Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Totally unsecured databse

amber-ramber-r Member Posts: 323

The mods are deleting every time someone posts about this on the official site but it's pretty widely known across the web.

 

It seems that it's incredibly easy to hack into the XIV main database, I would be amazed if this didn't end up with a rollback.

 

[mod edit - please don't post links, details, pics, or videos with instructions on how to exploit]

 

«1

Comments

  • SmellyNannerSmellyNanner Member Posts: 152
    So glad I haven't sunk any money into this game yet.. I've been sitting back waiting, watching, seeing what's going to happen with it. This is just another reason to wait even longer. This is sad, very sad.. This day and age, and they're having simple problems like this..? I haven't seen this in some lower budget games, wouldn't expect to see it. In this game though, just wow..
  • LizardEgyptLizardEgypt Member UncommonPosts: 333
    Have you considered that one of the reasons they delete these threads is not because they don't want people to know about it, but because you're now effectively telling anyone with database knowledge exactly where to start prodding to duplicate the exact same thing?

    Currently playing - FF14ARR
    Previous games - SWG, World of Warcraft, ShadowBane, Warhammer, Age of Conan, Darkfall, Planetside Asheron's Call, Everquest, Everquest 2, Too many.

  • ElderknightElderknight Member UncommonPosts: 322

    guess everyone will be 50 at least, but will still have nothing to do at 50.

  • AlamarethAlamareth Member UncommonPosts: 570

    Seriously old news, most of us have known about this for weeks.  The concern trolling is unnecessary and gratuitous.

    Remember the whole 365 billion taken out of the economy?  This was part of that.

    Mtibbs and I even referenced these kind of exploits in the multitude of threads complaining about gil confiscations.  Threads that you (the OP) were involved in.

    Glad to see the air below the sand is so fresh.

  • MattatronMattatron Member Posts: 226
    Originally posted by Alamareth

    Seriously old news, most of us have known about this for weeks.  The concern trolling is unnecessary and gratuitous.

    Remember the whole 365 billion taken out of the economy?  This was part of that.

    Mtibbs and I even referenced these kind of exploits in the multitude of threads complaining about gil confiscations.  Threads that you (the OP) were involved in.

    Glad to see the air below the sand is so fresh.

    So they really can't do any better because the foundation for the game's construction is garbage.

    This makes me feel a little better. I got "cheated" because the game is garbage because the developers are incompetent.

    Why do you still play knowing all this?

     

    edit: Is it just a matter of time, then, until someone finds a more-major exploit and as a result SE takes your level 90 gear or de-levels you? When you are mad and want to express your angry experiences here, then, who will you make fun of as you've done some of us? Yourself?

  • AlamarethAlamareth Member UncommonPosts: 570
    Originally posted by Mattatron
    Originally posted by Alamareth

    Seriously old news, most of us have known about this for weeks.  The concern trolling is unnecessary and gratuitous.

    Remember the whole 365 billion taken out of the economy?  This was part of that.

    Mtibbs and I even referenced these kind of exploits in the multitude of threads complaining about gil confiscations.  Threads that you (the OP) were involved in.

    Glad to see the air below the sand is so fresh.

    So they really can't do any better because the foundation for the game's construction is garbage.

    This makes me feel a little better. I got "cheated" because the game is garbage because the developers are incompetent.

    Why do you still play knowing all this?

     

    edit: Is it just a matter of time, then, until someone finds a more-major exploit and as a result SE takes your level 90 gear or de-levels you? When you are mad and want to express your angry experiences here, then, who will you make fun of as you've done some of us? Yourself?

    I think it's gotten to the point where people are just tired of hearing about the same thing from you. 

    Right, the good ole JUST WAIT - THE WORLD WILL BLOW UP....next time argument.  *yawn*

    I play because it's a good game.  It's fun and well worth the money.

  • aspekxaspekx Member UncommonPosts: 2,167

    im subbed and enjoying the game and will continue to do so for some time to come.

     

    however, that doesn't stop me from wanting to know wth is going on with SE and their incompetence. i want to know /because/ i care, not because i hate or troll.

    "There are at least two kinds of games.
    One could be called finite, the other infinite.
    A finite game is played for the purpose of winning,
    an infinite game for the purpose of continuing play."
    Finite and Infinite Games, James Carse

  • AlamarethAlamareth Member UncommonPosts: 570
    Originally posted by Kuraphimaru

     


    Originally posted by Alamareth
    Seriously old news, most of us have known about this for weeks.  The concern trolling is unnecessary and gratuitous.

     

    Remember the whole 365 billion taken out of the economy?  This was part of that.

    Mtibbs and I even referenced these kind of exploits in the multitude of threads complaining about gil confiscations.  Threads that you (the OP) were involved in.

