Go Back   Dreams in Vanadiel - Final Fantasy XI Forum > FFXI Game Related > General FFXI Discussion

Post New Thread Reply
 
LinkBack Thread Tools Display Modes
Old 12-12-2007, 05:48 AM   #1
Dynamis Guru
Bronze Ribbon of Service
 
Olorin401's Avatar
 
Join Date: May 2006
Location: Roe Dilund
Posts: 590
Style: Light Theme V7

Thanks: 267
Thanked 54x in 45 Posts
My Mood:
   
WARNING - Somepage linked to account hijackings

http://bluegartrls.com/forum/viewtopic.php?f=2&t=27256

A few weeks ago people were asking around about the ffxi database at Somepage.com not being updated. It turns out that the site was hacked.

The hackers implanted a ActiveX control (Internet Explorer only) that will auto-download a javascript-based trojan onto your computer, which will steal your FFXI account information. This exploit can be patched by installing this software patch for Realplayer.

As expected, the GMs are completely clueless to this, and have even stated to some players that the idea that a well-known FFXI informational website is the cause of the many compromised accounts recently. However they have supposedly made reports on this issue to the Special Task Force, so hopefully there will be a better response on SE's side. They can't claim that people are taking their chances anymore..

BG has setup a thread for the SPT to keep track of players whose accounts have been compromised. If you or someone you know has been hijacked, post the character information there.

BTW, use Firefox and you can probably avoid this problem. Don't risk it though guys.
__________________
Olorin of Ramuh! At least I used to be.. now I'm Scoopster - Host of irc.gamesurge.net #ffxivbeta
BRD77 WHM75 BLM75 RDM75 SCH50 SMN40 - TheAfterLife LS
Olorin401 is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 05:57 AM   #2
Chocobreeder
Bronze Ribbon of Service
 
KingOfZeal's Avatar
 
Join Date: May 2006
Posts: 670
Style: Light Theme V7

Thanks: 133
Thanked 111x in 72 Posts
My Mood:
   
Re: WARNING - Somepage linked to account hijackings

Funny how people thought those same things were coming from FFXIAH... or are these different hackings?
__________________
Kindadarii (Bahamut)
80PUP / 80BRD / 66WHM / 58SMN / 42DNC
68.9 + 2 Woodworking
42.1 Synergy


Breeding Chocobos? Visit Chocobreeder.com to find chocobos in your area!
KingOfZeal is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 05:58 AM   #3
Something soft on my face
Steelknight Emblem
 
Mhurron's Avatar
 
Join Date: May 2006
Location: Best Carolina
Posts: 5,801
Style: Light Theme V7

Thanks: 157
Thanked 2,276x in 1,290 Posts
Send a message via ICQ to Mhurron Send a message via Yahoo to Mhurron
   
Re: WARNING - Somepage linked to account hijackings

Best fix, get that Real player crap off your system.
Mhurron is online now   Reply With Quote Button by Aksannyi :)
The Following 7 Users Say Thank You to Mhurron For This Useful Post:
Akashimo (12-12-2007), Ameroth (12-12-2007), Feba (12-12-2007), Omniblast (12-12-2007), Prons (12-12-2007), Susurrus (12-22-2007), tdh (12-14-2007)
Old 12-12-2007, 06:00 AM   #4
Something soft on my face
Steelknight Emblem
 
Mhurron's Avatar
 
Join Date: May 2006
Location: Best Carolina
Posts: 5,801
Style: Light Theme V7

Thanks: 157
Thanked 2,276x in 1,290 Posts
Send a message via ICQ to Mhurron Send a message via Yahoo to Mhurron
   
Re: WARNING - Somepage linked to account hijackings

Quote:
Originally Posted by KingOfZeal View Post
Funny how people thought those same things were coming from FFXIAH... or are these different hackings?
Could be the same and could be different. If Somepage and FFXIah are using the same ad providers then both sites could serve up the same malicious ads.
Mhurron is online now   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:00 AM   #5
Junior Member
 
METDeath's Avatar
 
Join Date: Oct 2003
Location: Kennesaw, GA
Posts: 343
Style: Light Theme V7

Thanks: 0
Thanked 0x in 0 Posts
   
Re: WARNING - Somepage linked to account hijackings

And this is why you don't use realplayer... oh, and "buffering"
__________________
METDeath is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:10 AM   #6
Dynamis Guru
Bronze Ribbon of Service
 
Olorin401's Avatar
 
Join Date: May 2006
Location: Roe Dilund
Posts: 590
Style: Light Theme V7

Thanks: 267
Thanked 54x in 45 Posts
My Mood:
   
Re: WARNING - Somepage linked to account hijackings

I don't think RP causes the vulnerability.. The source of the exploit is an ActiveX plugin to IE - which means you don't necessarily need to have Realplayer installed to be a target.
__________________
Olorin of Ramuh! At least I used to be.. now I'm Scoopster - Host of irc.gamesurge.net #ffxivbeta
BRD77 WHM75 BLM75 RDM75 SCH50 SMN40 - TheAfterLife LS
Olorin401 is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:12 AM   #7
Something soft on my face
Steelknight Emblem
 
Mhurron's Avatar
 
Join Date: May 2006
Location: Best Carolina
Posts: 5,801
Style: Light Theme V7

Thanks: 157
Thanked 2,276x in 1,290 Posts
Send a message via ICQ to Mhurron Send a message via Yahoo to Mhurron
   
Re: WARNING - Somepage linked to account hijackings

BTW, no this is different. FFXIah ads tried to get you to download a file (presumably a trojan) whereas sompage's main page has a hidden iframe that is trying to do things automatically in the background.
Mhurron is online now   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:13 AM   #8
Something soft on my face
Steelknight Emblem
 
Mhurron's Avatar
 
Join Date: May 2006
Location: Best Carolina
Posts: 5,801
Style: Light Theme V7

Thanks: 157
Thanked 2,276x in 1,290 Posts
Send a message via ICQ to Mhurron Send a message via Yahoo to Mhurron
   
Re: WARNING - Somepage linked to account hijackings

Quote:
Originally Posted by Olorin401 View Post
I don't think RP causes the vulnerability.. The source of the exploit is an ActiveX plugin to IE - which means you don't necessarily need to have Realplayer installed to be a target.
No, the FFXIah one seems to be a real player exploit which is why Real Player has to patch it.
Mhurron is online now   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:16 AM   #9
Dynamis Guru
Bronze Ribbon of Service
 
Olorin401's Avatar
 
Join Date: May 2006
Location: Roe Dilund
Posts: 590
Style: Light Theme V7

Thanks: 267
Thanked 54x in 45 Posts
My Mood:
   
Re: WARNING - Somepage linked to account hijackings

Quote:
Originally Posted by Mhurron View Post
Could be the same and could be different. If Somepage and FFXIah are using the same ad providers then both sites could serve up the same malicious ads.


The malicious ActiveX control is implanted in that little box, which is actually an inline frame.

I'm not saying it couldn't be in the banner ads on FFXIAH - I work with banner ads all day at work so I know what kind of funky stuff can be weaved into them. I'm actually thinking that maybe these hackers might also have compromised FFXIAH, in which case we'll find the same kind of inline frame somewhere on the page.
------------------------------------------
Quote:
Originally Posted by Mhurron View Post
No, the FFXIah one seems to be a real player exploit which is why Real Player has to patch it.
Yeah.. this one on Somepage is the same exploit. Downloading the patch from Real will fix it.
__________________
Olorin of Ramuh! At least I used to be.. now I'm Scoopster - Host of irc.gamesurge.net #ffxivbeta
BRD77 WHM75 BLM75 RDM75 SCH50 SMN40 - TheAfterLife LS

Last edited by Olorin401; 12-12-2007 at 06:18 AM. Reason: Automerged Doublepost
Olorin401 is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:19 AM   #10
Just a glimpse of an ankle
Allied Ribbon of Glory
 
Ellipses's Avatar
 
Join Date: May 2006
Posts: 2,090
Style: Light Theme V7

Thanks: 186
Thanked 522x in 337 Posts
   
Re: WARNING - Somepage linked to account hijackings

Ha, nevermind. Thread kept going while I was typing and reading a bunch of stuff. Screw posterity! I'ma cover my dumbass tracks!
__________________
Ellipses on Fenrir
There is no rush. If you're not willing to take your time, don't be surprised when no one wants to give you much of theirs.
<3,
. . .

