Go Back   EQ2Flames Forum > General Discussion > General Gameplay

Reply
 
LinkBack Thread Tools
Old 03-27-2008, 04:35 PM  
Don't even think about it
 
Petgroup's Avatar
 
Character: Petgroup
Server: Gorgonnash

Posts: 1,210
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Quote:
Originally Posted by bmg2 View Post
And if it was Sony who got hacked, why haven't the people at the top of the richest list been hit hard?
There the ones behind it
__________________

Originally Posted by RadarX
Go play another game and wake up. SOE's Community Team does more than ANY other company.
Flames now has 0 support from anyone. No TTH, no Zam (although I'm not sure how much there was), no SOE, no one.
Petgroup is offline   Reply With Quote
Old 03-27-2008, 05:18 PM  
Regular
 

Posts: 189
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

so yet again come down to fucking name calling etc and monkey bob posted a link saying sony got hacked

so you shut the fuck up and wait for people to post before you go jumping the gun ok
axuis is offline   Reply With Quote
Old 03-27-2008, 05:22 PM  
Pet me.
 
Karmalina's Avatar
 
Character: Karmalina
Guild: The Lost
Server: Butcherblock

Posts: 216
Photos: (0)

Send a message via MSN to Karmalina
Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Quote:
Originally Posted by bmg2 View Post
And if it was Sony who got hacked, why haven't the people at the top of the richest list been hit hard?
Yeah, its a valid point, but at the same time, if it was SoE that was compromised you still don't know exactly what information they would have access to. A search of the richest players does not give you their account username.

Anyhow, its definately a frustrating problem and I really do wish that someone who had it happen could be a little more proactive in letting people know what they have found.
__________________
Karmalina Kismet, Fury of The Lost
Karmalina is offline   Reply With Quote
Old 03-27-2008, 05:37 PM  
n00b
 
MonkeyBob's Avatar
 
Character: Mubik
Guild: Gods of Greyhawk
Server: Runnyeye

Posts: 112
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

ok, so the PS3 accounts got hacked... heres a unproven, hypothetical, but plausible theory, with not a shred of evidence to support it:

1) all the people who got hacked have got PS3's
2) they have the same username/password for the PS3 account as their EQ2 account

Of course, that theory completely ignores the secret answer factor, but, meh...

Completely out of left field I know. Let the flames begin...
__________________


From Digg: They apparently feel the "Flames" crowd is a gangrenous wound that has to be amputated rather than cured. Unfortunately, you can't amputate your heart and hope to live.

Last edited by MonkeyBob; 03-27-2008 at 05:39 PM.
MonkeyBob is offline   Reply With Quote
Old 03-27-2008, 08:57 PM  
Visitor
 

Posts: 35
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

I finally got a honeypot 'infected' with the the keylogger/trojan of the recent attacks. Well at least it got infected with one of the downloaders from the malicious script (fuckjp.js) (You can find the supposed source here:

0x000000 # The Hacker Webzine

I took quite a few screenshots to document this, but dumbass me forgot to protect them when I nuked the honeypot.

Anyhow after it downloaded some stuff onto the infected machine it just sits idle. (JS_AGENT.OEZ - Technical details)

I did notice some timeouts when the downloader tried to connect to certain sites - this happend both before and after it had successfully downloaded some stuff ie. failed downloads.

Anyhow I could detect the behaviour that others have reported (Shadowserver Foundation - Calendar - 2008-03-13) as soon as I went anywhere with a password field. Didn't try any other browsers than IE.

I launched both the eq2.exe and everquest2.exe (The actual trojan/logger, the krnp32drv.dll, got injected into both of these processes).
I entered the username and the password and tried to connect to SOE (denied of course since I cancelled the accounts a long time ago). There was nothing transfered to the above mentioned server.

Since LOTRO has been mentioned as a target for these attacks I installed that and tried to log on - same thing as with EQ2 - nothing transfered.

From what little analysis I did of the krnp32drv.dll then it does not seem to be general system hook or 'all purpose' keylogger, it just seems to be on the hunt for password fields in IE - nothing specific against EQ2.

Although nothing I have done here is conclusive I have to say that I honestly don't think that the 2117966.net/fuck.js (which is the agent for the latest massive SQL injection attacks) has anything to do with the recent influx of compromised eq2 accounts - I would love to be thouroughly corrected by an in-dept analysis, but untill that happens I would look elsewhere.

To support this consider;
- quite a few people are reporting a password change, which would require the 'secret answer'.

(- though if folks use the same password / username elsewhere than just EQ2, and use either their username or password as the secret answer, then this keylogger would be a viable source)

- I haven't been able to find the same massive reports of compromised accounts in WoW or LOTRO - this would indicate that the target is in fact not against MMOs - who the fuck launches something this massive just to hit a dying MMO?.
Last years attack against guildportal, resulted in many reports of compromised WoW accounts on the WoW boards - I can't find anything similar this time around (prove me wrong though - haven't searched that thoroughly). Same thing with LOTRO - even though it has been reported as a targeted game (The Yahoo and ABC articles).
It would really be nice if SOE dished up some facts about this, they simply can not ignore it (it also has to drain a lot of resources) and they sit on all the information required to enlighten this affair - hopefully they are just ignorant and don't consider this a priority thing.


