A sinners confession

Status
Not open for further replies.
K

Kahland

Guest
You can always get tracked, but not my GOA XD

MrX cant be very clever, he didnt even earn money on it 8]
 
Z

Ziva

Guest
Originally posted by Laromia
I'm not after your respect.

So what are you trying to accomplish then? You tell us you want to get the truth out and you don't care about how people think. Yet you and Sharma are on this topic like two watchdogs trying to correct people and defend yourself and your actions in every reply.

I think people are entitled to have their own opinion after what you did. You posted your side of the story, fine... now let people reply to that without your interference.

Oh and another thing... what i find so hard to understand is how you can walk around for more then 3 weeks with the knowledge that someone you don't know very well is capable to destroy about everything people have been "working" for so long. Real "love" for the community you were a part of 17 months huh?

And to all the people with "chill it's just a game replies".. it's not up to you to judge how people should look upon this game. Even though i share that same view and do think "it's just a game", i do respect a lot of people take this game far more seriously then you think. They have been screwed by a couple of members from their own community (sure GOA took the game down but they did because of what you two did) and they have the right to be pissed off imo.
 
S

Shanaia

Guest
gif working link

Please tell me someone backed that one up.. it's down now :(
 
G

Gadd

Guest
well i read a lot of the start of this post (first 4 pages).

and i just wanna say:

so you lost 3 weeks big deal, these guys lost their accounts for good (which is probably what they deserved)

and also.

thank you laro, for exposing the holes and showing us how useless goa is ..... i think i'll get an american copy shipped over.
 
M

~Mobius~

Guest
Must laugh at the Excal players though, no idea whats going on. :)
 
O

old.ivan

Guest
Originally posted by Gadd
thank you laro, for exposing the holes and showing us how useless goa is ..... i think i'll get an american copy shipped over.

We always knew goa was useless and couldn't be helped, its old news imo. I seriously question the fact that anyone will benefit from such information exposure.

A guildie of mine couldnt play for a long period of time because of what the person did, and as everyone knows subs cost money. In some sense the entire guild couldnt function 100% since the person who suffered is high up in ranks.

Coming clean is all good and jolly, but please justify the fact that you denied so many people "the fun" for so damn long. Was that just to show us how incompetent goa security is ? imo in this case the ends dont justify the means.

To all you 1337 haxxor dudes with ego problems out there .... "go **** yourselves !!11one"

PS: this is my personal opinion, not the guilds.
 
O

old.Gromnir

Guest
Okay to choop it up a little.

The first part where he shows you the GM tool on the german server, and you log off and report it. Thumbs up for that.


The 2nd part, well you took the wrong part here. But then again I think alot of people would have done that if they where offered the title of "god" by the devil. If you had come clean at a sooner time, (before they shut you down) and had not been a twart and gone on a GM tool rampage then I might have said hell give her back her chars GOA !!

But fact is you dont deserve them realy, I think you got off light. You got one account back, empty but you got it back. Reason ... well you could have done wonders to your chars while having the GM tool is I take it its only fair they died.

MrX should be shut down, I hope he is, and reported to the police.

Laromia you could just as well be faced with "cybercrime" in the way that you where fooling around with items provided to you by a criminal and thus making yourself a part of the crime.
Same goes to Shama.

All I can say is im happy that it got an end and that we, I hope, got rid of MrX and this tools.
 
S

Sarnat

Guest
Originally posted by Gadd
so you lost 3 weeks big deal, these guys lost their accounts for good (which is probably what they deserved)

and also.

thank you laro, for exposing the holes and showing us how useless goa is ..... i think i'll get an american copy shipped over.

Big deal? It is a big deal for many people. They paid to play and now they cant. It's a major fucking deal to GOA, too. They must have lost tens of thousands euros on this incident.

And Mr Security expert, ever heard of the fact that no system is safe. There is always a security hole.

For example at my school, 2 of my friends were on a computer security course where they had an assigment about "social hacking". They did a series of 5 tests. One test was sending classic "this is superuser of the lab, send me your pass because xxx". Other one was gaining access to a switch room. And so on. Every single test was successful. Every system can be cracked if you know how.
 
J

Jaem

Guest
Whole thing stinks, only this came forward, but there will be more doing stuff like that imo.
 
V

Vim

Guest
So what are you trying to accomplish then? You tell us you want to get the truth out and you don't care about how people think. Yet you and Sharma are on this topic like two watchdogs trying to correct people and defend yourself and your actions in every reply.


You should just thank them that they actually ARE telling the facts. It's not like they are trying to "explain" or "apologize" or "gain back respect".. They're just telling us what GOA wouldn't

Thanks Laroma n Sharma.
 
