Welcome, Guest. Please login or register.
April 18, 2024, 04:08:25 PM

Login with username, password and session length

Search:     Advanced search
we're back, baby
*
Home Help Search Login Register
f13.net  |  f13.net General Forums  |  The Gaming Graveyard  |  Guild Wars 2  |  Topic: Security Issues 0 Members and 1 Guest are viewing this topic.
Pages: [1] 2 3 Go Down Print
Author Topic: Security Issues  (Read 23470 times)
Hawkbit
Terracotta Army
Posts: 5531

Like a Klansman in the ghetto.


on: August 29, 2012, 10:48:07 AM

I've got at least 10 emails in the last few days from Anet, people trying to change the password on my account.  Hell, six of them are from within the last few hours. 

Not that we need to be told - awesome, for real - but make sure you have a strong password.  It seems the hackers are going after this game hard.
Malakili
Terracotta Army
Posts: 10596


Reply #1 on: August 29, 2012, 10:50:52 AM

Yeah, just got one of those myself
Rasix
Moderator
Posts: 15024

I am the harbinger of your doom!


Reply #2 on: August 29, 2012, 10:50:53 AM

Yep, I've gotten 2 emails already.  I assume more will come.

-Rasix
kildorn
Terracotta Army
Posts: 5014


Reply #3 on: August 29, 2012, 10:52:12 AM

I've had one so far.
01101010
Terracotta Army
Posts: 12003

You call it an accident. I call it justice.


Reply #4 on: August 29, 2012, 10:57:50 AM

Three thus far... 10:35, 11:11, and 12:46. My abcd1234!@ passwords cannot be deciphered!!

Does any one know where the love of God goes...When the waves turn the minutes to hours? -G. Lightfoot
Trippy
Administrator
Posts: 23618


Reply #5 on: August 29, 2012, 11:22:54 AM

Change your account login --  your email you sign on with -- which is not to be confused by the email address A.Net sends notifications to which can be different Ohhhhh, I see.
kildorn
Terracotta Army
Posts: 5014


Reply #6 on: August 29, 2012, 11:47:35 AM

The lack of brute force protection is probably the first clownshoes IT thing I've seen from them. I wonder how much drama that actually would cause gaming companies.
Ginaz
Terracotta Army
Posts: 3534


Reply #7 on: August 29, 2012, 12:22:11 PM

Emails are fake and not from ANet.  I got 6 or 7 to an email thats not tied to my GW2 account.  As always, don't click on anything.  Change your password if you want but do it directly from their site and not the link in the emails.
Amaron
Terracotta Army
Posts: 2020


Reply #8 on: August 29, 2012, 12:25:01 PM

Do you mean you're getting mails from the password reset system?  I would think they wouldn't bother with that if they didn't have access to your email account.
Ginaz
Terracotta Army
Posts: 3534


Reply #9 on: August 29, 2012, 01:33:41 PM

Do you mean you're getting mails from the password reset system?  I would think they wouldn't bother with that if they didn't have access to your email account.

I have a seperate email account I use only for a few of my online games.  That one hasn't gotten any password reset requests.  My more general email, which has no connection to GW2 at all, has gotten at least 6 or 7 password reset emails.
Tannhauser
Terracotta Army
Posts: 4436


Reply #10 on: August 29, 2012, 04:04:58 PM

Yeah I got an email from ANet saying someone tried to change my password.  My password is strong, but I may change it anyway.
Abelian75
Terracotta Army
Posts: 678


Reply #11 on: August 29, 2012, 04:20:39 PM

Yeah, I got that too.  Kinda curious what the idea behind that is, because I'm pretty confident they don't have my email (I use a 2-step authenticator thingy for gmail.  Also, nobody's logged into my GW2 account or changed my password.).  Not sure what it accomplishes to do that before gaining access to the email account.

It doesn't appear to be a fake email, though.  Links seem to go to the actual guildwars2.com website.

I didn't change my password or click the links, in any event, if only because I figure if someone is trying to make me want to change my password, I probably should not do it.
Khaldun
Terracotta Army
Posts: 15157


Reply #12 on: August 30, 2012, 07:28:50 AM

There's actually a thing on login in their own interface at the login screen that asks to confirm the email used for the game when you first sign up--the puzzling thing for me is that the confirmation link that pops up in email always reads as "expired" even if I go to it five seconds after getting the email. I think there's something funky going on with Arenanet's basic security set-up.
MrHat
Terracotta Army
Posts: 7432

Out of the frying pan, into the fire.


