Forum Settings
       
Reply To Thread

Hacks still happening . . .Follow

#77 Sep 05 2009 at 6:16 PM Rating: Decent
*
63 posts
I tried to log in yesterday after work. Was ready for a long weekend of FFXI. Logged in used the popup keyboard thing were you enter your password with your mouse, I always use this in case of keyloggers. Next thing I know " Incorrect Playonline ID or Password" >< so I try again..."Incorrect Playonline ID or Password" WTF!!! So I try again "Your Account has been lock due to three incorrect password entries" GD IT I'VE BEEN HACKED!!!

Now I have a few good items and a little nest egg of gil but most of my stuff is Rare/EX. I have the normal Pld gear, Joytoy, jelly ring, AF boots, IR gear, but nothing that would make me stand out from any other pld. I've been back a total of 3 days and got hacked. The last time I played prior to this was back in Feb. and the only FFXI sites that I visit is ffxicyclopieda, and Allakhzam.
I'm also not even in a linkshell yet seeing as how I've been gone for six months. All I've been doing is Campain battles to check out how union works.

I'm hearing that I'm not the only one so hopefully a roll back is in the works for all of us. I play on Kujata btw.
#78 Sep 05 2009 at 6:35 PM Rating: Decent
Scholar
Avatar
****
6,268 posts
Okay, since we have a few in this thread now...

How many of these persons with compromised accounts have changed their billing info since the Verified/Securecode inception?

It opens to your external browser (but not necessarily firefox for security!!) and forces you to enter your zip code or whatever. It must send some portion of the login information when doing so.

I'm changing my passwords again after I change billing info to reactivate.

Edited, Sep 5th 2009 7:37pm by Raelix
____________________________
I've seen things you people wouldn't believe. Airships on fire off the shoulder of Bahamut. I watched Scapula Beams glitter in the dark near the Three Mage Gate...

Nilatai wrote:
Vlorsutes wrote:
There's always...not trolling him?

You're new here, aren't you?
#79 Sep 05 2009 at 7:41 PM Rating: Good
**
510 posts
As someone who was hacked last week and waiting for SE's internal "investigation" to conclude before they approve my rollback... it has been over a year since I changed any billing information, more then a handful of years since I logged into the Community site, no one knows my login info/password and my pc is completely virus/malware/greyware/keylogger free.

The fact that PC, PS2 and Security token holders have all managed to have their accounts compromised recently... I say ANY account information changes (password or billing or otherwise) should require their support peoples to contact the account holder via phone or email (email requiring account holder to contact SE) and live/verbal communication required for ANY info to change.

Who came up with the concept of making changing your password "easy" anyways? It should take a god damn act of congress to get a password or billing information changed.

My current opinion is obviously heavily influenced by the fact I have a locked account waiting for SE to decide if they are going to restore my account pre-compromise... i'll stop this post now before I just start *********


Edited, Sep 6th 2009 12:50am by drogier
#80 Sep 06 2009 at 6:13 AM Rating: Good
Quote:
but I suspect that is why they are getting hacked. They put their equips on display like look at what I got. Who's been hacked with standard equips? Low level accounts?


A friend of mine's second account, which was full of rare/ex and had maybe 2K gil on it, was hacked (along with his main.) By that theory, they left the poor newbie accounts alone.
#81 Sep 06 2009 at 6:42 AM Rating: Decent
Scholar
***
1,098 posts
Is anyone outside of SE gathering this "hacked info" anywhere to find a common ground to all the hackings?
____________________________




[ffxivsig]459049[/ffxivsig]
#82REDACTED, Posted: Sep 06 2009 at 7:55 AM, Rating: Sub-Default, (Expand Post) I am still very skeptical about ppl being hacked...
#83 Sep 06 2009 at 8:05 AM Rating: Good
Quote:
I am still very skeptical about ppl being hacked...

If it were so easy, all the hackers would do is go to the bazaar mall and snag the accounts of ppl with KC/Speed belt/ and other 20m+ Items while they are {long time} afk/mule accounts.


So we're all making this up for kicks?
#84 Sep 06 2009 at 8:07 AM Rating: Good
Quote:
Is anyone outside of SE gathering this "hacked info" anywhere to find a common ground to all the hackings?


Someone on BG discovered several PDF malware files on FFXIclopedia. Since anyone can edit a wiki, then its easy enough to slip some bad files into it. If you had NoScript running, however, the PDF files need your permission to load, and Adobe recently issued a patch that addressed the hole in Adobe Acrobat that allowed the scripting to run from PDF files.

Many of those hacked mentioned FFXIclopedia, FFXIAH, and Alla as the only gaming websites they visisted recently.

The other possibility is bad ads on FFXIAH. Adblock prevents this from getting in.

Since a few people who have been hacked use Adblock, NoScript, and the security token, then the odds of a hacker getting past all three are slim to none.
#85 Sep 06 2009 at 9:30 AM Rating: Default
*
92 posts
Quote:
So we're all making this up for kicks?



More like there is some common and key aspect to ppl being hacked. It is not something that can happen to anyone and is most likely not precise. HNM ls may be targeted because their website can be messed with, but this isn't a process where a hacker logs in, finds a character he wants to steal, then steals it...
#86 Sep 06 2009 at 9:33 AM Rating: Good
Quote:
HNM ls may be targeted because their website can be messed with


I suspected that as well. I did a data dump of my entire public_htm directory, and scanned it for viruses, malware, etc. Came up 100% clean.
#87REDACTED, Posted: Sep 06 2009 at 11:13 AM, Rating: Sub-Default, (Expand Post) I hope pretty much everyone reads this. The way you get hacked with the security token... Is by not cleaning your system. What happens, is that the one time passwords are good for quite a while in reality. So all someone has to do is have a trojan on your system, and get your one time password from the keylogger. Then while you are still logged in, remove your token from your SE account, then log in to your account, change your SE password and POL password. Then guess what, you are now hacked.
#88 Sep 06 2009 at 11:55 AM Rating: Excellent
A one time password cannot be used twice. Hence, "one time."

However, if it is unused, it is good for 27 minutes.
#89REDACTED, Posted: Sep 06 2009 at 12:48 PM, Rating: Sub-Default, (Expand Post) You sure about that? I know I am pretty sure I have logged in twice with the same number... but not completely sure.
#90 Sep 06 2009 at 12:49 PM Rating: Excellent
It's Just a Flesh Wound
******
22,702 posts
lightningcount wrote:
You sure about that?


Yes
____________________________
Dear people I don't like: 凸(●´―`●)凸
#91REDACTED, Posted: Sep 06 2009 at 12:57 PM, Rating: Sub-Default, (Expand Post) unused? I assumed these keys worked off of an algorithm related to their serial number. If i press the button it does not connect to se on its own and let them know a key was created, hence, there is no unused/27 min window situation possible.
#92 Sep 06 2009 at 1:00 PM Rating: Decent
Avatar
**
842 posts
I think I actually ducked the hacks since well, simply..

I haven't been using adobe acrobat for 2 years to view PDF files.

Yes; you got that right. Been using Foxit Reader instead. About that time, Acrobat Reader got way too much bloatware for me, so I switched.

Now, man oh man, I'm glad I did.
____________________________
Elizara, Mithran WHM of Quetzalcoatl
LS's: SpecialFriends, ShikigamiWeapon, Noble's, WeSayHurray, JingZen, Betrayed (Dynamis and Aby)

Still a MithraPride kitty at heart, tho that shell is gone..Also still CTY at heart forevah!

Midgard: NEVER FORGET.

Alla profile: http://ffxi.allakhazam.com/profile.xml?11530

Thinking about swapping from console to PC? Check here to do it right!
#93 Sep 06 2009 at 1:44 PM Rating: Good
Right, the algorithm is generated at SE's end based on the key on the back of your token. (Which, if SE's servers really were hacked and that info got out, would still need to be decrypted. There is no evidence this has happened yet, thank goodness.)

You push the button, it spits out a number.

