EVE Online Database Security Breach Leads to Downtime of Game, Website
"At 10:25 GMT today we discovered an anomaly in the EVE Online Database indicating a potential exploit," said CCP chief of operations Jón Hörðdal following the restoration of the company's website. "What we discovered was an indication that one of our databases was being accessed through a security breach."
Because the EVE website and game servers are tied together, both were brought down during the length of the emergency maintenance.
"Our policy in such cases is to mobilize a taskforce of internal and external experts to evaluate the situation," continued Hörðdal. "At 12:57 that group concluded that our best course of action was to go completely dark while an exhaustive scan of our entire infrastructure was executed."
Early rumors circulating amongst EVE player forums indicated that a CCP database administrator had at some point fallen victim to a keylogger, a computer program which captures a user's keystrokes. CCP representatives have since denied the rumors, claiming the information had originated from someone attempting to impersonate a CCP employee.
While some users feared the investigation might eventually lead to a rolling back of the game server, effectively erasing player progress made after the introduction of the exploit, Horodal stated that the database breaches benefited only the hacker. Game service has since been restored, with no noticeable changes.
"Our taskforce quickly found the security breach and prevented that from being used," added Hörðdal. "We can also confirm that no personal details such as users’ credentials or credit card numbers were exposed through this incident."
-
Shacknews.com...Keeping the faith and breaking the news at 3:46 on a Saturday morning. My fellow geeks of the night, I salute you.