One Hour One Life Forums

a multiplayer game of parenting and civilization building

You are not logged in.

#1 2020-04-24 06:35:10

jord1990
Moderator
Registered: 2018-03-03
Posts: 186

PSA: Account phising going on

Now I know we all know how the internet works, but on the off chance that some of you are new to the internet.

A salty loser is currently spreading phising links through discord. If anyone EVER sends you a random link. DONT CLICK ON IT. Its that easy.

If you there are any new web adresses to check out for the game you will hear about them through Jason himself, A moderator or a trusted member of the community.

Please note that ANY link that asks you to log into to ANY EXISTING ACCOUNT is likely a way to SCAM YOU.

This was internet 101, have a nice day!

Offline

#2 2020-04-24 06:56:00

DiscardedSlinky
DubiousSlinker
From: Discord
Registered: 2019-05-06
Posts: 688

Re: PSA: Account phising going on

Just for more info, they're trying to sell it as a way to get stats for your account.

The only way to get stats is through whatever's program https://onehouronelife.com/forums/viewtopic.php?id=5607

Or asking someone in the discord to get them for you.


I'm Slinky and I hate it here.
I also /blush.

Offline

#3 2020-04-24 14:14:44

jasonrohrer
Administrator
Registered: 2017-02-13
Posts: 4,805

Re: PSA: Account phising going on

Wow, this is weird.

Can someone email me a sample phishing link, just so I can check out how it works?

jasonrohrer AT fastmail DOT fm

Offline

#4 2020-04-24 20:37:36

Morti
Member
Registered: 2018-04-06
Posts: 1,323

Re: PSA: Account phising going on

jasonrohrer wrote:

Wow, this is weird.

Can someone email me a sample phishing link, just so I can check out how it works?

jasonrohrer AT fastmail DOT fm

:devious smile:
Azazello likes a good hunt.

Offline

#5 2020-04-24 22:17:58

sigmen4020
Member
Registered: 2019-01-05
Posts: 850

Re: PSA: Account phising going on

jasonrohrer wrote:

Wow, this is weird.

Can someone email me a sample phishing link, just so I can check out how it works?

jasonrohrer AT fastmail DOT fm

We had one, but he's disabled it to destroy evidence.

Last edited by sigmen4020 (2020-04-24 22:18:12)


For the time being, I think we have enough content.

Offline

#6 2024-03-12 03:53:50

ShadyForgotTempmailpass
Banned
Registered: 2024-03-12
Posts: 5

Re: PSA: Account phising going on

couldn't you make a bot that generates random numbers and letters than have another bot that enters them into a thing to fish out accounts at a constant rate till it gets a working link. That shit is bad ngl, all it takes is a group of github buddies and a c++ program written by chat gpt.

Last edited by ShadyForgotTempmailpass (2024-03-12 03:54:16)

Offline

#7 2024-03-12 03:57:48

ShadyForgotTempmailpass
Banned
Registered: 2024-03-12
Posts: 5

Re: PSA: Account phising going on

or you could load the randomly generated pins up like gulfballs in a gulfball cannon

Last edited by ShadyForgotTempmailpass (2024-03-12 03:58:00)

Offline

#8 2024-03-12 04:04:54

ShadyForgotTempmailpass
Banned
Registered: 2024-03-12
Posts: 5

Re: PSA: Account phising going on

just to understand how dangerous this is if someone were to find the algorithm for making these links a robot could go search through 1000's just for a specific line of text that indicates the search was a success via using its own algorithm to win over it. Just a very fat chance of finding it though. Like AI: extremely low, likely less than 0.000001% which to a computer is like a 100% chance because of how fast they are. (don't test that math)

Last edited by ShadyForgotTempmailpass (2024-03-12 04:05:36)

Offline

#9 2024-03-12 05:20:14

ShadyForgotTempmailpass
Banned
Registered: 2024-03-12
Posts: 5

Re: PSA: Account phising going on

i tested it and if you got the algorithm to a tea its entirely possible and really all you need is afew automation whatevers. I used a combination of 3 as an example. XXXXX-XXXXX-XXXXX. If somebody wanted to get it that would be 2000 out of infinite

Offline

#10 2024-03-12 06:26:08

ratshady
Banned
Registered: 2024-03-12
Posts: 5

Re: PSA: Account phising going on

but yeah u see what I'm saying, the chances of somebody getting the direct combination of 4 rows of five digits is very rare. XXXXX-XXXXX-XXXXX-XXXXX thats like trying to guess a pin made of numbers. also jason don't mistake this for account fishing smile just an observation I'm living on the edge because 20$ is an escape pod to not have to live and deal with any consequences

