Adblock breaks this site

Hacked Accounts:

Discussion in 'Approved Suggestions' started by S, Mar 2, 2013.

Thread Status:
Not open for further replies.
  1. S

    S noobies

    Joined:
    Mar 7, 2011
    Posts:
    15,907
    Referrals:
    4
    Sythe Gold:
    3,618
    Discord Unique ID:
    338182178238365701
    Discord Username:
    sm2797
    Two Factor Authentication User
    Hacked Accounts:

    Would it be possible to search inactive accounts of 6+months and automatically remove the recovery email attached to them? That's how most of the accounts have been recovered of recent and in the past, which has lead to countless hackings and scams.

    I think these past two weeks alone ~ 20 inactive semi reputable accounts were recovered and used to scam.

    Hotmail is terrible, and gets exploited frequently - An exploit was made known a few weeks ago, and hence a high chance that these hacked accounts are due to that.

    I know it would be a pain in the ass for Staff if these members did come back, and tried to regain control of their accounts... however I'm sure the staff can handle a few recovery threads if those users return.

    This is all theory, there is no definite way to know that the accounts are getting recovered due to the exploit, however it's by far the most plausible at this point.
     
  2. Fendle

    Fendle Grand Master
    Banned

    Joined:
    Mar 16, 2011
    Posts:
    3,345
    Referrals:
    0
    Sythe Gold:
    0
    Hacked Accounts:

    Support, this could stop so many scams.
     
  3. Punjabi3

    Punjabi3 ☬Grand Master☬
    Retired Sectional Moderator Cracker Head

    Joined:
    Jun 14, 2010
    Posts:
    4,881
    Referrals:
    0
    Sythe Gold:
    204
    Sythe's 10th Anniversary Two Factor Authentication User Halloween 2014 Detective Christmas 2014 Paper Trading Competition Participant In Memory of Jon
    Hacked Accounts:

    Support but NNK just got hacked somehow as well... and he's been active for a while now.
     
  4. Elena

    Elena Now Processing Donations Via RSGP :)
    Banned

    Joined:
    Dec 29, 2012
    Posts:
    2,215
    Referrals:
    1
    Sythe Gold:
    5
    Hacked Accounts:

    Support as well could potentially cut down on scams.
     
  5. S

    S noobies

    Joined:
    Mar 7, 2011
    Posts:
    15,907
    Referrals:
    4
    Sythe Gold:
    3,618
    Discord Unique ID:
    338182178238365701
    Discord Username:
    sm2797
    Two Factor Authentication User
    Hacked Accounts:

    Prob email recovery, via hotmail, aka exploit.
     
  6. Fendle

    Fendle Grand Master
    Banned

    Joined:
    Mar 16, 2011
    Posts:
    3,345
    Referrals:
    0
    Sythe Gold:
    0
    Hacked Accounts:

    Shame about NNK, sucks even more when the user is active because it has 2 victims the person who got scammed and the loss of the Sythe account and the repayments they have to make.
     
  7. S

    S noobies

    Joined:
    Mar 7, 2011
    Posts:
    15,907
    Referrals:
    4
    Sythe Gold:
    3,618
    Discord Unique ID:
    338182178238365701
    Discord Username:
    sm2797
    Two Factor Authentication User
    Hacked Accounts:

    Bumping
     
  8. Sythe

    Sythe Join our discord

    test

    Administrator Village Drunk

    Joined:
    Apr 21, 2005
    Posts:
    8,071
    Referrals:
    467
    Sythe Gold:
    5,281
    Discord Unique ID:
    742989175824842802
    Discord Username:
    Sythe
    Dolan Duck Dolan Trump Supporting Business ???
    Poképedia
    Clefairy Jigglypuff
    Who did this to my freakin' car!
    Hell yeah boooi
    Tier 3 Prizebox Toast Wallet User
    I'm LAAAAAAAME Rust Player Mewtwo Mew Live Free or Die Poké Prizebox (42) Dat Boi
    Hacked Accounts:

    I did a query based on what you suggested. Around 60,000 accounts with hotmail emails have not posted for a year.

    I'm not keen on removing the recovery emails from so many accounts. Many of them may be legitimate and those users may wish to come back at some point.

    Taking suggestions on how to tackle this.

    One thought is to modify the recovery emails so that they can be read off by staff for the purpose of a legit recovery, but not used to automatically recover. For example changing @hotmail.com to @hotmail.null.
     
  9. S

    S noobies

    Joined:
    Mar 7, 2011
    Posts:
    15,907
    Referrals:
    4
    Sythe Gold:
    3,618
    Discord Unique ID:
    338182178238365701
    Discord Username:
    sm2797
    Two Factor Authentication User
    Hacked Accounts:

    They can make a recovery dispute, and the staff can handle it from there. It's rare to see people return after such a long period of time, unless they were known within the community/ex-staff/ex-market traders.

    Personally I believe it would prevent a boatload of hackings and scams.
     