G

Glyph_mid

Guest
Originally posted by Derric
What these two guys did wasn't really the right thing to do,but when I look at the flames here it looks like they've killed someone and took his money.
Noone really got hurt,right? We lost some time in a computer game,oh no..let's roast them over an open fire..

Eh, you are missing out the fact that GOA lost alot of euroes, and although its just a company name, theres actually real people behind it, doing their job...good or not, and making a living that way
 
V

Vim

Guest
Originally posted by Sarnat And Mr Security expert, ever heard of the fact that no system is safe. There is always a security hole[/B]

Of course, this is obvious. But "Social Hacking" rarely works on large companies with really GOOD security (The reason why "normal employees" rarely have access to anywhere, they can be real security hole). Last resort is always raw force n remote computer so you won't get caught so easily.
 
H

Haldar

Guest
reposting story
=============
The inside story (10/09/03)

First words:

I would like to apologize for lying to all the people asking about what happened to my accounts during the past month. Obviously I, contrary to what I said, knew why my accounts had been banned, which I guess a lot of you probably figured out anyway. I'll get back to that later.
I also realize that this post will agitate a great deal of people who will be slagging me off, but as I got screwed over by GOA, and won't be playing again, I really don't care what people will say or think about me. I just thought the community deserved to know what really happened.
People are likely to be blaming me for all GOA's systems being down for the past 3 weeks, cause you need a scapegoat, and now you have one. To be honest, I couldn't care less. If you feel like you need to blame someone else than GOA, you can blame me.
In no way is this written to "win" sympathy from anyone.
English isn't my mother tongue, so bare with my written english.
I don't have any precise information on the technical aspect of this story (ie. how information was obtained) as, like described below, MrX was the backbone.
I have intentionally left out some bits of the story that contained a lot of "confidential" information from GOA, which I obviously have no interest in publishing.
It all began about 5 months ago, when I got to know a nice person (hereafter referred to as MrX) through a DAoC Emulator project, Dawn of Light. The friendship with MrX didn't really get interesting until about 2 months ago, when he confronted me, saying he had gained access to a gamemaster account on one of the german servers. Obviously I didn't believe MrX, so I went to Avalon to create a character, to have him prove that he did indeed have gamemaster status. By the time he had ported me to the Hibernian Dragonlair and altered my level to 70, I was convinced. MrX had indeed obtained access to a gamemaster account. He played around with altering my character for about 15 minutes until I decided it was too risky, and logged off the account. This all happened the night between the 22nd and 23rd July. I later, that same day, proceeded to submit a RightNow report about a "Hacked GM account", and also contacted Kemor (Prydwen Gamemaster) directly over ICQ telling him about the incident. I also had them wipe the level 70 stalker off my account that was created the night before. Needless to say, I never mentioned the reporting to MrX, and he didn't seem to care about the gamemaster account not working anymore at the time either. Also, as you might have guessed, the RightNow ticket was handled within 10 minutes, which must be some kind of a record.

As the day went by, MrX told me he found some cool documents, which he proceeded to send to me. Of course, I was curious, and started to read through the documents he had sent me. The documents were the internal Customer Support manuals from GOA. While I understood very little about the contents of those documents, I started to wonder where MrX got all this stuff from. Up until this point I hadn't questioned him about that. I didn't give it much more thought, and just ignored it. One day later, 24th of July, MrX contacted me again, asking me to log on to Carnac, a new french server. I'm not a complete moron, and I thought to myself "I bet he got hold of another GM account" and then proceeded to log on to Carnac. Surely enough, MrX had himself another character with gamemaster status, and wanted to play around some more. I had to leave for a few hours, and told him I would be back later that same evening. I returned the night between 24th and 25th of July around 1am, and at that time MrX had figured out how to create new working gamemaster characters. I won't bore you with all the details about what we did, but mostly we did harmless stuff like flying around, hitting epic mobs while invulnerable and stuff like that. I decided at the time not to report the incident again, and to be honest I don't really remember why. I guess my curiosity about what MrX was able to just shadowed my conscience so much I completely ignored the fact that what we were doing ingame was exploiting.

A couple of days later, 27th of July, MrX had obtained gamemaster accounts to all the european servers. I got greedy, and wanted to be able to do what he was doing (in terms of ingame actions) on the english servers, which is where I played, so I had him promote characters on my personal accounts to gamemasters on excalibur and prydwen. At the time, I didn't give much thought about my accounts getting banned, which was probably the biggest mistake I ever made. I mean, obviously they would find out eventually, and when they did, the chance of my accounts not getting banned would be very slim. But, I still went ahead and have gamemaster characters made. At this time, MrX had also got hold of the actual gamemaster manual, which he had also sent my way, so not knowing the right commands for doing stuff was not an issue anymore.

About 2 weeks passed without talking a lot with MrX, so I figured he had lost interest in what he was doing, so I didn't give it much thought. But, 12th of August, MrX once again contacted me very breifly, and sent me a character analysis tool for the us servers which wasn't working, so actually I have no idea why he sent it to me. I guess it was just a way to show me that he wasn't "done" yet. Another 4 days passed, now 16th of August, before I talked to MrX again, and this time he contacted me because he apparently needed a character promoted to gamemaster on Prydwen. I was busy at the time, but the day after, 17th of August, I promoted his character to gamemaster.

This is about when things started to go bad (in my point of view). 18th of August around noon, my accounts (2) were terminated. This is about 3 weeks after it all started. I submit a ticket to RightNow asking why I had been banned, as I hadn't got any notice about it. Obviously I knew why I had been banned, but I wanted to hear it from GOA, but as you might have guessed, all I got was a typical standard form answere saying "You account has been banned for multiple illegal activities".

That same evening, MrX had his account(s) banned as well. Up until this point, all I knew was MrX had access to a lot of GM accounts, but boys was I in for a suprise. Apparently, the time where we hadn't been communicating, MrX had been harvesting information from the GOA network. Obviously I won't share the information he gave me, but he had access to almost everything inside, that being RightNow, databases, gameservers and support/gm client machines. He even packed a copy of one of the gameservers for us to download! At this point, I was starting to get cold feet. Part of me was thinking, "I'm banned, why not have some fun with it" but the other was thinking "This is getting way out of hand".

After being frustrated with the RightNow answer I got, I decided to grab a couple of random unused accounts from the RightNow interface and cause some havoc. A good friend of mine, who will remain unnamed, joined me that evening with the "event". As you might have figured out, the "event" i'm talking about is the one that happened at APK in Emain on Prydwen the night between 20th and 21st of August. After about an hours fun with various epic mobs, we decided to log off. We had a great laugh doing that, and I was personally "snooping" (listening in on) the Bad Omen group that was in Emain at that time, and from what I could tell they were having fun as well. And my apologies to Blejsarus, the other person that was with me that evening seemed to hold a grudge against you, so he pretty much just put /stick on your ass and spawned mobs in your trail.

During the day of the 21st of August, I decided to confess my sins. I told MrX that I was going to come clean with GOA and tell them about what I did, and needless to say he wasn't too happy about that, since that would involve me giving GOA all the information he gathered for the past month. So I proceeded to contact Lawrence (a German Gamemaster) on IRC, and asked him if I gave them all the information I had (which supposedly could help them close their security breach) could I get my personal accounts reopened. At that time they still didn't know what information I could give, but Lawrence told me he would ask his teamleader (or supervisor) and let me know. He came back to me a couple of minutes later, saying that if I had information that could help them close the security breach, he had been authorized to reopen my accounts. This is also why I didn't come clean about what happened sooner, as I was hoping to get my accounts, and characters, back without too much information getting "out". I then proceeded to hand in all the information I had, which resulted in a 4 hour chat. Lawrence the told me, that he would pass the information to Kemor, who was the one investigating the case, and any further contact would be made by him. I later that same day asked Kemor about an approximately time of my accounts being reopened, and the answer was "early next week", that being around 25th/26th of August.

Nothing happened for 3 weeks. I was held off by being told, by Kemor, that they couldn't reopen my accounts because of RightNow being down. Then today, 10th of September, after contacting Kemor on ICQ, he told me one of my accounts had been reopened. I logged on, and was suprised to see the account completely stripped of characters. I contacted Kemor once again, asking what happened to my characters, and why only one of my accounts had been reopened when the agreement was reopening both my accounts. The answer I got was "I was told only to open one". Needless to say I wasn't very pleased with that answer, as logs I have of all the chatsessions clearly show the agreement was to reopen both my accounts. I then proceeded to ask why all my characters had been stripped, since that was never mentioned to me in the 1 month period. The answer was "You got your account back, be glad, period". Again I was really displeased by the answer I got. I know many of you will say "haha you muppet, that's what you deserved" and you might be right, but nonetheless I made an agreement with Lawrence upon first contact, and they screwed me over. So, now I have one account with all the characters stripped from it, which is also why I decided to write this "confession", as I very much doubt I will ever be playing again, and the community deserved to know what happened instead of all the lies published by GOA/Mythic.

