Welcome, Guest. Please login or register.
July 19, 2025, 07:00:40 AM

Login with username, password and session length

Search:     Advanced search
we're back, baby
*
Home Help Search Login Register
f13.net  |  f13.net General Forums  |  The Gaming Graveyard  |  World of Warcraft  |  Topic: My WoW-account's been compromised 0 Members and 2 Guests are viewing this topic.
Pages: 1 ... 4 5 [6] 7 8 ... 10 Go Down Print
Author Topic: My WoW-account's been compromised  (Read 134677 times)
raydeen
Terracotta Army
Posts: 1246


Reply #175 on: July 11, 2010, 04:51:05 AM

Said message gets sent out to every hacked account, as far as I can tell.  I'm guessing the GM's don't actually have the option to initiation a ban without an automated message.

I didn't get that particular email when mine was hacked. I seem to have been lucky enough to have been hacked by someone who just wanted to do some quick spamming with some level 1's. Far as I can tell, nothing else went on with any of my characters other than my one toon being deleted (which has since been restored).

I was drinking when I wrote this, so sue me if it goes astray.
Paelos
Contributor
Posts: 27075

Error 404: Title not found.


Reply #176 on: July 11, 2010, 08:47:36 AM

I got hacked on Thursday afternoon and had my stuff returned on Saturday afternoon. So I was pretty impressive with the overall turnaround. Also, I think they gave me a few boe's I never had, and some upgrades to my dps stuff for my trouble.

I think I came out ahead in the hack by ~12k gold in net assets.  why so serious?

CPA, CFO, Sports Fan, Game when I have the time
WindupAtheist
Army of One
Posts: 7028

Badicalthon


Reply #177 on: July 12, 2010, 11:36:47 AM

Routine AdAware scan turned up something suspicious. I can think of at least two places it's more likely to have slipped through than from anywhere WoW related but, after giving myself the full multi-program antivirus treatment and finding nothing else, I changed my bnet email and password again.

"You're just a dick who quotes himself in his sig."  --  Schild
"Yeah, it's pretty awesome."  --  Me
Abagadro
Terracotta Army
Posts: 12227

Possibly the only user with more posts in the Den than PC/Console Gaming.


Reply #178 on: July 28, 2010, 03:05:52 PM

I just received an email from WoWAccountReview@eu.blizzard.com entitled "Character Faction Change Notice."  I haven't played WoW since about two months after it came out.  Is this a phish or has my account already been hacked?  Kinda weird to have this happen the day after I sign up on b.net for SC2.

"As democracy is perfected, the office of president represents, more and more closely, the inner soul of the people. On some great and glorious day the plain folks of the land will reach their heart's desire at last and the White House will be adorned by a downright moron.”

-H.L. Mencken
Ingmar
Terracotta Army
Posts: 19280

Auto Assault Affectionado


Reply #179 on: July 28, 2010, 03:06:52 PM

Check the actual header of the message and check the links to see where they actually go (without clicking obviously), you can't put any stock in the From: address.

The Transcendent One: AH... THE ROGUE CONSTRUCT.
Nordom: Sense of closure: imminent.
Musashi
Terracotta Army
Posts: 1692


Reply #180 on: July 28, 2010, 03:58:34 PM

There's a shitload of things floating around that can swipe your email.  Likely from a friend's contact list or something.  It may not be you.  But that's phishing mail, for sure.  I get literally fifty of them per week after I got hacked.

AKA Gyoza
Azazel
Contributor
Posts: 7735


Reply #181 on: July 30, 2010, 04:16:40 AM

I just received an email from WoWAccountReview@eu.blizzard.com entitled "Character Faction Change Notice."  I haven't played WoW since about two months after it came out.  Is this a phish or has my account already been hacked?  Kinda weird to have this happen the day after I sign up on b.net for SC2.

I got the same email on the same day. I changed my password and sent a query email to blizz via the official wow website. I was almost 100% sure it was a phishing email since I logged into the WoW site with my wow-login, since I quit before they needed bnet addresses.


http://azazelx.wordpress.com/ - My Miniatures and Hobby Blog.
Paelos
Contributor
Posts: 27075

Error 404: Title not found.


Reply #182 on: July 30, 2010, 07:23:34 AM

I got the same email. I flipped out for a second, then remembered I had an authenticator and this was silly.

CPA, CFO, Sports Fan, Game when I have the time
WoopeeTuralyon
Terracotta Army
Posts: 200


Reply #183 on: July 30, 2010, 10:07:34 AM

Weird. I've never gotten a fake Blizz email, but I have been hacked!
Mattemeo
Terracotta Army
Posts: 1128


Reply #184 on: August 02, 2010, 12:39:53 PM

Here's the latest attempt. Much more convincing but after checking I could happily log into battle.net myself and checking out the support addresses were wrong in the mail it has been discounted.

Quote
New Login Account Confirmation‏

01/08/2010

 Blizzard Entertainm​ent

      Blizzard Entertainment
      WoWAccountAdmin@blizzard.com

From:   Blizzard Entertainment (WoWAccountAdmin@blizzard.com)
Sent:   01 August 2010 01:38:48


Hello,

Blizzard Entertainment recently received a request to change the e-mail address used to log in to the Battle.net account with the username myaddress@hotmail.com. The e-mail address k***@hotmail.com has been specified as the new username for this Battle.net account. An email has been sent to this new address containing a verification link to complete the change.

Once the new address has been verified, the e-mail address myaddress@hotmail.com can no longer be used to log in to this Battle.net account or any World of Warcraft accounts merged with this Battle.net account.

If you did not initiate this request, please click here to contact the Blizzard Billing & Account Services team immediately.

Sincerely,
The Battle.net Account Team
Online Privacy Policy

If you party with the Party Prince you get two complimentary after-dinner mints
Paelos
Contributor
Posts: 27075

Error 404: Title not found.


Reply #185 on: August 02, 2010, 12:48:58 PM

I'm getting Starcraft phishing mail now, telling me I've purchased things. Very Very odd.

CPA, CFO, Sports Fan, Game when I have the time
Morat20
Terracotta Army
Posts: 18529


Reply #186 on: August 02, 2010, 01:06:01 PM

Here's the latest attempt. Much more convincing but after checking I could happily log into battle.net myself and checking out the support addresses were wrong in the mail it has been discounted.

Quote
New Login Account Confirmation‏

01/08/2010

 Blizzard Entertainm​ent

      Blizzard Entertainment
      WoWAccountAdmin@blizzard.com

From:   Blizzard Entertainment (WoWAccountAdmin@blizzard.com)
Sent:   01 August 2010 01:38:48


Hello,

Blizzard Entertainment recently received a request to change the e-mail address used to log in to the Battle.net account with the username myaddress@hotmail.com. The e-mail address k***@hotmail.com has been specified as the new username for this Battle.net account. An email has been sent to this new address containing a verification link to complete the change.

Once the new address has been verified, the e-mail address myaddress@hotmail.com can no longer be used to log in to this Battle.net account or any World of Warcraft accounts merged with this Battle.net account.

If you did not initiate this request, please click here to contact the Blizzard Billing & Account Services team immediately.

Sincerely,
The Battle.net Account Team
Online Privacy Policy
I got that one too. Need to remember to warn the wifey. I just logged into Battlenet and checked.

I've simply gotten into the habit of never clicking email links, unless they are ones I'm expecting -- and even then, I mouse over it and verify it's to the right place.
proudft
Terracotta Army
Posts: 1228


Reply #187 on: August 02, 2010, 02:13:13 PM

I server transferred a guy the other day and later the same day got a phishing email about YOUR FACTION TRANSFER IS COMPLETE.

That one alllllmost got me, but hover-link saved the day again.  The timing was eerie, though.  Better luck next time, haxxors.
Merusk
Terracotta Army
Posts: 27449

Badge Whore


Reply #188 on: August 02, 2010, 03:32:02 PM

My former guild had someone with an authenticator get "hacked" the other day.  They deleted his character after selling everything off.   I'm willing to bet one of these latest social engineering e-mails was the true culprit, but he's too prideful to ever admit as such.  "Naw, it has to have been a common add-on or they're hacking B-net! I don't fall for that stuff."

The past cannot be changed. The future is yet within your power.
WoopeeTuralyon
Terracotta Army
Posts: 200


Reply #189 on: August 02, 2010, 09:20:22 PM

I was hacked one time a few years ago, and they deleted all my chars EXCEPT my level 12 rogue, who still had a couple hundred gold on him when I logged on. Weird. And I hadn't clicked any links either... so I guess I was just very unlucky.
Rendakor
Terracotta Army
Posts: 10138


Reply #190 on: August 02, 2010, 09:21:44 PM

I'm getting Starcraft phishing mail now, telling me I've purchased things. Very Very odd.
I got one of those today too. It strikes me as strange too since I've never gotten any WoW phishing ones. Pretty obvious though, since even the listed links were to us.battle.coderedemption.net/login.html.

"i can't be a star citizen. they won't even give me a star green card"
Mattemeo
Terracotta Army
Posts: 1128


Reply #191 on: August 04, 2010, 08:21:08 PM

Ok, the last one was at least competently written and made me need to check things out. Today's attempt is just sad... here's an exerpt from 'WoWAccountEU @ review.blizzard.com' (I don't even play on EU) :

Quote
Due to suspicious activity, the Battle.net account myaddress @ hotmail.com has been locked. You logined your account successfully at 11:26:56 on 2010-8-4 from the 175.242.12.5, but our system shows this IP isn't your registered IP. We are concerned about whether your account has been stolen. In order to guarantee the legitimacy of your account, we need you follow these steps:

Rest includes some seriously bad, overlong, blatantly phishy clickthrough urls, not even hyperlink-masked. I wouldn't usually have bothered posting an obvious one, but I'm guessing this one was just a shot in the dark.

If you party with the Party Prince you get two complimentary after-dinner mints
Lt.Dan
Terracotta Army
Posts: 758


Reply #192 on: August 04, 2010, 09:28:43 PM

Some of those phishing attempts are scary clever.  After getting a few in the last couple of weeks I've changed my bnet email and login to a new email address created specifically for WoW.  Hopefully that stops me falling for "your account has been stolen" or "cataclysm launcher" emails. 
Riggswolfe
Terracotta Army
Posts: 8046


Reply #193 on: August 05, 2010, 10:14:10 PM

Well, I think I got hacked but got very, very lucky as near as I can tell.

Earlier today I was on my highest level "main". My wife came home and I switched to my druid. I kept getting booted offline and I kept coming back on. The last time it didn't take my password so I changed it and got back on again. Then I got booted again and this time got the "your account has been suspended notification" followed later by an email. I've run Spybot, Malware Byes, am currently running Windows Security Essentials and plan to run AVG after that. None of them have found anything yet. As far as I know my characters didn't get touched unless it was during that 2-3 minutes were my password was changed.

Edit: I still haven't found anything. Do any of you guys have any hints? Do you think I have a key logger or was it just a brute force attack on my password?
« Last Edit: August 06, 2010, 07:00:17 AM by Riggswolfe »

"We live in a country, where John Lennon takes six bullets in the chest, Yoko Ono was standing right next to him and not one fucking bullet! Explain that to me! Explain that to me, God! Explain it to me, God!" - Denis Leary summing up my feelings about the nature of the universe.
Arthur_Parker
Terracotta Army
Posts: 5865

Internet Detective


Reply #194 on: August 06, 2010, 07:50:29 AM

How many characters in your old password out of interest?
Dren
Terracotta Army
Posts: 2419


Reply #195 on: August 06, 2010, 08:01:52 AM

If you actually changed your password and it still continued to happen, it has to be a keylogger doesn't it?   I can't believe brute force would come up with your new password that quickly.
Riggswolfe
Terracotta Army
Posts: 8046


Reply #196 on: August 06, 2010, 08:30:58 AM

If you actually changed your password and it still continued to happen, it has to be a keylogger doesn't it?   I can't believe brute force would come up with your new password that quickly.

Except I didn't actually change it. I was stupid and thought I was mistyping it so just reset it thinking I'd locked my account and put it right back to my old password. Yes, I was a moron. I wasn't thinking clearly, it was late and I was in a dungeon and my main thought was "got to get back on NOW". I'm paranoid about changing it now because if there is a keylogger they'll just get the new one anyway.

Edit: It is now actually changed. We'll see. The password I changed to isn't the one I was originally planning to use. So far, nothing I have tried has found anything except a trojan called Java/Downloader.P which I can't find any information on and something called Html/Framer.CX which I also haven't had much luck finding anything about. I'm wondering if they're both false positives. Have any of you heard of them?
« Last Edit: August 06, 2010, 08:46:07 AM by Riggswolfe »

"We live in a country, where John Lennon takes six bullets in the chest, Yoko Ono was standing right next to him and not one fucking bullet! Explain that to me! Explain that to me, God! Explain it to me, God!" - Denis Leary summing up my feelings about the nature of the universe.
Arthur_Parker
Terracotta Army
Posts: 5865

Internet Detective


Reply #197 on: August 06, 2010, 09:00:48 AM

Rendakor
Terracotta Army
Posts: 10138


Reply #198 on: August 06, 2010, 09:22:08 AM

You running an unsecured wireless network by any chance?

"i can't be a star citizen. they won't even give me a star green card"
Riggswolfe
Terracotta Army
Posts: 8046


Reply #199 on: August 06, 2010, 09:28:25 AM

You running an unsecured wireless network by any chance?

Hell no. If people want wireless they need to buy their own damned router. Now, my key could be hacked if someone was determined enough but you know, I doubt I'm important enough for some dude to park in front of my house and hack me and my neighborhood is mostly old people so I doubt any of them even know how to use one of these newfangled computer things.


Yes I am. I just updated them today. Thanks for the link. My googlefu is apparently weak today.
« Last Edit: August 06, 2010, 09:30:08 AM by Riggswolfe »

"We live in a country, where John Lennon takes six bullets in the chest, Yoko Ono was standing right next to him and not one fucking bullet! Explain that to me! Explain that to me, God! Explain it to me, God!" - Denis Leary summing up my feelings about the nature of the universe.
Morat20
Terracotta Army
Posts: 18529


Reply #200 on: August 06, 2010, 09:39:45 AM

Most common ways to get your password:

1) Phishing/social attacks.
2) You reusing name/password combos that have either been phished before, or hacked.
3) Trojans/keyloggers/the like.

Most likely explanation is you typed your ID/password somewhere you shouldn't have -- fake WoW site via phishing for instance. No matter how vigilant you are, sooner or later you'll brain fart and do this with SOMETHING. Second most likely is -- and we're pretty certain this is how my wife had hers compromised -- you used that username-password combo for something like, say, a WoW guild forum, which someone cracked and sold the id/password combos to.

The last is you got infected by something that was looking for and logged those things, and sent them off.

At least that's the general gist I got from the security courses and classes I've had to take, about how internet security is compromised. I'd just get a token. I've been meaning to get one myself -- we use RSA SecureID at work, and it prevents a lot of crap, and I understand the WoW authenticators work under similiar principles.
Riggswolfe
Terracotta Army
Posts: 8046


Reply #201 on: August 06, 2010, 09:46:21 AM

Yeah, I've ordered the authenticators and they should be here in a week or two.

Most common ways to get your password:

1) Phishing/social attacks.
2) You reusing name/password combos that have either been phished before, or hacked.
3) Trojans/keyloggers/the like.

1) I haven't even gotten any fake emails or the like.
2) yeah, I probably did this one. I'm bad about that, I won't lie.
3) This is my big worry mostly because it puts stuff besides WOW in danger.

It turns out that the framer "virus" AVG found is probably a false positive. That only leaves the java/downloader.p which it removed but I'm trying to find info on. Meanwhile I'm running other AVs and doing the "go overboard and scan the hell out of my comp" routine.

Edit: I will be unsuspended around 10pm central tonight. We'll see what I find when that happens. One of my worries is that they put a fake authenticator on my account. We'll see.
« Last Edit: August 06, 2010, 09:48:39 AM by Riggswolfe »

"We live in a country, where John Lennon takes six bullets in the chest, Yoko Ono was standing right next to him and not one fucking bullet! Explain that to me! Explain that to me, God! Explain it to me, God!" - Denis Leary summing up my feelings about the nature of the universe.
Morat20
Terracotta Army
Posts: 18529


Reply #202 on: August 06, 2010, 09:51:58 AM

Edit: I will be unsuspended around 10pm central tonight. We'll see what I find when that happens. One of my worries is that they put a fake authenticator on my account. We'll see.
They're pretty good about it, customer service wise, fixing stuff like that. Most farmers and hackers simply won't bother with a massive back and forth with customer service if you're disuputing it.

It'll help if you tended to use a credit card and not a pre-paid card, though, since it can tie "who is paying for this" to a specific person.
Riggswolfe
Terracotta Army
Posts: 8046


Reply #203 on: August 06, 2010, 09:58:00 AM

Edit: I will be unsuspended around 10pm central tonight. We'll see what I find when that happens. One of my worries is that they put a fake authenticator on my account. We'll see.
They're pretty good about it, customer service wise, fixing stuff like that. Most farmers and hackers simply won't bother with a massive back and forth with customer service if you're disuputing it.

It'll help if you tended to use a credit card and not a pre-paid card, though, since it can tie "who is paying for this" to a specific person.

I do. I was actually a little worried about that but the Blizzard rep said these guys don't usually mess with your credit card because that brings down alot more heat on them than getting your virtual stuff from a video game.

