Go Back   Dreams in Vanadiel - Final Fantasy XI Forum > Dreams in Vana'diel - Main Topics > General FFXI Discussion

Post New Thread Reply
 
LinkBack Thread Tools Display Modes
Old 12-12-2007, 05:48 AM   #1
Dynamis Guru
Bronze Ribbon of Service
 
Olorin401's Avatar
 
Join Date: May 2006
Location: Roe Dilund
Posts: 585
Style: Light Theme V7

Thanks: 267
Thanked 54x in 45 Posts
My Mood:
   
WARNING - Somepage linked to account hijackings

http://bluegartrls.com/forum/viewtopic.php?f=2&t=27256

A few weeks ago people were asking around about the ffxi database at Somepage.com not being updated. It turns out that the site was hacked.

The hackers implanted a ActiveX control (Internet Explorer only) that will auto-download a javascript-based trojan onto your computer, which will steal your FFXI account information. This exploit can be patched by installing this software patch for Realplayer.

As expected, the GMs are completely clueless to this, and have even stated to some players that the idea that a well-known FFXI informational website is the cause of the many compromised accounts recently. However they have supposedly made reports on this issue to the Special Task Force, so hopefully there will be a better response on SE's side. They can't claim that people are taking their chances anymore..

BG has setup a thread for the SPT to keep track of players whose accounts have been compromised. If you or someone you know has been hijacked, post the character information there.

BTW, use Firefox and you can probably avoid this problem. Don't risk it though guys.
__________________
Olorin - Ramuh Server
WHM75 BRD75 BLM75 RDM75 SMN39 SCH37 - TheAfterLife LS
Olorin401 is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 05:57 AM   #2
Chocobreeder
Bronze Ribbon of Service
 
KingOfZeal's Avatar
 
Join Date: May 2006
Posts: 529
Style: Light Theme V7

Thanks: 110
Thanked 83x in 54 Posts
My Mood:
   
Re: WARNING - Somepage linked to account hijackings

Funny how people thought those same things were coming from FFXIAH... or are these different hackings?
__________________
Kindadarii (Bahamut)
75BRD / 75PUP / 66WHM / 34SMN
68.2 + 2 Woodworking
19.7 Alchemy


Breeding Chocobos? Visit Chocobreeder.com to find chocobos in your area!
KingOfZeal is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 05:58 AM   #3
Senior Veteran
Iron Emblem of Service
 
Mhurron's Avatar
 
Join Date: May 2006
Posts: 5,118
Style: Light Theme V7

Thanks: 138
Thanked 1,759x in 1,037 Posts
Send a message via ICQ to Mhurron
   
Re: WARNING - Somepage linked to account hijackings

Best fix, get that Real player crap off your system.
__________________
I use a Mac because I'm just better than you are.
Paragon of Red Mage Excellence
Paragon of Black Mage Excellence

Maat Masher - RDM
Shining Ray of Awesome

HTTP Error 418 - I'm A Teapot - The resulting entity body MAY be short and stout.
Mhurron is offline   Reply With Quote Button by Aksannyi :)
The Following 7 Users Say Thank You to Mhurron For This Useful Post:
Akashimo (12-12-2007), Ameroth (12-12-2007), Feba (12-12-2007), Omniblast (12-12-2007), Prons (12-12-2007), Susurrus (12-22-2007), tdh (12-14-2007)
Old 12-12-2007, 06:00 AM   #4
Senior Veteran
Iron Emblem of Service
 
Mhurron's Avatar
 
Join Date: May 2006
Posts: 5,118
Style: Light Theme V7

Thanks: 138
Thanked 1,759x in 1,037 Posts
Send a message via ICQ to Mhurron
   
Re: WARNING - Somepage linked to account hijackings

Quote:
Originally Posted by KingOfZeal View Post
Funny how people thought those same things were coming from FFXIAH... or are these different hackings?
Could be the same and could be different. If Somepage and FFXIah are using the same ad providers then both sites could serve up the same malicious ads.
__________________
I use a Mac because I'm just better than you are.
Paragon of Red Mage Excellence
Paragon of Black Mage Excellence

Maat Masher - RDM
Shining Ray of Awesome

HTTP Error 418 - I'm A Teapot - The resulting entity body MAY be short and stout.
Mhurron is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:00 AM   #5
Junior Member
 
METDeath's Avatar
 
Join Date: Oct 2003
Location: Kennesaw, GA
Posts: 350
Style: Light Theme V7

Thanks: 0
Thanked 0x in 0 Posts
   
Re: WARNING - Somepage linked to account hijackings

And this is why you don't use realplayer... oh, and "buffering"
__________________
METDeath is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:10 AM   #6
Dynamis Guru
Bronze Ribbon of Service
 
