Just imagine what other vulnerabilities there could be these same people might exploit combined with the data they harvested this way. ![]()
FCCCP quality security coding ![]()
![]()
Just imagine what other vulnerabilities there could be these same people might exploit combined with the data they harvested this way. ![]()
FCCCP quality security coding ![]()
![]()
No.
I see no point in imagining such things, what would be the point?
I checked my accounts, all of my chars have been hit with that scheme, but the corpwallet where I store my Iskies hasnāt. ![]()
Which corporation wallet do you use?
The Main Wallet, has never been an issue so far. Maybe itās a good idea to make some sub-wallet the active one for all of my chars and transfer most of the ISK to that. Brilliant!
No, I mean, which corporation are you keeping your money on?
That will remain a mystery for everyone but myself, until someone worthy goes through the effort of finding out.
Id ask if you plan on reporting that player, something tells me you wont since you even hid their name
Well Iām not going to name and shame when I canāt be certain the person is involvedā¦though I canāt think of many innocent reasons for sending some random stranger 0 ISK. Iād also assume FC have looked for previous such incidents.
yeah, it could have been a mis-click
There can be another 0 day exploit or two, e.g. creating a contract for your wallet balance (minus 1 00 000 000 ISK cose you could buy something since Friday) that gets automatically accepted. BAM! Your wallet is empty.
@CCP_Stroopwafel thanks for being transparent with this security exploit info. 1st time I hear that such exploit is used against EVE playerbase.
ESI give that info. Simplify ESI Queries By Using /search/ - EVE: Developers
If not, then thereās EVEwho when you can search too.
No. They just said that it was not introduced with the recent changes. So it was sitting there for a long time probably.
Does it have any message attached?
I think that was the most common use of 0 ISK donations until this security leak.
I checked all my characters and mine were only affected on Sep 4 within that time frame Fenris quoted. My corp wallet was never affected.
Itās just a guess, but maybe whoever it was that did this, tried out their system first. It was said to be on a modified client, so it makes sense they had to test out things on their end first. Also, they may not have had a huge character name database yet at that point. Maybe just the Jita local.
Contracts donāt get automatically accepted. As far as I know there is no such functionality in the game. Somebody has to press the button. Of course, it might make it easier to scam people based on that snapshot, but even then itās only a tiny window of time which would allow for action.
To me, at the moment, this seems more like groping to see which players have a lot of liquidity in the game --that is the ONLY piece of information they got out of it. Among those players is a huge number of those who buy a lot of PLEX. One possible scenario is to approach and try to sell such players on RMT.
Probably because something or someone stopped the āscanā. It lasted 6 hours exactly according to FC. Strange it was so timed to the minute.
Read again. Iām writing about hypothetical exploit that makes your char accept it automatically bypassing the game client restrictions.
Anyway, if someone would do that so massively I thin FC would restore EVE from backup or reverse these wallet changes.
How would that happen exactly when there is no such functionality in the game? Iām pretty sure if Fenris thought to plug some holes beforehand, that would have been among the first ones.
Iām not saying itās not possible at all, but just claiming that such an exploit is possible without explaining how it can be possible, doesnāt go far.
Also, if there was such a vulnerability it would be discovered pretty quick, and whoever this person was that pinged our wallets, would also have made quick use of it.
This was just a preparation for something fishy/big. A scout was sent. The attack will come later.