    Glad to see the air below the sand is so fresh.


     

    Who is us and where else did you hear about this before? Just curious, since its my first time reading regarding this topic.

    People that read the official forums or Reddit.  There have been several screenshots of this happening, just got to these forums significantly later.

  • Fly666monkeyFly666monkey Member UncommonPosts: 161

    It's bad enough that they decided to store character data client side. (Tip for MMO dev's: that a no-no) But to then have that data not go through any form of validation whatsoever when being sent server side?! Is there a word in any language whatsover to adequately describe the level of FAIL being displayed here?!

    I'll be sure to warn any friends of mine to stay far, far away from this game.

  • aspekxaspekx Member UncommonPosts: 2,167
    this is not a troll thread for everyone. i do not spend all my spare time on reddit, et al., so finding out these things here is necessary for me.

    "There are at least two kinds of games.
    One could be called finite, the other infinite.
    A finite game is played for the purpose of winning,
    an infinite game for the purpose of continuing play."
    Finite and Infinite Games, James Carse

  • neumneum Member UncommonPosts: 143
    I can not wait for a skid to jack up the database.  it will be good times.

  • bcbullybcbully Member EpicPosts: 11,838
    Wow thought I had heard it all. 
    "We see fundamentals and we ape in"
  • g0m0rrahg0m0rrah Member UncommonPosts: 325

    Yea this is new info to me.  Its funny how people are trolling this thread by saying its a troll thread, kinda ironic.  Fanboys will go to any length to protect their MMO.

     

      I didnt read the exact details of this hack but if its simple sql injection, someone is probably getting fired.

  • TymorisTymoris Member UncommonPosts: 158

    Judging from SE's past every time someone took advantage of an exploit in such a blatant way, after a while there were massive bannings. Hell they were banning even people that were in close proximitiy to them just to be sure.

    Usually I just get a good laugh when the people that hacked to get their things started bitching about how "unfairly" they were banned.

    image
  • Asm0deusAsm0deus Member EpicPosts: 4,404
    Originally posted by DMKano

    Its still not fixed - a guildy just reported guy leveling alchemy to 50 (from lvl 17) in less than 2min.

    Such a huge exploit needs to be addressed ASAP, other MMOs would be in immediate maint mode with servers offline if you could send bugus DB commands from your client granting you mass XP and levels.

    The fact that this has been going on for weeks is a real shame.

     

    This is why I have not subbed yet, I am waiting for SE to prove to me they give rats arse and will do something about the issues they are having and will actually fix them.

     

    The top few that come to mind are the massive botting, the AOE lag issues and this, which has been known for awhile now. 

     

    Like Alamareth says the game is fun but unlike Alamareth I will not put my head in the sand and  make excuses or be an apologist for SE because I ultimately want them to take us seriously and improve the game.

    I have always felt the best way to encourage companies to do the right thing is with your wallet or lack of along with making sure people are aware of what is what so they can make an informed and accurate decision before purchasing a game.

    Brenics ~ Just to point out I do believe Chris Roberts is going down as the man who cheated backers and took down crowdfunding for gaming.





  • bcbullybcbully Member EpicPosts: 11,838
    This is news worthy. I don't think I've heard anything as bad in a major mmorpg. I wouldn't be surprised to see a few articles from the major gaming sites.
    "We see fundamentals and we ape in"
  • GrailerGrailer Member UncommonPosts: 893
    Originally posted by aspekx

    im subbed and enjoying the game and will continue to do so for some time to come.

     

    however, that doesn't stop me from wanting to know wth is going on with SE and their incompetence. i want to know /because/ i care, not because i hate or troll.

    Same here I subbed because I couldn't find a game that is better .

    Please if anyone knows of a better game that I haven't played let me know so I can start playing that .

     

     

  • GrailerGrailer Member UncommonPosts: 893
    Originally posted by Asm0deus
    Originally posted by DMKano

    Its still not fixed - a guildy just reported guy leveling alchemy to 50 (from lvl 17) in less than 2min.

    Such a huge exploit needs to be addressed ASAP, other MMOs would be in immediate maint mode with servers offline if you could send bugus DB commands from your client granting you mass XP and levels.

    The fact that this has been going on for weeks is a real shame.

     

    This is why I have not subbed yet, I am waiting for SE to prove to me they give rats arse and will do something about the issues they are having and will actually fix them.

     

    The top few that come to mind are the massive botting, the AOE lag issues and this, which has been known for awhile now. 

     

    Like Alamareth says the game is fun but unlike Alamareth I will not put my head in the sand and  make excuses or be an apologist for SE because I ultimately want them to take us seriously and improve the game.