Last edited by Ellipses; 12-12-2007 at 06:26 AM.
Ellipses is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:25 AM   #11
Where The Bad Things Go
Mythril Star
 
DakAttack's Avatar
 
Join Date: Jan 2005
Location: Confirmed
Posts: 3,994
Style: Light Theme V7

Thanks: 179
Thanked 487x in 344 Posts
   
Re: WARNING - Somepage linked to account hijackings

So how did Somepage get hacked? Giving away their information?
__________________

DakAttack is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:27 AM   #12
Pink Mage
Allied Ribbon of Bravery
 
Sabaron's Avatar
 
Join Date: May 2006
Location: Bastok/Illinois
Posts: 1,800
Style: Light Theme V7

Thanks: 196
Thanked 235x in 151 Posts
   
Re: WARNING - Somepage linked to account hijackings

Ok, that really sucks, but that's why I run Firefox. RealPlayer hasn't been cool for a long time--and the exploit is a buffer overrun which is very very sloppy since Windows development environments have been updated since what... 1999 or 2000 to deprecate functions without buffer overrun checks on them. That's rather poor coding at best. Does anyone actually make content for RP any more? I mean content that's worth getting that's not also available for Flash? Also, I think RP is still a "thick" client whereas Adobe Flash is much lighter and better integrated with teh Intarweb.

Oh and on another note, I can't believe that GD Internet Explorer, after all Microsoft's To-do about "security" is still running these f'in Active-X controls without even the slightest notification. "Oh sure Mr. Unsigned Active-X control, you can go ahead and do whatever you like. Oh that user guy? Nah, we don't need to tell him, I'm sure he doesn't want to be bothered anyway. Now, do you accept Mastercard or Visa? I've got both numbers, we can just set him up for automatic billing right now, I'm sure he'll appreciate the efficiency."
__________________

Last edited by Sabaron; 12-12-2007 at 06:33 AM.
Sabaron is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:35 AM   #13
The Hare
Administrator
Steelknight Emblem
 
Taskmage's Avatar
 
Join Date: Dec 2003
Posts: 5,672
Style: Light Theme V7

Thanks: 352
Thanked 1,106x in 551 Posts
Re: WARNING - Somepage linked to account hijackings

Well hell, what site can I go to anymore? And the irony is I switched back to IE from Firefox specifically because Firefox wasn't blocking the popups on somepage.
__________________
-
Taskmage is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:40 AM   #14
Something soft on my face
Steelknight Emblem
 
Mhurron's Avatar
 
Join Date: May 2006
Location: Best Carolina
Posts: 5,801
Style: Light Theme V7

Thanks: 157
Thanked 2,276x in 1,290 Posts
Send a message via ICQ to Mhurron Send a message via Yahoo to Mhurron
   
Re: WARNING - Somepage linked to account hijackings

Quote:
Originally Posted by DakAttack View Post
So how did Somepage get hacked? Giving away their information?
Could be anything. Maybe their password to their hosting site was easy to guess. The site does seem to have been abandoned, at least updates wise so maybe they don't even know or care to look.
Mhurron is online now   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 07:34 AM   #15
Kerio
 
Kerio's Avatar
 
Join Date: Nov 2007
Posts: 124
Style: Light Theme V7

Thanks: 3
Thanked 0x in 0 Posts
   
Re: WARNING - Somepage linked to account hijackings

Quote:
Originally Posted by Mhurron View Post
Best fix, get that Real player crap off your system.
this forum is starting to scare me... and what's wrong with real player? I never use it, it's kinda just sitting there on my computer. I use this thing called Zoom player and it works great. Got it with this CCC pack or "combined community codec" thing.
And also can you please keep me updated on the ffxiah thing?? i always use that... just don't tell me ffxiclopedia is bad too... aaaah i'm running out of places to look at for cooking recipes! And i mean GOOD recipe lists, GOOD ones.
Kerio is offline   Reply With Quote Button by Aksannyi :)
Post New Thread Reply

Tags
account, hijackings, linked, somepage, warning

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -8. The time now is 07:56 PM.
Site Powered by: vBulletin Version 3.8.1 Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.0 RC2
©2001-2009 SQUARE ENIX CO., LTD. All Rights Reserved. Title Design by Yoshitaka Amano.
FINAL FANTASY and VANA'DIEL are registered trademarks of Square Enix Co., Ltd. SQUARE ENIX, PLAYONLINE and the PlayOnline logo are trademarks of Square Enix Co., Ltd.
Comments and posts are property of their authors. All the rest, including video, articles, compiled game data, and sections, unless otherwise noted, are
©2002-2009 FFXIOnline.com: Dreams in Vana'diel. All rights reserved.

no new posts
Page generated in 0.53106 seconds with 23 queries