Page 30 of 32 FirstFirst ... 202829303132 LastLast
Results 291 to 300 of 316

Thread: Neopets security breach

  1. #291
    kiiraa's Avatar
    Joined
    Jul 2022
    Posts
    25
    Userbars
    4
    Thanks
    33
    Thanked
    17/9
    DL/UL
    11/0
    Mentioned
    5 times
    Time Online
    1d 22h 12m
    Avg. Time Online
    4m
    Quote Originally Posted by oventoast View Post
    (...) I would be surprised if even 1,000,000 million new entires are genuine since 2016. Most of it is duplicated or the same players over and over again. (...) So what are you paying for? $100k/4 BTC for maybe 100,000 genuine, non-duplicated, accessible identities at best. Most of those will be people who have been alerted about this and changed/secured their info. Maybe I am stupid, but I really doubt that a neopets username, email, password, IP and birthday is enough to compromise someone's identity in a way that would meaningfully make you enough money to justify spending 4 BTC. (...).
    Well, the older DB didnt have all players which join in +2013. I saw and didnt find my old account. So, maybe this time they have a more complete DB from the players than before, thats why you see the increase of the number of accounts. And about spending money, I think in this world there are people with a LOT of money and nothing to spend. So if you make 50k per month, why not spending 100k for fun? I guess if the hacker can secure it's a live DB access and sell to just one person, it'll sell very quickle. But can one person access all acount and steal all pets and nps? Probably no.

    The person with money to buy wont be using the DB to steal real money from people, they would probably using the info for fun. Like, why would you risk going to jail if you can go YOLO on neopets? Specially if you have 25k-100k to spend.

    I think the bigger problem is if they release the DB to the public and your account is there lol

  2. #292

    Joined
    Jun 2012
    Posts
    2,270
    Pronouns
    He / Him
    Userbars
    40
    Thanks
    1,505
    Thanked
    2,191/821
    DL/UL
    16/0
    Mentioned
    232 times
    Time Online
    65d 14h 33m
    Avg. Time Online
    22m
    Andrew is right, the real (monetary) value does not lie in Neopets itself, but rather the information that comes with the db.

    If you're talking about recovering your BTC's worth by selling Neo stuff, for 4 BTC, you're honestly not going to breakeven. For 1 BTC you could. And that's assuming the live db write access is not patched.

  3. The Following 4 Users Say Thank You to Shawn For This Useful Post:

    Erik. (07-23-2022),I_royalty_I (07-22-2022),oventoast (07-23-2022),Zapdos (07-23-2022)

  4. #293
    I_royalty_I's Avatar
    Joined
    Dec 2011
    Posts
    7,028
    Userbars
    78
    Thanks
    6,794
    Thanked
    10,970/3,916
    DL/UL
    30/0
    Mentioned
    1,998 times
    Time Online
    437d 22h 14m
    Avg. Time Online
    2h 29m
    Quote Originally Posted by Shawn View Post
    Andrew is right, the real (monetary) value does not lie in Neopets itself, but rather the information that comes with the db.

    If you're talking about recovering your BTC's worth by selling Neo stuff, for 4 BTC, you're honestly not going to breakeven. For 1 BTC you could. And that's assuming the live db write access is not patched.
    trust me - I’ve played this thing out 1000 times. I could buy this entire exploit almost 6 times over:.. but I don’t see the value at this point in time. You’d have to find some intrinsic value if you are to make this kind of purchase. But you’d also have to consider the costs of accessing a database with an unreliable proxy and being on the hook once law enforcement comes knocking. That’s not worth the risk. I can say I’d be tempted… just, literally, for my own entertainment.
    i bought so many of those lists from Joe, years ago, but I did it for fun and the thrill of finding some cool shit. I DID find ONE account that made it all worth it. But the odds of that again are slim to none. I see this going unsold, at least the full access, because it’s not worth it. Maybe 5-10 years ago - hell yeah. Gen NPs and items - so worth it. Now, no, not at all.
    Last edited by I_royalty_I; 07-22-2022 at 11:04 PM.
    What's my definition of success?
    Creating something no one else can
    Being brave enough to dream big
    Grindin' when you're told to just quit
    Giving more when you got nothin' left

  5. The Following 2 Users Say Thank You to I_royalty_I For This Useful Post:

    Erik. (07-23-2022),Shawn (07-23-2022)

  6. #294
    Synth Salazzle's Avatar
    Joined
    Mar 2017
    Posts
    2,573
    Pronouns
    Any
    Userbars
    70
    Thanks
    4,545
    Thanked
    4,228/1,697
    DL/UL
    15/0
    Mentioned
    196 times
    Time Online
    76d 11h 24m
    Avg. Time Online
    42m
    I honestly would just keep the bitcoins, nothing's worth getting wrapped up in that shit, they already said they're getting law enforcement involved, getting your hands dirty now is just straight up stupid and reckless.

    userbar: Charmander

    Roland SP-55 by: Honeycomb
    My contributions:
    (you need an account to see links)
    (you need an account to see links)
    (you need an account to see links)
    (you need an account to see links)
    (you need an account to see links)
    by: hearts
    Ryu art by dankRUSE

    Chegg

    by: Rattata


  7. The Following 4 Users Say Thank You to Synth Salazzle For This Useful Post:

    Double.Trouble (07-25-2022),♥ GreyFaerie ♥ (07-23-2022),I_royalty_I (07-23-2022),Miri (07-23-2022)

  8. #295

    Joined
    Jun 2012
    Posts
    2,270
    Pronouns
    He / Him
    Userbars
    40
    Thanks
    1,505
    Thanked
    2,191/821
    DL/UL
    16/0
    Mentioned
    232 times
    Time Online
    65d 14h 33m
    Avg. Time Online
    22m
    4 BTC for the DB + access??

    91,152 USD is a hefty chunk of change for most people.
    Paying 88,392 USD for this without being able to guarantee that the live access won't get patched, while having alerted Jumpstart to the presence of the exploit is too much risk to undertake for a buyer.
    Sure, I could see this sell for 20 to 35k USD, but expecting 102,316 USD for this is too much





  9. The Following 9 Users Say Thank You to Shawn For This Useful Post:

    Aero (07-28-2022),cornishwall (07-23-2022),danii (07-23-2022),♥ GreyFaerie ♥ (07-23-2022),Pringle (07-24-2022),r56 (07-27-2022),RicoBandito (08-01-2022),Tyranitar (07-23-2022),xmilo (07-23-2022)

  10. #296
    Rhymes with Witch's Avatar
    Joined
    Oct 2015
    Posts
    174
    Userbars
    15
    Thanks
    104
    Thanked
    333/117
    DL/UL
    59/0
    Mentioned
    41 times
    Time Online
    23d 13h 50m
    Avg. Time Online
    10m
    After reading this entire thread, honestly ... do we even have any proof this is real? 69 million users... incredibly public about selling... asking 4BTC for something that worth 1BTC... it seems like an overblown practical joke or worse.
    Last edited by Rhymes with Witch; 07-23-2022 at 09:03 PM.
    you talk to me you answer to my pig moomoo

  11. #297
    Jackalope's Avatar
    Joined
    Sep 2021
    Posts
    549
    Pronouns
    she/her
    Userbars
    37
    Thanks
    861
    Thanked
    1,131/457
    DL/UL
    27/0
    Mentioned
    81 times
    Time Online
    8d 20h 22m
    Avg. Time Online
    13m
    Quote Originally Posted by Rhymes with Witch View Post
    After reading this entire thread, honestly ... do we even have any proof this is real? 69 million users... incredibly public about selling... asking 4BTC for something that worth 1BTC... it seems like an overblown practical joke or worse.
    I think someone created an account in game and asked the seller to tell them what the internal info on the account was and the seller was able to tell them, implying that they do in fact have live access. I think someone else mentioned that the person who vouched for the validity was important to the site in some way? I honestly don't know much about that kind of thing but I remember seeing a screenshot to that effect.

    - - - Updated - - -

    That said the seller truly having the access to this swiss cheese ass site and a buyer actually being willing to risk it all for neopets dot com are two very different things.



    Thank you @Orbit for the Jackalope Ryu

  12. #298
    birdies's Avatar
    Joined
    Oct 2021
    Posts
    585
    Userbars
    61
    Thanks
    1,682
    Thanked
    1,790/509
    DL/UL
    7/0
    Mentioned
    61 times
    Time Online
    32d 15h 30m
    Avg. Time Online
    51m
    Jeezy creezy criminy christmas.

    I swear every time I take a break some nonsense goes down. I've just read 30 hecking pages.

    I do have a question though - I work for a company who run a 20+ year old website which has user accounts and message boards etc. Thing of the most ancient creaky form of ancient social media.

    Updating it to 2020+ has been a challenge, especially trying to make it work for an app, but stuff like - adding OTP at logins, adding 2FA for members who want it... that's not hard.

    Our dev team is three people and our site has never been hacked - the biggest problem with hackers we have comes through people's emails getting compromised. We don't need to use nonsense like stackpath to disrupt user experience.

    There are a LOT of creaky bits and a lot of the site is held together by string, but account security is the biggest priority.

    So why *haven't* TNT enabled 2FA? It seems like it would be the easiest way to help secure accounts at least from casual users with access to any previous data breach, and it's not hard to do. So it's just money?

    You'd think they'd save money by not having to bring in lawyers and forensic teams when this happens, but hey.

    Also, considering Neo_Truths contacted them ages ago to say he had DB access, and that site that was unconverting pets also had DB access, have neo not broken a few laws by not clearly informing us their DB wasn't secure before now?

    Honestly, I'll change a few emails and passwords but mainly I'm going to screenshot a bunch of stuff on my accounts because I feel like this dude won't be able to sell and may just put the database up somewhere as pay to access.

  13. The Following 5 Users Say Thank You to birdies For This Useful Post:

    funnybell (07-28-2022),♥ honeycomb ♥ (07-24-2022),Ice (07-24-2022),Pringle (07-24-2022),Synth Salazzle (07-24-2022)

  14. #299
    Kibba's Avatar
    Joined
    Apr 2021
    Posts
    1,391
    Pronouns
    He/Him
    Userbars
    77
    Thanks
    2,020
    Thanked
    2,853/955
    Mentioned
    249 times
    Time Online
    27d 51m
    Avg. Time Online
    35m
    I honestly don't know how TNT handles the information and security of all of its users... Like, Is it that hard to have an
    online security system? How are they facing another attack over and over like it's something that hasn't happened before?

    I'm starting to think the ''Breaches'' are always made by someone at TNT in order to bring the site back at everyones mouths 🙄


    Selling my NC Closet & UC Mutant and Darigan Hissi
    (you need an account to see links)


  15. The Following User Says Thank You to Kibba For This Useful Post:

    Synth Salazzle (07-24-2022)

  16. #300
    DarkSkies's Avatar
    Joined
    Sep 2021
    Posts
    3,099
    Pronouns
    She
    Userbars
    99
    Thanks
    8,014
    Thanked
    5,990/2,315
    DL/UL
    31/0
    Mentioned
    419 times
    Time Online
    84d 21h 11m
    Avg. Time Online
    2h 8m
    There haven't been an update from TNT about this? I honestly wouldn't mind if they shutdown the site for some days, like take your time but please enhance the security.








    ~~ Shooting stars ~~

    Many thanks to:

    @(you need an account to see links) for the Wolf Ryu and @(you need an account to see links) for the Kousetsu puppy <)
    @(you need an account to see links) for my howling wolf and @(you need an account to see links) for my wolf pumpkin <3
    @(you need an account to see links) for my custom userbars and @(you need an account to see links) for the lovely popsicle/lycanroc bar ^^
    @(you need an account to see links) for my star puppy and @(you need an account to see links) for my Rockruff avatar :3


  17. The Following User Says Thank You to DarkSkies For This Useful Post:

    Pringle (07-24-2022)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •