Announcement

Collapse
No announcement yet.

MAJOR Password Logging Scheme

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #16
    Re: MAJOR Password Logging Scheme

    Which leads us to the whole identity theft thing.

    My business card got ganked a month ago, only just found out about it through the bank ringing me up.

    Funny how it's never an issue until it happens to you -.-

    Comment


    • #17
      Re: MAJOR Password Logging Scheme

      Originally posted by Karinya View Post
      Except that any well-designed web browser won't allow a website to do that kind of monkeying with your local machine without user approval. There are security restrictions placed on web content running on local machines for exactly that reason.

      Which sort of brings us back to "don't use IE".
      IE requests approval before activating ActiveX and certain Javascript controls. It prompts before downloading and doesn't automatically run files after they've been downloaded.

      Everybody needs to get off the bandwagon already. It doesn't matter what you use, if you're an idiot you're going to screw yourself no matter what browser you're using.

      Comment


      • #18
        Re: MAJOR Password Logging Scheme

        This happened on Ifrit, too. I remember a LS mate talking about it.

        Joke's on any idiot that would send the /tell to me, though.

        1. They'd get reported.
        2. My FFXI is on my PS2, lulz on them.
        3. I never visit any links given to me by anyone, including my b/f, unless I know what they are in advance. I.E. being a youtube video, or some other well known site.

        That's just me though. I don't 'surf' or 'browse' the web. I go to a few forums, and that's about the extent of it.
        "If you keep me waiting much longer, it damn well better be the end of the Galaxy." ~ Kaidan

        ~There's gonna come a day, and I can't wait to see your face...~

        Comment


        • #19
          Re: MAJOR Password Logging Scheme

          Originally posted by DakAttack View Post
          IE requests approval before activating ActiveX and certain Javascript controls. It prompts before downloading and doesn't automatically run files after they've been downloaded.
          Everybody needs to get off the bandwagon already. It doesn't matter what you use, if you're an idiot you're going to screw yourself no matter what browser you're using.

          Thank you, someone finally sees the light. I havn't been using IE for years, but that's because of the memory leaks it's had for the longest time frame. Hell, even everyones beloved FireFox has horrible memory problems now, atleast, it did in 1.5.x (with multiple tabs open, I'd be using over 100,000 K of memory (hell, with 3 tabs open right now i'm using 120,000 ish, it's horrible).

          No matter what you use, you're going to have secruity risks. Over on the warcraft boards, people feel that it's Blizzards fault for having secruity problems for account safety.

          I'm glad that S-E is taking the right approach here.

          <b>IT IS NOT SquareEnix's RESONSIBILITY FOR YOUR ACCOUNT, IT IS YOURS, AND ONLY YOURS</b>

          That being said, don't be stupid on the internet, and you won't get burned.
          -Baka Inu!
          Nejiko - Mithra Current: [ 70 THF / 35 NIN ]
          Basic Jobs: [ 70 THF / 20 MNK / 11 WHM / 18 BLM / 22WAR / 05 RDM]
          Advance Jobs: [ 04 BST / 37 NIN / 02 SMN / 05RNG / 07 SAM / 07 PLD / 00 DRK / 31 BRD / 00 DRG]
          Aht Jobs: [07 COR / 00 BLU / 00 PUP]

          Comment


          • #20
            Re: MAJOR Password Logging Scheme

            I've found everyone ends up getting burned sooner or later, just a question of when and how. I get a kick out of people that go on about how others that get screwed deserve it since they are usually the ones wailing the loudest when it happens to them in an area they are less knowledgeable about.
            Thanks for the heads up I haven't seen it myself, but I can warn my younger brother who also uses my terminal just in case.
            BTW Yes a person should be careful but I don't think it's good to react with glee to someone getting nailed either.

            Comment


            • #21
              Re: MAJOR Password Logging Scheme

              No matter how well a program is coded...
              No matter how many prompts a person gets...
              No matter how careful a person can be...

              HUMAN STUPIDITY ALWAYS WINS.
              Hacked on 9/9/09
              FFXIAH - Omniblast

              Comment


              • #22
                Re: MAJOR Password Logging Scheme

                Not always stupidity, not having the knowledge is not the users fault.

                Comment


                • #23
                  Re: MAJOR Password Logging Scheme

                  Originally posted by hongman View Post
                  Not always stupidity, not having the knowledge is not the users fault.
                  Ya it is.
                  I use a Mac because I'm just better than you are.

