Account Break in

Topics related to Second Age
Kriav
UOSA Donor!!
UOSA Donor!!
Posts: 124
Joined: Mon Feb 06, 2012 2:34 pm

Account Break in

Post by Kriav »

I log in today and found my house under another account that is not mine.
This house was under my Sanka account. I logged in once or twice a week to refresh as I am busy with work.

I think that since we do not use encryption there is a possibility that some one stole my account.

I want to a list of IP addresses that my accounts used over the last 2 months. perhaps someone even unlikey that I know in irl is griefing me.

Can I get that list????

okgoace
Posts: 252
Joined: Mon Feb 18, 2013 5:36 pm

Re: Account Break in

Post by okgoace »

Kriav wrote:I log in today and found my house under another account that is not mine.
This house was under my Sanka account. I logged in once or twice a week to refresh as I am busy with work.

I think that since we do not use encryption there is a possibility that some one stole my account.

I want to a list of IP addresses that my accounts used over the last 2 months. perhaps someone even unlikey that I know in irl is griefing me.

Can I get that list????
I bet your password was super easy to guess. Secondly, Account 'guessing' has always been apart of UO.

Kriav
UOSA Donor!!
UOSA Donor!!
Posts: 124
Joined: Mon Feb 06, 2012 2:34 pm

Re: Account Break in

Post by Kriav »

okgoace wrote:
Kriav wrote:I log in today and found my house under another account that is not mine.
This house was under my Sanka account. I logged in once or twice a week to refresh as I am busy with work.

I think that since we do not use encryption there is a possibility that some one stole my account.

I want to a list of IP addresses that my accounts used over the last 2 months. perhaps someone even unlikey that I know in irl is griefing me.

Can I get that list????
I bet your password was super easy to guess. Secondly, Account 'guessing' has always been apart of UO.
no it is not it has letters and numbers interspersed

User avatar
Jill Stihl
UOSA Donor!!
UOSA Donor!!
Posts: 709
Joined: Wed Mar 17, 2010 6:25 pm

Re: Account Break in

Post by Jill Stihl »

Is it certainly your house? Same deco or whatever?

Just seems more likely from what you've posted that your house fell down and someone took the spot, it only takes one crash or refreshing error to lose a house if it's only refreshed once a week.

Kriav
UOSA Donor!!
UOSA Donor!!
Posts: 124
Joined: Mon Feb 06, 2012 2:34 pm

Re: Account Break in

Post by Kriav »

Jill Stihl wrote:Is it certainly your house? Same deco or whatever?

Just seems more likely from what you've posted that your house fell down and someone took the spot, it only takes one crash or refreshing error to lose a house if it's only refreshed once a week.
placement is exact same deco plaster

the pacement is the same due to the tree that is there.
i did once or twice a week.

Budner
UOSA Subscriber!
UOSA Subscriber!
Posts: 1927
Joined: Sun Feb 28, 2010 10:49 am

Re: Account Break in

Post by Budner »

If you can provide your exact password I'll let you know whether it's adequately secure.

Kaivan
UOSA Donor!!
UOSA Donor!!
Posts: 2923
Joined: Wed Aug 13, 2008 11:07 pm

Re: Account Break in

Post by Kaivan »

Account passwords are stored as a SHA1 hash on our servers, although passwords are sent in plaintext from your client. It would be advisable to check your system to make sure that you don't have any keyloggers or other malware on your system.
UOSA Historian and former staff member: August 11, 2008 - June 19, 2016

Useful links for researching T2A Mechanics

Stratics - UO Latest Updates - Newsgroup 1 - Noctalis - UO98.org

okgoace
Posts: 252
Joined: Mon Feb 18, 2013 5:36 pm

Re: Account Break in

Post by okgoace »

Kavian, looking for official word on the matter. Are players allowed to try and guess other acct/pass??

Kaivan
UOSA Donor!!
UOSA Donor!!
Posts: 2923
Joined: Wed Aug 13, 2008 11:07 pm

Re: Account Break in

Post by Kaivan »

We do not have rules against players guessing passwords. You are responsible for your own password, and quite frankly, any defenses or accusations are generally hearsay.
UOSA Historian and former staff member: August 11, 2008 - June 19, 2016

Useful links for researching T2A Mechanics

Stratics - UO Latest Updates - Newsgroup 1 - Noctalis - UO98.org

User avatar
Hemperor
UOSA Subscriber!
UOSA Subscriber!
Posts: 4368
Joined: Sat Jul 19, 2008 9:15 am

Re: Account Break in

Post by Hemperor »

Kaivan wrote:We do not have rules against players guessing passwords. You are responsible for your own password, and quite frankly, any defenses or accusations are generally hearsay.
I think you should be a bit clearer on this. I'd assume that if someone was on my account who wasn't me, for whatever reason, Derrick would take it seriously and likely lead to a ban for that person. Hopefully he can chime in on this.

