Go Back   EQ2Flames Forum > General Discussion > General Gameplay

Reply
 
LinkBack Thread Tools
Old 03-28-2008, 10:26 AM  
Regular
 

Posts: 189
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

ok we are on guk too and the same thing happend to my guildies loged out at 1 and came back in next day naked in front of a mail box naked in big bend

so this a bit of a coincenence that we both on guk and this is happend ?

again as i said in earlier posts all virus scanners up to date etc and i have been told they ran that web rooter as well only cookies found so where does this leave us? our gb wasnt stolen thank god as they didnt have permision to loot but we are with out 3 players at least until soe gets back to them and if they done every thing they can or could to stop this and it didnt stop it its bound to happen again

something def wrong when so many people are saying same story
axuis is offline   Reply With Quote
Old 03-28-2008, 11:23 AM  
Ily
"Hell hath no fury..."
 
Ily's Avatar
 
Character: RIP Girls...
Guild: Corner Speed
Server: Fuck SOE, I quit.

Posts: 3,231
Photos: (36)

Send a message via AIM to Ily Send a message via MSN to Ily
Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

So Pet, what do you reccomend for 64 users?
And what, if anything, do you know about StopSign/eAcceleration products?
Thats what Ive been running for the last 2 years and have had 0 problems.
__________________
Because I don't say it, don't mean I ain't thinking it
Next thing you know, they'll take my thoughts away
I know what I said, now I must scream of the overdose
And the lack of mercy killings...

Quote:
Originally Posted by Snark View Post
Id hit a mouse trap if it was lubed thats not the point
Ily is online now   Reply With Quote
Old 03-28-2008, 02:06 PM  
Regular
 
Character: Feldon
Server: Butcherblock

Posts: 125
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

According to Petgroup, the appropriate course of action for anyone who gets hacked is to box up your computer and ship it back to the manufacturer.

Why do I keep posting this? Cause you are being an asshole. 3 paragraphs about how you think everyone in this thread are idiot scum who are beneath you and should have been done the world a favor and been aborted and then 1 sentence about "btw run this and this tool" is really gonna get more people to post!

Last edited by feldon30; 03-28-2008 at 02:13 PM.
feldon30 is offline   Reply With Quote
Old 03-28-2008, 02:41 PM  
Visitor
 

Posts: 35
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Quote:
Originally Posted by Basta View Post
Posted first in TEch Support as the thread was found vua Google. Reposted here after reading more of the site.

...snip...

I inform the Guild Leader of what has happened and log off. Check virus scans for any thing and run a new full scan.




So where does that leave me. Yes my account information has been shared with one person, my son, and his account looked just like mine. Empty and naked. He has accessed only his account from his computer, both accounts have been accessed from my computer, but not in the last six months.

Just out of curiosity I logged in one of the toons that ended up in Big Bend to sww aht might be going on there. Zogun, Zipheethick, Kikam, Zogigoog, and Ojikog are all going from a small room by the mailbox there, bank, vendor and come back and stand next to another of these toons and then log. At any given time how many level 1 toons would be in Big Bend? They were all Level 1/1.

So where does this put me.....in the stupid class because I shared the account infor with my son. Or just maybe, just maybe is there something to what some of are saying.

I am definitely open to suggestion cause losing everything you've acquired in 2 years of playing really sucks. Granted, SoE, after investigation may replace your gear and GB items but I still feel as if I've been raped.
That is interesting. Trend Micro would definitely pick up on the infection if it was from the recent injection attacks. The agent is dormant now and TM have already categorised it so it should be detected.
That and the rest of the reports are definitely more fuel to the fire that this is not just a user issue.
Oswaldor is offline   Reply With Quote
Old 03-28-2008, 03:11 PM  
Regular
 

Posts: 189
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

well i have been saying this in a few posts but every one assumes its user error off the bat
axuis is offline   Reply With Quote
Old 03-28-2008, 03:47 PM  
To Gnome is to Loveme
 
Trepan's Avatar
 
Character: Lapsus Linguae
Guild: Vainglory
Server: Blackburrow

Posts: 72
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Quote:
Originally Posted by Basta View Post
So where does this put me.....in the stupid class because I shared the account infor with my son. Or just maybe, just maybe is there something to what some of are saying.
I'm curious if you've changed your password lately, like in the last 3 weeks or is it a password that could have been collected a while ago and only just recently been put to use.

Have you read the SoE forums on other machines (friends, neighbors, countrymen, coffee shops, comps on the network at Best Buy...?) and authenticated so as to have been able to post? Has your son logged on your toon at a friend's house to show him that shiny new item or loan a plat or help out?

There are plenty of opportunities to collect that information, your box need not have been the one compromised.

-----------

Oswaldor: Are you tracking all traffic from your honeypot over time? How does that altered DLL behave aside from having a different checksum?

-----------

I know some incarnations of botnets rely on sleeper processes that fire up for short periods to contact the master server and then go dormant again.

