No video

They're Locking RuneScape Accounts for Pay

  Рет қаралды 189,045

Crumb

Crumb

3 жыл бұрын

✅ My OSRS Figurines & Gifts: crumb.store/
- Code ‘20off’ at checkout for 20% off your order - available for the first 10 people
Today’s mini documentary covers the recent outbreak of OSRS Account Locking Services. These people are offering to lock players out of their RuneScape account for a fee and it is only possible because of Jagex’s flawed login system. I talk about why it is happening and how you can protect your own account.
Credits
MichaelRS Video:
• Getting Scammed by Ret...
My Links:
►Twitter / crumbosrs
►Instagram / crumbosrs
►Patreon / crumbyt
►Oldschool Runescape (2007) is provided by Jagex.You can play for free here. www.oldschool.r...

Пікірлер: 776
@CrumbRS
@CrumbRS 3 жыл бұрын
✅ My OSRS Figurines & Gifts: crumb.store/ - Code ‘20off’ at checkout for 20% off your order - available for the first 10 people
@dialga236
@dialga236 3 жыл бұрын
the airfresheners are hella neat
@1994tdr14
@1994tdr14 3 жыл бұрын
Just placed an order an hour or so ago. Hope my jad turns out as good as the one in the videos!
@CrumbRS
@CrumbRS 3 жыл бұрын
Thanks a bunch! The one Hanner was showing in the video will be what yours looks like too :) and of you're unhappy I offer free returns for the money back (no ones used this yet!)
@djbobbywip3901
@djbobbywip3901 3 жыл бұрын
runescape claimed to have security updates this year at runefest but theres only a month left and they really have fallen short of their promised goals
@idowhatiwantdowhatisaygoog2361
@idowhatiwantdowhatisaygoog2361 3 жыл бұрын
Yo you're selling boss figurines but not iconic characters like Gnome Child bust or buying gf guy? Cows, Rune chest plate drop, coin stack (on grass tile), life size runes etc
@rip8009
@rip8009 3 жыл бұрын
Jagex: we care about our game! Game literally falling apart Jagex: this is fine.
@ETurns
@ETurns 3 жыл бұрын
Thank you for bringing this more attention. It's pathetic how top players like Woox and Zezima can't play their accounts for literal years and Jagex still hasn't fixed it.
@Stephen_Viele
@Stephen_Viele 3 жыл бұрын
Someone needs to create one of these services and target b0aty faux mmorpg mr mammal and whatever big-name twitch streamers there are and see how long it takes for them to fix it lol.
@lightningfrom9396
@lightningfrom9396 3 жыл бұрын
they would be able to play them if they just changed their login to an email like they were offered, but they are stubborn loser nerds
@austiniscoolduh
@austiniscoolduh 3 жыл бұрын
Supposedly jagex offered zezima to change the login to his email on twitter, but he never responded
@andrewfornes5458
@andrewfornes5458 3 жыл бұрын
Woox is currently going through this. Have you not seen his league acct name? Its literally Cantlogin
@fazeext9777
@fazeext9777 3 жыл бұрын
@@austiniscoolduh why would he tho dumb offer
@spiritofnex
@spiritofnex 3 жыл бұрын
Jagex honestly needs to focus MOST of their man power on this issue. Security is MUCH more important than fun game updates. This is absolutely game breaking, and Jagex is a multi hundred million dollar company. This is completely unacceptable in a modern internet age, and should be fixed as soon as possible.
@morrowmorrow4811
@morrowmorrow4811 3 жыл бұрын
Completely agree with this. Their priority should be SECURITY of their player's accounts.
@reheyesd8666
@reheyesd8666 3 жыл бұрын
Probably understaffed, underfunded, over stressed workers to make those millions
@Pomelu
@Pomelu 3 жыл бұрын
but muh jagex does everything it can do ! the mods are so nice !
@TinyMaxfer
@TinyMaxfer 3 жыл бұрын
'Fun updates' are created by content creators, who have no understanding of security issues. You cant just tell them to stop making updates and invest time into security because they arent the right people for the job..
@JM-zh6zd
@JM-zh6zd 3 жыл бұрын
@@TinyMaxfer he’s talking about jagex as a company, not about their content creator team(s). That’s obvious and your comment is stupid.
@gebot.
@gebot. 3 жыл бұрын
Jagex fix your damn game security, its 2020 almost 2021 ffs. This isnt 2007 anymore.
@hubb3498
@hubb3498 3 жыл бұрын
The real jagex grew old and retired, these new guys are just cashing in.. the only thing they brought to the table was rs3 and that was a huge flop.
@chrislee1774
@chrislee1774 3 жыл бұрын
What surprised me most is they literally *give* your information away with minimal social engineering tactics. It's like these devs don't know a single good practice. It's pathetic.
@hardboiled2987
@hardboiled2987 3 жыл бұрын
jagex is part of this shady shit
@NZRAMBO20
@NZRAMBO20 3 жыл бұрын
Some british teen saying hes gonna mobilize a swat team to your house over runescape my lord
@kylejones1532
@kylejones1532 3 жыл бұрын
I would just laugh at these morons trying to scare you into giving stuff 😂 I would just say yeah okay bye and leave the call
@ErosExMachina
@ErosExMachina 3 жыл бұрын
why do they literally all sound the same too, all northern british guys who are aged 16-21
@deathninja16
@deathninja16 3 жыл бұрын
@@kylejones1532 just laugh they're empty threats. And if they're discovered they go to prison. New laws with extradition will surprise them.
@ATOMiiCChicken
@ATOMiiCChicken 3 жыл бұрын
@@kylejones1532 yeah exaclty you just go alright then lock my fucking account I'll just play a different game cya later
@WB_Mel
@WB_Mel 3 жыл бұрын
@@ErosExMachina We don't consider northerners English its okay
@kyle9954
@kyle9954 3 жыл бұрын
You know it's scary when it's 2020 and Jagex still doesn't let you use special characters and uppercase letters for your password.
@MonaGC.
@MonaGC. 3 жыл бұрын
Uh. It has for a while now. Caps wise
@DrSquillo
@DrSquillo 3 жыл бұрын
@@MonaGC. no it doesnt, go try and get back to me
@ObiJUANcanolli
@ObiJUANcanolli 3 жыл бұрын
@@MonaGC. hes correct, your password on runescape is not case sensitive
@Skullmiser
@Skullmiser 3 жыл бұрын
I have illegal characters in my runescape password.
