If we have been hacked (which we haven't)

General out-of-character discussion among players of Cantr II.

Moderators: Public Relations Department, Players Department

returner
Posts: 948
Joined: Sun Nov 01, 2009 8:11 am
Location: Melbourne, Australia

If we have been hacked (which we haven't)

Postby returner » Thu Jun 03, 2010 7:26 am

The 'Cantr down? Check here' thread is locked so I can't reply there.

If Cantr's security has been compromised by this hacker, myself and the rest of the community NEED to know ASAP if our passwords are also jeapordised. This is an extremely serious matter as some people use the same password everywhere and internet banking etc is at risk, so please advise the Cantr community as soon as possible.
This account is no longer active - please send any PMs to my new one.
User avatar
Miri
Posts: 1272
Joined: Wed May 16, 2007 3:32 pm

Re: If we have been hacked,

Postby Miri » Thu Jun 03, 2010 8:19 am

returner wrote:The 'Cantr down? Check here' thread is locked so I can't reply there.

Because it's a strictly announcement topic.

From what I've heard passes are hashed, so the hacker was trying to fish them from players using support mail.

And, honestly, don't you think using same pass for some online game that gives you no real warranty of safety and for your bank account is... kind of... silly? :roll:
User avatar
EchoMan
Posts: 7768
Joined: Fri Aug 26, 2005 1:01 pm
Location: Stockholm, Sweden

Re: If we have been hacked,

Postby EchoMan » Thu Jun 03, 2010 8:22 am

There is no way of knowing 100% what the hacker got or didn't get.

Using the same password on several places is a big no-no.
returner
Posts: 948
Joined: Sun Nov 01, 2009 8:11 am
Location: Melbourne, Australia

Re: If we have been hacked,

Postby returner » Thu Jun 03, 2010 8:34 am

I obviously don't, that's why I said 'some people'. But passwords are still passwords and should not be visible to anyone. Good to hear they're hashed.

Thanks for the replies guys.

Probably inappropriate to put here, but has it been considered that a staff member or someone who got to view the code is the hacker? Joo, who created tick timings and may have had a sneak peak at the code, seemed strangely defensive of the hacker.. :P :lol:
This account is no longer active - please send any PMs to my new one.
User avatar
Wolf
Posts: 381
Joined: Wed Oct 12, 2005 4:25 pm

Re: If we have been hacked,

Postby Wolf » Thu Jun 03, 2010 8:53 am

Miri wrote:And, honestly, don't you think using same pass for some online game that gives you no real warranty of safety and for your bank account is... kind of... silly? :roll:


Silly, yes, but he does have a point.
People are people, there will always be someone who pays 5000 dollars/euro's/pounds/whatever for a printed piece of paper saying they now own a piece of the moon.
There will always be someone who uses their name, a celebrity name, or a word easily found in the dictionary or that's in the news for their password in every place they need a password for.

I even know of a few examples where someone has the same password for everything from their router to their online banking to auction sites to games... so as silly and as no-no as it is, it happens.

Returner, even hashed data can be crunched into simple readable data but depending on which hashing is used, it can and should take long enough to take the wind out of the sails of any wanna-be hacker (scriptkiddies we called them in my days), though for a real hacker itr would just be another reason to do it - a real hacker would first of all have a few reasons to try and get into a system, whichever those reasons be, and then consider the needed effort and time as an additional reason for having a challenge.
A real hacker wouldn't be bothering with Cantr, unless he/she played the game and someone really pissed them off, but the scriptkiddy-category, they'd be pulling that sort of crap just for the heck of it alright.
hmmmmm beer.... pizza.... computers.... women... stir-fried furry little critters...
User avatar
joo
Posts: 5021
Joined: Fri Jun 17, 2005 2:26 pm
Location: London, UK

Re: If we have been hacked,

Postby joo » Thu Jun 03, 2010 10:31 am

returner wrote:I obviously don't, that's why I said 'some people'. But passwords are still passwords and should not be visible to anyone. Good to hear they're hashed.

Thanks for the replies guys.

Probably inappropriate to put here, but has it been considered that a staff member or someone who got to view the code is the hacker? Joo, who created tick timings and may have had a sneak peak at the code, seemed strangely defensive of the hacker.. :P :lol:

:roll: I've never seen Cantr's code... but I'm glad to see my subtle troll worked. :D
returner
Posts: 948
Joined: Sun Nov 01, 2009 8:11 am
Location: Melbourne, Australia

Re: If we have been hacked,

Postby returner » Thu Jun 03, 2010 11:18 am

Hehehe I know it was you Joo!!!
This account is no longer active - please send any PMs to my new one.
User avatar
Hustler0ne
Posts: 56
Joined: Thu Dec 04, 2008 2:30 am
Location: The cheese state

Re: If we have been hacked,

Postby Hustler0ne » Thu Jun 03, 2010 2:13 pm

returner wrote:The 'Cantr down? Check here' thread is locked so I can't reply there.