    I have always felt the best way to encourage companies to do the right thing is with your wallet or lack of along with making sure people are aware of what is what so they can make an informed and accurate decision before purchasing a game.

    I don't think they give a rats arse about anything ,  the gil spamming should be easy fix but they haven't done anything about chat spam .

    The AOE lag is a joke ,  I have to run around like a turkey to avoid AOE that might occur in the next 2 seconds .Seems to be server side too .

    A new game will come out soon and this game will be bai bai thanks for the fun , next time learn how to program.

     

     

  • Sircampsalot08Sircampsalot08 Member Posts: 20
    The first screenshot I'd be a little skeptical about.  The game doesn't send packets using JavaScript, which is what a JSON is.  The 2nd screenshot was an exploit with the leve system that was fixed earlier this week.
  • KyleranKyleran Member LegendaryPosts: 43,498
    Originally posted by bcbully
    This is news worthy. I don't think I've heard anything as bad in a major mmorpg. I wouldn't be surprised to see a few articles from the major gaming sites.

    Well, unless of course it isn't really true, then you might not hear much about it.

     

    "True friends stab you in the front." | Oscar Wilde 

    "I need to finish" - Christian Wolff: The Accountant

    Just trying to live long enough to play a new, released MMORPG, playing New Worlds atm

    Fools find no pleasure in understanding but delight in airing their own opinions. Pvbs 18:2, NIV

    Don't just play games, inhabit virtual worlds™

    "This is the most intelligent, well qualified and articulate response to a post I have ever seen on these forums. It's a shame most people here won't have the attention span to read past the second line." - Anon






  • Pratt2112Pratt2112 Member UncommonPosts: 1,636
    Originally posted by Rhoklaw

    I don't get why anyone would get angry about a thread popping up here thats 3 week old news about a very serious problem that has a severe effect on a game, especially a PvE focused game. Economy is everything in a PvE MMO and if that gets out of whack within the first month, then takes 3-6 months to completely fix, you've already had the snowball effect screw everyone else over.

    People are getting angry because a serious flaw in "their game" that has been mostly unknown (not everyone reads reddit, etc) has now been blown open to more people... and there's no way for them to defend or spin it. It's absolutely an indefensible screw-up on SE's part (not that people won't try to defend it anyway).

    So, instead, they turn to insulting the people posting about it. Classic ad hominem. What else can they do? Admit that SE blew it on something? You know that ain't gonna happen. They can't admit SE did anything wrong. It's against their "code of honor"... or whatever it is that makes them defend the game and the devs against every single misstep that comes up. And boy is this game racking up the missteps.

     

  • svannsvann Member RarePosts: 2,230
    Originally posted by Kuraphimaru

     


    Originally posted by Alamareth
    Seriously old news, most of us have known about this for weeks.  The concern trolling is unnecessary and gratuitous.

     

    Remember the whole 365 billion taken out of the economy?  This was part of that.

    Mtibbs and I even referenced these kind of exploits in the multitude of threads complaining about gil confiscations.  Threads that you (the OP) were involved in.

    Glad to see the air below the sand is so fresh.


     

    Who is us and where else did you hear about this before? Just curious, since its my first time reading regarding this topic.

    You can always count on someone saying "This is old news, and stop telling people".

  • GrailerGrailer Member UncommonPosts: 893

    you can pretty much buy cheat software for this game that allows you to get lvl 50 on all jobs and even edit what gear you want .  Pretty crazy stuff that they allowed client to be so much in control .

     

    Wonder if they will fix it or are they just poor programmers ?

  • TwoThreeFourTwoThreeFour Member UncommonPosts: 2,155
    Originally posted by Grailer

    you can pretty much buy cheat software for this game that allows you to get lvl 50 on all jobs and even edit what gear you want .  Pretty crazy stuff that they allowed client to be so much in control .

     

    Wonder if they will fix it or are they just poor programmers ?

    Crafting leve exploit has been proven to exist but there is no proof yet that it isn't limited by your leve allowences amount, so far from s ure that you would be able all crafts to lv50 in 1 day using it.

     

    As for the "edit what gear you want", what proof do you have for it? It is certainly not enough to assume it is true just because someone advertises to sell it.

  • PhryPhry Member LegendaryPosts: 11,004
    Originally posted by Kyleran
    Originally posted by bcbully
    This is news worthy. I don't think I've heard anything as bad in a major mmorpg. I wouldn't be surprised to see a few articles from the major gaming sites.

    Well, unless of course it isn't really true, then you might not hear much about it.

     

    Kind of reminds me of one of Terry Pratchet's 'sayings'

    a lie is twice around the world before the truth has got its boots on.. or something like that. image

Sign In or Register to comment.