/index.php)
-   Graal Main Forum (English) (https://forums.graalonline.com/forums/forumdisplay.php?f=4)
-   -   !Hacked Accounts! (https://forums.graalonline.com/forums/showthread.php?t=44466)

mhermher 04-24-2003 03:28 PM

!Hacked Accounts!
 
It shows that some accounts have been "hacked", including a friends account..

There was some guy who was advertising for a website about graal.. Please, unless you want your account hacked, i suggest do NOT go on ANY website that someone PM's you, i repeat.. DO NOT go on ANY website that someone masses/pms you! The site is sending your password to someones email!

This is my word, follow it or not, i have warned you.

Spark910 04-24-2003 03:37 PM

Well yesterday, unless you didnt know, there were about 50hackers on graal. And yes dont go to any forums/website.

Spark910 04-24-2003 03:59 PM

Quote:

Originally posted by Kaimetsu
It's impossible to make a site access your registry without having the user consent to run a program on his/her machine.
All they get off the site is IPs and they take it from there. Most people will give them passwords to email accounts without realsing it. And so they can re-email password change to get it.

Cynicism 04-24-2003 05:40 PM

If people aren't smart enough to avoid such threats, then tough luck I say. :\

Loriel 04-24-2003 06:13 PM

Quote:

Originally posted by Kaimetsu
It's impossible to make a site access your registry without having the user consent to run a program on his/her machine.
ActiveX :)


Quote:

Originally posted by Spark910
All they get off the site is IPs and they take it from there. Most people will give them passwords to email accounts without realsing it. And so they can re-email password change to get it.
You are saying that people can get other people's account's passwords by only knowing their IP address?
I seriously doubt that, as your IP is mostly send to other players while playing Graal.

Spark910 04-24-2003 06:51 PM

Quote:

Originally posted by Loriel

ActiveX :)



You are saying that people can get other people's account's passwords by only knowing their IP address?
I seriously doubt that, as your IP is mostly send to other players while playing Graal.

No not at all. I was refering to the email account passwords.

Loriel 04-24-2003 09:24 PM

Quote:

Originally posted by Spark910
No not at all. I was refering to the email account passwords.
Hm, then what do IPs have to do with that? And also, I still do not understand how they get email passes :)

magicbud3344 04-25-2003 12:51 AM

yes how the heck does an IP get you an email pass?
most forums have things where any moderator can see your IP address. they didn't put sup leet hacks into the caz forums to get it. when i was a mod at James's aquanetwork i could see people IP's....not that you can really do anything with IPs, besides ping the heck out of people, and i still don't know what that means eather XD

Loriel 04-25-2003 12:55 AM

Duh, the webserver itself logs the IPs. No need for a forum to do so :)

magicbud3344 04-25-2003 01:14 AM

so basicly any site you visit logs IPs :O?
also this is how they may be ahcking accounts.
you sign up for their forums, give them your e-mail then pick a password for the forums, if your like most people you use the same password as you do for e-mail?
then walla :X

Milkdude99 04-25-2003 01:48 AM

Quote:

Originally posted by magicbud3344
so basicly any site you visit logs IPs :O?
also this is how they may be ahcking accounts.
you sign up for their forums, give them your e-mail then pick a password for the forums, if your like most people you use the same password as you do for e-mail?
then walla :X

I use many differnt passwords for things , to keep the same password for many things is a good way to lose any and all your info about you if someone gains access to your comp. You really shouldn't use the same password on anything.

funnylinkwantsbomys 04-25-2003 03:22 AM

Quote:

Originally posted by Kaimetsu
It's impossible to make a site access your registry without having the user consent to run a program on his/her machine.
or they could code something in php to take your password :P

davidpsy 04-25-2003 03:43 AM

I had downloaded something off that somesite someone massed but I thought it was a hack. It did what it was supposta but I got rid of it anyway and changed my password. Also even if they did get my email password which I dought but if they did it wouldent matter because thats not the email address with which I made my account with.

nikoma5000 04-25-2003 04:33 AM

My account became hacked :(

HoudiniMan 04-25-2003 09:39 AM

Quote:

Originally posted by davidpsy
I had downloaded something off that somesite someone massed but I thought it was a hack. It did what it was supposta but I got rid of it anyway and changed my password. Also even if they did get my email password which I dought but if they did it wouldent matter because thats not the email address with which I made my account with.
You just admitted you downloaded and used a hack?...

