Do hackers ever stop here?

7 pages Page 3
Fril Estelin
Fril Estelin
So Serious...
#41
Test the strength of your password:
http://www.microsoft.com/protect/you...d/checker.mspx
http://www.securitystats.com/tools/password.php
http://rumkin.com/tools/password/passchk.php

Use a password manager (such as PasswordSage, among the many that exist). Check these tips.

I've seen before people telling me that they never shared their password, only to realise they had it written on a piece of paper put somewhere where colleagues, friends or less friendly people could see it.

To do a full thorough security check of your PC: first of all, do it offline with your antivirus and the standard antispywares; then download another antivirus, such as the trial of NOD32 or Kaspersky, and try another check, again offline.

Regina: it's worth investigating, there seems to be a lot of strange events happening.
RedNova88
RedNova88
Krytan Explorer
#42
This is very troubling news. I've also had troubles recencly with a trojan that just seemed to appear on my computer. Not to assume it's the same one, but it's not impossible. It's sad that RMT and hacking has escalated to something so bad. MMO companies need to start installing things in their own product to prevent against this sort of thing, should take note of Perfect World's security system that lets you lock down your account. This prevents character deletion as well as trading/selling/buying/dropping or destroying of any kind until a timer is up.

I suggest to everyone to do the following:

Download Firefox if you don't have it
Download the Noscript addon if you don't have it
Download one or all of the decent free AV programs. Avast, Spybot: Search and Destroy, Ad-Aware (the basic version) are all free. There are also others that do well.

Best of luck to the folks out there, getting hacked can't be fun, especially when there is only so much that Anet can do. It's sad that we can't kill the problem at the source... Yet.
daze
daze
Jungle Guide
#43
Do you use IE or Firefox?
How strong is your password?
Do you click on any other GW links?

I use Firefox
I make sure that my passwords are at least 10 characters and have special characters, numbers, upper and lower case. Also i dont use this password for any other thing (email, porn, bank, etc.). Also changing your password periodically helps prevent slip ups.

"[email protected]" is an example of a strong password.
T
Tushi
Frost Gate Guardian
#44
Logged on my account just to check, i have obsi + chaos gloves so i might looked rich. But all the poor hacker got was 1k and 1 zkeys.
xD
newbie_of_doom
newbie_of_doom
Wilds Pathfinder
#45
thats what you get for watching porn
Arduin
Arduin
Grotto Attendant
#46
Quote:
Originally Posted by wire dawg View Post
if your are able to log into your account u don't need to worry about a plaync account anymore u can change your pw by changing your account at the bottom they did away with needing the plaync as a lot forgot their pw and so on and not being able to access the emails
Ah, it is working indeed! No need to go to PlayNC anymore, very helpful.

@ Shayne Hawke: Hope you can think up on a hard to crack password.
refer
refer
Jungle Guide
#47
Quote:
Originally Posted by RedNova88 View Post
This is very troubling news. I've also had troubles recencly with a trojan that just seemed to appear on my computer. Not to assume it's the same one, but it's not impossible. It's sad that RMT and hacking has escalated to something so bad. MMO companies need to start installing things in their own product to prevent against this sort of thing, should take note of Perfect World's security system that lets you lock down your account. This prevents character deletion as well as trading/selling/buying/dropping or destroying of any kind until a timer is up.

I suggest to everyone to do the following:

Download Firefox if you don't have it
Download the Noscript addon if you don't have it
Download one or all of the decent free AV programs. Avast, Spybot: Search and Destroy, Ad-Aware (the basic version) are all free. There are also others that do well.

Best of luck to the folks out there, getting hacked can't be fun, especially when there is only so much that Anet can do. It's sad that we can't kill the problem at the source... Yet.
Does anybody still use Ad-Aware lol. Not sure what is out there for free firewalls though (you left that out)... Online Armor, Zone Alarm, Comodo... but Agnitum Outpost is BY FAR the best firewall if you have money... fully customizable, easy to use, fast, presets for everything, life time licenses are out for it now I think too.
Arduin
Arduin
Grotto Attendant
#48
Quote:
Originally Posted by daze View Post
"[email protected]" is an example of a strong password.
Not according to Microsoft:

Quote:
Avoid using only look-alike substitutions of numbers or symbols. Criminals and other malicious users who know enough to try and crack your password will not be fooled by common look-alike replacements, such as to replace an 'i' with a '1' or an 'a' with '@' as in "M1cr0$0ft" or "[email protected]". But these substitutions can be effective when combined with other measures, such as length, misspellings, or variations in case, to improve the strength of your password.
Either way, I'd like Anet to implement some kind of extra barrier to prevent the hackers from accessing your characters after they've brute-forced their way into your account. The permanently locking of characters has been suggested before, as well as temporarily suspending your account after 3 failed login attempts.

