Hack The Server

H

HackTheServer

Guest
Hack The server
------------------

First of all, don't expect anything special, everything i'll explain here is plain obvious.
What i'm going to explain is how a hacker thinks. A Hacker doesn't even have to know you in real life.
He can do it the hard way, by using self written programs/finding leaks in software or,
he can do it the easy way. And with Easy i mean really Easy. You'd be surprised how easy it is to 'Hack' Someone.

A Hacker only needs to know 2 things to get access to someones DAoC Acc.
1. His E-mail Address and
2. His Login/Password.
Alot people use Free Email Server sites. Sites like Yahoo,Hotmail,MSN,Mail,Casino,.. .
Most private Email Servers from providers also have a login to the Email Inbox on their site.
Maybe you don't know immediatly from where @telenet.be comes but i'm pretty sure you'd figure out fast
which site gives access to that Emailbox. Now Lets start with (1) How do I get someone Email Address.
prolly the easiest one of the 2. Lets just take Barrysworld. The info from your victim was immediatly
viewable in his 'Info'. Getting someone EMail by asking his is another way .I Don't think you'd sound
suspisious when you would ask your victim for his Email Address. Now only thing that rests is the Password.
Since many EmailServers use EmailAddress as Login .Only thing left is the password and you're in.
It seems hard but it isn't. First of all you can guess, normally you won't have much luck with this
except when you know him in real life, then you'd have a large library of words he uses alot..
But like I said at the beginning, you don't know him in real life. So what can I do?
Most Subscribe Emailsites have a password Recovery system (something you don't have
with provider EmailSites normally). But Hotmail and even old Barrysworld had/have(?) this.
They ask you for the already know EmailAddress and then followed by an option:
1. Send me an Email
2. Answer secret question.
Pretty sure everyone knows these Questions:
'What is your mom's Name', 'What is your Dog's Name' , 'What's your Birthday?'
Heh how hard can it be..

-Hacker Enters random private chat
-Hacker : OMG, my dog just died ;((((
-Victim : I feel sorry for you m8, I myself got one too..
-Hacker : Oh really?? Whats his name. *Bingo*

Now this method only works on 1 person. A guy which you focus on. But I, I want to do it good,
I want to hit the jackpot. I want to know the password of 30% of the server. Now let's say i'm starting a LottoForum.
But a Lotto where you can't loose. Every Week i'm giving away 10plat to the guy who rolls the highest number between 1-100.000
if the number is lower then 50.000 the Jackpot doubles next week to 20plat!.
Some guilds already use some similar system to lotto stuff the Guild won on raid X.
I make some commercial on Freddyshouse , IRC, use to friends together in this complot to spread the news..
But To Participate you need to Subscribe (login) Now who wouldn't do this, who isn't interested in this Jackpot.
You "Can't loose"!! and its Free!!. Wrong, I'd have it all. I, mister Admin ,
just recieved the EmailAddress from so many blind people, and their matching password. Since more then 90% uses the same password
over and over again because otherwise i'd be hard to remember Password X for site X and Password Y for site Y etc.
So In the end, I'm the owner of alot new accounts. ofcouse if you want to do this good you give away 1-2 weeks the Jackpot.
The more ppl subscribe to your LottoForum, the better for you! :D
Not Reality? Ofcouse this doesn't exist. Or does it? Every Server has about 100 guilds, every guild got a site ,
some even have an own public and private forum and I think you can figure out the rest...
Currently every Forum Admin controls your account. Some people think they are smart, they make a new Email Account for
private stuff: keys for programs, bank stuff, passwords to accounts, etc. nodoby knows this EmailAdress, so you'd think you're safe!
To Activate your private EmailAddress you need to Activate it with your "Funny" EmailAddress account.
But like everyone knows, every EmailSite got this default setting "[x] Send me Junkmail". So your "private" EmailSite is sending your
"Funny" EmailAddress some junk once in a while. A hacker only needs to wait for a mail like this or browse his "deleted/junkmail box"
and bingo he knows your "Private" EmailAdress. Browse to the site, Choose 'Lost Password' & 'Send me Email with new password'
(to the Funny Email Account) and he's in.