Last edited by ratshady (2024-03-12 06:34:15)

Offline

#11 2024-03-14 03:36:24

squishysquid
Member
Registered: 2023-01-16
Posts: 23

Re: PSA: Account phising going on

ShadyForgotTempmailpass wrote:

couldn't you make a bot that generates random numbers and letters than have another bot that enters them into a thing to fish out accounts at a constant rate till it gets a working link. That shit is bad ngl, all it takes is a group of github buddies and a c++ program written by chat gpt.


people figured that out early days of the internet how to handle that. you just rate limit it, 1 login attempt a minute per ip address and you'd be waiting years to find 1 account.

probably doesn't even need to do that because it's with email combination.

Last edited by squishysquid (2024-03-14 03:38:03)

Offline

#12 2024-03-14 06:27:21

ShadyDeRats
Banned
Registered: 2024-03-14
Posts: 62

Re: PSA: Account phising going on

Not if you use the account key with the attached link which is a vulnerability, and on top of that with a virtual machine you could be running more than one of these. The actual login where you get the secret forum code and your email and password is susceptible because it uses the actual account key at the end and all you need is the key to get all the information to the account. It even tells you if its wrong or not with no rate limit because its designed to give you your account than walk off, with the algorithm you could have one of those big servers handling all of this at a rate of 10,000's per vm. So Jason should really get that checked out, it is early internet software afterall, right? Now we got programs that can do all that using simple microsoft extensions and Ai that can teach the average kid to do just about anything.

Last edited by ShadyDeRats (2024-03-14 06:32:56)


5,350 days alive!!!!

Offline

#13 2024-03-15 20:14:27

selalov734
Member
Registered: 2021-06-01
Posts: 77

Re: PSA: Account phising going on

shady could you calculate how long it would take to guess a correct key if you have 1 million tries a second?

first how many possible keys exist? you said the key is 20 characters long, how many different characters can one position be?
is it from A-Z (25) and also has numbers (10), so 35 different possibilities for each character.

Lets assume there are 10 million valid keys and we can guess 1 million times per second than we can calculate it like this:

press F12 to open javascript console and paste this in:

Math.pow(35, 20) / 1e6 / 1e7 / 60 / 60 / 24 / 365

Math.pow(35, 20) = how many possible keys exist
1e6 = 1 million tries per second
1e7 = 10 million valid keys
/ 60 / 60 / 24 / 365 = per year

it would roughly take 24129830992 years to find a valid key
24 billion years

Offline

#14 2024-03-15 20:47:15

ShadyDeRats
Banned
Registered: 2024-03-14
Posts: 62

Re: PSA: Account phising going on

I think you've underestimated a single man's capability in a world where opportunity is everywhere.

----------------------
server

----------------------
server

----------------------
server

----------------------

server

---------------------
----------------------
server

----------------------
server

----------------------
server

----------------------

server

---------------------
----------------------
server

----------------------
server

----------------------
server

----------------------

server

---------------------
The amount of computers that can be ran with copies of this theoretical software and multiple instances at that is unbelievable. There could be a trillion tries a second, don't underestimate humans. Keep in mind that we covered our entire planet in wires to communicate and sent machines into space that allow us to scan the earth just so we can know the weather and how to drive. We landed on the moon, the amount of accounts one man with real dedication could fish is impossibly high. An average company server has 64 gb of ram, so sandbox levels of ram. All they gotta do is set up a big network and run the software very very very hard and all that yadayadayada. If there is a human than it will happen.

Last edited by ShadyDeRats (2024-03-15 20:49:28)


5,350 days alive!!!!

Offline

#15 2024-03-15 21:02:34

selalov734
Member
Registered: 2021-06-01
Posts: 77

Re: PSA: Account phising going on

ShadyDeRats wrote:

----------------------
server

----------------------

server

---------------------
----------------------
server

At first I thought it is impossible, but than i saw you copy pasting many lines with server and dashed lines and suddenly i realized it is possible.

Offline

#16 2024-03-16 05:42:15

ShadyDeRats
Banned
Registered: 2024-03-14
Posts: 62

Re: PSA: Account phising going on

yes


5,350 days alive!!!!

Offline

Board footer

Powered by FluxBB