Account / Password Security
Posted: Thu Jan 12, 2012 9:19 am
So, essentially, this thought occurred to me recently dealing with an Imperial member / related matter and a line from a conversation I had in the past with another Imperial member was triggered: "My game account was hacked." If you get to thinking about that statement, you have to realize and sorta understand the limitations in hacking. How does a game account actually get hacked? I am going to try and walk you guys through a hacker's mindset.
Lets look at the facts; to hack a game account requires 2 things: account name and account password. Next step, getting that information. On Pangaea, since it is an old game, most people don't choose complexity over convenience, so in many cases your forum account user name and password is your game account name and password and even if it's not, the layer of complexity to the password, probably is not representative of the word 'complex'. The password, arrow, comes to mind . Again, the next step remains, how do I get that information. First option is using SQL injection tools that exploits a vulnerability in the phpbb code of the forum, which is doable with some -minimal- effort or abuse a gm account (harder to do) and the last option is possibly to use some other medium (social network sites [FB, MySpace, BeBo etc.], IM chat program [ICQ, Miranda, Trillian, YahooMessenger, AIM, MSN etc.]) to get the information I need. In the process, convince them I'm a nice guy and persuade them to accept this file (jpg, pdf, doc, ppt etc.) or executable malware disguised as a legit program or embedded in one of the attachments listed above (eg. jpg, pdf etc.) which runs malicious code that grabs information and beacons info to a DNS under my control. Conclusion = Winning.
Realistically, the only way for a game account on Pangaea to get hacked is via forum account being same as IG account or GM account abuse.
My point is this: I believe the current system of security can be upgraded. Correct me if i'm wrong (staff) but most if not all account/password information is currently available to ALL (old and new) staff members. I am sure that all of us have known at least one person that has said, "my account was hacked". While I do not believe current staff (Icarus included) would abuse any game accounts, I am not so optimistic that previous staff have / would not. If we look at the history, in regards to previous staff maintaining both a player and game master account and recall some of the abuses that have transpired over the near decade of Pangaea's history, I believe, this should be a cause for concern and worth the time to implement some changes regarding account security. We owe it to Pangaea to keep the shard secure.
Lets look at the facts; to hack a game account requires 2 things: account name and account password. Next step, getting that information. On Pangaea, since it is an old game, most people don't choose complexity over convenience, so in many cases your forum account user name and password is your game account name and password and even if it's not, the layer of complexity to the password, probably is not representative of the word 'complex'. The password, arrow, comes to mind . Again, the next step remains, how do I get that information. First option is using SQL injection tools that exploits a vulnerability in the phpbb code of the forum, which is doable with some -minimal- effort or abuse a gm account (harder to do) and the last option is possibly to use some other medium (social network sites [FB, MySpace, BeBo etc.], IM chat program [ICQ, Miranda, Trillian, YahooMessenger, AIM, MSN etc.]) to get the information I need. In the process, convince them I'm a nice guy and persuade them to accept this file (jpg, pdf, doc, ppt etc.) or executable malware disguised as a legit program or embedded in one of the attachments listed above (eg. jpg, pdf etc.) which runs malicious code that grabs information and beacons info to a DNS under my control. Conclusion = Winning.
Realistically, the only way for a game account on Pangaea to get hacked is via forum account being same as IG account or GM account abuse.
My point is this: I believe the current system of security can be upgraded. Correct me if i'm wrong (staff) but most if not all account/password information is currently available to ALL (old and new) staff members. I am sure that all of us have known at least one person that has said, "my account was hacked". While I do not believe current staff (Icarus included) would abuse any game accounts, I am not so optimistic that previous staff have / would not. If we look at the history, in regards to previous staff maintaining both a player and game master account and recall some of the abuses that have transpired over the near decade of Pangaea's history, I believe, this should be a cause for concern and worth the time to implement some changes regarding account security. We owe it to Pangaea to keep the shard secure.