"We live in a country, where John Lennon takes six bullets in the chest, Yoko Ono was standing right next to him and not one fucking bullet! Explain that to me! Explain that to me, God! Explain it to me, God!" - Denis Leary summing up my feelings about the nature of the universe.
Morat20
Terracotta Army
Posts: 18529


Reply #204 on: August 06, 2010, 10:05:40 AM

I do. I was actually a little worried about that but the Blizzard rep said these guys don't usually mess with your credit card because that brings down alot more heat on them than getting your virtual stuff from a video game.
My wife got her account hacked, had it played and used for farming, then the account perma-banned. She didn't notice for a YEAR. It took Blizzard customer service about 4 days to reinstate the account, and they were apologetic that they couldn't get her stuff back.

Not that it mattered. She got a free WoTLK upgrade out of it (the farmers had upgraded her account) and had a bank full of farmed materials. She was just upset at someone having moved her main through TBC and WoTLK, so started an alt while slowly relearning her main and going through all the quests. (The farmer hadn't bothered with that).
Arthur_Parker
Terracotta Army
Posts: 5865

Internet Detective


Reply #205 on: August 06, 2010, 12:39:24 PM

That only leaves the java/downloader.p which it removed but I'm trying to find info on. Meanwhile I'm running other AVs and doing the "go overboard and scan the hell out of my comp" routine.

This it?

http://forums.avg.com/pl-en/avg-free-forum?sec=thread&act=show&id=93653#post_93653
Riggswolfe
Terracotta Army
Posts: 8046


Reply #206 on: August 06, 2010, 01:09:19 PM

That only leaves the java/downloader.p which it removed but I'm trying to find info on. Meanwhile I'm running other AVs and doing the "go overboard and scan the hell out of my comp" routine.

This it?

http://forums.avg.com/pl-en/avg-free-forum?sec=thread&act=show&id=93653#post_93653

It looks like he had the same thing at least though it doesn't say what it was. AVG cleaned it out. I'm just trying to figure out if it was what got my password or if I need to keep looking. I'm running something called Webroot now which is supposed to be pretty good. All it's found so far are various tracking cookies. I think I know where I got it I just want to know if it's gone for real or if it's being missed.

"We live in a country, where John Lennon takes six bullets in the chest, Yoko Ono was standing right next to him and not one fucking bullet! Explain that to me! Explain that to me, God! Explain it to me, God!" - Denis Leary summing up my feelings about the nature of the universe.
Riggswolfe
Terracotta Army
Posts: 8046


Reply #207 on: August 07, 2010, 10:33:59 AM

Well, my account unlocked at 9:45pm yesterday. I got in and nothing was missing and obviously no authenticator. So far there has not been anything else suspicious going on. That said, I don't know if they're just waiting or if I really did save myself through password changes and running multiple security programs. They never seemed to find anything major but maybe I got lucky and it was just brute force?

"We live in a country, where John Lennon takes six bullets in the chest, Yoko Ono was standing right next to him and not one fucking bullet! Explain that to me! Explain that to me, God! Explain it to me, God!" - Denis Leary summing up my feelings about the nature of the universe.
proudft
Terracotta Army
Posts: 1228


Reply #208 on: August 07, 2010, 10:36:41 AM

Could be.  WoW passwords are apparently non-case specific and have no # of attempts limiter so it is actually fairly feasible for someone to write a custom brute force login thing.  Plus they tend to be short, and your email is floating around somewhere already.  Take a look at these times if you want to be scared:

http://www.lockdown.co.uk/?pg=combi

Then get an authenticator.   Ohhhhh, I see.
« Last Edit: August 07, 2010, 10:38:39 AM by proudft »
Riggswolfe
Terracotta Army
Posts: 8046


Reply #209 on: August 07, 2010, 01:39:29 PM



Then get an authenticator.   Ohhhhh, I see.

I bought one for my wife and myself. Really, my biggest worry is a key authenticator logger. Not because of wow but because of stuff like ordering online with a credit card and stuff.
« Last Edit: August 08, 2010, 12:18:42 AM by Riggswolfe »

"We live in a country, where John Lennon takes six bullets in the chest, Yoko Ono was standing right next to him and not one fucking bullet! Explain that to me! Explain that to me, God! Explain it to me, God!" - Denis Leary summing up my feelings about the nature of the universe.
Pages: 1 ... 4 5 [6] 7 8 ... 10 Go Up Print 
f13.net  |  f13.net General Forums  |  The Gaming Graveyard  |  World of Warcraft  |  Topic: My WoW-account's been compromised  
Jump to:  

Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC