Our server costs ~$56 per month to run. Please consider donating or becoming a Patron to help keep the site running. Help us gain new members by following us on Twitter and liking our page on Facebook!
Current time: February 14, 2025, 10:30 pm

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Hack Attempt
#4
RE: Hack Attempt
Heh.

Since you play Blizzard games, let me inform you of a little security "secret" (open secret) that Blizzard wants to pretend isn't there.

Battle.net is in a bind.

Their old system from Warcraft II: Battle.net Edition uppercased all letters in the password entry.

That means that:

mYSeCrEtPassWoRD and MYSECRETPASSWORD and all variants in between validate for an account that uses any form of "mysecretpassword"

Due to this, the Blizzard does not know the original password that the user "knows".

If they were to fix this but not force a mass password reset (bad), the best they could do is split the authentication services to direct all older services to a legacy framework and all new "improved" services to the new framework.

But they didn't.

Battle.net 2.0, if I recall, suffers the same flaw.

Meaning that it is relatively simple still to break a users password if it is mostly alphabetical symbols, since the casing is irrelevant.

Herp derp Blizzard.

This is what I recall from my days participating the in Broodwar hacking community.
Slave to the Patriarchy no more
Reply



Messages In This Thread
Hack Attempt - by zebo-the-fat - March 18, 2013 at 12:58 pm
RE: Hack Attempt - by Autumnlicious - March 18, 2013 at 1:12 pm
RE: Hack Attempt - by Kayenneh - March 18, 2013 at 1:14 pm
RE: Hack Attempt - by Autumnlicious - March 18, 2013 at 1:28 pm
RE: Hack Attempt - by Kayenneh - March 18, 2013 at 1:36 pm
RE: Hack Attempt - by Autumnlicious - March 18, 2013 at 1:47 pm
RE: Hack Attempt - by Phish - March 19, 2013 at 6:26 am
RE: Hack Attempt - by zebo-the-fat - March 19, 2013 at 11:33 am
RE: Hack Attempt - by Phish - March 19, 2013 at 1:35 pm
RE: Hack Attempt - by jstrodel - April 6, 2013 at 11:07 pm

Possibly Related Threads...
Thread Author Replies Views Last Post
  SpaceX Catch attempt zebo-the-fat 14 780 October 31, 2024 at 2:14 am
Last Post: Fake Messiah
  Analysis of a Facebook social engineering/Javascript "hack" Autumnlicious 4 3549 March 2, 2011 at 9:29 am
Last Post: fr0d0



Users browsing this thread: 2 Guest(s)