Email Address:
Password:
Forgot Password?
Advanced Search
Active Players on Sylestia
Category Total Yesterday
Players 2,440 389
Sylestia Pet Data
Category Total Yesterday
Pets 8,234,189 1,275
Generated 655,955 49
Captured 1,189,822 102
Bred 6,388,320 1,124
Statistics updated daily at midnight
Forum Index > News and Announcements > IMPORTANT: Account Security
Page 1 1, 2, 3... 11, 12, 13 Go to Page:
Author Thread Post
Krinadon
Level 75
Shadow of the Moon
Site Administrator
Joined: 12/17/2012
Threads: 1,119
Posts: 14,683
Posted: 12/12/2020 at 7:00 PM Post #1
Hello, all.

So, I discovered a malicious attempt over the past 24-36 hours by an individual who was trying to brute force their way into accounts. The good news is that I do not believe that anything on the site/server was vulnerable, compromised, or anything like that. So I do not think anyone's information was at all compromised on our end.

What was happening was someone was essentially just brute forcing our log in system with specific Username/Password combinations phishing for a match. The vast majority of attempts were Usernames that do not even exist on Sylestia. So my assumption is this person had a list of known compromised Usernames/Passwords and was just trying it on our site using a bot script.

Unfortunately, they ended up discovering 400 matches over the past 24-36 hours. From what I can tell, the vast majority of these matches were for accounts long since abandoned. Every single one of these accounts has had their password forcibly reset. I will eventually be sending out emails to the affected accounts notifying them of the circumstances. But if you happened to be one of these ~400 accounts, your password will no longer work and you will need to use the Forgot Password page to reset it.

Again, just to reiterate, I do not believe anything on Sylestia was compromised during this. This was just a brute force access attempt from some sort of list someone obtained with known Username/Password combinations. This list did not come from Sylestia. I am confident that our data is secure and not at all compromised.

That said, I would advise players to make sure that their Sylestia password is unique and not something used elsewhere.


Changes Will Be Coming

In light of this situation, I will be making quite a few changes to our entire log in system. I will be trying to implement these changes as quickly as I can. I have already implemented some of them to help mitigate against this brute force 'attack'. These are the following changes I am planning:

1. I plan on changing the log in to be your Email Address instead of your Username. This will make it much harder for someone to guess half of your log in credentials right from the start.

2. I plan on improving server-side tracking for log in attempts and put systems in place to automatically thwart brute force attempts. Some of this is already active now after today.

3. I plan on creating an option for players to utilize a form of Two-Factor Authentication via their email. Essentially, if enabled and if a log in action is taken from an unknown or un-whitelisted IP Address, instead of allowing that log in to happen, the server will send a code to your Email Address that will then have to be submitted to allow the log in to complete.

4. I may also change the backup security option from Date of Birth to something else more secure.


Again, I will be trying to implement these improvements as quickly as I can. Please let me know if you have any questions or concerns. Thank you for taking the time to read this.


Update: 12/16 @ 5:30AM
Alright - I have released the first pass of login/account security updates. Firstly, I have added the following Account Security Settings under Account -> Settings:



This new setting has replaced the existing IP Safeguard setting. The IP Safeguard is still active in the background with whatever settings you left it at, however, that will be phased out within a few weeks. It's just a matter of cleaning up the code and getting it out of the system.

This new setting has 4 options:

Safeguard Login Attempts Against: Unknown IP Address (Default Option)
Safeguard Login Attempts Against: Unknown Device/Browser
Safeguard Login Attempts Against: Every Login Attempt
Safeguard Login Attempts Against: None (Not Recommended)


When enabled for a selected option, any successful login attempt (meaning, someone logs in with the correct Username and Password) from an 'unknown' source will result in the following verification process:



This will also send an Email to your account's Registered Email address that will look something like this:



Simply follow the instructions from the prompts to authenticate your login attempt. Once successful, you will log into Sylestia like normal and the IP Address (if that safeguard is selected) or the Device/Browser (if that safeguard is selected) will be stored for 90 Days. After 90 Days, it will expire and you will need to re-authenticate from that location/device again. Please note, the Device/Browser safeguard relies on storing a cookie on that Browser. So if you don't save cookies, it will think you are logging in from a new Device every login attempt.

If you select the safeguard option for every login attempt, then, well, every login attempt will require the authentication verification. This is obviously the most secure option, but might not be suitable for everyone.