Fun thing to do if bored: Search for "www.2117966.net/fuckjp.js" on google and observe just how sites are infected..;)
Oswaldor is offline   Reply With Quote
Old 03-27-2008, 09:12 PM  
n00b
 
MonkeyBob's Avatar
 
Character: Mubik
Guild: Gods of Greyhawk
Server: Runnyeye

Posts: 112
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Edited because im an idiot...
__________________


From Digg: They apparently feel the "Flames" crowd is a gangrenous wound that has to be amputated rather than cured. Unfortunately, you can't amputate your heart and hope to live.

Last edited by MonkeyBob; 03-27-2008 at 09:22 PM.
MonkeyBob is offline   Reply With Quote
Old 03-27-2008, 09:15 PM  
n00b
 
MonkeyBob's Avatar
 
Character: Mubik
Guild: Gods of Greyhawk
Server: Runnyeye

Posts: 112
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Nice to see that google is posting "this site may harm your computer" under a lot of those listings when you do that search too. Its not obvious, but it is there...
__________________


From Digg: They apparently feel the "Flames" crowd is a gangrenous wound that has to be amputated rather than cured. Unfortunately, you can't amputate your heart and hope to live.
MonkeyBob is offline   Reply With Quote
Old 03-28-2008, 02:14 AM  
Lil Newbie
 
Character: Basta
Server: Guk

Posts: 5
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Posted first in TEch Support as the thread was found vua Google. Reposted here after reading more of the site.

I would like to think that I'm not in the category that a lot of people are referring to here as %$$#@* Stupid Group who shares information or downloads things they are not aware of or visit sites that could be considered questionable.

So....I feel.think I have a fairly secure system. Firewall, Anti Virus, no automatic downloads and my sites frequented can usually be counted on 1 hand. EQ2 Forums, Guild Web Site, Google, EQ2Flames (as of today) and MySpace/Photobucket where I keep in touch with my children.

I use Trend Micro as my Anti-Virus/Spyware. It is set up to scan the Windows System Folder every day at 4:00 am, the disk drives every Tuesday and Saturday and a full scan every Thursday. ALL downloads are prompted, IE is not installed, I have been using Firefox since it first came out.

Sometimes, if I see an interesting article or news snippet in Google I may browse there but I ma not a huge Web Surfer.

The point of all this. I played my main toon until 1:30 AM Sunday morning and then logged and went to bed. When I awoke around 10:00 and logged in my main character is standing at the Death Grotto Portal and naked! Upon opening my bags I see a few items left but of course they are lore, no-trade, no-value. I quickly make the trip to the house there and discover that any item of value has been taken. I travel to the bank to dscover that my bank is empty, Broker is empty as is GB's 1,2 and 3 of anything of value. Looking at the buy back option on the broker my only options are Pristine Carpets at 12c and 1 Frostfell candle.

My other two toons I play regularly are both in Big Bend, naked and standing in front of their brand spanking new 1 room inn's. One had move to a bigger Inn in West Freeeport and the other a 3 room house in South Freeport.

OK, so now I'm convinced that someone othe than me has been on. That is verified when a friend sends me a tell wanting to know why I was rude an never replied to her when she asked for help that morning. Uhmmm, what time was that. "Oh, somewhere around 3:00 am". Logs on GB verify that my toon cleaned out the GB's between 2:30 and 3:06.

I inform the Guild Leader of what has happened and log off. Check virus scans for any thing and run a new full scan.




So where does that leave me. Yes my account information has been shared with one person, my son, and his account looked just like mine. Empty and naked. He has accessed only his account from his computer, both accounts have been accessed from my computer, but not in the last six months.

Just out of curiosity I logged in one of the toons that ended up in Big Bend to sww aht might be going on there. Zogun, Zipheethick, Kikam, Zogigoog, and Ojikog are all going from a small room by the mailbox there, bank, vendor and come back and stand next to another of these toons and then log. At any given time how many level 1 toons would be in Big Bend? They were all Level 1/1.

So where does this put me.....in the stupid class because I shared the account infor with my son. Or just maybe, just maybe is there something to what some of are saying.

I am definitely open to suggestion cause losing everything you've acquired in 2 years of playing really sucks. Granted, SoE, after investigation may replace your gear and GB items but I still feel as if I've been raped.
Basta is offline   Reply With Quote
Old 03-28-2008, 04:05 AM  
Don't even think about it
 
Petgroup's Avatar
 
Character: Petgroup
Server: Gorgonnash

Posts: 1,210
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Quote:
Originally Posted by Basta View Post


Please try running the Webroot Free scan.

Direct Download

If that finds nothing but cookies, then something big is going on. Trend Micro is a reputable company but I gave that up for Webroot with my customers.

Thank you for the screenshot.
__________________

Originally Posted by RadarX
Go play another game and wake up. SOE's Community Team does more than ANY other company.
Flames now has 0 support from anyone. No TTH, no Zam (although I'm not sure how much there was), no SOE, no one.
Petgroup is offline   Reply With Quote
Old 03-28-2008, 05:16 AM  
Regular
 
Flipmode's Avatar
 
Character: Optical
Guild: Archon
Server: Crushbone

Posts: 250
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Quote:
Originally Posted by Petgroup View Post
Please try running the Webroot Free scan.

Direct Download

If that finds nothing but cookies, then something big is going on. Trend Micro is a reputable company but I gave that up for Webroot with my customers.

Thank you for the screenshot.

So I ran this webroot scan that you linked. It found about 50 cookies but they all have a low threat level. Does this mean something shady is happening on my computer or what?
Flipmode is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


Sponsor Ads


All times are GMT -4. The time now is 05:05 PM.


Design By: Miner Skinz.com Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0