Page 26 of 28 FirstFirst ... 162425262728 LastLast
Results 251 to 260 of 274

Thread: Techo Morpher Resurfaces

  1. #251
    Raposa's Avatar
    Joined
    Mar 2015
    Posts
    618
    Pronouns
    any
    Userbars
    30
    Thanks
    4,625
    Thanked
    540/276
    DL/UL
    97/0
    Mentioned
    62 times
    Time Online
    19d 4h 24m
    Avg. Time Online
    8m
    Quote Originally Posted by GeoffryHawk View Post


    This is interesting and new, the NC Transaction log and Premium log in sections are showing a weak security connection now. Something is amiss with the Neopets Hashing.
    That's sp00ky af

    Sent from my SHIELD Tablet using Tapatalk

  2. #252
    Sakuras's Avatar
    Joined
    May 2014
    Posts
    1,806
    Userbars
    23
    Thanks
    11,768
    Thanked
    2,255/724
    DL/UL
    3/0
    Mentioned
    149 times
    Time Online
    40d 6h 6m
    Avg. Time Online
    15m
    Quote Originally Posted by GeoffryHawk View Post


    This is interesting and new, the NC Transaction log and Premium log in sections are showing a weak security connection now. Something is amiss with the Neopets Hashing.
    i don't use NC but what the actual fuck

  3. #253


    Raichuu's Avatar
    Joined
    May 2013
    Posts
    161
    Userbars
    4
    Thanks
    57
    Thanked
    58/37
    DL/UL
    2/0
    Mentioned
    25 times
    Time Online
    23d 9h 16m
    Avg. Time Online
    8m
    I theorize Tony is the Techo Morpher, converting more UC like an ass

  4. #254


    Joined
    May 2014
    Posts
    139
    Userbars
    2
    Thanks
    20
    Thanked
    47/20
    DL/UL
    20/0
    Mentioned
    19 times
    Time Online
    5d 17h 5m
    Avg. Time Online
    2m
    Quote Originally Posted by GeoffryHawk View Post


    This is interesting and new, the NC Transaction log and Premium log in sections are showing a weak security connection now. Something is amiss with the Neopets Hashing.
    That's because of the certificate. Chrome is very anal about certs signed below SHA-2.

    Nothing's changed on Neo's end, and that's the problem. Chrome evolves and SHA-1 becomes much less secure than it was a couple of years ago. In fact, (you need an account to see links).

    (you need an account to see links)

    Neo's "secure" website gets a (you need an account to see links). Not a good sign.
    Last edited by paradox; 06-17-2016 at 09:54 PM.

  5. The Following 4 Users Say Thank You to paradox For This Useful Post:

    DJ Music Man (06-17-2016),Raposa (06-18-2016),Requiem (06-17-2016),Shizuku (06-17-2016)

  6. #255

    Requiem's Avatar
    Joined
    Apr 2016
    Posts
    116
    Userbars
    1
    Thanks
    44
    Thanked
    66/34
    Mentioned
    11 times
    Time Online
    52d 20h 17m
    Avg. Time Online
    25m
    Do you think that might be part of the reason why the techo morpher is able to keep getting into accounts?

  7. The Following 3 Users Say Thank You to Requiem For This Useful Post:

    DJ Music Man (06-17-2016),Raposa (06-18-2016),Sakuras (06-18-2016)

  8. #256


    Joined
    May 2014
    Posts
    139
    Userbars
    2
    Thanks
    20
    Thanked
    47/20
    DL/UL
    20/0
    Mentioned
    19 times
    Time Online
    5d 17h 5m
    Avg. Time Online
    2m
    Quote Originally Posted by Monorail View Post
    Do you think that might be part of the reason why the techo morpher is able to keep getting into accounts?
    Maybe, if he managed to exploit this part of the website. Although since this deals with NC and payment info, I doubt it.

    Neo is so insecure (the regular website) that anyone using a packet sniffer can see your password in plain text if they are on the same WiFi network as you. So if you log in with public WiFi unencrypted and some genius is running Wireshark for some reason, they'll be able to see that as you submit the form (and your username). They likely wouldn't be interested in your Neopets account, but it goes to show that we're in 2016 and Neopets doesn't even use or enforce HTTPS on every page (which isn't hard at all - I could set that up in 2 hours).

    It's a mess. Over the years Neo has been vulnerable to so many things - and exploited almost as much. SQL injection, XSS (cross-site scripting), you name it. This Techo morpher is probably using an SQL injection of some sort to get access to the passwords. I doubt it was from a 2013 dump.

    (you need an account to see links) (if you're curious)

  9. The Following 4 Users Say Thank You to paradox For This Useful Post:

    Deirdre (06-17-2016),Raposa (06-18-2016),Requiem (06-17-2016),Sakuras (06-18-2016)

  10. #257

    Requiem's Avatar
    Joined
    Apr 2016
    Posts
    116
    Userbars
    1
    Thanks
    44
    Thanked
    66/34
    Mentioned
    11 times
    Time Online
    52d 20h 17m
    Avg. Time Online
    25m
    Makes me wonder why I even spend money on Neopets when it's apparent the staff couldn't care less about the security and privacy of its users. :/

  11. #258
    Bottom Frag Hero Hawk's Avatar
    Joined
    Mar 2016
    Posts
    322
    Userbars
    7
    Thanks
    19
    Thanked
    478/122
    DL/UL
    3/0
    Mentioned
    15 times
    Time Online
    17d 14h 5m
    Avg. Time Online
    8m
    @(you need an account to see links)

    Well it's hard ot update and fix the site when you fire everyone who knew what they were doing eh?

  12. #259


    Joined
    May 2014
    Posts
    139
    Userbars
    2
    Thanks
    20
    Thanked
    47/20
    DL/UL
    20/0
    Mentioned
    19 times
    Time Online
    5d 17h 5m
    Avg. Time Online
    2m
    Quote Originally Posted by GeoffryHawk View Post
    @(you need an account to see links)

    Well it's hard ot update and fix the site when you fire everyone who knew what they were doing eh?
    Doubt it. The previous staff had been there for years and they hadn't implemented things that kept users safe either.

  13. #260
    Bottom Frag Hero Hawk's Avatar
    Joined
    Mar 2016
    Posts
    322
    Userbars
    7
    Thanks
    19
    Thanked
    478/122
    DL/UL
    3/0
    Mentioned
    15 times
    Time Online
    17d 14h 5m
    Avg. Time Online
    8m
    @(you need an account to see links)

    I dunno, Nickelodeon had helped, but any updates they had made are now well outdated, and the server move crippled everything. It'd take like a dedicated team and to just take the site down to put it all back together and fix it at this point.

    But now they can't do that they don't have the player base to maintain downtime.

  14. The Following User Says Thank You to Hawk For This Useful Post:

    Raposa (06-18-2016)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •