[POE2: EA] Final Update on the Hack

แชร์
ฝัง
  • เผยแพร่เมื่อ 4 ก.พ. 2025
  • stivanablon responded!
    He didn't say much and when pressed, immediately ignored me.
    I think we found our man.
    Not much we can do here tbh. If GGG wants to investigate further, they can always ask me for more information. I've already made a report on this guy, please don't take things into your hands and contact him. Also, ever since the server maintenance, I've not lost anything else.
    Hope you guys enjoyed this investigation and had fun!

ความคิดเห็น • 40

  • @Creamagination
    @Creamagination หลายเดือนก่อน +2

    GGG Said in the forums that their systems are robust and players who got hacked are at their own fault.

  • @alexanderngo8910
    @alexanderngo8910 หลายเดือนก่อน +4

    Do update us on GGG response to your hack. Hopefully its a PoE isolated incident cause if ppl can use a game to backdoor access your machine, GGG will be in so much heat, and from folks they dont want to be associated with.

    • @ErikaPwnz
      @ErikaPwnz หลายเดือนก่อน

      Nah, mindless fanboys will justify everything. If it was every other arpg, fanboys would have already buried them alive.

  • @laizerwoolf
    @laizerwoolf หลายเดือนก่อน

    Your password and steam account is safe. The hacker probably exploit a well known poe1 bug, where sometimes you can access other people character in the character selection screen. If the hacker can exploit the bug in a controlled manner, they might have access to other people account, bypassing login and steam account.
    Here is the quote from reddit :
    "just happened to me too. i was switching characters and the character list had someone elses names. i logged in and was able to look into their stash.
    i had to log back to title screen to get back to mine."

  • @boki1337
    @boki1337 หลายเดือนก่อน +5

    I got hacked too. I have (had) 2 good gear characters worth each around 100 div + 160div from my stash is gone. One character was completly stripped naked the other one wasn touched. Seems like the sessionID is maybe even only for a character not the whole account. I didnt play the untouched character for ~2weeks.
    Other fun fact:
    I could not login via Standalone at POE2 EA Release because my mailadress is pretty old and it got deactivated by the provider + i cannot retrieve the mailadress because i used fake information as a kid back then and cant confirm my ID/Data to them. (Right now i only play via Steam and 2FA). I have a open ticket at GGG since release day and they even LOCKED my standalone account until they resolve the issue and change my mailadress to a new one after i have to do several checks to confirm its my account (im at mail 2 right now and didnt heard back from then since december 18th)
    Still i got hacked with a locked standalone account with literally no access to the mail and steam 2fa.. The hijacking is 100% on ggg's server end

  • @TheTmkGOD
    @TheTmkGOD หลายเดือนก่อน +2

    Some players atm prefer not to trade, to not be vulnerable. seems like the vulnerability might be related to grabbing your session id while trading, and might be also related to staying in your hideout after you log out, but not sure.
    i stopped trading atm and scattered my orbs across my stashes so in case of a hack, they won't find all of my stuff and i can recoup and not start over

    • @Uberjager
      @Uberjager  หลายเดือนก่อน +1

      I think all we have is speculation at this point till GGG releases a statement (if they will).
      Tbh, I'm pretty chill about it. All I essentially lost was a mirror and 150 divs and (thank god) my characters can still play.
      I'm no holding my breath for GGG to talk about this issue and I'll be moving on to do other stuff.

    • @Gopstop222
      @Gopstop222 หลายเดือนก่อน

      that is cope anyone who gets hacked is doing one of these 3 things and then they cry they got hacked
      1. used RMT site
      2. downloaded some kinda overlay program for PoE 2
      3. clicked some fishy link he thought isnt fishy

  • @Nuttapon2537
    @Nuttapon2537 หลายเดือนก่อน +1

    i got hacked too , so bad news in morning
    ggg cant help us

  • @talazarrt6931
    @talazarrt6931 หลายเดือนก่อน +1

    He probably freaked out on how the hell you found out it was him 😂

  • @Rakschas666
    @Rakschas666 หลายเดือนก่อน

    If someone wrote that to me I wouldnt discuss anything with them. The questions here are already establishing that you are accusing him. That might be rightfully so, wether there were innocent or guilty, the only correct move here is to put the person that is "out of the blue" spamming you with accusations or hacking on ignore. After all this hacking shit, are you really blaming a guy for not trading or for putting his PoE profile on private?! That makes ZERO sense. That is an "I know it was him officer, because he looks guilty!" statement. I can get behind all the other investigative stuff and find it perfectly reasonable to go with options that are "most likely" or "best guess" and certainly this is good enough to forward it to GGG.

    • @Uberjager
      @Uberjager  หลายเดือนก่อน

      I didn't start the conversation with accusations.
      I started by saying hi and wanting to start a conversation. He didn't reply (for 15-20 minutes).
      When he didn't respond I figure the only way to actually get him to say something is to say something provocative to see if it would trigger a response and it did. (which is why you have this video)
      I stated throughout this video that I'm not sure if its him. I only stated my suspicions and the likelihood that it could be him.
      I do NOT condone that viewers take things into their own hands, if they do so its their decision to make and hence their consequences to bear (if any). My only role here is to provide information into my problem and my own investigation into that problem. I don't want or expect other people to do anything about a problem that is clearly mine. My objective here is to investigate my account breach and document it, not start a witchhunt. Hope this is clear.

    • @Rakschas666
      @Rakschas666 หลายเดือนก่อน

      @@Uberjager Yo mate, dont take this as me making a harsh judgement. What you did was totaly within the limits what what is or what at least should be considered reasonable actions of someone affected by illegal actions of another. They fucked with your shit. No one likes that to have happen to them. I sympathize with your situation first and foremost. It was just me saying his reaction is somewhat understandable and non-sussy as "the kids" would put it these days. I hope they catch the bastards doing this, I hope some small measure of ... restitution or "satisfaction" can be given to you folks who got their experience ruined. Hope you are well personally. Godspeed.