@turtleownage
@turtleownage 3 жыл бұрын
Excuse me? If your password isn't case sensitive then they're storing their password in plaintext so if someone gets in their databases, they have all passwords, rather than hashes or having to bypass encryption.
@MrLinuxFreak
@MrLinuxFreak 3 жыл бұрын
as a programmer the solution is pretty easy, just change the api endpoints and request a modern captcha every 5 requests or so like they use on their main website
@CrumbRS
@CrumbRS 3 жыл бұрын
Exactly. Tons of papers on the proper way to implement these systems. An overhaul is the solution, not cobbling another fix on an ancient system
@dannyhuigen1613
@dannyhuigen1613 3 жыл бұрын
Programmer here aswell, this is just terrible api design and should be very easy to fix for Jagex. Almost unbelievable the api is designed like this...
@LN_997
@LN_997 3 жыл бұрын
well if you've seen the going rates of pay at jagex you have your answer...
@Alex-qt9om
@Alex-qt9om 3 жыл бұрын
I feel like this system wouldn't work well because there are other services out there that charge a little amount to solve those captchas
@davidbergkvist8352
@davidbergkvist8352 3 жыл бұрын
As a programmer you should realize that this is not a sufficient solution. You can easily solve captchas programmatically without human interaction. An actual easy way to solve this issue is using an IP whitelist to disallow any unwanted login attempts. If your IP is whitelisted you may attempt to proceed to login and use the current system.
@MClolkroketje
@MClolkroketje 3 жыл бұрын
This scares me. Just straight up scares me.
@luisernestochaconguerrero778
@luisernestochaconguerrero778 3 жыл бұрын
its horrible, I got hacked this way some months ago, I couldnt login for days and when I finally manage to get in I was almsot clean..
@dimski6733
@dimski6733 3 жыл бұрын
at this point im just thinking to start grinding a second account so when my main gets hacked it hurts less.... i guess
@kylejones1532
@kylejones1532 3 жыл бұрын
Have 2 step on email worst thing they can do is lock you out of the account for abit only way they can access ya email then is if they have ya phone lol
@user-lq1dk6gr3p
@user-lq1dk6gr3p 3 жыл бұрын
if Gagex would actually pay someone with real skills about hacking/engineering methods/systems to break the game, this would have been PREVENTED
@user-lq1dk6gr3p
@user-lq1dk6gr3p 3 жыл бұрын
@@AnOliviaShapedGremlin IMO the people who do this are people that are younger and very good with computers, student like people testing their abilities. They know how little risk is involved when manipulating a game like this has..
@CrouchingGrandpa
@CrouchingGrandpa 3 жыл бұрын
Disgusting. I sincerly hope that no one has to get hurt before Jagex takes action. By that I mean I don't want to see a swatting related shooting, suicide due to harassament and doxing or anything like that.
@TheZombiesAreComing
@TheZombiesAreComing Жыл бұрын
All of the above happens to Conservatives on a regular basis.
@HowIyy
@HowIyy 3 жыл бұрын
I'm really started to realize Jagex is kind of a laughing stock.
@HebiSnake
@HebiSnake 3 жыл бұрын
Less of that and more that hackers / black hats / exploiters are getting much scarier than they used to be.
@seegreen6484
@seegreen6484 3 жыл бұрын
@@HebiSnake but how can jagex not fix the login spam? There's a way even if it takes a lot of work. They gotta do it if they want to keep the longevity of the game healthy
@HebiSnake
@HebiSnake 3 жыл бұрын
@@seegreen6484 No shit they need to fix that problem I never said they didn't. But there will ALWAYS be some exploit or some shit that bad actors will use to their advantage. It'll take work and they need to do it, and I'm sure jagex will do so, but it takes some time to do that; it's not an easy solution that takes 5 minutes like people act like it is.
@madcroc111
@madcroc111 3 жыл бұрын
@@HebiSnake But this has many easy solutions. They just do not care unless it's public enough. They can give an individual login limit for IPs that have already been used to login. Would fix very many cases. They can say "Due to suspicious activity lately, confirm this login through email" etc. Very easy fix. They have a mobile app that can be used to confirm. 2fa can be used to confirm.
@HebiSnake
@HebiSnake 3 жыл бұрын
​@@madcroc111 Just because a solution is straightforward conceptually does not make it simple to implement if you have to simultaneously alter/remove the existing system without having problems/security breaches in the process. The problem isn't the idea itself, but how to implement that idea without negative repercussions.
@GameDevRogie
@GameDevRogie 3 жыл бұрын
Of COURSE ReturnOfWilderness is in that call, I'll pretend to be surprised for just a minute.
@reececrawford1688
@reececrawford1688 3 жыл бұрын
Just press accept
@omgsurfer
@omgsurfer 3 жыл бұрын
It's years old at this point, ROW is gone
@Eric12886
@Eric12886 3 жыл бұрын
@@omgsurfer the channel is gone but he's still very active scamming and black market
@FlyinRaptorJesus
@FlyinRaptorJesus 3 жыл бұрын
Row is a pos
@prsfdthefdsf8416
@prsfdthefdsf8416 3 жыл бұрын
He scammed me too. He's the biggest scumbag in runescape.
@ericsarason9099
@ericsarason9099 3 жыл бұрын
Botting: Jagex brings in data scientists and machine learning and still fails Brute force attempts: Account wide locks, not even limited to the attacking IP.
@yourdailydab8578
@yourdailydab8578 3 жыл бұрын
If this is happening to you, try to log in on mobile, the “play now”button works even when your pc is locked out. After being logged in on mobile for 10-30 mins, log back in with pc. Works every time. If you have to type password for mobile it’s the same problem unfortunately. And you have to wait. But having mobile logged in is the only tool I know of to combat the issue. Also, change your password. The log in issue hasn’t happened to me in a few weeks now. Like if this helped you
@observer3984
@observer3984 3 жыл бұрын
Steam version also works its the same system as the mobile login
@Szklar
@Szklar 3 жыл бұрын
Do you log in on mobile, then change password, and then log out of mobile, and log right away in pc? what exactly do you do? Cause I dont think it worked for me
@observer3984
@observer3984 3 жыл бұрын
@@Szklar changing password does nothing, but if you're on mobile you can bypass the too monay tries thing because it's an active session, then play a few minutes on mobile, logout and immediately go online on your PC
@Szklar
@Szklar 3 жыл бұрын
@@observer3984 I'll give it a shot thanks for the advice
@DanielLopez0224
@DanielLopez0224 3 жыл бұрын
This is currently happening to me, however it doesn't let me log in to mobile either.. Same error. I checked and my account isn't locked though. What should I do?
@BTChanOSRS
@BTChanOSRS 3 жыл бұрын
How to get a login?? contact customer support, jagex does leak that info their acc recovery is the biggest compromise to acc security they rely on billing details and other stupid stuff that in no way is a real secret so it just makes hijacking jagex easy
@austiniscoolduh
@austiniscoolduh 3 жыл бұрын
Have you ever tried to recover an account? It’s not as easy as ppl make it out to be. When I was trying to recover my account, I needed a Ridiculous amount of info, beyond just billing info. I assume many people can’t even recover their own accounts if they tried because they don’t have enough info. Someone would have to have a lot of data leaked from hacking/db breaches in order for someone to have their account recovered. The majority of hacked accounts are happening because of recovery, mainly hacked emails or other things like that
@noobsaywhat
@noobsaywhat 3 жыл бұрын
dont flex on g.e this will probl save your ass too
@pakazemuk
@pakazemuk 3 жыл бұрын
The accounts first ever used password used to work very well
@MasterLPG
@MasterLPG 3 жыл бұрын
@@noobsaywhat I suspect these people running the log-in attempt macros to block people from accessing their accounts and charging/blackmailing them money for returned access are wise to not target the famous players like B0aty, Mr Mammal, A Friend and Torvesta, but rather the numerous rich players who possess most/all BIS gear in the game but lack any known reputation in the community and are 'nobodies' in the sense that few people care about them, as that way they'll get a lot of money out of these people (be it in-game currency or real life money) without attracting the 'wrong attention' so to speak by targeting Jagex's 'golden boys', meanwhile the rest are left to rot and fend for themselves, courtesy not of Jagex themselves but their master from an 'exotic' foreign land indeed who have fooled some by pretending to now being American via the use of a shell company of sorts. *Ah, the joys of OSRS's darker side of the community! :P*
@BTChanOSRS
@BTChanOSRS 3 жыл бұрын
@@pakazemuk not really, relying on a single password is like building a house over quicksands Osrs needs optional yubikey logins, just like military stuff Customer support is idiot-friendly, but for users with a yuge $ bounty in the game, its so flawed and insecure as jagex can be hijacked, if not yourself
@Pingvinuz
@Pingvinuz 3 жыл бұрын
One super big tip and problably something that will end up fixing this. Since rs3 is on steam you can connect your osrs and steam account and bypass this to many login attempts bug. And i would assume same thing will work on osrs once it comes out on steam Edit: should work if your account is linked to phone too :)
@robbecrabbe6426
@robbecrabbe6426 3 жыл бұрын
If this really works, please like the hell out this comment ^
@Pingvinuz
@Pingvinuz 3 жыл бұрын
@@robbecrabbe6426 it does cause you entirely skip the login screen i have tried it. (For now its rs3 only tho)
@robbecrabbe6426
@robbecrabbe6426 3 жыл бұрын
@@PingvinuzDamn, would be an easy fix!
@alperdogan6760
@alperdogan6760 3 жыл бұрын
If you are able to log in on the website and have an Android, try this; 1) Log in on the website 2) In settings, under 'Linked Accounts' link your Google account to RS 3) Log in using Google via your Android phone on the RS app This worked for my friend to bypass the same thing
@Pingvinuz
@Pingvinuz 3 жыл бұрын
@@alperdogan6760 oh yea you should work the same maybe if you have it linked thru phone
@user-sm3pp8tb1y
@user-sm3pp8tb1y 3 жыл бұрын
Lmao they're like the OsRs Mafia, paying for a protection fee "That's a nice Runescape account ya got there.... Be a shame if... Something happened to it, I'm gonna make you an offa you can't refuse"
@blueeyeddemon6117
@blueeyeddemon6117 3 жыл бұрын
Underrated comment 😂
@Don-xy8yr
@Don-xy8yr 3 жыл бұрын
Finally non leagues content to CONSUME
@ProDiGyZ3rO
@ProDiGyZ3rO 3 жыл бұрын
Its the dmm content that kills it for me
@guitarbass22
@guitarbass22 3 жыл бұрын
There was leagues content in the background.
@askinperson2839
@askinperson2839 3 жыл бұрын
So true
@conker1596
@conker1596 3 жыл бұрын
Plot twist: zezima is locked out because people covering this topic are false logging into his account to use the error for footage.
@MetalRaimon
@MetalRaimon 3 жыл бұрын
Just makes you not want to play this game anymore. It's just crazy... From the toxicity, to scammers, to IRL threats, and crazy exploits like this. Runescape definitely ain't what it used to be anymore.
@Hornhautx
@Hornhautx 3 жыл бұрын
it was never different lul I still remember how I was threatened in skype calls as a little boy because a couple of scammers couldn't get their way. I would lie if I said that it wouldn't have scared me back then, but at least I stubbornly blocked instead of giving in
@LOIN_Official
@LOIN_Official 3 жыл бұрын
Great video man, very informative.
@humantent945
@humantent945 3 жыл бұрын
rust moment
@Zendetta.
@Zendetta. 3 жыл бұрын
Start uploading again
@kea4185
@kea4185 3 жыл бұрын
I love how ironically having an OG log in name is probably the most secure your account can be (as long as you have name changed).
@stephensmith4124
@stephensmith4124 3 жыл бұрын
Yeah I was thinking that, just let people have the classic login name and character name, no email to leak, no back door hacks just type it in or keep logged in and maybe authentication to your recovery email changes, stop all of it
@TryPuttingItInRice
@TryPuttingItInRice 2 жыл бұрын
I love how these companies willingly give out information if you socially engineer it well enough for whomever you're talking to at the support center. What makes it funny is that all these companies say "we will never ask for your information" to prevent scams.
@seffer9772
@seffer9772 2 жыл бұрын
This isn't social engineering. People need to stop using the term so loosely...