I think this makes things clear for people that already have been hacked. There are so many ways to 'Hack' someone on an Easy way.
The point of this story was to show how easy it is, how dumb and blind some people are. Mostly if you got hacked,
it's your own fault. Real hackers which use Programs and Leaks to get information don't do this
kind of dangerous work for stupid DAoC accounts, There is so much to tell, a hacker will always find a backdoor.
But mostly, it is you giving him the key to it.

A.
 

ReaLX

Fledgling Freddie
Joined
Jan 22, 2004
Messages
139
So let's sum it up:


You just made that "anonymous" HackTheServer account on FH. The admins (biffeh, etc...) can gather ip information. U can then check the ISP from your IP address. Then u know the Provider. U phone the provider to ask "your" e-mail address, because your "forgot" it, and 90% of the ppl have static ip addresses, and your broadband connection has a static ip known at the ISP, so they can check it out for you. So now we have YOUR email address.

Oh let's also do a /who <ip> on irc so we can have a chat about my dead dog, so i know your secret question, for your webmail bases ISP mail with DAoC info...

Got yourself hacked....


Go jerk off on real ICT skills mate, FO here, and FO "hacking"....
morons :/
 

Jaem-

Can't get enough of FH
Joined
Jan 20, 2004
Messages
2,498
This post this anon twit has made, just gives people ideas.

There are enough warnings around to try to prevent being targeted imo, don't need people provoking the curious minds of some wannabe script kiddie.
 

Blondy

Fledgling Freddie
Joined
Dec 24, 2003
Messages
294
Damn this guys a muppet.
+1 lol

But seriously go post on some other forum please.

OMG HE GONNA HACKZOR ME?!
 

Escape

Can't get enough of FH
Joined
Dec 26, 2003
Messages
1,643
I'm not sure why you're freaking out and flaming the guy when he's made a very valid point: Don't use the same password on every site.

At least a different password should be used for your work/home PC, email logins, forums etc.
Use completely random passwords for guilds and similar websites.

And keep a seperate email address for invoices, etc.
 

Sigurd

Banned
Joined
Dec 25, 2003
Messages
911
Anyone with an ounce of common sense would realise this, I've hacked games sites repeatedly just by tricking idiots into giving me their passwords. That was a long time ago though, I'm good now etc.
 

Nxs

One of Freddy's beloved
Joined
Dec 23, 2003
Messages
478
Interesting post that will hopefully remind people :-

Use different passwords
Use different email accounts (if possible)
Never give your details to anyone

Ohh... and you're refering to a Cracker... not a Hacker <stops nitpicking>
 

Haki

Fledgling Freddie
Joined
Feb 1, 2004
Messages
54
Now the hacker will get you!!

That is very important to know! Everone shall be carefull with this!
I just waiting on my password now (i have waited in 6months almost) and maybe it is a hacker! I dont get my password back! I do everthing but i just awaysting my time, ill never get the password i think! I have one level 50 and 3 level 20 and 1 level 21!! And the hacker is in there and take everthing!! I hate hackers!!!!!!!!!

My words to the Hackers: kiss my ass :kissit: Someone gonna kill you and leave you in the woods! :touch:
You are just bad monsters wishing to mezz with other nice people!! Thats just boring!
:flame: Im so happy that EVERONE OF YOU GONNA DIE AND BURN IN HELL! :flame:
 

Stranger

Fledgling Freddie
Joined
Dec 27, 2003
Messages
249
lol @ ppl laughing at truth...
it's like laughing at someone telling that: milk is white, fridge is white.. and then asks: what cow drinks? most ppl would say MILK at once (that's tested so about 90% caught on this, and u are one of them :p ) but cows drink water... if u got the point here, dont be so selfassured... there's always one guy, who's smarter than u are.
 

Lejemorder

Fledgling Freddie
Joined
Jan 9, 2004
Messages
891
Nxs said:
Interesting post that will hopefully remind people :-

Use different passwords
Use different email accounts (if possible)
Never give your details to anyone

Ohh... and you're refering to a Cracker... not a Hacker <stops nitpicking>

yep a hacker only look on anotherws comp and maybe change the background to show he have been there.

a crackers goal is to infict another comp, by deleting stuff or just fucking u comp.

In many way aint hacking illegal, it r just like going in to u garden or maybe going in be the unlocked door and then leave a msg bout he have been here.
where the cracker is the theif there want to steal.
 

yaruar

Can't get enough of FH
Joined
Dec 22, 2003
Messages
2,617
Lejemorder said:
yep a hacker only look on anotherws comp and maybe change the background to show he have been there.

a crackers goal is to infict another comp, by deleting stuff or just fucking u comp.

In many way aint hacking illegal, it r just like going in to u garden or maybe going in be the unlocked door and then leave a msg bout he have been here.
where the cracker is the theif there want to steal.

Actually a hacker is just someone who hacks code (programs with no real design paradigm).

A cracker is anyone who breaks into systems.

This is pure social engineering, which TBH is a piece of piss for anyone with half a brain (and easy to guard against, all you need to do is keep your wits about you)
 

Cyfr

Banned
Joined
Dec 22, 2003
Messages
1,726
I think you will find the ways of 'hacking' you have posted are simply social enginering.

edit: *notices yaruar's post* You beat me dam it :(
 

yaruar

Can't get enough of FH
Joined
Dec 22, 2003
Messages
2,617
Cyfr said:
I think you will find the ways of 'hacking' you have posted are simply social enginering.

edit: *notices yaruar's post* You beat me dam it :(

Social engineering itself is a bit of a hobby of mine. It's facinating how much stuff you can get and find out about people. Fortunately i'm not a malicious or greedy individual because it's so easy to do.

It's also come in handy in previous jobs. Once I had to make changes to our corporate website but they had lost all the details of it. It only took me 30 minutes on the phone to get them to change the administrator passwords and send them to me. I didn't even use any formal identification. It's ludicrous just how slack many companies are in their procedures. I spend a lot of time advising people as to how to avoid this kind of stuff and it's actually something i'd like to work on more in a proventative sense.

Everyone is so worried about crackers compromising their systems without realising just how easy it is to get hold of information in low tech ways.
 

Jaem-

Can't get enough of FH
Joined
Jan 20, 2004
Messages
2,498
Alot of cash in that Preventive Security area ;P

A friend of my mothers, was on a couple of hundred a day and all he did was travel around to companies and showed them how easy it was to screw their computers.

Is that the line of work your refering to, Varuar?
 

yaruar

Can't get enough of FH
Joined
Dec 22, 2003
Messages
2,617
Jaem- said:
Alot of cash in that Preventive Security area ;P

A friend of my mothers, was on a couple of hundred a day and all he did was travel around to companies and showed them how easy it was to screw their computers.

Is that the line of work your refering to, Varuar?

sort of, more putting together a decent team and going in and doing full security assessments and audits, although doing more than what most people do in so much as analysing the staff and training them as well as securing the systems. People are complacent when they think computers are secure, when most people in the know realise that the biggest security risk is careless staff.

Simple things like telling my old local pub that hanging credit cards for the tabs up behind the bar in plain view of the drinkers and people outside is just plain careless. All i would have eeeded is t be outside with my 200mm telephoto and I would have acquired 20 cc numbers......
although the money would be in corporations.

although I wouldn't work for 200 a day on it ;)
 

cemi0

Can't get enough of FH
Joined
Dec 31, 2003
Messages
1,791
So HackTheServer is saying:
A) Its stupid to have a email adress at a free provider etc hotmail
B) Its stupid to have same password on your email address as on your profiles

Or? Well, this would be the easy way instead of explaining every kid how to hack.
 

klavrynd

Fledgling Freddie
Joined
Dec 22, 2003
Messages
336
<bangs fist on table> Dammit! Why can't i have the same UI as those guys in the movie , now i'll never be a tuff cr4xx0r! (
 

Moo

Fledgling Freddie
Joined
Dec 22, 2003
Messages
1,106
what i dont get is people leaving their email on hotmail etc with their passwords in it

if you delete them then no one can get to ur daoc acc by hacking ur email

simple.
 

Users who are viewing this thread

Top Bottom