| View previous topic :: View next topic |
| Author |
Message |
PirateCotton
Joined: 08 Feb 2006 Posts: 320
|
Posted: Sun Feb 25, 2007 12:47 am Post subject: DarkLife hacked - $400us stolen |
|
|
Hi folks. I'm pasting a message I got from DarkLife co-founder today, Mark Busch.
| Quote: |
When I came back from holiday I noticed my secondlife account was empty. When I went away it was still about 112.000 L$
So I looked what happened, and it turned out on the 17th my account got robbed by some dude named 'CheckOutThis Hax' and 'Data Lindman'.
Probably the same guy as 'Client Hax' who had hacked darklife before.
He used a part of the shop script that gives back the L$ if the buy fails. The only way he can do that is if he knows the channel number (and judging from the previous levelup-hack he does).
But how did he know the channel number? 3 possibilities:
-Secondlife had a bug for like 7 hours some time ago where everything bought would be copy-mod, including scripts.
-He found a new bug in SL (Client Hax means Client Hack?)
-He used a scanner: but this seems highly unlikely, there are 4 billion channel numbers. On each channel he would have to listen, then wait if anything is being said (for how long?) even IF he would be able to do 100 scans in 1 second (which seems impossible to me, because he doesn't know how long to listen on a channel) it would still take about 2 years of full scanning to test all channels, and let's say 1 year before he finds it.
So I guess either 1 or 2.... anyway it's very very bad. we've been robbed for about 400 USD
|
I've posted this to the developers and on the SL Games Forum. We're not sure how this affects the future of Second Life. I firmly believe that without bugs in the SL client this attack would not have been possible, so I would like to see LL credit us with 2 months of rent, at a minimum.
In any case, you should all be aware of this bug and pass on the word to your friends that they need to carefully seperate their cash-holding accounts from their 'transacting' accounts so that a potential thief will be limited in what he/she can steal.
Pirate Cotton
Co-Dev DL |
|
| Back to top |
|
 |
PirateCotton
Joined: 08 Feb 2006 Posts: 320
|
Posted: Sun Feb 25, 2007 7:57 am Post subject: |
|
|
Further to this, the hackers returned today and crashed the sim repeatedly and also adjusted peoples levels. We can fix that for you if you wish, btw.
As far as game access goes, we've had to restrict access to Navora to the group "Navora Access". You can get an invite to this group by messaging a moderator, Ethan Hawke or Trevor Langdon.
Apologies for the inconvenience I'm sure you all understand.
Note: Client Hax was in the DarkLife Players channel when I passed on some updates to people. I removed the guy, but he was still able to talk. No idea how.
PC |
|
| Back to top |
|
 |
Ethen Pow
Joined: 08 Feb 2006 Posts: 336 Location: Oregon
|
Posted: Sun Feb 25, 2007 9:01 am Post subject: |
|
|
the group is "Drakeal" its one of my unused groups :/ _________________ I will come out of no were
I help keep the navora sim healthy and clean  |
|
| Back to top |
|
 |
Ethen Pow
Joined: 08 Feb 2006 Posts: 336 Location: Oregon
|
Posted: Thu May 31, 2007 9:43 am Post subject: |
|
|
| PirateCotton wrote: | | Ethan Hawke |
Ethan Hawke? whos he? _________________ I will come out of no were
I help keep the navora sim healthy and clean  |
|
| Back to top |
|
 |
|