@Pawlkoko
@Pawlkoko 3 жыл бұрын
I never played this game, but after seeing few of the videos about this game, it seems like the overall quality of the game is at the same level as it’s graphic
@bogachan4702
@bogachan4702 3 жыл бұрын
I would gladly use that website to lock JMod accounts and see the payment as a donation to the osrs community.
@TheMISTIK2000
@TheMISTIK2000 3 жыл бұрын
And the community don't give a shit about this, they even defend it. As a new player, last day I asked about taking membership but I wasn't so sure because some stuff like this happening. I got called nitpicky, that those ain't problems, crybaby, etc just because I told them there was issues (and I also linked top posts of the subreddit telling very recent history about other kind of problems) They don't care. EDIT : when I created my account I was BAFFLED to see that the password dosen't accept special characters. This is a MAJOR security issue.
@DreamItCraftIt
@DreamItCraftIt 3 жыл бұрын
Yeah this is messed up
@derous
@derous 3 жыл бұрын
btw no one should try searching their login on that rs breach site as they track search data on the site. kinda surprised crumb didn't say that
@TheOisannNetwork
@TheOisannNetwork 3 жыл бұрын
The worst part is that it isn't even hard to fix this issue in general, they just have many badly engineered systems on top of each other.
@eliop14
@eliop14 3 жыл бұрын
Being locked out daily! The reason I've left the game and stopped making videos. Wish Jagex would offer a solution.
@ramis9836
@ramis9836 3 жыл бұрын
I remember your streams/vids! You’re a pker, right? Anyway, facing the same issue here. Someone’s brute forcing my login and there’s nothing I can do about it. Any luck?
@turnipkupo7263
@turnipkupo7263 3 жыл бұрын
Holy shit this is such a strange game in so many ways xD I hope it never dies
@zoinx3260
@zoinx3260 3 жыл бұрын
I don’t even play RuneScape, never have and probably never will but these topics are so interesting. And for that sir you earned my sub
@rabbitofdeth
@rabbitofdeth 3 жыл бұрын
I’m a victim of the spam login bs... Jagex really needs to fix account security and now.. it’s 2020 ffs
@MasterJabbs
@MasterJabbs 3 жыл бұрын
I am also a victim of this scam :/ I was wondering how they got my deets...
@huntershonour2433
@huntershonour2433 3 жыл бұрын
try changing networks, worked for me once.
@TaggedByTim
@TaggedByTim 3 жыл бұрын
@@huntershonour2433 that's actually even worse tbh
@coletrain7464
@coletrain7464 3 жыл бұрын
@arch btw not how it works u tard
@VirgoDPS
@VirgoDPS 3 жыл бұрын
@arch btw did you even watch the video...? And actually pay attention..?
@markhunt3975
@markhunt3975 3 жыл бұрын
Yo I swear to god this started happening to me like a week ago man wtf Edit: I was also rank 3 on leagues around the time and was suspecting being doxxed because of being top page .
@markhunt3975
@markhunt3975 3 жыл бұрын
Update: not had the login error for 3/4 days now, have been playing cold war mostly so the person must be watching my league ranks go down, Joynz is my ign if u want to see what my stats was at the time.
@conker1596
@conker1596 3 жыл бұрын
This reason is the biggest FU jagex can turn their heads on. like if i was approaching the top and i get locked out, i'd practically quit.
@markhunt3975
@markhunt3975 3 жыл бұрын
@@conker1596 I was close to quitting till someone in the comments of a video said that the bug doesn't effect mobile users so I hopped on there and it worked perfectly, while I played mobile I kept trying to login on my computer till it gave me the message "your account is still logged in" then I knew the bug was over, also side note if you try change worlds while logged in it will also kick you out the game and give you that message after.
@Bronek0990
@Bronek0990 3 жыл бұрын
-I'm gonna send a SWAT team to your door -really? What continent do I live on? -... -you know most continents don't have American SWAT? -...
@Not_Facts
@Not_Facts 3 жыл бұрын
They do tbh
@aperson7303
@aperson7303 3 жыл бұрын
@@Not_Facts well no cause it's not american
@ChezBing
@ChezBing 3 жыл бұрын
The website where you fill in your information to see if your account is breached seems like a honeypot made by hackers
@FruitsOfTheHearts
@FruitsOfTheHearts 3 жыл бұрын
@@DelPlays ummm dude, plenty of people use their email account for other services......this is an issue entirely made by Jagex, not Crumb. You're not making any sense bro...
@FruitsOfTheHearts
@FruitsOfTheHearts 3 жыл бұрын
@Bing Honeypots are basically fake infrastructure set to examine the attack against the honeypot. The concept you are referring to could be considered something else, maybe a weird type of phishing attempt? Its pretty sketchy though hahaha
@CrumbRS
@CrumbRS 3 жыл бұрын
@@DelPlays ihavebeenpwned is extremely credible
@wrytte
@wrytte 3 жыл бұрын
I have used haveibeenpwned for years. Helped get my non-tech savy family members to change their passwords since it easily explaines what websites have been breached and when it was. It's absolutely worth checking out.
@FruitsOfTheHearts
@FruitsOfTheHearts 3 жыл бұрын
@@wrytte Yeah I made the same mistake when I was younger. Now I use a password managing software for my PC and phone. Its a lot safer. Kinda like a makeshift SSO. Maybe in the future we'll have integrated SSO with websites? who knows. Temporary security tokens could be the future hahaha
@deathmock5
@deathmock5 3 жыл бұрын
This is what happens, when a game studio get bought out by investors. Its not about the game anymore. Its about the money. Its really not the developers faults either, there told to focus on content, and things that get player engagement by there shareholders. My bets, when this gets enuff stink about it that it might impact the share price. Then they will be told to do something about it. But it will be too late. Blame Macarthur Fortune Holding for this. Even on there website its "Client first" And if you play RS your not the client, your the product.
@MasterLPG
@MasterLPG 3 жыл бұрын
I suspect these people running the log-in attempt macros to block people from accessing their accounts and charging/blackmailing them money for returned access are wise to not target the famous players like B0aty, Mr Mammal, A Friend and Torvesta, but rather the numerous rich players who possess most/all BIS gear in the game but lack any known reputation in the community and are 'nobodies' in the sense that few people care about them, as that way they'll get a lot of money out of these people (be it in-game currency or real life money) without attracting the 'wrong attention' so to speak by targeting Jagex's 'golden boys', meanwhile the rest are left to rot and fend for themselves, courtesy not of Jagex themselves but their master from an 'exotic' foreign land indeed who have fooled some by pretending to now being American via the use of a shell company of sorts. *Ah, the joys of OSRS's darker side of the community! :P*
@zimbu_
@zimbu_ 3 жыл бұрын
This seems more like a problem where the last person who knew anything about Runescape login servers left the company seven years ago.
@haydc608
@haydc608 3 жыл бұрын
Runescape is the only service I know where a password is not case sensitive. Login system is fucked.
@KittyCatsBrokenLeg
@KittyCatsBrokenLeg 3 жыл бұрын
Jagex doesn't give a fuck. Why I haven't played in 6 years. Enjoy your content through.
@markanthony9096
@markanthony9096 3 жыл бұрын
It never seizes to amaze me how theirs always some shenanigans going on in rs and someone’s always up to some bullshit. Love the vids crumb 👍🏼
@chrispearce2081
@chrispearce2081 3 жыл бұрын
@adawbwa no there’s kid not there you fucking idiot
@markanthony9096
@markanthony9096 3 жыл бұрын
@adawbwa learn to spell idiot
@shooterhub2
@shooterhub2 2 жыл бұрын
I recently have been hacked and i have no clue how since i have two step authenticator . For the past two keeps I have been unable to log in with the " too many log in attempts message" that should had been a red flag for me to register a new email and password . I was at my parents house and downloaded runelite , got on for 5 minutes and logged off . The next day I logged in and all my valuables estimated in 300m+ were gone . The person even wiped my pots and food and strangely kept other things in the bank to seem like my account wasn't touched . I feel like I fell for a phishing site but then again i downloaded rune lite from the official website so idk what happened honestly . I have registered a new email with 2SA and changed the password about 3 times and I'm STILL getting locked from my account for hours before I can actually play again , idk what to do or what is happening , jagex replied to my email saying they will try their best to fix the problem and the best way I can play is through Steam 😢
@ChrisChaquay
@ChrisChaquay 3 жыл бұрын
It never ceases to amaze me how much shady and corrupt s*** goes down on RS. Just mind boggling
@schauffeur8393
@schauffeur8393 3 жыл бұрын
Quickest way to sort these things out is to come togethet as a community. If most people stop playing the game for a few days they might realise that they need to do something. As long as everything is going o as usual and they hit daily player targets they wont care.
@matz0rz4o8
@matz0rz4o8 3 жыл бұрын
This shit is scary .. and dark .. I’ve known about this flaw and I have a seperate RuneScape email written on paper with no linked emails and 2fa on everything from email to social media , bank pin , still I try my best to stay safe With display names it’s a lot harder to find out info but there’s always a small chance .. stay safe yall
@yoyoyo3335
@yoyoyo3335 2 жыл бұрын
This is still an issue today, came home from work to this bullshit tonight. My account should be safe, it's just mad annoying.
@michael_austin
@michael_austin 3 жыл бұрын
Literally stopped playing OSRS only because of the community. This video shows perfectly how bad it gets, so sad.
@i42ooldschoolrs65
@i42ooldschoolrs65 3 жыл бұрын
i can relate to that, my accounts got banned simply because i got mass reported by some clan, ofc i appeal and get denied, then on twitter they tell me to appeal again, but nothing happens... its honestly sad how toxic the entire game has become
@giuliano.
@giuliano. 3 жыл бұрын
I've been getting the "too many login attempts" prompt for at least three months, the only way around is setting a VPN with a different IP adress every time I try to login, otherwise it won't let me play at all. I hope they fix this once and for all.
@gbvengeance3827
@gbvengeance3827 3 жыл бұрын
i get the exact same issue mate :( have to do the same it's getting to be a joke now
@LBandCOOLJ
@LBandCOOLJ 3 жыл бұрын
Interesting. I get the message when I'm on a VPN
@seegreen6484
@seegreen6484 3 жыл бұрын
If you login through mobile it will bipass the issue (for android at least)
@giuliano.
@giuliano. 3 жыл бұрын
@@seegreen6484 Yup, as long as you use data.
@MasterLPG
@MasterLPG 3 жыл бұрын
@@gbvengeance3827 I suspect these people running the log-in attempt macros to block people from accessing their accounts and charging/blackmailing them money for returned access are wise to not target the famous players like B0aty, Mr Mammal, A Friend and Torvesta, but rather the numerous rich players who possess most/all BIS gear in the game but lack any known reputation in the community and are 'nobodies' in the sense that few people care about them, as that way they'll get a lot of money out of these people (be it in-game currency or real life money) without attracting the 'wrong attention' so to speak by targeting Jagex's 'golden boys', meanwhile the rest are left to rot and fend for themselves, courtesy not of Jagex themselves but their master from an 'exotic' foreign land indeed who have fooled some by pretending to now being American via the use of a shell company of sorts. *Ah, the joys of OSRS's darker side of the community! :P*
@larryhoward7949
@larryhoward7949 3 жыл бұрын
this just solidifies the fact that Runescape is such an unhealthy game to play spiritually, physically and mentally and it's just not worth the time that you have to invest in it, imagine spending 10 years on something then all of that is stolen from you because the devs are too busy counting their bankrolls to even give a flip about you or the security of you're account. Really sad tbh
@joeturenne640
@joeturenne640 3 жыл бұрын
Lol you sent me down a mad RuneScape KZbin rabbit hole with the return of wilderness stuff 😂.
@Grrimhildr
@Grrimhildr 3 жыл бұрын
tbh everytime i see updates about runescape, its about scams, hacks, bots and it honestly makes me wanna quit
@JackBarnes14
@JackBarnes14 3 жыл бұрын
I get the log in attempt bug when I try and play with Nord VPN running on my PC, anyone else get that?
@JackBarnes14
@JackBarnes14 3 жыл бұрын
Also, great video man!
@hipnog8002
@hipnog8002 3 жыл бұрын
I literally had the bug yesterday and the only, ONLY solution that worked until it resolved itself somehow today, was to enable a vpn when logging in or world hopping
@derekmayo9517
@derekmayo9517 3 жыл бұрын
i Definitely think the bug is caused by VPNs, i get it all the time with mine
@_NetPositive
@_NetPositive 3 жыл бұрын
While this is a real issue, the only reason Zezima can't log in, is because he wants to log in with his name, instead of switching to an email. Jagex have contacted him saying that all he has to do is change to an email, and he will be able to log in. Kinda disingenuous.
@mrjojahoka9362
@mrjojahoka9362 3 жыл бұрын
Tell that to someone who has logged in with their username for years and because Jagex doesn't fix this issue he needs to change it? Nuhuh man
@dtc603
@dtc603 3 жыл бұрын
Why though? I've been logging in with just my user name since 2009 or so.
@dtc603
@dtc603 3 жыл бұрын
I know they switched it like a year later but it has never once requested me to change to an email.
@sparkoceanic
@sparkoceanic 3 жыл бұрын
Na. Easier to just fix this issue on their side rather than just making zezima change to an email
@sparkoceanic
@sparkoceanic 3 жыл бұрын
You can't just deal with hundreds of thousands of accounts changing to an email all of a sudden
@0mnishade
@0mnishade 3 жыл бұрын
I have a separate issue with the "Too many login attempts" message. Sometimes when I try to log in using my home's internet, no matter what I do or what account I use it says "Too many login attempts". If I use a VPN or tether my phone to my computer, it lets me log in and I can even disconnect afterwards and play off my home's internet. Can't swap worlds or log out though or else I'll need to do it all over again.
@Subxenox15
@Subxenox15 3 жыл бұрын
Hopefully this will draw immediate attention to how terrible Jagex customer support is, and FORCE them to do something about it.
@darck5240
@darck5240 2 жыл бұрын
i'm facing the " too many login attempts bug ", i can't login from my isp so i just connect to my mobile hotspot login then i reconnect back to my router, it's strange because sometimes it allows me to login from my router directly but at other times i have to switch to my mobile hotspot
@aluckyshot
@aluckyshot 3 жыл бұрын
Not sure why I am watching this, but big thumbs up to you for making a product and selling your own creations. Way cooler than 99% of merch shills, good job.
@taylorzen1
@taylorzen1 3 жыл бұрын
thought i should let you know that when the guy told woox jagex gave him his info, he was trolling. jagex doesn't just hand over player info. i've tried to get the names of emails of accounts i'd forgotten in the past with zero luck.
@yourjuggalobrother
@yourjuggalobrother 3 жыл бұрын
this happened to me b4 and it scared the s*-*t out of me
@ntarcet6305
@ntarcet6305 3 жыл бұрын
The strange thing is - having an account lockout is actually a security recommendation. Failure to have an account lockout is, according to the National Cyber Security Center (NCSC) and any penetration testing services, a vulnerability - since it leads to brute force attacks. The issue here is the implementation. Normally we'd expect to see either an IP account lockout (however this is bypassed by any VPN service) or a quick unlock method (since Multi-factor exists this is kinda easy to implement). In regards to the "username enumeration" - in that it's possible to work out the valid usernames/emails based on the authenticator response - yeah that's another security vulnerability that Jagex needs to look into. With regards to data dumps - nothing much Jagex can do about that, besides looking through the dumps themselves and ensuring no username:password combinations match those in the dumps. You'd be surprised how many websites are vulnerable to this style of attack (most common social media platforms are).
@SzaboB33
@SzaboB33 2 жыл бұрын
They could implement some CAPTCHA which would mitigate this very well.
@Eversionz
@Eversionz 3 жыл бұрын
So this is why when i logged in today after getting too many logins all my items were missing?
@Tucnak2o0
@Tucnak2o0 2 жыл бұрын
I'm facing the same problem now, I even tried making a fresh e-mail and a fresh osrs account and they won't work either, it's seriously annoying and it's disgusting that Jagex won't do anything for years now
@darck5240
@darck5240 2 жыл бұрын
have you tried using a vpn?
@IanFire
@IanFire 3 жыл бұрын
Awesome video brother. Crazy this is going on.
@Eddie2P
@Eddie2P 3 жыл бұрын
i dont understand why jagex doesnt implement some sort of idea where you only allow certain ip adresses to attempt to bypass the time wait and to also login more than x amount of times an minute
@Pz519
@Pz519 3 жыл бұрын
-*I have been locked out on two accounts for hours at a time, sometimes weeks.* I don’t think I’m going to make a 3rd Rebuild, I have cancelled all subscriptions and quit the game. It’s been a good 14 years RuneScape, bye.
@torva4546
@torva4546 3 жыл бұрын
Hey man it's not over yet, try to use a VPN and see if that fixes your problem. Proton VPN, Express VPN, etc... Give it a shot and lmk if that worked. It works for me so I hope it works for you.
@torva4546
@torva4546 3 жыл бұрын
Just dont get an infernal cape if that works until jagex fixes this problem or you can get banned.
@BBCjer
@BBCjer 3 жыл бұрын
pretty sure you can bypass it with vpn or logging in on mobile
@loopy221
@loopy221 3 жыл бұрын
@@torva4546 is a vpn going to work if the account log in servers are under jagex’s log in system? Doubt it
@torva4546
@torva4546 3 жыл бұрын
@@loopy221 Yeah you can it literally works for me, it must be a bypass or something.
@wrytte
@wrytte 3 жыл бұрын
This was an incredible video! It's absolutely terrifying to see this happening, this is something that really needs to get fixed
@leviblanc2827
@leviblanc2827 3 жыл бұрын
This happened to me a few weeks ago, couldn't log in for a few days and even had to make a twitter account to contact Jagexs more than questionable customer support
@zLiies
@zLiies Жыл бұрын
This has just happened to me a year after you uploaded this video. I hope my account isn't being hacked. I don't even have that much
@Piraja27
@Piraja27 3 жыл бұрын
as a rs3 player I am glad playing via steam bypasses this system so I cannot face the bug or extortion luckily
@seegreen6484
@seegreen6484 3 жыл бұрын
The people threatening swats should be in prison. Theres got to be a way for discord to track them
@annekedebruyn7797
@annekedebruyn7797 3 жыл бұрын
There have been public discords filled with child porn and Discord did nothing about that. Highly doubt they care about a few teens threatening with swatting.
@Petrofskiz
@Petrofskiz 3 жыл бұрын
My account has this issue. It began months ago and it still plagues me. My account is not hacked is the thing though and no one is attempting to access it, it seems only my log in info is leaked. I can log in to my account on mobile, using the 1 click log in method. How has jagex not implemented some type of 1 click log in method for PC as that would fix this issue.........