Otherwise you open the door for all sorts of malicious behavior.
Image

[22:26] <ian> why am i making 3750 empty kegs
[22:27] <ian> 1125000 for 3750 empty kegs
----------------------------------------
[10:44] <ian> a good cat is a dead cat

okgoace
Posts: 252
Joined: Mon Feb 18, 2013 5:36 pm

Re: Account Break in

Post by okgoace »

Hemperor wrote:
Kaivan wrote:We do not have rules against players guessing passwords. You are responsible for your own password, and quite frankly, any defenses or accusations are generally hearsay.
I think you should be a bit clearer on this. I'd assume that if someone was on my account who wasn't me, for whatever reason, Derrick would take it seriously and likely lead to a ban for that person. Hopefully he can chime in on this.

Otherwise you open the door for all sorts of malicious behavior.
malicious behavior? guessing your username is hemp hempy or hemperor and your password is pass password pass123 right?

Kaivan
UOSA Donor!!
UOSA Donor!!
Posts: 2923
Joined: Wed Aug 13, 2008 11:07 pm

Re: Account Break in

Post by Kaivan »

I'm not sure what more there is to be clear on.

If a player has acquired your account password due to you giving it away or through some sort of negligence on your part, if that player attempts to guess your password, this is your responsibility. Of course, this does not give anyone license to try and pound our login servers with an account name and various password combinations, as this would be viewed as a network attack, but this does not mean that we must carefully evaluate every login attempt and determine exactly who is trying to do what. Also, assuming that a player did acquire your account name and password, and we could verify who did it, that still wouldn't be grounds for termination or any compensation, because the circumstances surrounding the acquisition of the password is still a matter of hearsay. In this hypothetical circumstance, the only thing that could happen would be for you as the account owner to change the password to your account using the in-game commands.
UOSA Historian and former staff member: August 11, 2008 - June 19, 2016

Useful links for researching T2A Mechanics

Stratics - UO Latest Updates - Newsgroup 1 - Noctalis - UO98.org

Schmitty
Posts: 11
Joined: Sat Mar 30, 2013 7:14 pm

Re: Account Break in

Post by Schmitty »

man i love this server but lets get real here. if this is really happening and its all legit and someone really hacked into his account and you guys are like oh that's fair game.. that is total bull especially when you can get banned for lying about a trade on the forums.... totally horrible

i dont understand how its hersey either.. look at the ips match the login ip to another account not linked to the OPs ee how many attempts he was unsuccessful with so that you will know if he was just guessing or if it was something else.... 30 minutes tops thats all it takes... i suppose the moving dead bodies behind walls glitch to get into houses is fair game too then? because that is alot less bogus than giving people free reign to steal accounts

okgoace
Posts: 252
Joined: Mon Feb 18, 2013 5:36 pm

Re: Account Break in

Post by okgoace »

Schmitty wrote:man i love this server but lets get real here. if this is really happening and its all legit and someone really hacked into his account and you guys are like oh that's fair game.. that is total bull especially when you can get banned for lying about a trade on the forums.... totally horrible

i dont understand how its hersey either.. look at the ips match the login ip to another account not linked to the OPs ee how many attempts he was unsuccessful with so that you will know if he was just guessing or if it was something else.... 30 minutes tops thats all it takes... i suppose the moving dead bodies behind walls glitch to get into houses is fair game too then? because that is alot less bogus than giving people free reign to steal accounts
Its simple, dont have an easy password:
easy = 123,abc, abc123
difficult = Off to see the Wizard = 0ff2c7h3w1z412d

If someone guesses your account name, shame on you.
If they guess your password, hats off to them.

This is almost as bad as asking for handouts. You should probably go back to your land of carebears, your kind doesnt belong here. obv.

Budner
UOSA Subscriber!
UOSA Subscriber!
Posts: 1927
Joined: Sun Feb 28, 2010 10:49 am

Re: Account Break in

Post by Budner »

I think he's saying it's hearsay because the mods won't know who to believe. Account owner says this guy hacked my account, the hacker says he gave me the password.

I do agree that if, in theory, it could be proven that someone hacked an account, that such hacking should result in a ban. But good luck proving who did it, or that the person didn't come by the password legitimately.

Post Reply