Author Topic: How did they get your password?  (Read 11658 times)

Offline Fa3z

  • Donator L3
  • *****
  • Posts: 125
  • "la ilaha illallah"
  • Registered: 19/05/2012
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • Ingame: [GG]Fa3z
Re: How did they get your password?
« Reply #15 on: 21 03, 2014, 05:14:41 pm »
once I was gonna get hacked  by a guy name Never-Killer, saying want donator  level,asking account name + password to make us fool that arran need password + account  for transfering donator level etc
https://imageshack.com/i/0mucpsp
The only memories I got of CIT are of Guard_Ghosts
-Left

beerman123

  • Guest
Re: How did they get your password?
« Reply #16 on: 21 03, 2014, 05:38:52 pm »
People who get hacked usually give their information voluntarily for others to log in. If a security question is added then I think they'd just share that aswell. I was thinking maybe you could link your ingame account to your forum account? That way you could recover your ingame account through the forum (or authorize serials). Force players to have a different password for the two of them then though.

Offline Axl

  • Senior Community Member
  • ****
  • Posts: 29
  • Winter is coming
  • Registered: 20/02/2012
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • Group: SWAT Team
  • Ingame: OPSV-Axl*SWAT
  • Squad: Project X
Re: How did they get your password?
« Reply #17 on: 21 03, 2014, 06:15:48 pm »
Long time ago, a guy posted a link in shoutbox, saying "If you want free drugs, go here" idk how many people got trapped but I didn't open it, maybe some hackers knows that how to fool someone. Newb hackers (I think) use links thingy, like sending a link to a guy saying check this or any trap and because of what, they gets the password by scripting/programming the system etc.

Indeed, most of the time you just get input fields and everything typed in this field is stored in an SQL database, of course, it's stored in a non-encrypted format.

About keylogger, there are ways to block programs in your config panels or antivirus softs, google would help you I think


Laskan13

  • Guest
Re: How did they get your password?
« Reply #18 on: 21 03, 2014, 06:22:33 pm »
the poeple with real hacks pay for poeple that making hacks, and much of these poeple dont show them in the public, so only they know it and it is hard to know who is hacking if nobody knows he is a hacker with a hack...

the most poeple get a OWN hack that nobody knows, only the maker and the buyer. its hard to know who is a hacker and who not.

Offline Dehea

  • Donator L1
  • ***
  • Posts: 88
  • CIT's Official bat user
  • Registered: 04/06/2013
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • Group: 1337
Re: How did they get your password?
« Reply #19 on: 21 03, 2014, 06:32:17 pm »
What if players must be able to login only from their IP adress'?
If player trying to login in account with another IP, he'll need to enter password sent to his email by CIT.

Just don't use stupid programs called "AIMBOT FOR MTA 1.3.5, WORKING 1000%" as there are many stealers in every game, and don't tell your password anybody else
« Last Edit: 21 03, 2014, 06:38:26 pm by DeheA` »
Founder of 1337.
RUSSIA  > eu

fadyjoseph21

  • Guest
Re: How did they get your password?
« Reply #20 on: 21 03, 2014, 06:43:42 pm »
Hey Arran,

Account hacking is not always because of players stupidity.

as I got hacked some weeks ago because I logged in from a PC that is attacked by a backdoor or something like that from a net cafe and I reported the serial to kaka and he banned it and after I got hacked I decided to suggest my idea to the server and the idea got denied because it didn't meet the requirement of votes. Here is it
and today I got amazed from people replies here .. all like your idea and all support it. then why they downvoted my suggest ? anyway > I suggested it exactly what you suggest now but I wanna add a little thing to your suggest

1) This system not forcing players to add there serials and force them to use this system.
2) Adding a radio button to disable/enable this system.
3) If a serial which not listed in the player's white list then he must confirm that its his account from his e.mail or whatever or if it possible to add phone numbers to confirm that it's your account with a pin code that the server will send to the owner's mobile. but I think this needs some payments from Arran but it will help in the server security.

so this system will be for players who think that someone trying to hack.

and here is an example GUI for what im talking about
Show content


Thanks,
Regards,
FaDY-Jo.
« Last Edit: 21 03, 2014, 06:49:23 pm by FaDY-Jo »

Offline MajdeTheGamer

  • Regular Community Member
  • ***
  • Posts: 189
  • I Am Kind Because I Am A Best Friend <3
  • Registered: 17/02/2014
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • Group: xCode
  • Ingame: Majde
  • Squad: The_Expendables
Re: How did they get your password?
« Reply #21 on: 21 03, 2014, 07:06:35 pm »
guys there a little buggy things hackers where using and it is when you login to CIT and save your login any one can hack you from that PC by entering mta sa > mods > resources > CITaccount > and he will find your registered account so be carefull :D

Offline VazZ

  • The Outrageous
  • Honorable
  • *****
  • Posts: 167
  • Registered: 08/09/2012
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • Group: ILC
  • Ingame: GOVH-Vazz|ILC|
Re: How did they get your password?
« Reply #22 on: 21 03, 2014, 07:50:20 pm »
guys there a little buggy things hackers where using and it is when you login to CIT and save your login any one can hack you from that PC by entering mta sa > mods > resources > CITaccount > and he will find your registered account so be carefull :D

That isn't any bug. When you save your password it gets saved locally and the people just grab the file to get the password. They're not even hackers, just some children who think they'd be hackers but really just try hard

This can be prevented by
- Never let someone teamview you while you are AFK (install mods yourself, dont trust randoms, watch when someone is using teamviewer)
- Never let a "friend" go to your computer while you are not there to watch
- Never save your password in the login panel in a net café or someone elses computer
- Never accept any file from an unrelilable source, though noone listens to this last part anyways
Industry and Landwork Company

since 28.10.2013

“In view of the fact that God limited the intelligence of man, it seems unfair that he did not also limit his stupidity.”
- Konrad Adenauer

Are you group leader or founder? Rent GMP now

Offline MajdeTheGamer

  • Regular Community Member
  • ***
  • Posts: 189
  • I Am Kind Because I Am A Best Friend <3
  • Registered: 17/02/2014
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • Group: xCode
  • Ingame: Majde
  • Squad: The_Expendables
Re: How did they get your password?
« Reply #23 on: 21 03, 2014, 08:01:08 pm »
I am not hacker just was testing some resource and I found CITaccount and when I entered it I found my accname and password and be carefull again guys

ExTRa.

  • Guest
Re: How did they get your password?
« Reply #24 on: 21 03, 2014, 08:15:16 pm »
If something happens ın the computer.
be changed if available okay.  ;)

VPK4

  • Guest
Re: How did they get your password?
« Reply #25 on: 21 03, 2014, 09:27:42 pm »
guys there a little buggy things hackers where using and it is when you login to CIT and save your login any one can hack you from that PC by entering mta sa > mods > resources > CITaccount > and he will find your registered account so be carefull :D
Not really a "hack" but pretty well used by account thiefs I suppose, why not encrypt that file using some kind of smart algorithm like acorp which uses binary math to modify each single byte in the password string and salt it with somethnig that is constant and uniq like the serial. That would also prevent thiefs from copying the file into another computer, I assume that you already got a feature with password reset based on email. Another solution would be to force harder passwords using pregmatch to force capital letters numbers etc. since most people just use simple ones like "12346" or "password" etc..

jackrockman

  • Guest
Re: How did they get your password?
« Reply #26 on: 22 03, 2014, 04:08:00 am »
Well, I thinked about something and I hope you like it



My suggestions is :-

We make a window called " Security account log-in " when the player log-in  .. he write his security password  .. With that way.. No one will get hacked.. Because they will steal the password not the " Security password " .. and Everyone have his "Security password "

Mr.Johnson

  • Guest
Re: How did they get your password?
« Reply #27 on: 22 03, 2014, 05:23:00 am »
The most important thing every member of CIT wants to protect is money, vehicles and property. So adding PIN or personal identification number to:-

Buying Or selling vehicles
Withdrawal of money
Buying or selling of property

If the player puts in a false PIN then the ability of making any kind of transaction is disabled and an email is sent to the owner consisting of the new PIN and why was it changed.

PIN will change in 1 attempt only because we dont want to take the risk of keeping it 3 attempts. The hacker might be trying out possibilities.

As for email address, I think it should be enforced by the staff to have an email address linked to an account

Offline Ginga_Ninja

  • *
  • Posts: 5
  • Shut yer cock holster
  • Registered: 15/05/2013
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • Group: TSF
  • Ingame: TSF|GingaSamurI
Re: How did they get your password?
« Reply #28 on: 22 03, 2014, 05:36:59 am »
Yeah sure.... because I will just open my arms and have a family reunion... :fp: Makes perfect sense when I'm American and my supposed "cousin" is from a third world country...
Also last I checked, CiT isnt the "trend" I don't see how somebody would have friends IRL that live near them that play a Server on a Multiplayer mod on a game from 2004...
Maybe Titanfall or BF4, or some MODERN game but not a SERVER from a game developed in 2004. I just like CIT because you can meet people from all over the world, but you shouldn't give your Personal Info to them. :fp:

Offline Hakeem

  • Junior Community Member
  • **
  • Posts: 92
  • Registered: 22/02/2013
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears