Go Back   EQ2Flames Forum > General Discussion > General Gameplay

Reply
 
LinkBack Thread Tools Search this Thread
Old 03-20-2008, 04:58 PM  
Regular
 
quasigenx's Avatar
 
Character: Zaquelle
Guild: Siege
Server: Najena

Posts: 168
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

I wish SoE would provide a way to lock your account to certain IP addresses. Or perhaps to lock your account to the CD key that you installed with. Kind of like iTunes only allows you to play songs registered to your key. Neither piece of info would be easily obtainable via a key logger. They would need to make sure the CD key wasn't laying around in plain text anywhere, and that the process to register a new IP address or CD key had some protection around it, like mandatory wait times. Not perfect, but it would make me feel better.
__________________
quasigenx is offline   Reply With Quote
Old 03-20-2008, 05:02 PM  
Mighty Mouse
 
Sqee's Avatar
 
Character: Sqee
Guild: Children of Darkness
Server: Nektulos

Posts: 844
Photos: (0)

Send a message via MSN to Sqee Send a message via Skype™ to Sqee
Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Quote:
Originally Posted by LFG View Post
I do not know, but it would be interesting to discover how many of those who got hacked used some type of low budget 3rd party hacker track/exploit type of program.
Thats what i've been saying for a while too.
Sqee is online now   Reply With Quote
Old 03-20-2008, 05:08 PM  
Nakir In'herear
 
Gtwo's Avatar
 

Posts: 617
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Quote:
Originally Posted by Sqee View Post
T Quote:
Originally Posted by LFG
I do not know, but it would be interesting to discover how many of those who got hacked used some type of low budget 3rd party hacker track/exploit type of program.

Thats what i've been saying for a while too.
From what ive read u would be wrong. While the use of a 3rd party program's can open your PC up to being vulnerable to the author of said program, its appears recent attacks have not been affiliated with that at all.
Gtwo is offline   Reply With Quote
Old 03-20-2008, 05:12 PM  
Mighty Mouse
 
Sqee's Avatar
 
Character: Sqee
Guild: Children of Darkness
Server: Nektulos

Posts: 844
Photos: (0)

Send a message via MSN to Sqee Send a message via Skype™ to Sqee
Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Quote:
Originally Posted by Gtwo View Post
From what ive read u would be wrong. While the use of a 3rd party program's can open your PC up to being vulnerable to the author of said program, its appears recent attacks have not been affiliated with that at all.
How many bots out there do you open up then start EQ? Wouldnt be such a far stretch for some one to patch the program with a keylogger. Assuming bots patch, which with as much as EQ itself patches i would assume they would have to.. yes, there is allot of assumptions involved in my theory, but its not that far stretched.
Sqee is online now   Reply With Quote
Old 03-20-2008, 05:17 PM  
Nakir In'herear
 
Gtwo's Avatar
 

Posts: 617
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Quote:
Originally Posted by Sqee View Post
How many bots out there do you open up then start EQ? Wouldnt be such a far stretch for some one to patch the program with a keylogger. Assuming bots patch, which with as much as EQ itself patches i would assume they would have to.. yes, there is allot of assumptions involved in my theory, but its not that far stretched.
I'm sorry you failed to comprehended my post.
Gtwo is offline   Reply With Quote
Old 03-20-2008, 05:18 PM  
GM Alvarez
 
alvarez's Avatar
 
Character: alvarez
Guild: aftermath
Server: butcherblock

Posts: 356
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

you're ignoring the whole fucking internet raving about what's going on and insisting it's gotta be bot software? .. hello?
__________________
alvarez is online now   Reply With Quote
Old 03-20-2008, 05:19 PM  
Mighty Mouse
 
Sqee's Avatar
 
Character: Sqee
Guild: Children of Darkness
Server: Nektulos

Posts: 844
Photos: (0)

Send a message via MSN to Sqee Send a message via Skype™ to Sqee
Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

who's insisting? EQ2flames put a hack in my computer and LFG stole all my plat!!
Sqee is online now   Reply With Quote
Old 03-20-2008, 05:22 PM  
Nakir In'herear
 
Gtwo's Avatar
 

Posts: 617
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Quote:
Originally Posted by Sqee View Post
who's insisting? EQ2flames put a hack in my computer and LFG stole all my plat!!
That would be worthy of its own thread go for it buddy....try the official forums they might even support your quest.

Sqee:
On a side note.....I found out how to fix your virus protection to be immune to all key loggers......turn your tower around......and change the virus protection from 110 to 220, it will be twice as good.

Last edited by Gtwo : 03-20-2008 at 05:24 PM.
Gtwo is offline   Reply With Quote
Old 03-20-2008, 05:31 PM  
Mighty Mouse
 
Sqee's Avatar
 
Character: Sqee
Guild: Children of Darkness
Server: Nektulos

Posts: 844
Photos: (0)

Send a message via MSN to Sqee Send a message via Skype™ to Sqee
Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Quote:
Originally Posted by Gtwo View Post
That would be worthy of its own thread go for it buddy....try the official forums they might even support your quest.

Sqee:
On a side note.....I found out how to fix your virus protection to be immune to all key loggers......turn your tower around......and change the virus protection from 110 to 220, it will be twice as good.
lol... thats funier than a monkey throwing shit at a lady in a white dress... or maybe not, i dont know... i imagine it would be pretty funny though..


But seriously, i play on a laptop, i dont even own a tower.. Anything else that would help?

I'm not insisting that its a 3rd party bot, i very much agree with the internet raving bugged keyloggers and bad Vbulletin software, and add companies and blah blah blah... I still think some if it is bot programs.

You guys are so cute when you try to be mean, come on.. lets hold hands and sing songs!
Sqee is online now   Reply With Quote
Old 03-20-2008, 05:40 PM  
To Gnome is to Loveme
 
Trepan's Avatar
 
Character: Lapsus Linguae
Guild: Vainglory
Server: Blackburrow

Posts: 71
Photos: (0)

Default Re: Toon Hacking/Account Stealing/Keylogging Consolidated Thread

Quote:
Originally Posted by Oswaldor View Post
Care to dish up some references for those claims?
Computer Security Research - McAfee Avert Labs Blog
Computer Security Research - McAfee Avert Labs Blog

Quote:
Also the 'websites' have not installed any keyloggers. Think about it.
That is true, the websites themselves do nothing except serve up data. What the users or their systems decide to do with the data is a different story. Serving up information that was not planned due to xss vulnerabilities that process unsanitized inputs is the weakness.

You get to pick that nit for free.

Quote:
It is more likely that the browsers were unpatched. Ordinary users hardly ever fiddle with those settings. Since it has documented (see some of the threads on the official forums) that the attack targeted year old vulnerabilities, an unpatched system is enough. Also there is no such thing as a JavaScript control, xxs has nothing to do with this (you don't load 'stuff' from elsewhere with xss, you inject stuff into something else).
Thats another nit, but it stops short. Yes, you inject stuff into something else, but that injected 'stuff' can be code that WILL load 'stuff'. For your edification:

DOM-based attack
  1. Mallory sends a URL to Alice (via email or another mechanism) of a maliciously constructed web page.
  2. Alice clicks on the link.
  3. The malicious web page's JavaScript opens a vulnerable HTML page installed locally on Alice's computer.
  4. The vulnerable HTML page contains JavaScript which executes in Alice's computer's local zone.
  5. Mallory's malicious script now may run commands with the privileges Alice holds on her own computer.
Now, that attack hinges on there being a page existing on Alice's computer already. This one does not. It relies instead on finding a vulnerability in a site that is already trusted by Alice and her browser's settings.

Non-Persistent
  1. Alice often visits a particular website, which is hosted by Bob. Bob's website allows Alice to log in with a username/password pair and store sensitive information, such as billing information.
  2. Mallory observes that Bob's website contains a reflected XSS vulnerability.
  3. Mallory crafts a URL to exploit the vulnerability, and sends Alice an email, making it look as if it came from Bob (i.e., the email is spoofed).
  4. Alice visits the URL provided by Mallory while logged into Bob's website.
  5. The malicious script embedded in the URL executes in Alice's browser, as if it came directly from Bob's server. The script can be used to email Mallory Alice's session cookie. Mallory can then use the session cookie to steal sensitive information available to Alice (authentication credentials, billing info, etc) without Alice's knowledge.
What is your 'correct' term for javascript code that pops a window and loads content into that window from somewhere else? 'control' may not be the exact right word, but to those less pedantically minded it conveys the same connotations.

Quote:
Seriously dude, stop getting your information from online forums. Start reading about the underlying technologies. Perhaps then you might actually see just how retarded your comments are.
I know this comment will go laughably in this forum, but perhaps if people like yourself who do 'know' would be less condescending to people who WANT to know but don't, those others would be more receptive to listening to what you have to say and learn from it.

You're welcome for the attention your unctuous personality has caused me to spend on you. Savor it.
__________________
Trepan is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


Sponsor Ads


All times are GMT -4. The time now is 06:57 PM.


Design By: Miner Skinz.com Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0