Reply #13 on: August 31, 2012, 08:42:45 AM

Well, that's great.

Got an email while I was playing that said my account email has been changed.

Guess who didn't change it?

Put in a support ticket as I'm unable to log in now.

Super duper.
Hawkbit
Terracotta Army
Posts: 5531

Like a Klansman in the ghetto.


Reply #14 on: August 31, 2012, 09:11:05 AM

I dropped your guild privs for the time being to remove the ability to withdraw items from the guild.  Let us know when it gets up and running. 

The guild stash has been open to all, the guild vault is deposit only for the time being.
MrHat
Terracotta Army
Posts: 7432

Out of the frying pan, into the fire.


Reply #15 on: August 31, 2012, 09:12:22 AM

I dropped your guild privs for the time being to remove the ability to withdraw items from the guild.  Let us know when it gets up and running. 

The guild stash has been open to all, the guild vault is deposit only for the time being.

Thanks.  Glad I burned my collectors stuff already.
Merusk
Terracotta Army
Posts: 27449

Badge Whore


Reply #16 on: August 31, 2012, 06:44:58 PM

So I decided to try GW1 again and had my NCsoft pw reset and sent to me on Thursday.  This morning it was hacked after I had changed the login email  to a new account unconnected to anything. They've got some bad security problems over there.

The past cannot be changed. The future is yet within your power.
MisterNoisy
Terracotta Army
Posts: 1892


Reply #17 on: August 31, 2012, 11:23:27 PM

Hilarious - I don't even have a GW2 account and have been getting emails about this shit.

XBL GT:  Mister Noisy
PSN:  MisterNoisy
Steam UID:  MisterNoisy
koro
Terracotta Army
Posts: 2307


Reply #18 on: September 01, 2012, 10:52:52 AM

I got two emails last night: One of them alerting me that a password change had been requested on my account.

The second? The confirmation email for the previous password change. All links (barring the confirmation one, 'cause I wasn't clicking that) were legit.

I do not have a Guild Wars account.  swamp poop
Mosesandstick
Terracotta Army
Posts: 2474


Reply #19 on: September 01, 2012, 01:33:53 PM

I think my IP got changed because of some repairs being done my ISP. Now I need to re-authenticate but I'm not receiving a damn email...
Evildrider
Terracotta Army
Posts: 5521


Reply #20 on: September 01, 2012, 01:50:14 PM

I think my IP got changed because of some repairs being done my ISP. Now I need to re-authenticate but I'm not receiving a damn email...

This is affecting a lot of people.  I haven't been able to log in all day.  :( 
Nevermore
Terracotta Army
Posts: 4740


Reply #21 on: September 01, 2012, 01:55:57 PM

Yup.  Apparently their system is so terrible sensitive that even people with dynamic IP addresses through their ISP are getting this, and their backend is so horrible overloaded that the emails aren't being sent.  You can't even log into the website (when it's actually up) since it also asks for the verification.

Over and out.
Amaron
Terracotta Army
Posts: 2020


Reply #22 on: September 01, 2012, 02:09:29 PM

All links (barring the confirmation one, 'cause I wasn't clicking that) were legit.

I do not have a Guild Wars account.  swamp poop

I'm lost on this as well.  I got some messages to an email that isn't associated with the GW2 account. The links are legit though.

Are they changing emails on already hacked accounts to ferret out which emails already have accounts?
Ingmar
Terracotta Army
Posts: 19280

Auto Assault Affectionado


Reply #23 on: September 01, 2012, 02:15:52 PM

Almost all well-made phishing spam uses legit links on everything but one of the links. You can't base anything off the fact that it has legit links in it, unless even the actual confirmation link they want you to click is legit. I bet it isn't.

The Transcendent One: AH... THE ROGUE CONSTRUCT.
Nordom: Sense of closure: imminent.
Amaron
Terracotta Army
Posts: 2020


Reply #24 on: September 01, 2012, 02:29:35 PM

Almost all well-made phishing spam uses legit links on everything but one of the links. You can't base anything off the fact that it has legit links in it, unless even the actual confirmation link they want you to click is legit. I bet it isn't.

It is and it's the only link.  Goes to account.guildwars2.com (even in the highlight).  I can only think that they have a hacked account which they then attempt to change to known emails in order to fish out the ones with existing accounts.
Ingmar
Terracotta Army
Posts: 19280

Auto Assault Affectionado


Reply #25 on: September 01, 2012, 03:02:22 PM

Yup.  Apparently their system is so terrible sensitive that even people with dynamic IP addresses through their ISP are getting this, and their backend is so horrible overloaded that the emails aren't being sent.  You can't even log into the website (when it's actually up) since it also asks for the verification.