I know I'd like to be able to remove all traces of my hacks once I've gotten the goods. If they log which information was collected from which IP they were from (there are lots of situations where a DHCP'd address can be fairly static and not re-assigned to a new MAC), then what, besides a certain level of sophistication, is to stop it from sending a "ok, rape accomplished (successful or not). Delete yourself" the next time that little guy fires up and pings the botnet master server?

-----------

As for why a company would not want to step forward and announce that they've been hacked... you'll find reticence from any publicly traded company to do that. Sprinkle that with the reminder that SoE was burned last year due to an employee at the company who did their billing selling subscriber contact information to marketing companies, and you can easily imagine a lot of people standing around in a board room wondering what course of action to take.

There are InfoSec companies out there who are focused on fighting fires in the background so that their clients don't have to announce breeches of security. Unless there was personal information leaked, there is no law in the US that requires acknowledgment of any such breech (if one did occur).
__________________
Trepan is offline   Reply With Quote
Old 03-28-2008, 04:37 PM  
Don't even think about it
 
Petgroup's Avatar
 
Character: Petgroup
Server: Gorgonnash

Posts: 1,210
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Quote:
Originally Posted by feldon30 View Post
According to Petgroup, the appropriate course of action for anyone who gets hacked is to box up your computer and ship it back to the manufacturer.
Actually, I've said it about 20 times. Run the free Webroot scan and see what it finds.

In my 1,000+ posts on this site find anything remotely close to me saying "Box up your computer and ship it back to the manufacturer" I probably haven't even used box & manufacturer in the same sentence till this post.

I enjoy being this so called asshole who offers a year free subscription to Webroot for the first hacked player who posts a screenshot showing Webroot free scan found the culprit.

Thats $40 out of my pocket or $69 if I sold it to you on a service call. I don't have to do shit, I'm offering a resolution to hacked players in a game I don't even play or will ever play again. It's for the flames community. Yet you call me an asshole and say I think everyone is scum and beneath me. Fuck off.


Quote:
Originally Posted by Ily View Post
So Pet, what do you reccomend for 64 users?
And what, if anything, do you know about StopSign/eAcceleration products?
Thats what Ive been running for the last 2 years and have had 0 problems.
I use Trend on my 64bit Vista & I'm surprised it didn't find this magical hack going around. I've never used Stop Sign but there commercials are just as annoying as Head On.
__________________

Originally Posted by RadarX
Go play another game and wake up. SOE's Community Team does more than ANY other company.
Flames now has 0 support from anyone. No TTH, no Zam (although I'm not sure how much there was), no SOE, no one.

Last edited by Petgroup; 03-28-2008 at 04:40 PM.
Petgroup is offline   Reply With Quote
Old 03-28-2008, 05:22 PM  
Ily
"Hell hath no fury..."
 
Ily's Avatar
 
Character: RIP Girls...
Guild: Corner Speed
Server: Fuck SOE, I quit.

Posts: 3,231
Photos: (36)

Send a message via AIM to Ily Send a message via MSN to Ily
Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Yeah, I actually started using them before I ever saw a commercial because I had another 64bit buddy reccomend them... But youre right, they are annoying ads.
__________________
Because I don't say it, don't mean I ain't thinking it
Next thing you know, they'll take my thoughts away
I know what I said, now I must scream of the overdose
And the lack of mercy killings...

Quote:
Originally Posted by Snark View Post
Id hit a mouse trap if it was lubed thats not the point
Ily is online now   Reply With Quote
Old 03-28-2008, 05:38 PM  
Visitor
 

Posts: 35
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Quote:
Oswaldor: Are you tracking all traffic from your honeypot over time? How does that altered DLL behave aside from having a different checksum?
It is not an altered dll - it is the actual trojan that gets injected into most processes using the standard windows injection scheme.
I haven't monitored it over time, just observed that as soon as it got something it liked (ie. a password field in IE) it transmitted some encrypted data to 61.188.39.175:2034.

Unfortunately my honeypot lived only a short life - it was created using a standard XP installation disc with absolutely no updates. Needless to say it died pretty quick, when I turned off the firewall.
Oswaldor is offline   Reply With Quote
Old 03-28-2008, 06:00 PM  
proud owner of an inny
 
Bitmap's Avatar
 
Character: Bitmap
Guild: Dominion
Server: Unrest

Posts: 1,545
Photos: (104)

Send a message via ICQ to Bitmap Send a message via AIM to Bitmap Send a message via MSN to Bitmap Send a message via Yahoo to Bitmap
Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Quote:
Originally Posted by Petgroup View Post
I use Trend on my 64bit Vista & I'm surprised it didn't find this magical hack going around. I've never used Stop Sign but there commercials are just as annoying as Head On.
I use trend as well and it didnt pick up on a trojan my system picked up, but doing a double check with kapersky did pick it up.
__________________

Be the 10th person to PM LFG a complaint about this post and win a prize!
Bitmap is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


Sponsor Ads


All times are GMT -4. The time now is 11:28 AM.


Design By: Miner Skinz.com Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0