Page 6 of 7

Re: Accounts on vac mode hacked.

Posted: Sat Nov 14, 2009 11:28 am
by Lithium
it was not an accusation , i intented to sell to him and added to msn , then i saw what a member said :- this guy told me about the hacking accounts, then i saw only 3 posts of him and thought that smone might be creating forum accounts similiar to ingame names.
it happened a week b4 that a forum memebr was fakin ingame personalities with id's and names.

Re: Accounts on vac mode hacked.

Posted: Sat Nov 14, 2009 4:20 pm
by Shinobii
That's odd, he didn't put my account on vacation mode or whatever. Maybe because I caught it and emailed admin rather than staying afk?

Re: Accounts on vac mode hacked.

Posted: Sat Nov 14, 2009 5:14 pm
by CABAL
What.

You mean the passwords aren't hashed and salted? #-o [-X

Re: Accounts on vac mode hacked.

Posted: Sat Nov 14, 2009 5:30 pm
by GeneralChaos
CABAL wrote:What.

You mean the passwords aren't hashed and salted? #-o [-X


Exactly, plain text for the loss,

Also i noticed admin did not put Hensenshis account back on vac mode, but he put the Pragma one on vac mode, strange.

Re: Accounts on vac mode hacked.

Posted: Sat Nov 14, 2009 6:00 pm
by Tekki
Yeah he didn't put all the accounts on vacation just some of them.

Oumar's is still available for example.

Re: Accounts on vac mode hacked.

Posted: Sat Nov 14, 2009 11:50 pm
by Caprila
Shinobii wrote:That's odd, he didn't put my account on vacation mode or whatever. Maybe because I caught it and emailed admin rather than staying afk?


I did tell him you and 311 had managed to log back into your accounts. Possible he saw you'd changed teh passwords and left them alone. I sent norbe a msg about it, because I wasn't 'sure' if he had or not.. and didn't want you think 'OMG i've been hacked again' if you couldn't log in again #-o

Re: Accounts on vac mode hacked.

Posted: Sun Nov 15, 2009 3:11 am
by Shinobii
Yea, it's not a big deal. Now with the server ppt i can't go on vacation for a bit. Whatever, it's not like logging in every now and then is going to kill me.

Re: Accounts on vac mode hacked.

Posted: Sun Nov 15, 2009 5:08 am
by bamse
I got it confirmed yesterday by one of Oumar's real life friends that he ain't playing at all.. So someone took his account out of vacation mode and used it for their evil purposes.

Re: Accounts on vac mode hacked.

Posted: Sun Nov 15, 2009 11:12 pm
by Oumar
Okay due to Tekki's and Bamse's efforts, I was notified that my account was hacked. I have not logged on in over a year. I will need to look into what needs to be done to put my account back right, but here are the brokers I found.

Oumar Ymer 32,708,435,135,147 Naquadah 1 Untrained Nov 12, 2009, 4:37 am Completed.
Oumar Tajj 32,704,212,625,600 Naquadah 1 Untrained Nov 12, 2009, 4:14 am Rejected&Returned.
Oumar Tajj 100,414,000 Untrained 1 Naquadah Nov 12, 2009, 4:11 am Expired.
Oumar shinobii 32,648,717,949,329 Naquadah 1 Untrained Nov 12, 2009, 1:34 am Rejected&Returned.
Oumar Antistatic 90,000,000 Untrained 1 Naquadah Nov 11, 2009, 9:48 pm Completed.
Oumar Antistatic 10,000,000 Untrained 1 Naquadah Nov 11, 2009, 9:45 pm Completed.
Kronos the Mighty Oumar 58,700,000 Untrained 1 Naquadah Nov 11, 2009, 4:55 pm Completed.
mattwell Oumar 21,999,639,316,283 Naquadah 1 Turns Nov 11, 2009, 4:47 pm Completed.

Re: Accounts on vac mode hacked.

Posted: Mon Nov 16, 2009 12:07 am
by bamse
Glad you're "back" mate :) .. Too bad things are in a shamble..

Re: Accounts on vac mode hacked.

Posted: Mon Nov 16, 2009 1:22 am
by Lithium
viewtopic.php?f=130&t=150180

Antistatic selling thread

Re: Accounts on vac mode hacked.

Posted: Mon Nov 16, 2009 1:32 am
by Legendary Apophis
Lithium wrote:http://talk.gatewa.rs/viewtopic.php?f=130&t=150180

Antistatic selling thread

It seems to have started over a month ago...so I don't know if it's linked to that.
However, I'm more curious to know if people who accepted brokers from Oumar did so by naivety, or because they were controlled by the hacker.

Accounts I noticed being off vacation unlisted yet. Don't know if they came back, or if they are controlled by hacker.
Yamosas id=5161

Re: Accounts on vac mode hacked.

Posted: Mon Nov 16, 2009 3:00 am
by Tekki
Yamosas is back temporarily because Yamosas took the account off PPT when they realised Zaphor had been hacked. I got ingame PMs from Yamosas and MSN with him.

FINALLY managed to get in touch with Oumar and he is going to Email Jason about his account. Thanks to Ossetian for the help there.

Re: Accounts on vac mode hacked.

Posted: Mon Nov 16, 2009 3:20 am
by Lithium
Apophis The Great wrote:
Lithium wrote:http://talk.gatewa.rs/viewtopic.php?f=130&t=150180

Antistatic selling thread

It seems to have started over a month ago...so I don't know if it's linked to that.
However, I'm more curious to know if people who accepted brokers from Oumar did so by naivety, or because they were controlled by the hacker.

Accounts I noticed being off vacation unlisted yet. Don't know if they came back, or if they are controlled by hacker.
Yamosas id=5161


well recently he has been selling a lot and not buying that many at's , we cant prove anything by forum posts but its a start.
however accepting broker or farming heavy quantities of cheated resources is cheating as well , it shall be reported while hopping admin can remove those resources coming from nowhere.

Re: Accounts on vac mode hacked.

Posted: Mon Nov 16, 2009 6:29 am
by Caprila
I have changed the password on all accounts who have not logged in for a long time. This, combined with the 6month reminder to change passwords, will ensure all old passwords are not the same as they were when this game/admin was active (1+year ago).

I have also tracked IPs that look to be associated with the reactivation of old accounts, and updated both emails and passwords, such that they are in effect disabled. I have no real way of knowing who currently controls said accounts, old user or other, so felt this disabling was the safest route. I am also not 100% sure those changed were even affected, but it is a 'best guess'...worst case the user needs to send an email to get back active...so I felt it was worth it.

I have also (as of today) added appropriate messaging to the login, which will inform the users affected what has happened, when they try to login.

People who have only had password changed (due to long time no login) can use 'forgot pass' link to get the new pass.
People who have had email and pass changed, must email support@stargatewars.com to get it reactivated.
Again, the login message will reiterate this, when the user tries to login.


If you could please post this email in the appropriate places on forums, it would be muchly appreciated.

thanks!
jason.