Yeah this is happening to us as well today. Clownshoes.

The Transcendent One: AH... THE ROGUE CONSTRUCT.
Nordom: Sense of closure: imminent.
Nevermore
Terracotta Army
Posts: 4740


Reply #26 on: September 01, 2012, 04:52:21 PM

I just saw a post by someone on Guild Wars 2 Guru that if you run the launcher as an administrator you'll get the email.  I was doubtful but I tried it and it worked.

Edit: sounds like it was just a coincidence.
« Last Edit: September 01, 2012, 05:11:25 PM by Nevermore »

Over and out.
Phred
Terracotta Army
Posts: 2025


Reply #27 on: September 02, 2012, 12:17:30 AM

Hilarious - I don't even have a GW2 account and have been getting emails about this shit.
* Phred points MrNoisy at the definition of Phishing.
MrHat
Terracotta Army
Posts: 7432

Out of the frying pan, into the fire.


Reply #28 on: September 02, 2012, 01:28:45 PM

Well, that's great.

Got an email while I was playing that said my account email has been changed.

Guess who didn't change it?

Put in a support ticket as I'm unable to log in now.

Super duper.

Just an update: 3 days later and not a word from the guild wars team.  Seems my fun time with GW2 has ended.
KallDrexx
Terracotta Army
Posts: 3510


Reply #29 on: September 02, 2012, 03:02:27 PM

Just an update: 3 days later and not a word from the guild wars team.  Seems my fun time with GW2 has ended.

Not that it's any consolation, but according to their status page they are inundated with tickets and are only at August 30th tickets currently
Venkman
Terracotta Army
Posts: 11536


Reply #30 on: September 02, 2012, 03:55:54 PM

Just an update: 3 days later and not a word from the guild wars team.  Seems my fun time with GW2 has ended.

No idea if this helps. But in the latest Anet update they note:

Quote
Our customer support team is prioritizing tickets from customers with hacked accounts or who are otherwise blocked from logging into the game. If your account was hacked, please follow these instructions for submitting a ticket, to make sure that your ticket is correctly prioritized and to make sure you're submitting all the information we need to restore your access.

I hope it helps!
MrHat
Terracotta Army
Posts: 7432

Out of the frying pan, into the fire.


Reply #31 on: September 02, 2012, 05:24:08 PM

Ya, I did everything correctly, looks like a 4-7 day turn around on accounts.  Ah well.
MrHat
Terracotta Army
Posts: 7432

Out of the frying pan, into the fire.


Reply #32 on: September 02, 2012, 08:26:21 PM

Back in, password new and improved.

Hopefully no more shenanigans anymore.

Tyrnan
Terracotta Army
Posts: 428


Reply #33 on: September 03, 2012, 12:40:20 AM

From the latest update on the wiki page:

Quote
Scanning Accounts & Email Spam
    Yesterday, three malicious users each changed the account names of their own Guild Wars 2 accounts thousands of times, scanning through lists of email addresses stolen from other games and web sites, presumably to determine which email addresses were available (not already used for a Guild Wars 2 account) and which were taken. It obviously shouldn't be possible to change your own account name so frequently. We temporarily disabled account name changes and have now restored but limited them to prevent this.

    To the thousands of people who received emails stating, "the email address for your Guild Wars account has been changed," and are not even our customers, we sincerely apologize for the spam. Please be aware that your email address is on a list of account credentials that hackers have apparently stolen from other games and web sites and are systematically scanning.

    To Guild Wars 2 customers whose email addresses are being tested by hackers but not stolen, thank you for protecting your account by choosing a new, unique password for Guild Wars 2. Even though your unique password should protect you, we think you deserve to know if hackers have your email address on their list of credentials stolen from other games and web sites, so we'll send you periodic notifications when we see hackers testing your account.

Reset Password
    We're leaving "reset password" disabled for now. Please contact customer support if you forgot your password.

    We believe hackers also have lists of compromised credentials for email accounts, and we don't want to allow them to login to a compromised email account and then use "reset password" to steal the associated Guild Wars 2 game account.
Arinon
Terracotta Army
Posts: 312


Reply #34 on: September 03, 2012, 07:37:12 AM

Why did we start forcing account names to be e-mail addresses again?
Pages: [1] 2 3 Go Up Print 
f13.net  |  f13.net General Forums  |  The Gaming Graveyard  |  Guild Wars 2  |  Topic: Security Issues  
Jump to:  

Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC