Over the last several days, the FSE staff has been dealing with one or more entities exploiting vulnerabilities in the FSE Game World website. You've probably noticed some odd forum posts about account / group issues, have seen occasional errors, or in some cases popup messages which were caused by them exploiting these vulnerabilities. Some of these entities were moving money and assets around between new accounts they were able to create, as well as hijacking the accounts of other players and deleting groups owned, moving money, etc...

Unfortunately, these actions have caused dozens of hours of unexpected work by the all-volunteer staff, who gave up their entire weekend to deal with the aftermath and attempt to return money and assets to player's accounts who were affected and, as best they could, close and prevent the vulnerabilities that were known. One of the entities did provide some breadcrumbs on what they were doing, but it is unclear if they were also the ones cracking the accounts for some reason, such as to "make a point", "show their skill set", "show how stupid we are", etc...

As most people know, the FSE codebase is over 16 years old. There is simply no way that it can be completely brought up to date to current security standards without a nearly complete overhaul. Something the current management staff simply doesn't have the time to do. In the future, we'd appreciate it if those with the skill sets to discover these vulnerabilities simply tell us about them and work with us, as opposed to hitting us and making us chase our tails unexpectedly. 

Although we've done our best to close most of the obvious holes, we can only assume at this point that the entities using these exploits still have the capability to do further damage. Sadly, if it comes to that, there will come a point where we will have no other option but to simply close the doors, turn off the lights, and call it the end of an era.

If you have noticed missing money or assets, please know that we've been following the log trails and attempting to restore these things where we can, and hopefully we'll be able to recover your assets if needed.