If you select no safeguard, there will never be a verification prompt and anyone who has your Username and Password can log in undeterred.


Additional Notes
So, just to reiterate, this is the first pass at improving account security. I have already started some additional security measures behind the scenes that will be fully implemented over the upcoming weeks/months.

At this point, everyone's account is automatically defaulted to the Safeguard against Unknown IP Addresses. Additionally, everyone's original registration IP Address as well as their last log in IP Address were automatically saved as 'Known' IP Addresses for the next 90 days.

If you wish to change this Safeguard setting, just navigate to Account -> Settings and change to the desired setting.

When I have more time, I plan on expanding player customization for these security safeguards. This will include being able to see your currently saved 'Known' locations/devices as well as adjusting the expiration time (which at the moment is defaulted to 90 Days).


Overall, this was quite a chore to integrate into our existing login system. I tried to make sure everything is all synced up properly, but if I missed something and you do encounter any issues, please do not hesitate to let me know.

If you have any questions about anything regarding this update or future updates, please don't hesitate to ask.
Edited By Krinadon on 12/16/2020 at 5:35 AM.
Dragonsrcool54
Level 56
The Perfectionist
Joined: 5/7/2018
Threads: 75
Posts: 65,372
Posted: 12/12/2020 at 7:02 PM Post #2
Thank you for telling us this, Krin. This is very good to know. I hope that guy gets caught and slapped, because hes a moron.
LuciDatum
Level 70
Ghost Writer
Joined: 4/2/2019
Threads: 44
Posts: 865
Posted: 12/12/2020 at 7:05 PM Post #3
Thank you, Krin. I'm glad nobody was hurt, though I haven't a single idea what the reason behind such an attempt would be.
Savynn
Level 75
Sweet Solver
Joined: 12/18/2012
Threads: 214
Posts: 4,485
Posted: 12/12/2020 at 7:06 PM Post #4
What would this person have to gain by doing this?
Krinadon
Level 75
Shadow of the Moon
Site Administrator
Joined: 12/17/2012
Threads: 1,119
Posts: 14,683
Posted: 12/12/2020 at 7:09 PM Post #5
Link: https://www.sylestia.com/forums/?thread=95099&page=1#4
Author: Savynn
Time Posted: 12/12/2020 at 7:06 PM
What would this person have to gain by doing this?


Hard for me to really answer that. Could have just been some personal pet project for the person to see if it would work. Or perhaps they wanted to create a bot army of Sylestia accounts - although that seems very strange to me lol... There's almost no way someone could do that without being noticed and just getting the accounts banned and whatnot.

I really don't have a real answer to that question though.
Edited By Krinadon on 12/12/2020 at 7:10 PM.
Eclipticgalaxy
Level 37
Joined: 9/4/2020
Threads: 16
Posts: 1,242
Posted: 12/12/2020 at 7:11 PM Post #6
ty krin
Theialish
Level 70
Warden of Umbra
Joined: 2/8/2019
Threads: 60
Posts: 4,986
Posted: 12/12/2020 at 7:11 PM Post #7
will everyone be auto-logged out when the email login goes live?

any, nyte revamp when?
Wolfpack2020
Level 70
Warden of Umbra
Joined: 2/10/2018
Threads: 91
Posts: 3,193
Posted: 12/12/2020 at 7:20 PM Post #8
Thank you for telling us Krin, I honestly wonder what kind of a person would want to do this and how in the world they thought it would benefit them.
Dashingash
Level 75
Guardian
Joined: 2/21/2020
Threads: 16
Posts: 258
Posted: 12/12/2020 at 7:21 PM Post #9
Thanks for informing us Krin
Midnightwolf001
Level 75
Candy Dispenser
Joined: 10/8/2018
Threads: 7
Posts: 101
Posted: 12/12/2020 at 7:31 PM Post #10
Thankyou soo much for letting us know of this happening. I greatly appreciate it.
Go to Page:
1, 2, 3... 11, 12, 13
This Page loaded in 0.011 seconds.
Terms of Service | Privacy Policy | Contact Us | Credits | Job Opportunities
© Copyright 2011-2024 Sylestia Games LLC.
All names and logos associated with Sylestia are Trademarks of Sylestia Games LLC.
All other trademarks are the property of their respective owners.
For questions, comments, or concerns please email at Support@Sylestia.com.