Security update

Thats pure imagination. What the current bug did cause was an “info sniffing” because the modified client could display an information that was obviously part of the transaction confirmation sent by the receiving client. It was always there, a normal EVE client simply wouldn’t display it.

To believe the same “method” could be used to somehow send “commands” to other clients is not even closely backed up by logic.

1 Like

This is great idea.

What I find strange is that FC knew what was sent back to the attacker. This is very uncommon to know what has leaked and what not in such a short time from an attack especially from a modified client. Unless FC knows from their code what is sent to 0 ISK “command” to the client but FC just don’t display it in a game…but after the scan attack FC can assume what modified client intent was.

Yes, that is just my speculation about “what if” other 0 days are there.

Exactly what I was thinking. It was there all the time just not displaying info.

All “commands” are done in the DB. Attacker don’t need your active client to do so some exploit actions on your behalf. I’m writing about IDOR/RCE and you mean XSS (active client). That scan was not involving other clients. Just EVE server.

No but I remember the incident as it just seemed odd at the time. I was heading out of Jita to Sobaseki, and as soon as I arrived in Sobaseki I got a message saying someone had deposited 0 ISK in my account. The person sending the 0 ISK was in the system at the time. I thought it all a bit odd…but just carried on.

If that was true, then there would be no point in playing this game, as anyone could just take control of your characters remotely and do with them as they please. This is not the case. Not even close. They can access information on server side, sure, they can’t execute commands on behalf of other players’ clients.

You know the concept of 0 day exploit, don’t you?

1 Like

Which, to be honest, is not very helpful in this situation. A new vulnerability isn’t necessary to exploit the information gathered from this exercise. The most likely attack vector is the same sort of misleading contracts you see spammed in the trade hubs all day, every day, except now targeted in a spear-fishing campaign. And remember, those scam contracts are not against the rules. If you accept one, there is no recourse.

You also don’t need magical self-accepting contracts when people who deal with tens or hundreds of contracts a day are likely to click accept without paying close attention to the details (i.e., the number of zeros in a price). These kind of mistakes happen often enough already.

How does that explain self-accepting contracts again?

You’re saying that since A (0 day vulnerability) exists, ergo B (self-accepting contract) exists/is possible. But that math is incorrect. You haven’t explained the mechanics behind B. Just that A exists.

That’s the point. Why bother siting in Jita when you can silently empty dormant accounts with big wallets that nobody will complain about?
Similar to smart contract exploits in blockchain.

You reminded me why I left this forum. Thanks! o7

1 Like

What a sh*t show. Im mad at myself because i havent been able to get on the forums all day because of meetings and incompetent people.

Ill log on to see if anything is crazy looking. Not sure why people are snap shooting peoples isk amounts or what ever.

This thread is 90 posts long so im not going to ask repeated questions or expect repeated answers.

Edit:

Okay, ive logged in and i also got a donation.. Hooraay for me…do i get a medal?
image

My other account also got a donation from fxprobe1. Thats two medals im owed.

:military_medal: :rose:

1 Like

At this point, there’s nothing specific to worry about. Just follow the same precautions you would normally:

  1. Make sure your account is secured with a strong password and 2FA.
  2. Carefully review any contracts before accepting them.

If you want to be extra safe, create a new alt and transfer the bulk of your ISK to that character. Going forward, withdraw as needed to your active accounts. If you have a corp wallet you control, consider moving the bulk of your ISK out of the master wallet and into a restricted wallet division. This should largely mitigate accidental losses due to oversights, malicious contracts, or exploitative market orders.

Better to send your ISK to me. I’ll double it.

1 Like

Im not worried about anything. Ive seen a slew of ugly exploits in the game through the years…i was fine then, ill be fine now.

Nope, not going through that trouble. Its all overkill at this point.

Im very careful about transactions in this game. I can say proudly that ive never been robbed, scammed, or anything like that in 18 years of playing. As far as somebody slipping in and taking isk…dont think thats going to happen unless somebody just plain hacks into your account and steals it outright.

1 Like

When CCP gave all players the ability to start pinging the server for extra details that aren’t on the interface, they opened the floodgates for massive cheats and advantages.

Everyone’s paranoid mind came up with the same conclusions right? The only reason to sniff account values is to know who to steal from. And the next attempt will be more directed. And after that we will see a discount offered on cheap ISK on some Russian website. I know Im not the only person who has logged into other games naked at the mailbox with zero gold. Except in this game, permissions are shared between massive coalitions. It is honorable that you guys are owning it.

I’ve been through worse. Once played a game that got DDOS so hard that the server fried and we all lost everything. Had to reroll a new server lol. It was actually a great time and lots of fun.

Why are you talking to yourself Mina/Distaine?

1 Like

@Gerard_Amatin No. i was on my phone walking and used it to speak instead of my desktop. There is a limit on edits and one of my main reasons to play eve means I require the edits. It doesnt matter… its just odd sometimes for others who notice. For future reference, i am every character in this corp (and do not use any that are not, on the forum). You can call me Kernite… none of these toons in particular. I dont roleplay. It does look like im talking to myself doesnt it lol. Ill keep that in mind.

1 Like

Just an FYI, do with it what you will, but some folks (myself included) really do not like sock puppets. I suggest you pick a “main” for purposes of the forum and limit your posting to that character. Otherwise, you may find all of your aliases added to someone’s ignore list.

2 Likes

Don’t be so hard on yourself.