Account hacking figured out! It was server based and Trion has patched the hole.

ewoksrule

Active Member
http://www.riftjunkies.com/2011/03/19/rift-junkies-not-the-source-of-account-hacks/

Finally, last night on the official forums, a user by the name of ManWitDaPlan (coincidence?) made the nightmares go away. He made a shocking post titled “ATTENTION TRION – I HAVE VERIFIED THE AUTHENTICATION SYSTEM CAN BE BYPASSED, BY SUCCESSFULLY LOGGING INTO ANOTHER ACCOUNT WITHOUT NEEDING ITS CREDENTIALS.” and “This is a huge security hole. Accounts can be accessed without needing any information at all from clients.” (post found here) He was indeed correct. This was the holy grail security hole that Trion has been trying to locate and fix. How else could you possibly explain all of the account hacking’s in such a short duration of time? Just minutes after he made that post Trion had contacted him and then shortly after patched the security hole as well as made changes to the coin lock system.


http://forums.riftgame.com/showthread.php?130521-Pre-Weekend-Coin-Lock-Update

Trion is amazing...from discovered exploit to deployed patch in less than two hours on a million-plus-player MMO.

more links about the process for those interested.
http://forums.riftgame.com/showthre...y-Discussion&p=1747442&viewfull=1#post1747442
http://forums.riftgame.com/showthre...y-Discussion&p=1752989&viewfull=1#post1752989
http://forums.riftgame.com/showthre...y-Discussion&p=1752657&viewfull=1#post1752657
 
Last edited:
Was the "fix" a matter of disabling the auto-relogin part of the code? I haven't let my client time out since we started discussing how Pax got hit.
 
Back
Top