You enter this number to log in. SE's algorithm backwards computers the last 50 numbers, and if at least one matches, you are allowed in. Someone on BG did the math; a new number is generated every 32 seconds - 32 x 50 = 1600 seconds, or 26.666~ minutes.

However, if one of those 50 has been used, it will not be accepted a second time.

Hackers have a 1 in 20,000 shot at getting a working one time password number.
#94 Sep 06 2009 at 2:01 PM Rating: Good
***
1,448 posts
lightningcount wrote:
if I can ever get the registry in Wine to work correctly... Then I will have the ultimate security XD.


FFXI through Wine is pretty stable now. If you copy dxdiagn.dll over from a windows installation, manually register it, and set FFXI's settings for it to native, you shouldn't have any issues. The winehq page has recently updated the instructions, though I haven't read through the new version to see what's been changed. It's nice knowing I'm pretty much immune to all this (never registered with LS community site and I play through Wine but browse natively in Linux). My heart goes out to those affected though.

Also, if it is a security hole in adobe acrobat that has allowed people to become infected, it doesn't surprise me given the number of security holes discovered in it on a fairly regular basis.

Quote:
Anyone who uses any email service like outlook is doubly affected. Anytime you log in to outlook, it DOWNLOADS all of your emails on to your computer. Meaning you do not even have to look at the malicious email for it to infect your computer.


Can you back this up with an article? Not bashing you, just interested - I haven't heard much about exploits for outlook that allow execution of code without previewing the email or opening attachments. The closest I can think of that I've been aware of is this old security hole in outlook (fixed in 2000), and a few buffer-overflow issues, also a few years old.

Edited, Sep 6th 2009 10:43pm by KisharBlack
#95REDACTED, Posted: Sep 06 2009 at 3:03 PM, Rating: Sub-Default, (Expand Post) Square is taking your accounts and selling them on the open market! ENGAGE CONSPIRACY THEORY.
#96REDACTED, Posted: Sep 06 2009 at 4:53 PM, Rating: Sub-Default, (Expand Post) Anyone know Ianora on phoenix? Pretty sure that account got hijacked. You can look up their ffxiah stuff. Undercutting people for about 50k, and sold all their equips in the last two days.
#97 Sep 06 2009 at 9:04 PM Rating: Good
*
166 posts
lightningcount wrote:
I hope pretty much everyone reads this. The way you get hacked with the security token... Is by not cleaning your system. What happens, is that the one time passwords are good for quite a while in reality. So all someone has to do is have a trojan on your system, and get your one time password from the keylogger. Then while you are still logged in, remove your token from your SE account, then log in to your account, change your SE password and POL password. Then guess what, you are now hacked.

The hackings that are happening even with the security token are half the victim's fault and half SE's fault for not making the password invalid after one usage.

Just because you have a security token does not guarantee you protection from the RMT. CLEAN YOUR SYSTEM DAILY. Yes DAILY. Anyone who uses any email service like outlook is doubly affected. Anytime you log in to outlook, it DOWNLOADS all of your emails on to your computer. Meaning you do not even have to look at the malicious email for it to infect your computer. Remember that you can still be hacked and people are still being hacked. IF you "NEED" some bot to claim your NMs, then use a brain. Don't use your FFXI PC to download it. You can buy a POS 10 year old PC from used PC store for around 50 dollars. (Although at that price you are still getting ripped off) I use my old PC to surf the ffxi pages, and my new one to play ffxi. And if I can ever get the registry in Wine to work correctly... Then I will have the ultimate security XD.


Even IF the token wasn't one-time usage (which, as others have said, tested, and proved, it is), your method of "protection" is still about as absurd as any I've seen. Anyone who thinks they need to clean their system daily just shouldn't be on the internet; it's about as absurd as saying you need to fill up your car's gas tank every single time you go to the store. "Oh, but I MIGHT get in a traffic jam so bad that the car idles too long and runs out of half a tank of gas!" You've better odds of winning the lottery, or getting struck by lightning. It's not that dangerous, for &*#@'s sake. Stop trying to freak people out into spending hours of computer time in a fruitless effort to keep their computer "clean".
#98 Sep 07 2009 at 4:26 AM Rating: Default
"8- you use internet explorer instead of firefox"


No offence, but i know people who can hack through firefox three times as fast as IE. Its a fact that IE and Microsoft is more secure because of all the updates they do. Only difference is no one really bothers hacking anything except microsoft and thats because the world is microsoft. Once hackers realise MACs etc are on the increase they will start on them.

So ignore the statement of IE vs Firefox on security levels, firefox is no more secure. IE more secure but more targetted or FF which is less secure and less targetted.

But will agree with the other statements.
#99 Sep 07 2009 at 5:23 AM Rating: Excellent
***
1,448 posts
Lonix wrote:
Its a fact that IE and Microsoft is more secure because of all the updates they do.


This is absolute twaddle. I agree with you that MS is more targeted, but the notion that this somehow makes them more secure is nonsense. Don't post things as 'facts' unless you can back them up.

First of all, bugs and security flaws tend to get fixed faster in open source projects due to the fact that there are large numbers of people able to look at the problem and contribute time and effort to fixing it.

Secondly, your assertion that Microsoft issues updates more frequently due to being the target of frequent attacks is completely incorrect. Microsoft is hampered by its fixed-cycle of updates (monthly, on 'patch Tuesday', the second Tuesday of every month. 'Patch Tuesday', amusingly enough, is followed by 'Exploit Wednesday', when malware authors have the longest time-until-update, and potentially new holes introduced by the update to play with).

IE was left stagnant for years after the demise of Netscape, and became riddled with holes and legacy crap. It's improved with IE8, certainly - but the security issues during that period were certainly more to do with the actual quality of the product than they were to do with 'targeting the most popular choice'.

This link is a reasonably good example of the differences between the two browsers in terms of critical security flaws (there's a follow-up article which is a good example of the FUD/history distortion Microsoft tries whenever issues like this get raised in the press).

CAVEAT to the above: people advocating Firefox as the safer choice are generally correct, but often neglect to mention that it only really shines in terms of security when configured well. Firefox + NoScript set up correctly is probably the single best security feature you could have while browsing the web, but Firefox out of the box isn't inherently vastly more secure than IE out of the box these days.

Edited, Sep 7th 2009 1:44pm by KisharBlack
#100 Sep 07 2009 at 7:21 AM Rating: Good
Quote:
Firefox + NoScript set up correctly is probably the single best security feature you could have while browsing the web, but Firefox out of the box isn't inherently vastly more secure than IE out of the box these days.


Yep, one of my tokenless friends who was among the first round of hacking victims a few weeks back was like, "But I use Firefox!"

Turns out he'd never heard of NosScript and Adblock. The exploits that infect through IE7 an IE8 get through to Firefox just as easily, since most of them are coming through additional content, like flash banner ads.

I have NoScript turned off here on Alla since as a premium member I don't see ads, and on my own personal website since I don't run any ads on it (someone asked me why I didn't have that, or a donation button, but I'd personally rather pay $7 a month than open that can of worms.)
#101 Sep 07 2009 at 7:31 AM Rating: Excellent
Avatar
****
4,153 posts
KisharBlack wrote:

CAVEAT to the above: people advocating Firefox as the safer choice are generally correct, but often neglect to mention that it only really shines in terms of security when configured well. Firefox + NoScript set up correctly is probably the single best security feature you could have while browsing the web, but Firefox out of the box isn't inherently vastly more secure than IE out of the box these days.

In addition to NoScript and AdBlock+, I also use the free version of the KeyScrambler addon. The developer claims that it will encrypt keystrokes at the driver level, so that any keyloggers will only end up with garbage. The Premium version (which is about $45) also works on WoW and other online games.
____________________________
FFXI-Garuda 2003-2009; Lakshmi 2011-8/20/13 (retired)
FFXIV: ARR - Ghost Bear, Balmung server
Reply To Thread

Colors Smileys Quote OriginalQuote Checked Help

 

Recent Visitors: 441 All times are in CST
Nanako, Anonymous Guests (440)