![]() |
|
08-18-2014
|
1 |
|
Alumni
Join Date: Sep 2011
Location: Babord Police Department
Posts: 739
|
UN Security Breach *if you play UN*
![]() If you've logged onto UN in the past couple of months, might wanna change your PW password, Just a word of Caution. |
|
08-18-2014
|
2 |
|
Sparrer
Join Date: Aug 2014
Location: Earth
Posts: 135
|
Changed.
|
|
08-18-2014
|
3 |
|
Registered User
Join Date: Dec 2013
Posts: 117
|
Where did he post this?
|
|
08-18-2014
|
4 |
|
Uguu~
Join Date: Mar 2013
Location: Canada, NS
Posts: 1,046
|
|
|
08-18-2014
|
5 |
|
Banned
Join Date: Jan 2012
Location: Massachusetts
Posts: 57
|
This is an exploit he found out. It's done via GS2 (from what he told me), and is currently only local to the servers he had access to. The server I know he had access to are Atrius and Unholy Nation. There could be more, but I definitely hope I hear back from a Global soon on this topic. It sure needs to be patched up, as it can cause quite a bit of damage.
|
|
08-18-2014
|
6 |
|
:pluffy:
Join Date: Aug 2011
Location: Sweden
Posts: 5,946
|
Is he still staff on UN?
|
|
08-18-2014
|
7 |
|
Banned
Join Date: Jan 2012
Location: Massachusetts
Posts: 57
|
He is no longer staff. He attempted to delete the server, and has been globally banned for life by Unixmad himself.
|
|
08-18-2014
|
8 |
|
Alumni
Join Date: Sep 2011
Location: Babord Police Department
Posts: 739
|
|
|
08-18-2014
|
9 |
|
the KattMan
Join Date: Sep 2011
Location: United States
Posts: 4,204
|
So...anybody with NPC Server access can access the accounts/passwords of anybody who has logged into that server?...
|
|
08-18-2014
|
10 |
|
Banned
Join Date: Jan 2012
Location: Massachusetts
Posts: 57
|
If they know the exploit, yes. NaS did not tell me how exactly he did it, all he told me was that it was simple GS2 with some undocumented built-in functions. Hopefully this issue will raise awareness to PWA, and other Global staff. It needs to be fixed.
|
|
08-18-2014
|
11 | |
|
Enguard & Alumni
Join Date: Sep 2011
Posts: 5,773
|
oh wow, NaS finally found something himself rather than relying on people like Ruxxter and I to do it and then taking credit for it in the UN announcements after we quit such as:
|
|
|
08-18-2014
|
12 |
|
Bushwhacked
Join Date: Jun 2014
Location: Southern California.
Posts: 440
|
Hmm, interesting.
|
|
08-18-2014
|
13 |
|
The muffin man
Join Date: Sep 2011
Location: Burger Refuge
Posts: 2,262
|
I think I'm aware of this function set lol. It was used for when Stefan was developing scripts for iServer. Alot of people probably know about it I bet. So actually... everyone's password is at danger of being discovered. But you can trust honest admins right!?
|
|
08-18-2014
|
14 |
|
Bushwhacked
Join Date: Jun 2014
Location: Southern California.
Posts: 440
|
I know we take compromised accounts very seriously, although we do not have any sort of economy or anything that can be abused... other than reputation and trust, I suppose!
|
|
08-18-2014
|
15 |
|
The General
Join Date: Apr 2012
Location: England
Posts: 1,753
|
When I read UN security breach I thought of the United Nations. Was not what I was expecting.
|