Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×
PC Games (Games) Role Playing (Games) Entertainment Games

Ragnarok Online Hacked Again 29

An anonymous reader writes "According to a Stratics article, Ragnarok Online, a primarily Asian MMORPG, has been hacked yet again. As many people will remember , Ragnarok was hacked in late June, and a file with every user's passwords/usernames was distributed." Another anonymous reader claims: "Someone logged on as a GM, loaded arbitrary items and distributed them, used the in-game announcement system to announce their accomplishment, and was able to delete all of the official GM accounts." As yet, there's no official statement from the Ragnarok developers on this latest alleged issue.
This discussion has been archived. No new comments can be posted.

Ragnarok Online Hacked Again

Comments Filter:
  • by Anonymous Coward on Tuesday August 05, 2003 @05:47AM (#6613795)
    If they just wouldn't store passwords as cleartext, this kind of thing would happen much less often. Read this interesting article [slashdot.org] for more on the subject.
  • by Hougaard ( 163563 ) on Tuesday August 05, 2003 @06:02AM (#6613839) Homepage Journal
    Why do you think its called "Ragnarok" ...

    The old nordic mythology tales about the end of the world, and offen used (here in Denmark) as a description of when things gets out of control !! /Erik
  • by nunofgs ( 636910 ) on Tuesday August 05, 2003 @06:17AM (#6613881)
    There are no infidel hackers in Ragnarok! Never!
  • by Anonymous Coward on Tuesday August 05, 2003 @06:24AM (#6613896)
    One of my friends is one of the Sub GM - The Korean management of Gravity has decided they want nothing more to do with the Americans who consistently cause more trouble than they are worth. There has been no announcement because the GM staff has been dismissed except for a skeleton crew. Word is office supplies and such are being boxed up for return to Korea, and iRO will shut down at the end of the week. They simply don't have enough customers left to support operations in the face of continuous attacks.
    • This is certainly no surprise to me. So is America turning into some kind of monster to MMOs, like Asia is to the record/DVD industry? More trouble than we're worth, so we won't even bother selling there.

      Apologies if this seems crazy. Probably is. I just woke up.

      Also, I wonder why they think the American hackers that do this now won't just obtain a Korean copy of Ragnarok online and do the same thing from across the Pacific?
      • Korea and KSSNs (Score:5, Interesting)

        by Schezar ( 249629 ) on Tuesday August 05, 2003 @08:30AM (#6614428) Homepage Journal
        Before Rag Online came to the US, a bunch of us tried to sign up for the Korean version...

        We couldn't. In Korea, almost every online game requires you to provide a valid KSSN (Korean Social Security Number). Furthermore, these numbers aren't like US SSNs. The number itself reveals such information as birth year and gender (and they tend to enforce gender in the games as well). You can't just make one up, since it either wouldn't have the proper checksum, wouldn't exist in the database, or wouldn't match the age or gender you need. Plus, the Korean government investigates "suspicious use of a KSSN." If a Korean citizen's KSSN is regularly connecting to a game server from the United States, something is likely amiss.

        Granted, there are sites that will "sell" you KSSNs, but they often get shut down by the Korean government. We gave up trying and just waited for the American release. (Not that it was worth waiting for -_- Stupid macro-based boring laggy POS MMORPG...)
        • Re:Korea and KSSNs (Score:3, Interesting)

          by analog_line ( 465182 )
          OK, how about the Japanese version? Is there a simmilar restriction on that? I know there's a Japanese release of Ragnarok.
        • The number itself reveals such information as birth year and gender (and they tend to enforce gender in the games as well)

          Damn, there goes my main reason to play online games.

  • Not too shocking... (Score:2, Interesting)

    by heyyojay ( 695081 )
    I am not supprised that it was hacked. Why would you put all of the passwords in the same spot. Some other smart online games have passwords stored in several servers, not in just one file. I am afriad i cant feel bad for them. I feel that it is thire own fault...
  • by ASkGNet ( 695262 ) on Tuesday August 05, 2003 @10:37AM (#6615469) Homepage
    Last time I checked, they did not even bother to upgrade their security after June's attack. But let's not speculate, and look at a known case:

    Private servers.

    Anybody that cared to dig up a bit the history of Ragnarok Online's private servers knows that a sizeable portion of it originated from Aegis. Aegis was the codename of the actual server software that Gravity runs on their servers. Indeed, there was a case of a few hackers in Korea beating the security (or lack of it thereof) and causing the leak of server software to public. This was in mid 2002 if I am not mistaken.

    Now, let us jump 1 year forward, to June 2003. Second attack on Gravity servers. Massive leaks of account data. One may think that after the first fiasco, the security measures were strengthened. However reports show up that passwords were stored in plaintext. Therefore one must conclude that if there was not enough attention to this small (and easy-to-fix) detail, the overall security is in the same state.

    Which ultimately means that nobody bothered to upgrade their security - if you check your RO client now with a sniffer, you will see that it sends login data in plaintext(?!), not to talk about actual server-side databases.

    If they could not fix this in a year, almost year and a half since the first attack, what would make them magically fix it in 1 month. Therefore, attacks like this one will happen, and leaks like this one will happen. It's not a one-time occurence.
  • What's with this 'alleged' stuff. This is /. dammit, and I expect no less than any other tabloid news distributor!
  • I've seen a few just on message boards I frequent. 2 of the 5 I visit most often got hit. Maybe just coincidence.
  • This just in, the account that was hacked has been discovered, it was
    Username: Administrator
    Password: Default


    On the serious side though, remember Sega Japan using the excuse of America being full of nogoodniks as the reason they were going to charge twice as much for PSOv2 then they did in Japan? I guess they were right.
  • The Ragnorok Online hint of the day (brought to you by mountain dew, when you level up do the dew)

    Todays tip: stop playing ragnarok online

    All kidding aside, Suppose I started an airline "Mofo air" and it suffered 2 major crashes in less than a month all due to sloppy security and terrible maintance. How many of you would still be buying tickets? How poorly does one have to run a company before people get the picture that it sin't going to get better?

    Im sure there will be some law suits in the next
  • Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net], Grumpy Watkins [uklinux.net],

You can tune a piano, but you can't tuna fish. You can tune a filesystem, but you can't tuna fish. -- from the tunefs(8) man page

Working...