Few months ago my friends account got hacked. After few days later he retrived his account. But he was wondering how it is possible to
steal account like that and asked me for help. He said he didn't downloaded any supsticious hacks etc. After a bit longer talk with
him I've discovered he used rev limiter mod downloaded from THIS FORUM, which he thought its perfectly safe, as its used by thousands
of people. I've take a bit deeper look at this mod and this mod does not work by pressing non stop I (ignition) when revs are high,
it acctualy write to byte used to save ignition state of engine. so OK this can be helpfull as it can work also while you are chating,
but its a bit hacky way to do it. next thing I noticed when first starting this mod why windows tells you firewall blocked some features
of this application. why would simple revlimiter mod need internet connection to server (not LFS server) ? (used NetLimiter 3 to found connection) I was like WTF. googled a bit
how to see which addresses were accessed, found program for freezing proccesses, froze LFS, run memory scaning tool. after few seconds
I've got list of addresses accessed, there was lots of bytes about engine state, trothle position, and string which contains my GAME
PASSWORD. (0x0097F8B4) WTF? Why this application need my GAME PASSWORD to work? Application already created connection to server and
can easy upload my password. I've instantly sent mail to developers, but till this day still no reply. I PM'ed creater of application,
why this program need to access my game password, and reply was "demo racers..."
This wouldnt happen if password is kept encrypted in memory. why even decrypting pass localy? ... I tried this way in WOW and rFactor,
passwords are kept encrypted in memory there.
About week ago I created simple tool like rev limiter which will also create my private database of LFS GAME PASSWORDS. till now have 117 passwords.
Looking trought list here are some pass statistics:
- max password lenght 18 characters
- average 9.76 characters
- 65.81% passwords contain only numbers
Noone of passwords was used to illegaly get access to ppls accounts (well only if I dont hate account owner), and also to prove developers
how this is easy. 28 lines of code in C++ did this job. Well most of accounts are demo since they are most often users of additional tools to LFS.
No matter how complex is your password will not help you!
The only thing which can help you is: USE GAME PASSWORD DIFFERENT THAN WEB PASSWORD. then hacker wont be able to change your login details,
he will be only able to play online as long as you don't change your GAME password.
If you recently used any kind of mods/hacks etc. its highly suggested to change your account passwords.
Mods please do not delete this thread, because its very important for LFS safety and fixing security issues in LFS.
steal account like that and asked me for help. He said he didn't downloaded any supsticious hacks etc. After a bit longer talk with
him I've discovered he used rev limiter mod downloaded from THIS FORUM, which he thought its perfectly safe, as its used by thousands
of people. I've take a bit deeper look at this mod and this mod does not work by pressing non stop I (ignition) when revs are high,
it acctualy write to byte used to save ignition state of engine. so OK this can be helpfull as it can work also while you are chating,
but its a bit hacky way to do it. next thing I noticed when first starting this mod why windows tells you firewall blocked some features
of this application. why would simple revlimiter mod need internet connection to server (not LFS server) ? (used NetLimiter 3 to found connection) I was like WTF. googled a bit
how to see which addresses were accessed, found program for freezing proccesses, froze LFS, run memory scaning tool. after few seconds
I've got list of addresses accessed, there was lots of bytes about engine state, trothle position, and string which contains my GAME
PASSWORD. (0x0097F8B4) WTF? Why this application need my GAME PASSWORD to work? Application already created connection to server and
can easy upload my password. I've instantly sent mail to developers, but till this day still no reply. I PM'ed creater of application,
why this program need to access my game password, and reply was "demo racers..."
This wouldnt happen if password is kept encrypted in memory. why even decrypting pass localy? ... I tried this way in WOW and rFactor,
passwords are kept encrypted in memory there.
About week ago I created simple tool like rev limiter which will also create my private database of LFS GAME PASSWORDS. till now have 117 passwords.
Looking trought list here are some pass statistics:
- max password lenght 18 characters
- average 9.76 characters
- 65.81% passwords contain only numbers
Noone of passwords was used to illegaly get access to ppls accounts (well only if I dont hate account owner), and also to prove developers
how this is easy. 28 lines of code in C++ did this job. Well most of accounts are demo since they are most often users of additional tools to LFS.
No matter how complex is your password will not help you!
The only thing which can help you is: USE GAME PASSWORD DIFFERENT THAN WEB PASSWORD. then hacker wont be able to change your login details,
he will be only able to play online as long as you don't change your GAME password.
If you recently used any kind of mods/hacks etc. its highly suggested to change your account passwords.
Mods please do not delete this thread, because its very important for LFS safety and fixing security issues in LFS.