@LilGamingYes
@LilGamingYes 3 жыл бұрын
Two solutions I see would be: 1- Too many login attempts locks the IP, not the account 2- Two step login, no not authenticator, login. First login you can fail, it will never lock the account, second can fail and will lock it. Exemple: First login Name is X and password is 123, second it lets you access the login for the accounts within X, you can't see what accounts are there and still need the password. Say Zezima is within the account X then someone would need to login to X then login to Zezima, you couldn't log in to Zezima directly. This would mean a hell of a lot of work though for the accounts that already exist for both OSRS, RS3 and the website and probably needs something more reliable than "we've sent you an e-mail to create your first login account." Lock by IP is more viable and easier to do for sure. There probably are thousands of ways to fix this issue though and my second one is probably way too complicated for nothing, but for whatever reason it came to mind during that video.
@Tobykaani
@Tobykaani 3 жыл бұрын
Blacklisting the IP is really the nobrainer right solution here. Sure, this means people can setup proxy farm to try bruteforce passwords with large enough proxies, but with strong passwords that is not a problem since it's so tediously slow. This denial of service aspect of security sucks big time. Like, the least you could do is let the machine that has already logged in to account previously have priority / bypass the restriction.
@davidbergkvist8352
@davidbergkvist8352 3 жыл бұрын
1. How would that prevent anything? There are rotating proxies readily available with millions of IPs in their pool.
@Tobykaani
@Tobykaani 3 жыл бұрын
@@davidbergkvist8352 His point is that the account would not get locked after failed logins, only the IP would be timelocked to try login. This would render this malicious use useless as you could not lock the owner out of the account.
@davidbergkvist8352
@davidbergkvist8352 3 жыл бұрын
@@Tobykaani But that just defeats the purpose of the lock function. Do you think a hacker only has 1 IP? They could just remove the whole lock function then. The solution is to add an IP whitelist containing allowed addresses who may attempt to log in to the game. The whitelist should be editable on the website and not apply to website login.
@LilGamingYes
@LilGamingYes 3 жыл бұрын
@@davidbergkvist8352 People are not trying to hack the accounts, they are locking people out of their own accounts. They don't try 50 different passwords, they try the same abc123 50 times in a row so you can't log in. A whitelist of IPs could work too, but then if they manage to hack your account they just have to log onto the website, remove your IP and add their own and it's GG, same old problem. There is no perfect solution, there are just slightly better ones. Two-Step auth needs to be more reliable too, as it is right now hackers can have it removed without you even being notified of it until you log in the next day and everything is gone.
@glenndiddy
@glenndiddy 3 жыл бұрын
well, good thing none of my accounts are in any databases according to the search thing. That puts my mind at ease somewhat
@SnackFoodOSRS
@SnackFoodOSRS 3 жыл бұрын
Crazy research man! Great video!
@kavarisservice4709
@kavarisservice4709 3 жыл бұрын
I honesty don't how some people can be this disgustingly evil
@kavarisservice4709
@kavarisservice4709 3 жыл бұрын
@@JamaiiQ haha no doubt
@terminallydrunk1900
@terminallydrunk1900 3 жыл бұрын
its for the money. people do some fucked up shit for money.
@user-lq1dk6gr3p
@user-lq1dk6gr3p 3 жыл бұрын
"To make it worse it doesn't look ike Jagex is going to be fixing this issue anytime soon". Maybe because they sold out to the Chinese, and only care about MONEY. Their whole team is a sham!
@chrispearce2081
@chrispearce2081 3 жыл бұрын
I actually get followed by a lot of the names you see on the list they are also scammer accounts boyyyyyy this video shows no where near how bad it truly is
@ramis9836
@ramis9836 3 жыл бұрын
Been locked out my account for 4 days now... e-mailed Jagex like 5 times, all their responses were the same, they can’t do anything about it but they’re “investigating” the issue. They just link you to the same generic email. I don’t understand why they don’t just add a recaptcha for every 5 failed login attempts or something, to fight off the login bots.
@SanreZai
@SanreZai 3 жыл бұрын
Has it resolved yet? Because ive been facing this issue for 15 hours now. About too many login attempts
@zacko5242
@zacko5242 3 жыл бұрын
Having the authenticator present whether the password is correct or not is the correct procedure for 2-factor. Otherwise brute-forcing becomes extremely easy. Just FYI
@mateocarrera5623
@mateocarrera5623 3 жыл бұрын
imagine having your job be ruining a video game... pathetic. Thanks for making vids to highlight this issue man
@rambi1072
@rambi1072 3 жыл бұрын
RS and OSRS have increased profits every year since 2015, Jagex really shouldn't be letting these problems slide just so they can develop flashy new content instead. Why not just reinvest some of irl mils they're making into important stuff that'll prevent your more committed from quitting
@null301_
@null301_ 3 жыл бұрын
If i use my Google account to login on RuneScape do i have to worry about that?
@solzstice
@solzstice 3 жыл бұрын
Another problem not being talked about is the lack of ability to change your login e-mail.
@jvillzy
@jvillzy 3 жыл бұрын
Why do you pronounce Woox as Wux and Zezima as Ze-zeema?
@C4Bbx
@C4Bbx 3 жыл бұрын
WOW!....this is Greasssssyyyyyyyyyyyy never showing my email, also glad i use VPN protection, and not the free kind either ^-^
@dikbilrskk
@dikbilrskk 3 жыл бұрын
where do i see if any of my usernames or password have been compromised?
@defil3d
@defil3d 3 жыл бұрын
Google: Have I Been Pwned
@TechCGagn
@TechCGagn 3 жыл бұрын
Hi is it still a problem? Can people still lock player accounts just by knowing their username and spamming wrong passwords?
@CrumbRS
@CrumbRS 3 жыл бұрын
yep, still not fixed
@aBradApple
@aBradApple 3 жыл бұрын
Gotta love how we use Zezima against Jagex. Luv ya Z!
@yaboytpoo9083
@yaboytpoo9083 Жыл бұрын
Is this still an existing thing? I just fell for a fishing scam and immediately changed my password and bank pin once I reilized what happened but I'm scared that it's not enough
@yaboytpoo9083
@yaboytpoo9083 Жыл бұрын
I wish I could change my login email
@CrumbRS
@CrumbRS Жыл бұрын
@@yaboytpoo9083 You'll be fine if: 1) Your new password is unique, never used before for anything 2) You have 2-Factor setup on RuneScape 3) Your email has a unique password never used for anything else 4) Your email has 2-Factor enabled
@nicolinrucker5181
@nicolinrucker5181 3 жыл бұрын
"Jagex should not be handing you log in information without being absolutely sure you are who you" Ok, what if I last logged in five years ago and remember very little about my account? Should I just, lose access to my account now?
@Neocasturn
@Neocasturn 3 жыл бұрын
Yes
@jackdominguez207
@jackdominguez207 3 жыл бұрын
Yes
@maxwellplaysvideogames
@maxwellplaysvideogames 3 жыл бұрын
would you rather have these people have targeted denial attacks against people actively playing the game or would you rather have a handful of people lose accounts they haven't played for years? if you forgot about the account details and didn't write them down or save them anywhere then it obviously wasn't very important to you.
@nicolinrucker5181
@nicolinrucker5181 3 жыл бұрын
@@maxwellplaysvideogames Ah yes, it's not like I moved 6+ times in those five years and lost far more in those moves than the account details for one game, I wonder, did I have them in one of the USB drives I lost or was it a bookmark in one of the books I was actively reading that vanished, maybe I'd stuck it in a game CD that got lost, Before I had Steam I've had to buy the same game several times due to losing the CD while moving. But no, there's no possibility that outside factors had ANY INFLUENCE AT ALL in my loss of my account details, it ABSOLUTELY must be that I just didn't care. Of course, that also assumes that it wasn't very important to me and therefore could never regain importance... Which, honestly, why would you assume that anyway?
@ziawrsps6881
@ziawrsps6881 3 жыл бұрын
My account is on one of those leaked databases. I was reckless with private servers when I was younger and lost many accounts including my rs account. I had to change my username and password combo. It was a lesson learned for sure.
@dreamking893
@dreamking893 3 жыл бұрын
I'm curious what OSRS runs on. Is it modern hardware or legacy hardware? Through personal experience upgrading security around applications while running on legacy hardware is a major pain and typically requires migrating everything to new up-to-date hardware which is very expensive, time consuming and has a lot of risks. For example, Blizzard struggled to get WoW classic to run on current architecture due to how outdated and incompatible it was. I wonder if OSRS has those same issues. Wish I could work with their IT team T.T
@CaptainNoFace
@CaptainNoFace 3 жыл бұрын
How is it that Jagex hasn't been brought up by some kind of tribunal or some shit? You'd think with the amount of data breaches people exploit in this game, they'd at least be investigated as a company as to why this is happening. Instead it's like a complete black hole where the money goes because it certainly isn't going into maintaining one of the most important and fundamental things about any game... the security that allows you to play the bloody thing without fear of being targeted. Just knowing you can be a potential target for a laundry list of cyber threats in this game and that Jagex 90% of the time won't even help you, let alone resolve the issue, is an apocalyptic failure on the part of the company itself.
@shaharpaz
@shaharpaz 2 жыл бұрын
but whats crazy is when i go to a friends few streets away i can login from his house...
@elusive6755
@elusive6755 3 жыл бұрын
I quit because i cant log in and when i do log in to do anything i have 30 people following me telling me im permed from doing anything i cant chop trees pk literally anything they find me in 5 seconds somehow and harass me everywhere i go i could record it and show you
@phaminator2031
@phaminator2031 3 жыл бұрын
My account says it’s disabled. I haven’t played on it for a couple years and decided to come back. Anyone know a solution?
@LowieX
@LowieX 3 жыл бұрын
scammers have such a big ego like if i get scammed id be pissed of for likes 2 days then ill get over it But scammers think they are game ending someone's life
@ameerkhress8763
@ameerkhress8763 3 жыл бұрын
dear crumb my max account still blocked because too many attempts i sent message to the game but after the fixed it its back what i need to do plz help
@mintysquinty2989
@mintysquinty2989 3 жыл бұрын
Incredibly easy fix by letting players change old accounts to an email login. Jagex just has fucking horrendous customer support and they don't give a shit about you.
@voteZDLR
@voteZDLR 3 жыл бұрын
The fact they're offering premium accounts and services for some people and yet completely unwilling to fix glaring security issues is an absolute joke.
@AlphaLeaderZ
@AlphaLeaderZ 3 жыл бұрын
I got rangers boots on my iron and someone hacked me and took all my food and my rangers. Idk if I will continue playing. I don't even understand how my bank was accessed with a pin.
These Players are being Falsely Banned
16:43
Crumb
Рет қаралды 162 М.
How Rollbacks Almost Ruined RuneScape
16:25
Crumb
Рет қаралды 143 М.
لااا! هذه البرتقالة مزعجة جدًا #قصير
00:15
One More Arabic
Рет қаралды 51 МЛН
Why Is He Unhappy…?
00:26
Alan Chikin Chow
Рет қаралды 104 МЛН
SPILLED CHOCKY MILK PRANK ON BROTHER 😂 #shorts
00:12
Savage Vlogs
Рет қаралды 45 МЛН
Parenting hacks and gadgets against mosquitoes 🦟👶
00:21
Let's GLOW!
Рет қаралды 12 МЛН
Why RuneScape Won’t Stop These Bots
11:48
Crumb
Рет қаралды 270 М.
From Rank 1 to Jagex Sabotage | The Fall of SUOMI
14:18
Crumb
Рет қаралды 408 М.
RuneScape HD Gameplay (2011)
5:37
hooldenord
Рет қаралды 31 М.
The History of Cheating Sleep in RuneScape
14:10
Crumb
Рет қаралды 168 М.
The Story of RuneScape's Infamous DDoSer
13:24
Crumb
Рет қаралды 381 М.
I Blew Open a Scamming Ring
13:22
Crumb
Рет қаралды 387 М.
Venezuelan Gold Farmers Have Moved
11:36
Crumb
Рет қаралды 393 М.
The "Game Breaking" Bugs That Closed Classic
10:39
Crumb
Рет қаралды 104 М.
Losing a $20,000 RuneScape Name
19:17
Crumb
Рет қаралды 240 М.
لااا! هذه البرتقالة مزعجة جدًا #قصير
00:15
One More Arabic
Рет қаралды 51 МЛН