Ragnarok Online Hacked Again 29
An anonymous reader writes "According to a Stratics article, Ragnarok Online, a primarily Asian MMORPG, has been hacked yet again. As many people will remember , Ragnarok was hacked in late June, and a file with every user's passwords/usernames was distributed." Another anonymous reader claims: "Someone logged on as a GM, loaded arbitrary items and distributed them, used the in-game announcement system to announce their accomplishment, and was able to delete all of the official GM accounts." As yet, there's no official statement from the Ragnarok developers on this latest alleged issue.
Why Clear Text Passwords are Bad, and How to Avoid (Score:3, Insightful)
That nemesis ... (Score:5, Funny)
The old nordic mythology tales about the end of the world, and offen used (here in Denmark) as a description of when things gets out of control !!
Re:That nemesis ... (Score:3, Funny)
what? that's propostorous! (Score:3, Funny)
GRAVITY IS CLOSING UP SHOP (Score:4, Interesting)
Re:GRAVITY IS CLOSING UP SHOP (Score:2)
Apologies if this seems crazy. Probably is. I just woke up.
Also, I wonder why they think the American hackers that do this now won't just obtain a Korean copy of Ragnarok online and do the same thing from across the Pacific?
Korea and KSSNs (Score:5, Interesting)
We couldn't. In Korea, almost every online game requires you to provide a valid KSSN (Korean Social Security Number). Furthermore, these numbers aren't like US SSNs. The number itself reveals such information as birth year and gender (and they tend to enforce gender in the games as well). You can't just make one up, since it either wouldn't have the proper checksum, wouldn't exist in the database, or wouldn't match the age or gender you need. Plus, the Korean government investigates "suspicious use of a KSSN." If a Korean citizen's KSSN is regularly connecting to a game server from the United States, something is likely amiss.
Granted, there are sites that will "sell" you KSSNs, but they often get shut down by the Korean government. We gave up trying and just waited for the American release. (Not that it was worth waiting for -_- Stupid macro-based boring laggy POS MMORPG...)
Re:Korea and KSSNs (Score:3, Interesting)
Re:Korea and KSSNs (Score:2)
Damn, there goes my main reason to play online games.
Not too shocking... (Score:2, Interesting)
Last time I checked... (Score:5, Insightful)
Private servers.
Anybody that cared to dig up a bit the history of Ragnarok Online's private servers knows that a sizeable portion of it originated from Aegis. Aegis was the codename of the actual server software that Gravity runs on their servers. Indeed, there was a case of a few hackers in Korea beating the security (or lack of it thereof) and causing the leak of server software to public. This was in mid 2002 if I am not mistaken.
Now, let us jump 1 year forward, to June 2003. Second attack on Gravity servers. Massive leaks of account data. One may think that after the first fiasco, the security measures were strengthened. However reports show up that passwords were stored in plaintext. Therefore one must conclude that if there was not enough attention to this small (and easy-to-fix) detail, the overall security is in the same state.
Which ultimately means that nobody bothered to upgrade their security - if you check your RO client now with a sniffer, you will see that it sends login data in plaintext(?!), not to talk about actual server-side databases.
If they could not fix this in a year, almost year and a half since the first attack, what would make them magically fix it in 1 month. Therefore, attacks like this one will happen, and leaks like this one will happen. It's not a one-time occurence.
Alleged (Score:2)
Alot more attack recently? (Score:1)
Security improving everyday... (Score:2, Funny)
Username: Administrator
Password: Default
On the serious side though, remember Sega Japan using the excuse of America being full of nogoodniks as the reason they were going to charge twice as much for PSOv2 then they did in Japan? I guess they were right.
Same as it ever was (Score:2)
Todays tip: stop playing ragnarok online
All kidding aside, Suppose I started an airline "Mofo air" and it suffered 2 major crashes in less than a month all due to sloppy security and terrible maintance. How many of you would still be buying tickets? How poorly does one have to run a company before people get the picture that it sin't going to get better?
Im sure there will be some law suits in the next
Re:Same as it ever was (Score:2)
For a MMORPG player, this is the same thing. Characters take hours and hours to build up (weeks, months, years even), and to lose it all because the host of your game can't keep their servers protected is a very hard thing to over look. This combined with Gravity's past "its your fault you got hacked" attitude (im not kidding on that one, after a number of hacks during one of the betas their offical statement was that it was the users fault for not changing their passwords often e
last post winner (Score:1)