As some of you might think after reading this (if you made it this far) is that i'm making all this up to slag off GOA even further. However, I have logs of all the chatsessions I had with Lawrence/Kemor from day one, which I have been reading through while writing this, and nowhere did they mention stripping off all my characters, or did they mention I would only get one of my two accounts reopened. In the end, the "good cop bad cop" act Lawrence and Kemor put up almost had me fooled.

It's been a nice 17 months of playing on and off, but unless GOA decides to do a 180 and stick to their original agreement this will be my official goodbye.



Signed,

Laroma
================================

well, alll i can say that /dev/hands of goa employers protrude from /dev/arse.
 
V

Vim

Guest
Eh, you are missing out the fact that GOA lost alot of euroes, and although its just a company name, theres actually real people behind it, doing their job...good or not, and making a living that way

May it be a lesson for them. GOA has been losing thousands of euros since the release of EU DAOC by bad CustomerCare (What is indeed one of the most important aspects of tomorrows business life, GOA just doesn't figure it out) and general fuckups, slow patching and so forth (altho patching is slowly getting better)

And yes i know it's because of the translations..
 
P

Perka

Guest
HAHA... I'm gonna try that social hacking shit... mailto:kemor@goa.com "This is teh supahvis0r, gifv me passwords kthx"

And... I wanna know who this MrX is, from the looks of it he's either gotten quite lucky or is a good hacker. Either way, lucky for us that atleast one person was brave enough to come forth with the info.

If this had not been reported to GOA there could have been some seeeerious mayhem... if MrX had access to all the things reported and he knew what he was doing he could have caused so much damage to possibly make goa go bankrupt...

So thanks for being honest and reporting this. I would absolutely have toyed around a little if I got the oppurtunity as would everyone else, if they say they wouldn't they are lying.
 
O

old.yaruar

Guest
Originally posted by Sharma
Any good hacker knows to cover his tracks, its possible to leave an IP that traces to a BT internet/phone box in London..
Any decent cracker wouldn't have been doing this, and certainly wouldn't have been passing out the information to strangers. Smells like disgruntled employee or semi literate script kiddie to me. Both of whom don't usually cover their tracks that well.

If it had been a good hacker we probably still wouldn't have known about the breach unless they left goa a calling card.
 
O

old.yaruar

Guest
Originally posted by Sarnat
Big deal? It is a big deal for many people. They paid to play and now they cant. It's a major fucking deal to GOA, too. They must have lost tens of thousands euros on this incident.

And Mr Security expert, ever heard of the fact that no system is safe. There is always a security hole.

For example at my school, 2 of my friends were on a computer security course where they had an assigment about "social hacking". They did a series of 5 tests. One test was sending classic "this is superuser of the lab, send me your pass because xxx". Other one was gaining access to a switch room. And so on. Every single test was successful. Every system can be cracked if you know how.
Social engineering is the true tool of the cracker. Mitnick admitted he got most of his information through charm alone.

I've personally managed to convince web companies to give me administrator passwords by just sweet talking them (legally I might add as they were sites the companies I worked for owned, just they had lost the passwords...) it's scarily easy. And even easier if you can get physical access to the office, which again isn't that tricky...
 
P

Perka

Guest
This was very interesting reading if you have time to spare... quite long, but very interesting indeed.

grc.com/dos/grcdos.htm

can't post full url's :/ just put the www infront of the adress
 
J

Jupitus

Guest
Originally posted by Perka
So thanks for being honest and reporting this. I would absolutely have toyed around a little if I got the oppurtunity as would everyone else, if they say they wouldn't they are lying.

I wouldn't.

You calling me a liar?
 
D

dr_doctor

Guest
What a bunch of sympethetic pathetic posts.

I assume Laroma got hell to pay. And frankly, with good reason.
 
O

old.Attle

Guest
I seriously hope you and your friends get your asses dragged into court for this. GOA shouldn't let these extra costs be covered by our subscriptions. Imo the l33t h4xx0rz should pay for this. This must have cost GOA 100 000's euros if you count bad PR, Administrative costs, 1 month free subscription, extra staff, overtime and so on. Enjoy!

Regarding your "The inside story" is all just a big fat lameass excuse. It's really sad to see how poor your judgement is. You knew that you shouldn't have access to GM account, still you used it. I guess if you had found a loaded gun and the street you would have picked it up and used it, even though you know that its wrong, claiming "It wasn't my fault, someone put it there."

I'm sure you'll have a nice time in court, and I'll really hope you get your asses nail to the wall for this.

Have a nice day!
 
Z

Zii

Guest
sooo agree with you old.Attle and i hope you get what you deserve for doing this laro..
 
Status
Not open for further replies.

Users who are viewing this thread

Top Bottom