Hacker around???

What's going on in Kapilands?
This section is for all about the game itself.

Moderator: moderators

Post Reply
Guest

Hacker around???

Post by Guest » 03.07.2010, 08:09

I've just had an odd request from a new account asking me to send the link for the newspaper as theirs is not working.
When I looked at my link I realised that it contained what seemed to be my unique internal ID, which I certainly do not want anyone else to be aqble to access (I'm quite capable of losing my own money).
Take care.
Alan

Guest

Post by Guest » 03.07.2010, 08:19

Your reaction is absolutely correct! Simply don't respond, but report! :)

Never publish any links from out of your account.
Every link to the newspaper works - so if someone tells you that his link to the KapiTimes does not work he wants to cheat.

In such cases you should directly contact the upjers-support or myself via PM, passing on the User-ID (very important!) of the company asking for your links. Please contact me now. Thanks!

Some helpful links:
Ingame-Profile and User-ID
Unallowed trades/Cheating/Giving accounts away/etc.

Guest

Post by Guest » 07.07.2010, 06:00

That unique number... is that the long string of numbers and letters at the end of the newspaper URL?

User avatar
pearlbay
Posts: 1671
Joined: 14.09.2007, 09:52
Location: Pearlbay Holdings (R1), Bay of Pearls (R2)

Post by pearlbay » 07.07.2010, 07:19

That number is your session ID, and if you pass a link on containing that number, it is quite possible that another player can access your account. The link to the newspaper should also work without that session ID, so like this:

http://www.kapilands.com/zeitung.php4

But generally if a player asks you this, they are after your session ID, as most people would just copy the entire link, including the number at the end. So please always notify our support in such cases under:

http://support.upjers.com

and give us the player's name and - very important - the player's User-ID, so we can make sure he doesn't lure other players into that trap!

Best regards,

pearlbay
In case of urgent problems or questions, please use our support form!

Guest

Post by Guest » 08.07.2010, 06:00

why dose not programmer change that, so it dose not display your session id etc... u know they can make your browser display any address actually that technique is called masking ...
come on its basic as it can be from programing side to do that , even more urgent from security side.. i shouldn't be telling them that, they need to know that .. even make it an must in those days

or is it just excuse for sloppy codding?
Last edited by Guest on 08.07.2010, 06:14, edited 2 times in total.

Guest

Post by Guest » 08.07.2010, 06:06

Ok, thanks Pearlbay.

I have a follow up question. If I were to create a link to my showcase, would that be as disasterous? The text below the info section says:
This showcase is part of the browser game www.kapilands.com
All products mentioned are virtual products and don't have any actual financial value.
This page is not used for commercial purposes as the company only exists inside the game.
That implies that it's possible/allowed to link to it.

User avatar
pearlbay
Posts: 1671
Joined: 14.09.2007, 09:52
Location: Pearlbay Holdings (R1), Bay of Pearls (R2)

Post by pearlbay » 08.07.2010, 07:18

No, the showcase is specifically intended to be used on other websites to present your showcase to other internet-users. All it includes is your user ID. :-)

The session ID and the User ID are actually quite easy to tell apart. You can find your user ID in your Profile - mine on Server 2 for instance is 200407. The session ID is a combination of letters and numbers, and is of course different every time you log back into the game (new session). :-)

Best regards,

pearlbay
In case of urgent problems or questions, please use our support form!

Guest

Post by Guest » 09.07.2010, 07:58

Ok thanks. :D

Been thinking of adding a little Kapiland and Kapi-Regnum blurb to my website.

User avatar
pearlbay
Posts: 1671
Joined: 14.09.2007, 09:52
Location: Pearlbay Holdings (R1), Bay of Pearls (R2)

Post by pearlbay » 09.07.2010, 10:03

Make sure to pick up a few Coins if you do that. ;-)

http://www.forum.kapilands.com/viewtopic.php?t=775

Cheers,

pearlbay
In case of urgent problems or questions, please use our support form!

Guest

Post by Guest » 08.08.2010, 08:45

I just wanted to mention, that in my time of trying different browsers, some have prevented certain pages from opening.

One of those was the newspaper, another was any players showcase.
Both of these appear to be considered pop-ups, which many browsers obviously try to prevent.
And although it can work ok with many sites, a few, including kapilands, continue to have them blocked... Sometimes even with the pop-up blocker switched off.

Now I'm not saying the player was innocent, because I don't know... I'm just saying there is a slight chance that a suggestion of a different broswer might be worth considering for future events like this. It would help to determine wether someone is trying to cheat or not.
A genuine player would obviously try it. A cheat would persist elsewhere.

Many browsers work just fine... But I've used a few that specifically prevent the newspaper and showcases from popping up, even with customised settings.

Guest

Post by Guest » 08.08.2010, 13:40

bogeyboy corp wrote:I just wanted to mention, that in my time of trying different browsers, some have prevented certain pages from opening.

One of those was the newspaper, another was any players showcase.
Both of these appear to be considered pop-ups, which many browsers obviously try to prevent.
And although it can work ok with many sites, a few, including kapilands, continue to have them blocked... Sometimes even with the pop-up blocker switched off.

Now I'm not saying the player was innocent, because I don't know... I'm just saying there is a slight chance that a suggestion of a different broswer might be worth considering for future events like this. It would help to determine wether someone is trying to cheat or not.
A genuine player would obviously try it. A cheat would persist elsewhere.

Many browsers work just fine... But I've used a few that specifically prevent the newspaper and showcases from popping up, even with customised settings.
As for the showcase and newspaper: right clicking + "open in new window" would make sure most browsers no longer see it as a popup.
And with all these warnings that have been given out concerning the session ID in the URL, it would be a stupid idea to still ask for it and not expect trouble. :P

Post Reply