Security update

Just imagine what other vulnerabilities there could be these same people might exploit combined with the data they harvested this way. :thinking:

FCCCP quality security coding :eyes:

:psyccp:

No.

I see no point in imagining such things, what would be the point?

I checked my accounts, all of my chars have been hit with that scheme, but the corpwallet where I store my Iskies hasn’t. :slight_smile:

Which corporation wallet do you use?

The Main Wallet, has never been an issue so far. Maybe it’s a good idea to make some sub-wallet the active one for all of my chars and transfer most of the ISK to that. Brilliant!

No, I mean, which corporation are you keeping your money on?

That will remain a mystery for everyone but myself, until someone worthy goes through the effort of finding out.

2 Likes

Id ask if you plan on reporting that player, something tells me you wont since you even hid their name

Well I’m not going to name and shame when I can’t be certain the person is involved…though I can’t think of many innocent reasons for sending some random stranger 0 ISK. I’d also assume FC have looked for previous such incidents.

yeah, it could have been a mis-click

There can be another 0 day exploit or two, e.g. creating a contract for your wallet balance (minus 1 00 000 000 ISK cose you could buy something since Friday) that gets automatically accepted. BAM! Your wallet is empty.

@CCP_Stroopwafel thanks for being transparent with this security exploit info. 1st time I hear that such exploit is used against EVE playerbase.

ESI give that info. Simplify ESI Queries By Using /search/ - EVE: Developers
If not, then there’s EVEwho when you can search too.

No. They just said that it was not introduced with the recent changes. So it was sitting there for a long time probably.

Does it have any message attached?

I think that was the most common use of 0 ISK donations until this security leak.

I checked all my characters and mine were only affected on Sep 4 within that time frame Fenris quoted. My corp wallet was never affected.

It’s just a guess, but maybe whoever it was that did this, tried out their system first. It was said to be on a modified client, so it makes sense they had to test out things on their end first. Also, they may not have had a huge character name database yet at that point. Maybe just the Jita local.

Contracts don’t get automatically accepted. As far as I know there is no such functionality in the game. Somebody has to press the button. Of course, it might make it easier to scam people based on that snapshot, but even then it’s only a tiny window of time which would allow for action.

To me, at the moment, this seems more like groping to see which players have a lot of liquidity in the game --that is the ONLY piece of information they got out of it. Among those players is a huge number of those who buy a lot of PLEX. One possible scenario is to approach and try to sell such players on RMT.

Probably because something or someone stopped the ā€œscanā€. It lasted 6 hours exactly according to FC. Strange it was so timed to the minute.

Read again. I’m writing about hypothetical exploit that makes your char accept it automatically bypassing the game client restrictions.
Anyway, if someone would do that so massively I thin FC would restore EVE from backup or reverse these wallet changes.

How would that happen exactly when there is no such functionality in the game? I’m pretty sure if Fenris thought to plug some holes beforehand, that would have been among the first ones.

I’m not saying it’s not possible at all, but just claiming that such an exploit is possible without explaining how it can be possible, doesn’t go far.

Also, if there was such a vulnerability it would be discovered pretty quick, and whoever this person was that pinged our wallets, would also have made quick use of it.

1 Like

This was just a preparation for something fishy/big. A scout was sent. The attack will come later.