Olorin401's Avatar
 
Join Date: May 2006
Location: Roe Dilund
Posts: 585
Style: Light Theme V7

Thanks: 267
Thanked 54x in 45 Posts
My Mood:
   
Re: WARNING - Somepage linked to account hijackings

I don't think RP causes the vulnerability.. The source of the exploit is an ActiveX plugin to IE - which means you don't necessarily need to have Realplayer installed to be a target.
__________________
Olorin - Ramuh Server
WHM75 BRD75 BLM75 RDM75 SMN39 SCH37 - TheAfterLife LS
Olorin401 is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:12 AM   #7
Senior Veteran
Iron Emblem of Service
 
Mhurron's Avatar
 
Join Date: May 2006
Posts: 5,118
Style: Light Theme V7

Thanks: 138
Thanked 1,759x in 1,037 Posts
Send a message via ICQ to Mhurron
   
Re: WARNING - Somepage linked to account hijackings

BTW, no this is different. FFXIah ads tried to get you to download a file (presumably a trojan) whereas sompage's main page has a hidden iframe that is trying to do things automatically in the background.
__________________
I use a Mac because I'm just better than you are.
Paragon of Red Mage Excellence
Paragon of Black Mage Excellence

Maat Masher - RDM
Shining Ray of Awesome

HTTP Error 418 - I'm A Teapot - The resulting entity body MAY be short and stout.
Mhurron is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:13 AM   #8
Senior Veteran
Iron Emblem of Service
 
Mhurron's Avatar
 
Join Date: May 2006
Posts: 5,118
Style: Light Theme V7

Thanks: 138
Thanked 1,759x in 1,037 Posts
Send a message via ICQ to Mhurron
   
Re: WARNING - Somepage linked to account hijackings

Quote:
Originally Posted by Olorin401 View Post
I don't think RP causes the vulnerability.. The source of the exploit is an ActiveX plugin to IE - which means you don't necessarily need to have Realplayer installed to be a target.
No, the FFXIah one seems to be a real player exploit which is why Real Player has to patch it.
__________________
I use a Mac because I'm just better than you are.
Paragon of Red Mage Excellence
Paragon of Black Mage Excellence

Maat Masher - RDM
Shining Ray of Awesome

HTTP Error 418 - I'm A Teapot - The resulting entity body MAY be short and stout.
Mhurron is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:16 AM   #9
Dynamis Guru
Bronze Ribbon of Service
 
Olorin401's Avatar
 
Join Date: May 2006
Location: Roe Dilund
Posts: 585
Style: Light Theme V7

Thanks: 267
Thanked 54x in 45 Posts
My Mood:
   
Re: WARNING - Somepage linked to account hijackings

Quote:
Originally Posted by Mhurron View Post
Could be the same and could be different. If Somepage and FFXIah are using the same ad providers then both sites could serve up the same malicious ads.


The malicious ActiveX control is implanted in that little box, which is actually an inline frame.

I'm not saying it couldn't be in the banner ads on FFXIAH - I work with banner ads all day at work so I know what kind of funky stuff can be weaved into them. I'm actually thinking that maybe these hackers might also have compromised FFXIAH, in which case we'll find the same kind of inline frame somewhere on the page.
------------------------------------------
Quote:
Originally Posted by Mhurron View Post
No, the FFXIah one seems to be a real player exploit which is why Real Player has to patch it.
Yeah.. this one on Somepage is the same exploit. Downloading the patch from Real will fix it.
__________________
Olorin - Ramuh Server
WHM75 BRD75 BLM75 RDM75 SMN39 SCH37 - TheAfterLife LS

Last edited by Olorin401; 12-12-2007 at 06:18 AM. Reason: Automerged Doublepost
Olorin401 is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:19 AM   #10
Just a glimpse of an ankle
Allied Ribbon of Glory
 
Ellipses's Avatar
 
Join Date: May 2006
Posts: 2,090
Style: Light Theme V7

Thanks: 186
Thanked 521x in 336 Posts
   
Re: WARNING - Somepage linked to account hijackings

Ha, nevermind. Thread kept going while I was typing and reading a bunch of stuff. Screw posterity! I'ma cover my dumbass tracks!
__________________
Ellipses on Fenrir
There is no rush. If you're not willing to take your time, don't be surprised when no one wants to give you much of theirs.
<3,
. . .

Last edited by Ellipses; 12-12-2007 at 06:26 AM.
Ellipses is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:25 AM   #11
Where The Bad Things Go
Sterling Star
 
DakAttack's Avatar
 
Join Date: Jan 2005
Location: Confirmed
Posts: 3,106
Style: Light Theme V7

Thanks: 111
Thanked 269x in 200 Posts
   
Re: WARNING - Somepage linked to account hijackings

So how did Somepage get hacked? Giving away their information?
__________________
suck it
DakAttack is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:27 AM   #12
Pink Mage
Allied Ribbon of Bravery
 
Sabaron's Avatar
 
Join Date: May 2006
Location: Bastok/Illinois
Posts: 1,778
Style: Light Theme V7

Thanks: 190
Thanked 232x in 149 Posts
   
Re: WARNING - Somepage linked to account hijackings

Ok, that really sucks, but that's why I run Firefox. RealPlayer hasn't been cool for a long time--and the exploit is a buffer overrun which is very very sloppy since Windows development environments have been updated since what... 1999 or 2000 to deprecate functions without buffer overrun checks on them. That's rather poor coding at best. Does anyone actually make content for RP any more? I mean content that's worth getting that's not also available for Flash? Also, I think RP is still a "thick" client whereas Adobe Flash is much lighter and better integrated with teh Intarweb.

Oh and on another note, I can't believe that GD Internet Explorer, after all Microsoft's To-do about "security" is still running these f'in Active-X controls without even the slightest notification. "Oh sure Mr. Unsigned Active-X control, you can go ahead and do whatever you like. Oh that user guy? Nah, we don't need to tell him, I'm sure he doesn't want to be bothered anyway. Now, do you accept Mastercard or Visa? I've got both numbers, we can just set him up for automatic billing right now, I'm sure he'll appreciate the efficiency."
__________________

Last edited by Sabaron; 12-12-2007 at 06:33 AM.
Sabaron is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:35 AM   #13
不完全の花
Administrator
Iron Emblem of Service
 
Taskmage's Avatar
 
Join Date: Dec 2003
Posts: 5,401
Style: Light Theme V7

Thanks: 295
Thanked 940x in 467 Posts
Re: WARNING - Somepage linked to account hijackings

Well hell, what site can I go to anymore? And the irony is I switched back to IE from Firefox specifically because Firefox wasn't blocking the popups on somepage.
__________________

明日がほしいです
Taskmage is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 06:40 AM   #14
Senior Veteran
Iron Emblem of Service
 
Mhurron's Avatar
 
Join Date: May 2006
Posts: 5,118
Style: Light Theme V7

Thanks: 138
Thanked 1,759x in 1,037 Posts
Send a message via ICQ to Mhurron
   
Re: WARNING - Somepage linked to account hijackings

Quote:
Originally Posted by DakAttack View Post
So how did Somepage get hacked? Giving away their information?
Could be anything. Maybe their password to their hosting site was easy to guess. The site does seem to have been abandoned, at least updates wise so maybe they don't even know or care to look.
__________________
I use a Mac because I'm just better than you are.
Paragon of Red Mage Excellence
Paragon of Black Mage Excellence

Maat Masher - RDM
Shining Ray of Awesome

HTTP Error 418 - I'm A Teapot - The resulting entity body MAY be short and stout.
Mhurron is offline   Reply With Quote Button by Aksannyi :)
Old 12-12-2007, 07:34 AM   #15
Kerio
 
Kerio's Avatar
 
Join Date: Nov 2007
Posts: 124
Style: Light Theme V7

Thanks: 3
Thanked 0x in 0 Posts
   
Re: WARNING - Somepage linked to account hijackings

Quote:
Originally Posted by Mhurron View Post
Best fix, get that Real player crap off your system.
this forum is starting to scare me... and what's wrong with real player? I never use it, it's kinda just sitting there on my computer. I use this thing called Zoom player and it works great. Got it with this CCC pack or "combined community codec" thing.
And also can you please keep me updated on the ffxiah thing?? i always use that... just don't tell me ffxiclopedia is bad too... aaaah i'm running out of places to look at for cooking recipes! And i mean GOOD recipe lists, GOOD ones.
Kerio is offline   Reply With Quote Button by Aksannyi :)
Post New Thread Reply

Tags
account, hijackings, linked, somepage, warning

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -8. The time now is 11:25 AM.
Site Powered by: vBulletin Version 3.8.1 Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.0 RC2
©2001-2009 SQUARE ENIX CO., LTD. All Rights Reserved. Title Design by Yoshitaka Amano.
FINAL FANTASY and VANA'DIEL are registered trademarks of Square Enix Co., Ltd. SQUARE ENIX, PLAYONLINE and the PlayOnline logo are trademarks of Square Enix Co., Ltd.
Comments and posts are property of their authors. All the rest, including video, articles, compiled game data, and sections, unless otherwise noted, are
©2002-2009 FFXIOnline.com: Dreams in Vana'diel. All rights reserved.

no new posts
Page generated in 0.52298 seconds with 23 queries