If Cantr's security has been compromised by this hacker, myself and the rest of the community NEED to know ASAP if our passwords are also jeapordised. This is an extremely serious matter as some people use the same password everywhere and internet banking etc is at risk, so please advise the Cantr comunity as soon as possible.


I knew it.
returner
Posts: 948
Joined: Sun Nov 01, 2009 8:11 am
Location: Melbourne, Australia

Re: If we have been hacked,

Postby returner » Thu Jun 03, 2010 2:29 pm

Hustler0ne wrote:
returner wrote:The 'Cantr down? Check here' thread is locked so I can't reply there.

If Cantr's security has been compromised by this hacker, myself and the rest of the community NEED to know ASAP if our passwords are also jeapordised. This is an extremely serious matter as some people use the same password everywhere and internet banking etc is at risk, so please advise the Cantr comunity as soon as possible.


I knew it.


You knew what? There's nothing to 'know' there, it's a statement-question.
This account is no longer active - please send any PMs to my new one.
Illidan
Posts: 301
Joined: Wed Oct 22, 2008 10:51 pm

Re: If we have been hacked,

Postby Illidan » Thu Jun 03, 2010 2:53 pm

wtf is this hacker stuff, i'm reading this on the forum for a long time, what we did to this guy? Why is he attacking?

Ok, i know it was not him that made the green world sleep for a bit, but my curiosity is increasing.

Sorry about my bad english skills.
User avatar
nateflory
Posts: 586
Joined: Tue Jan 17, 2006 5:54 pm
Location: upstate, NY

Re: If we have been hacked,

Postby nateflory » Thu Jun 03, 2010 3:00 pm

Illidan wrote:wtf is this hacker stuff, i'm reading this on the forum for a long time, what we did to this guy? Why is he attacking?


Ok, forgive the pun, but it must be said...
We were not prepared! :roll:
(WoW joke, for those who do not play it. Illidan's phrase when you encounter him as an end-boss)
---------------------------------
"Nature may reach the same result in many ways." - Nikola Tesla
"Dare to be naïve". - "Unity is plural and, at minimum, is two." - Bucky Fuller
User avatar
Doug R.
Posts: 14857
Joined: Wed Mar 23, 2005 6:56 pm
Contact:

Re: If we have been hacked,

Postby Doug R. » Thu Jun 03, 2010 3:42 pm

Illidan wrote:what we did to this guy? Why is he attacking?


Possibly nothing. Lots of benevolent players have pointed out security flaws in Cantr, and this is one that was malevolent. He's probably just "playing." It's a relatively safe place to test his abilities.
Hamsters is nice. ~Kaylee, Firefly
User avatar
SekoETC
Posts: 15526
Joined: Wed May 05, 2004 11:07 am
Location: Finland
Contact:

Re: If we have been hacked,

Postby SekoETC » Thu Jun 03, 2010 4:10 pm

If the GET string wasn't encrypted, it would be easier for regular users to play around and find exploits (and hopefully report them as well). Just because it's encrypted doesn't mean it couldn't be altered since it can be decrypted elsewhere. Also hidden data can be altered, as for example Wiro posted out earlier, so it is or was for example possible to start manufacturing items that aren't released in public because they wouldn't work as one would imagine. I think it would be better to stop sweeping things under the carpet and start thinking about how to fix the holes.
Not-so-sad panda
User avatar
Pilot
Administrator Emeritus
Posts: 7603
Joined: Thu Sep 21, 2006 3:32 pm

Re: If we have been hacked,

Postby Pilot » Thu Jun 03, 2010 5:51 pm

SekoETC wrote:I think it would be better to stop sweeping things under the carpet and start thinking about how to fix the holes.

Well said, Seko :)
User avatar
CantrFreak
Posts: 1243
Joined: Sun Nov 19, 2006 5:57 pm

Re: If we have been hacked,

Postby CantrFreak » Thu Jun 03, 2010 6:15 pm

Is there a chance of the world getting reset?
Image

Return to “General Discussion”

Who is online

Users browsing this forum: No registered users and 1 guest