  10. szskateman22

    szskateman22 Oh My Goat.
    $200 USD Donor New

    Joined:
    May 10, 2011
    Posts:
    1,533
    Referrals:
    0
    Sythe Gold:
    11
    St. Patrick's Day 2013 SytheSteamer Doge Two Factor Authentication User
    Hacked Accounts:

    What about sending out a notification to those that have inactive accounts for 1 year+ & hotmail extensions.

    If they do not respond about changing e-mail addresses within 2 weeks, then their account's e-mail will be modified to a void mail (like you suggested Sythe).
     
  11. S

    S noobies

    Joined:
    Mar 7, 2011
    Posts:
    15,907
    Referrals:
    4
    Sythe Gold:
    3,618
    Discord Unique ID:
    338182178238365701
    Discord Username:
    sm2797
    Two Factor Authentication User
    Hacked Accounts:

    I'm pretty sure that would put alot of strain on the server. Also the fact that those emails could already be compromised.
     
  12. szskateman22

    szskateman22 Oh My Goat.
    $200 USD Donor New

    Joined:
    May 10, 2011
    Posts:
    1,533
    Referrals:
    0
    Sythe Gold:
    11
    St. Patrick's Day 2013 SytheSteamer Doge Two Factor Authentication User
    Hacked Accounts:

    It was just a suggestion. And if those accounts are not compromised, then the users could still be using them. You can't NOT inform them about the change. If they have another means of contact you could use that instead.

    Request they change to a different mailing system (gmail/yahoo/etc.) until the security issues are cleared up. I mean I'm just tossing ideas around.
     
  13. Sythe

    Sythe Join our discord

    test

    Administrator Village Drunk

    Joined:
    Apr 21, 2005
    Posts:
    8,071
    Referrals:
    467
    Sythe Gold:
    5,281
    Discord Unique ID:
    742989175824842802
    Discord Username:
    Sythe
    Dolan Duck Dolan Trump Supporting Business ???
    Poképedia
    Clefairy Jigglypuff
    Who did this to my freakin' car!
    Hell yeah boooi
    Tier 3 Prizebox Toast Wallet User
    I'm LAAAAAAAME Rust Player Mewtwo Mew Live Free or Die Poké Prizebox (42) Dat Boi
    Hacked Accounts:

    Cannot send 60k emails at once. Will be blacklisted by mail exchanges.
     
  14. BamBamBiim

    BamBamBiim Active Member
    Banned

    Joined:
    Feb 27, 2013
    Posts:
    143
    Referrals:
    0
    Sythe Gold:
    0
    Hacked Accounts:

    Interesting, support.
     
  15. S

    S noobies

    Joined:
    Mar 7, 2011
    Posts:
    15,907
    Referrals:
    4
    Sythe Gold:
    3,618
    Discord Unique ID:
    338182178238365701
    Discord Username:
    sm2797
    Two Factor Authentication User
    Hacked Accounts:

    This might be too far fetched, what about adding other factors in? E.G, accounts that have been inactive for 6+ months, have 1k+ pc, 2009 or earlier join date. Would it be possible to have an automatic search function do all that?
     
  16. Savitar

    Savitar Active Member
    Banned

    Joined:
    Feb 27, 2013
    Posts:
    233
    Referrals:
    0
    Sythe Gold:
    0
    Hacked Accounts:

    Since hotmail is so well-known for having its exploits, why not just prevent users from registering with hotmail in the future? It doesn't help with the main problem of people recovering old accounts, but it does prevent this sort of thing from happening in the future.
     
  17. ASAPgang

    ASAPgang King
    Banned

    Joined:
    Mar 31, 2012
    Posts:
    2,948
    Referrals:
    0
    Sythe Gold:
    0
    Hacked Accounts:

    What about the people who only own a hotmail account? that would scare them off upon registration, as they would have to register with a new mail provider.
    Support this notion, don't know how we would go about it though.
     
  18. Savitar

    Savitar Active Member
    Banned

    Joined:
    Feb 27, 2013
    Posts:
    233
    Referrals:
    0
    Sythe Gold:
    0
    Hacked Accounts:

    If people really want to be on this site, one of the biggest markets on the Internet, creating a new email address isn't a big deal. Why, it could be done in approximately 3 minutes.
     
  19. S

    S noobies

    Joined:
    Mar 7, 2011
    Posts:
    15,907
    Referrals:
    4
    Sythe Gold:
    3,618
    Discord Unique ID:
    338182178238365701
    Discord Username:
    sm2797
    Two Factor Authentication User
    Hacked Accounts:

  20. I_DONT_BOT

    I_DONT_BOT Free MMing & Sythe Help - PM me
    I_DONT_BOT Donor

    Joined:
    Sep 30, 2009
    Posts:
    9,548
    Referrals:
    25
    Sythe Gold:
    2
    Tier 1 Prizebox
    Hacked Accounts:

    That's a brilliant idea, if they want to recover their account they can post in the acc recovery section and if the I.P's match it can be recovered. Good shout.
     
< Sticky. | Sythe OFFICIAL Servers >
Thread Status:
Not open for further replies.


 
 
Adblock breaks this site