Loriel 04-25-2003 11:45 AM

Quote:

Originally posted by Kaimetsu
Usually can't run without the user's permission.
Many people allow their browser's to run ActiveX stuff though. I read about a hacker club in Germany that demonstrated how to steal money from a bank account with it, and got in all kinds of newspapers.

Lyndzey 04-25-2003 02:09 PM

Don't worry about it, the few accounts that were "hacked" are from people who gave away their passwords. No one can hack your account unless you download a virus from them or give out your password.

Spark910 04-25-2003 02:22 PM

Quote:

Originally posted by magicbud3344
so basicly any site you visit logs IPs :O?
also this is how they may be ahcking accounts.
you sign up for their forums, give them your e-mail then pick a password for the forums, if your like most people you use the same password as you do for e-mail?
then walla :X

No its not that, if someone has a hotmail address, I can explain it, it may not work, but still.

melissa1988 04-25-2003 05:01 PM

Actually Kai, that's not true. Internet Explorer allows them to run automatically, and the average user is not smart enough to figure out how to turn them off, or at least make it prompt before allowing it. And if they do know how, they are too lazy to do it anyway.

funnylinkwantsbomys 04-25-2003 05:33 PM

Quote:

Originally posted by Kaimetsu


By default, my IE was set to prompt for signed and decline for unsigned. I don't know if other versions of Windows etc are any different.

it comes with prompt as default so people wont get a security risk and wont have their fav java applits ect not be able to run so its always on prompt to clear confusion

NPToita2 04-25-2003 08:52 PM

Going into Registry is not hard
 
All the person has to do is know alot about ASP. Include a function of one of the shells built in to your windows to retrieve that pass from your registry and Walla.

Loriel 04-25-2003 11:24 PM

Re: Going into Registry is not hard
 
Quote:

Originally posted by NPToita2
All the person has to do is know alot about ASP. Include a function of one of the shells built in to your windows to retrieve that pass from your registry and Walla.
You say ASP code run on some website I visit can get into my registry?

davidpsy 04-26-2003 12:58 AM

Quote:

Originally posted by HoudiniMan


You just admitted you downloaded and used a hack?...

No when I say I thought it was a hack I ment there was a sub 7 virus in the program to steal my password. This program is supposta change Gui Images for you in graal but I thought it might be a hack so I got rid of it.

ZanderX 04-26-2003 01:09 AM

Quote:

Originally posted by Kaimetsu


Maybe, but probably not the majority.

The majority don't know how to turn it off.

By default, ActiveX is enabled and not-prompted in non-XP Windows operating systems.

Admins 04-26-2003 01:16 AM

Quote:

Originally posted by ZanderX


The majority don't know how to turn it off.

By default, ActiveX is enabled and not-prompted in non-XP Windows operating systems.

Yes and the windows update complains when activex is disabled, so people who don't know that activex is bad might think they need to enable it again.

ZanderX 04-26-2003 01:19 AM

Quote:

Originally posted by Stefan


Yes and the windows update complains when activex is disabled, so people who don't know that activex is bad might think they need to enable it again.

Exactly. :\ I don't use Internet Explorer, so I avoid ActiveX. :)

Loriel 04-26-2003 01:28 AM

Quote:

Originally posted by ZanderX
Exactly. :\ I don't use Internet Explorer, so I avoid ActiveX. :)
I don't use Windows, to avoid, uh, security holes.

Loriel 04-26-2003 10:47 AM

Re: Re: Going into Registry is not hard
 
Quote:

Originally posted by Kaimetsu
Totally wrong. Isn't ASP a serverside language like PHP?
It is, I think, as ASP means Active Server Pages last I checked.

AlkarenHyralt 04-26-2003 08:22 PM

Re: Re: Going into Registry is not hard
 
Quote:

Originally posted by Kaimetsu


Totally wrong. Isn't ASP a serverside language like PHP?

Indeed, it is. But it is an evil scripting language. PHP is just easier to script, and oh so sexy.

Loriel 04-26-2003 11:36 PM

Re: Re: Re: Going into Registry is not hard
 
Quote:

Originally posted by AlkarenHyralt
Indeed, it is. But it is an evil scripting language. PHP is just easier to script, and oh so sexy.
Ruby is better.


All times are GMT +2. The time now is 11:02 AM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.