Old usgn accounts exploits?
18 replies



21.09.14 05:19:11 pm
Well, It was another day moderating at -[IFwsI]- Jail when I saw the familiar name of an account I banned, named Herobrine Steve. Anyhow, I check his USGN and he had one surprisingly but what was more surprising was this:



Another moderator suggested that it was DC himself, but I overruled that idea because of the total nabbiness of an aura overflowing from him.
Apart from just our lil' herobrine here, another usual player also had a really old usgn.


I'm perplexed at this. Were the account compromised by them or what? Because when I checked, both of the accounts had a "Last Active: 11 years ago" and both of these accounts were created back in 2003/2004. If these accounts were hacked then this would compromise the integrity of all the USGN accounts.
Note: I've seen both of these players with multiple USGNs or none at all.
Cheers, nighthawk.



Another moderator suggested that it was DC himself, but I overruled that idea because of the total nabbiness of an aura overflowing from him.
Apart from just our lil' herobrine here, another usual player also had a really old usgn.


I'm perplexed at this. Were the account compromised by them or what? Because when I checked, both of the accounts had a "Last Active: 11 years ago" and both of these accounts were created back in 2003/2004. If these accounts were hacked then this would compromise the integrity of all the USGN accounts.
Note: I've seen both of these players with multiple USGNs or none at all.
Cheers, nighthawk.
That weird for me too, maybe they have hacked these accounts to control the entire functionality (include the data of join and play).
I checked these usgn's and i found the accounts: @
K0dO_ShOrOn: and @
HILFlos:.
I don't know if this is true but it may be.
I checked these usgn's and i found the accounts: @


I don't know if this is true but it may be.
Some little smart-asses recently took control over various old accounts by simply registering expired e-mail accounts which were connected to these accounts.
I stopped that exploit several weeks ago by blocking recovery for super old accounts. I banned all suspicious accounts but it's possible that I missed some or that people found other ways to get access to them.
I'll investigate this even though I'm pretty tired of all the account trouble.
Edit:
First obviously hijacked by guessing password.
Second: I don't know but it's simply too suspicious.
Both banned.
To everyone: Stop claiming old accounts. It's not allowed and it will lead to a ban of your other accounts as well. Even trying to log in into accounts which aren't yours can lead to punishments.
I stopped that exploit several weeks ago by blocking recovery for super old accounts. I banned all suspicious accounts but it's possible that I missed some or that people found other ways to get access to them.
I'll investigate this even though I'm pretty tired of all the account trouble.
Edit:
First obviously hijacked by guessing password.
Second: I don't know but it's simply too suspicious.
Both banned.
To everyone: Stop claiming old accounts. It's not allowed and it will lead to a ban of your other accounts as well. Even trying to log in into accounts which aren't yours can lead to punishments.
edited 1×, last 21.09.14 07:13:29 pm
Just for the fun of it before this topic dies.
145.255.79.53 and U.S.G.N. ID #136
145.255.79.53 and U.S.G.N. ID #9887
103.14.60.173 is using U.S.G.N. ID #23
No confirmation for general usgn O.o
145.255.79.53 and U.S.G.N. ID #136
145.255.79.53 and U.S.G.N. ID #9887
103.14.60.173 is using U.S.G.N. ID #23
No confirmation for general usgn O.o
I see. O.o I'll attempt a lil' check on suspicious players on servers myself and report any compromised USGN findings here.
ID 1 is DC's ID, so it can't be used through the "bug" mentioned here.
Hexenverbrennung, Inquisition, Kreuzzüge... Wir wissen, wie man feiert! - Ihre Kirche

ID 1 is DC's ID, so it can't be used through the "bug" mentioned here.
Your ID can't be used too, because you're so smart
Greetings again, I got report from @
eledah: of Herobrine loitering in the server again with the usgn: @
puRe: (6547). It could probably be the same guy, but I'm not sure as I've seen this "puRe" guy playing before. But this herobrine name sure is quite popular. ._.
Anyhow, this could be a "false positive".


Anyhow, this could be a "false positive".
@
DC: CS2D 1.2.6 IDEA!
add View USGN ID in CS2D View Details
#ID Nick (S:|D:) @USGN_ID
it's very useful!

add View USGN ID in CS2D View Details
#ID Nick (S:|D:) @USGN_ID
it's very useful!

Please use the CS2D idea thread for all suggestions. (don't really do it in this particular case as this has been suggested and declined already!)
30.09.14 04:41:54 pm

Hey Guys i met This USGN Account Hacker Name
C4 Name : -[Crazy]- Furty_@()
Facebook Name : M-h---a c---a g-m---r
Country : Indonesia
He's my Friend Now

he says he can Hack all our Account and you DC
and he can hack Facebook credits
and he have 6 accounts in usgn and 1 is real Hidden
he's Powerful Hacker and [Censored]
DC my private message to you is "i'm Honest" Right!
then here!, this is my Warn! to all
Starkzz,DC,Engineer he can hack account

@
davidgumazon: I can't believe him what he said, he want to scare us to be in the center of attention.
In my opinion this is totaly fake what he said that he is powerful hacker.


In my opinion this is totaly fake what he said that he is powerful hacker.
@
GeoB99: ok you want a proof ?
he tell me username and password this user
http://pastebin.com/RNU9HqBq
Try Login! and it works
Wuhahahahahhahahaha!
he didn't say he's powerful hacker
he's powerful hacker for me

he tell me username and password this user
http://pastebin.com/RNU9HqBq
Try Login! and it works
Wuhahahahahhahahaha!

he didn't say he's powerful hacker
he's powerful hacker for me

@
davidgumazon: Not accepting people here who are threatening me and the website and who are wasting my time with shit like this. Full ban for you. Grow up.
p.s.: this guy is not a "hacker" at all and you are pathetic if you think he's powerful. But if he is such a powerful hacker: Ask him to unban you with his unbelievable hacking powers. Haha...

p.s.: this guy is not a "hacker" at all and you are pathetic if you think he's powerful. But if he is such a powerful hacker: Ask him to unban you with his unbelievable hacking powers. Haha...
Apologies for the 319 days bump but this happened as of now, same guy, another exploited USGN. ;0
Edit: Seems the usgn was already reported by Capn' kenpachi, but anyhows, still not banned. o.o
Code:
1
#12 name: [Troll clan]Herobrinestev , usgn: 9887 , ip: 188.135.47.8
Edit: Seems the usgn was already reported by Capn' kenpachi, but anyhows, still not banned. o.o
How can you tell that it is stolen? I can't tell for sure. There was no website activity with it at all in the last 6 years. So at least it has not been stolen using the old e-mail trick that has been discussed here earlier.
No website activity for that long but in-game logins are suspicious too though. Might be a case of "super weak password that has been guessed / brute forced easily". I decided to ban it.
No website activity for that long but in-game logins are suspicious too though. Might be a case of "super weak password that has been guessed / brute forced easily". I decided to ban it.
It's stolen because:
Herobrine Steve has multiple really old USGN accounts
I haven't seen his exploited USGNs have website activity except for in-game activity (as you stated).
Herobrine Steve doesn't use USGNs.
I've banned(in-game) whatever USGN he's had, which includes the latest prefix numerical USGN(s) of "14".
Therefore, wouldn't that make this individual's USGN usage absolutely suspicious? ;0



I've banned(in-game) whatever USGN he's had, which includes the latest prefix numerical USGN(s) of "14".
Therefore, wouldn't that make this individual's USGN usage absolutely suspicious? ;0