Because losing all your money and Zkeys is indeed horrible, losing your character that's nearly 4 years old is on a whole different scale of loss...

Getting a bit paranoid here...
zelgadissan
zelgadissan
Forge Runner
#49
My friend got hacked yesterday as well, what's weird is that the only thing they took was straight cash. Had ectos, rubies, sapphires, elite armors - they weren't touched - but instead he lost ~175k. He worked with computers; he knows what he's doing with this stuff. He filed a support ticket last night. He doesn't use any forums.

I'm curious to hear if this is above the normal amount of hacks, or if everyone on Guru is just suddenly saying something at once?

Editing with the great list Shayne posted:
Quote:
Originally Posted by Shayne Hawke View Post
- Happened recently. - yesterday
- One character was moved to the Great Temple of Balthazar. - correct
- Many items of value that were not tied to the character/account were taken/lost. i.e. Undedicated minis, Z-Keys, uncustomized weapons. - 100k+
- Items of much less value will sometimes be left in place of what was taken/lost. - some gold armor of sup fast casting
- No characters were deleted. - correct again
Stuart444
Stuart444
Krytan Explorer
#50
I think the best thing to do is leave this thread open for Regina (and perhaps someone should post it on her wiki), judging by how many people are saying they have been hit. it probably is a good idea to investigate it.

The best way to prevent it probably is if they modify the client to make it lock out after 5 failed attempts (since a brute force would need more than 5 attempts to hack into it) and it would lock out for about 30 mins to 1 hour (best way I can think of to protect the persons account but not keep owner of the account locked out for a long time)
Shayne Hawke
Shayne Hawke
Departed from Tyria
#51
I think it's safe to say that the only hackings that we're really trying to consider follow these criteria:

- Happened recently.
- One character was moved to the Great Temple of Balthazar.
- Many items of value that were not tied to the character/account were taken/lost. i.e. Undedicated minis, Z-Keys, uncustomized weapons.
- Items of much less value will sometimes be left in place of what was taken/lost.
- No characters were deleted.

I personally feel that I've done nothing to warrant access to my account by someone else, and it seems many others here who have been hit by this feel the same way. To me, this sounds like some dangerous trend starting to form.
fenix
fenix
Major-General Awesome
#52
Quote:
Originally Posted by Stuart444 View Post
The best way to prevent it probably is if they modify the client to make it lock out after 5 failed attempts (since a brute force would need more than 5 attempts to hack into it) and it would lock out for about 30 mins to 1 hour (best way I can think of to protect the persons account but not keep owner of the account locked out for a long time)
That's what it does now, Gaile said a while ago. If you get the password wrong a few times, it kicks you out for an exponentially increasing amount of time, so brute forcing won't work. This must be keylogging or some packet manipulation or something.
Lyynyyrd
Lyynyyrd
Banned
#53
Quote:
Originally Posted by fenix View Post
That's what it does now, Gaile said a while ago. If you get the password wrong a few times, it kicks you out for an exponentially increasing amount of time, so brute forcing won't work. This must be keylogging or some packet manipulation or something.
More likely an addiction to kinky pornography.
I
IxiRancid
Academy Page
#54
Some things to check:
- is your password same for GW game client and Xunlai Predicitons
- is your password + email same for GW game client and email (like Gmail or other)
- do you suspect you might have clicked anything suspicious on the internet (nooo {puts away the handkerchiefs} )
- does your AntiVirus software report any malicious software (I'd like to point out that there are some popular AV not quite competent, not naming any...)
- do you use IE6 and your latest Service Pack for Windows XP is SP1 *

*
websites (GWguru amongst them) were infected with iFrame malware that spreads with ads.
About iFrame exploit

And about passwords -> ¬itt1e.sTar¤ w0Ot
Alt+0172 = ¬
Alt+0164 = ¤
Forgotton200
Forgotton200
Lion's Arch Merchant
#55
Eight years of online rpg/mmorpg and I never been hacked. I download files everyday from a certain site that's known for trolls uploading keylogger, trojan, virus but none has ever worked cause I'm just that awesome.
t
thig
Academy Page
#56
According to microsoft theres been a increase in online games trojans this month, although Guild Wars are not mentioned as one of the top targets. You can see more details about the attacks by following this link

Quote:
Originally Posted by Microsoft Malware Protection Center
So what tops the detection and removal list this month? Online game password stealers (PWS) Win32/Taterf and Win32/Frethog are the top two threat families, with 981,051 and 316,971 machines cleaned respectively a week after MSRT release. Taterf removals are already 171% higher than the full month's volume in January.
Sir Skullcrasher
Sir Skullcrasher
Furnace Stoker
#57
Not trying to point blame to anyone. But do you have the same email/password for GW as same as the one you have on Guru? Maybe whoever is doing this is picking off the information from Guru and using it on GW to see if they access it?
I
Inde
Site Contributor
#58
This seems to happen at least once a year. For those who are paranoid (hey, you have every right to be) I'm going to review the incidents that have happened.

