New danger of having accounts stolen

from evenbalance:

Friday 10.22.2004 [4:30PM]

"Players need to be aware of the existence of a new exploit on non-SCI servers that has appeared with the newly released v2.2 AA patch. Using new undocumented PB server commands in combination with PB screenshots, a malicious Admin can in unlikely circumstances capture in a PB screenshot the player's AA account password stored in user.ini (the "Remember Username/Password" box on the "Personnel Jacket" screen controls whether or not the password is stored in that file). This does not affect official servers nor other servers leased from SCI. When playing on servers hosted elsewhere, players should leave the server immediately if the user password appears on the screen during gameplay. This will prevent any requested screenshots from transferring to the malicious admin. Please report to us at [email protected] the IP address of any servers that are trying to make use of this exploit by displaying your password on your playing screen during gameplay."

ie might be best sticking only to official servers for the time being
 
Top