    • @Uberjager
      @Uberjager  หลายเดือนก่อน

      @@Rakschas666 hey np dude. just explaining my stance and point of view. Have a good day ahead!

  • @Fanny-cv3ul
    @Fanny-cv3ul หลายเดือนก่อน

    Hey man , i have some questions for the stat stacking build u Made , can i reach u on Discord or something else?

  • @yzwme586
    @yzwme586 21 วันที่ผ่านมา

    So was this due to the steam admin account being compromised or? GGG came out with a statement and discussed it in their questions video a day or two ago. Just wondering if we're good now as far as accounts being hacked. I hope they catch the bastards that did this though, they'd get permabanned if it was me...

    • @Uberjager
      @Uberjager  20 วันที่ผ่านมา

      No idea. Just waiting for GGG to do an investigation.

  • @IanDonoo
    @IanDonoo หลายเดือนก่อน +1

    I dont understand. How does one manage to go into someones account just by the session ID? Any IT experts out there who can enlighten me?

    • @TheTeramon
      @TheTeramon หลายเดือนก่อน

      Session ID in PoE is an unique account key for the API and the site. It is unknown at the moment, how they get into account without changing password. But, in theory, someone can access your account on site with knowledge of session id. Perhaps, it is a vulnerability in API from GGG side.

    • @beta_J
      @beta_J หลายเดือนก่อน

      I haven't read up on this in particular but it sounds like some client side exploits I'm familiar with.
      Basically, many sites after you use your password create a session key or cookie to store what is used to access your account.
      This usually has a time out but is stored locally in your browser to give you access for a period of time. It's not your "password" but usually some kind of hash created with your password and a salt or something that can be verified by the website.
      Because these are stored locally in your browser and in traffic they can be stolen if someone has either access to your browser or unencrypted traffic.
      You can then replay this traffic with tools like burpsuite to gain access.
      Again, I'm not familiar with the situation but this is what it sounds like you were asking about. I am a security researcher though, so I'll try to look into what's been happening

    • @TheTeramon
      @TheTeramon หลายเดือนก่อน

      @@beta_J yes, you can gain access to account with session id in browser, but how do they access the account in game without changing password and going through geo-lock? This is really weird.
      Also, this is a major problem, but GGG is dead silent on this. Something really bad going on behind the scenes.

    • @laizerwoolf
      @laizerwoolf หลายเดือนก่อน

      ​​ I read a reddit account of someone that logged in on an account and get access to other player(not his own), it's replicable up to 3x and it's actually a known poe1 bug. If the hacker is able to exploit the bug in a controlled manner, it's possible that he got access to other player account by passing login and steam accounts. The way he targets accounts probably have something to do with how the trade website works.

    • @laizerwoolf
      @laizerwoolf หลายเดือนก่อน

      ​​
      Here's from reddit :
      #1
      So earlier I log on one of my character and when i log off to switch character, the character selection was someone else. I thought it was a visual bugged, so I log in on one of his character and it was another person account. I didn't do anything on it, just run around a bit feeling confuse then got Dc as he logged back on.
      #2
      just happened to me too. i was switching characters and the character list had someone elses names. i logged in and was able to look into their stash.
      i had to log back to title screen to get back to mine

  • @JK-jw3po
    @JK-jw3po หลายเดือนก่อน +1

    Did the first guy show any proof, or did you just take his word on the name? I mean we expose this dude including his account name to a bunch of internet degenerates, better make sure this is 100% him?

    • @Uberjager
      @Uberjager  หลายเดือนก่อน

      Well all I can say is my role here is to conduct my own investigation (since GGG has not responded) and that this is the result of my investigation.
      I'm not in any way telling other people to take things into their own hands, I have no interest in vigilante justice. If other people want to do that, that's their decision and they have to deal with the consequences of it themselves. I strongly advise that everyone not do anything (since this is my problem, not theirs) and my approach is to let GGG handle what is clearly a GGG problem at their own time and pace.

  • @ferologics
    @ferologics หลายเดือนก่อน

    today i got a message about rmt trade saying 1 div costs 0.2$ ??? wonder if proceeds from those hacks are fueling that (i have a link and discord name screenshot)

    • @gabrielsmith3993
      @gabrielsmith3993 หลายเดือนก่อน +2

      Of course it's all fueled by RMT

  • @BoGGoljubGaming
    @BoGGoljubGaming หลายเดือนก่อน +1

    Let's all keep sending him messages ingame asking the same thing :D

  • @QanarIsDelirious
    @QanarIsDelirious หลายเดือนก่อน

    waiting for final final final update

  • @mas0ny11
    @mas0ny11 หลายเดือนก่อน

    Ggg ban hammer pls although that guys probably a mule pls fix vulnerability

  • @Suzuki-
    @Suzuki- หลายเดือนก่อน

    Wow I hope they ban him for sure

  • @WOMFT
    @WOMFT หลายเดือนก่อน

    Quaking rn

  • @MegasaloPT
    @MegasaloPT หลายเดือนก่อน

    Final final update hahah

    • @Uberjager
      @Uberjager  หลายเดือนก่อน

      Haha I honestly expected him to never respond.

    • @MrJimGaming
      @MrJimGaming หลายเดือนก่อน

      @@Uberjager god dammit, I was hoping your wife was selling divines :( would make for a cool story

  • @stanyeo6650
    @stanyeo6650 หลายเดือนก่อน

    Swee