The last slew of "hacked" accounts was on 05/05/08... this was a specific hacking that went around involving 2 accounts that were used to hack into players accounts. It was suspected that the guilty party were using a key logger or a fake website to obtain account information. Anet was very helpful in this case and reported that they had banned the accounts.

There was another incident right after this on 05/28/08. Anet stated that they did not see any increase, more then normal, in hacked accounts. They always say that if it was a problem it would be more widespread. See below for more on that.

The hacking incident that parallels this one was actually about 2 years ago. We had at least 25+ reported hacks. Zkeys being stolen and the like. Here was Anet's response:

Quote:
You're asking us for far too much. You're asking us to protect the player from himself. Forgiveness is divine, but covering someone's patootie if he shares an account with a friend, if he uses a weak password, if he downloads a third party program is asking too much.

If your car is stolen, do you contact GM to replace it? GM builds the cars with secure door locks, and security systems, and you're responsible for using the door locks and the security systems. If you forget to lock up, if you give your keys to someone else, the loss isn't at the car manufacturer's head, but at yours. Give you ATM card to someone, and write your PIN on the back? I don't think the bank is going to say "Oh, that wasn't you? Well, here, have that 500 bucks back, by all means!"

I ask this: Players must accept responsibility for all that they can and should be responsible for. We will gladly accept responsibility for all that we can and should be responsible for. In fact, we do, every single day.

In the last couple of weeks, there have been, what? Five threads about account thefts? One every couple of days, out of how many accounts? Millions? While I sympathize with those impacted, believe me, that's tiny. This isn't a "major issue," this is the proverbial drop in a bucket.

Now, I am not minimizing the loss of the players involved. I am simply pointing out the hysteria, and the cries of "Change this!" and "Give us that!" in the name of "making us more secure" is entirely unrealistic. It's like hearing a match was struck three states away and demanding a firetruck in your backyard.

Player, hear the facts! You are responsible for your security, and nothing that has been pointed out in any of the recent thread leads me to believe that the extraordinary measures you demand would have prevented a single instance of account theft so posted. In fact, if you read carefully, some of those affected have come to the conclusion that their security may have been, or even was , somewhat lacking. Players truly do need to take their individual responsibility to heart, rather than asking for more and costly tools that still do not prevent the loss of accounts when teh accounts are not properly handled, maintained, or secured by the players themselves.

Thank you for reading, and please understand, this isn't a brush off, this is a rallying cry for a more security-oriented mindset for all of us.
And Skullcrasher, it's suggested every single time. You'll get a mixed response of people that do and people that don't. For all the people that swear they use great passwords and protect themselves, even on Guru I can tell you that there are over 900+ forum users who have "password" or their username as their password. VBulletin has a great lil' feature that displays the # of vulnerable accounts (no it doesn't give me access to view which accounts). So yes, from that alone you can just imagine how many people do the same with their Guild Wars accounts. I am, of course, not suggesting that those above were careless or that this is even them but it shows you that many players do not secure their accounts. Why does this keep happening? It happens in all games. Go to any MMO forum and you'll see reports of hacked accounts. Sometimes you will never know why. With every safeguard in place, it seems that some are still vulnerable. Which either tells us they are smart and subtle or that there is no protection. Forums can be hacked, yes. Though I can tell you that our server admin has been on our servers for the past 3 straight days and I can assure you that no suspicious activity happened. Game clients can be hacked, yes. Good luck getting any developer or company to admit to this unless it's catastrophic.

And just to answer all the other questions, because they come up every single time...

No one, not even an admin has access to the password you use on this site. To be more specific VBulletin uses a non-standard encryption method. Consisting of taking the md5 hash of the password, concatenating a salt string and taking a second md5 hash. What does this mean? This is a multi-encrypted password that no one can read.
Vel
Vel
Lion's Arch Merchant
#59
In your email program have a rule set up that removes all emails to trash bin with words "guild" and does not come from NCSoft's or ANET's valid email domains.
SilentAssassin
SilentAssassin
Wilds Pathfinder
#60
Well, I got hacked and 2 weeks later I got a permanent ban.

I have send numerous support tickets and they don't want to change it back because it seems he used a third party program.

Do you think this is fair? K, I am responsible for my account, I don't really care that there are items gone, lots of cash, but that they give me a permanent ban for what that guy did isn't fair.

I paid 250 euros for my account, I am a long time member (from the World preview events) and they just give me a ban... I had 11 characters... Played lots of PvP.

This makes me sick, that they don't want to listen. Yes I am just one of the many millions, bah it makes me sick.

I am trying to contact regina etc, because support doesn't want to listen anymore.