                  HTTP Error 418 - I'm A Teapot - The resulting entity body MAY be short and stout.

                  loose

                  Comment


                  • #24
                    Re: MAJOR Password Logging Scheme

                    Originally posted by Albert Einstein
                    Two things are infinite: the universe and human stupidity; and I'm not sure about the universe.
                    or

                    Originally posted by Albert Einstein
                    Two things are infinite: the universe and human stupidity and I'm not sure about former.
                    I never said it was the user's fault.
                    It's how you interperate it. I could mean that it's M$ IE's fault for not coding it right. I could mean it's the operating system that their using giving them so many pop up messages that they don't bother reading. I could mean it's the web host's fault. There's too many variables. A lot of it has to do with Human error.

                    To err is to human no?
                    Hacked on 9/9/09
                    FFXIAH - Omniblast

                    Comment


                    • #25
                      Re: MAJOR Password Logging Scheme

                      Not having knowelege about idenity safety IS infact the users responsiblity.

                      If you mess up, it's your fault, not SE's, not your banks, not your mothers.

                      It's yours.
                      -Baka Inu!
                      Nejiko - Mithra Current: [ 70 THF / 35 NIN ]
                      Basic Jobs: [ 70 THF / 20 MNK / 11 WHM / 18 BLM / 22WAR / 05 RDM]
                      Advance Jobs: [ 04 BST / 37 NIN / 02 SMN / 05RNG / 07 SAM / 07 PLD / 00 DRK / 31 BRD / 00 DRG]
                      Aht Jobs: [07 COR / 00 BLU / 00 PUP]

                      Comment


                      • #26
                        Re: MAJOR Password Logging Scheme

                        This happen on valefor yesterday!
                        Nagasaki - Odin - 75 Puppetmaster


                        Comment


                        • #27
                          Re: MAJOR Password Logging Scheme

                          Here's a detailed account of someone on Ramuh who lost their account last night:

                          Roughly 6PST(9EST), I, and as far as I know, everyone else on the server did as well, received a tell from a person named "Themoonlight" saying "This is the gilsellers secret http://LINK REMOVED FOR YOUR SAFETY Enjoy"

                          I figured it was just a good video, perhaps some lame ass but funny pictures about gilsellers, so I checked it out. Anyhow it turned out to be a program. I deleted it, under the impression it could be a keylogger or something of the sort. I then checked my programs to see if anything had secretly installed itself, taking any precaution to be sure I wasn't compromised. I found nothing~

                          After checking my computer for problems, I went onto PlayOnline to change my password, as I know that even if someone keylogs your information, they can only get it once. Unfortunately, PlayOnline was doing server maintenance at this time, so no PW info could be changed.

                          I played around like normal until about 8:30PST, when I was kicked off my character, with the error being "You've been logged on by another terminal". At this point I knew what was happening, and spent the better part of the next 1:30 fighting back/forth with the hacker as a race to see who could change the PW first when the maintenance lifted. I had a friend of mine call a GM during this time to see if they could help me out in any way. I asked them to suspend my character, anything to help. but to no avail.

                          Around 9:45~10:00PST, the "Hacker" successfully changed the PW before me, and I lost my account. I contacted PlayOnline at 9:00AM PST when the opened the following day (Today), only to hear nothing can be initially done to get my account back. The "Hacker" changed the CC info to his own, so even with complete and total evidence that the characters pertaining to the account are my own, I cannot reclaim my account at this time.

                          Overall, this person was brilliant with their strategy. They waited until PlayOnline Registration Maintenance started, they sent the tell to EVERYONE on our server on at the time, possibly multiple servers, as bait for their trap. At this point even if you knew it was a keylogger (as I did), nothing could be done or helped. They then raced at maintenance lift to change the PW of these accounts, and permanently had access to them.

                          Now. the only way I can get my account back, is if PlayOnline gets proof that this wasn't an isolated incident. I don't expect everyone to do so, but anyone who doesn't mind, please call (858)790-7529 (PlayOnline's official Help Office number) if you received this tell on May 14, and just have them note this was sent to you also. That is all that needs to be done, and they claimed that if they get enough complaints about the issue, they will give accounts back to people with valid proof, CC, and character information.

                          This is all I can hope for~ Call me a f'ing idiot for even checking the file, that's pretty much how I feel. However immediately after checking the file, I knew what it was, but all the traps where in place, and their was nothing I could do. This was a hell of a plan, and it worked~

                          Note: I wasn't using windower and never ran the program. This is the first program I've heard of to-date that allows them to get information without the use of a 3rd Party program, or ever even running the program.
                          Host of irc.gamesurge.net #FF14 - TheAfterLife XI & XIV LS
                          Olorin (Ramuh): BLM75 BRD78 WHM75 RDM75
                          Olorin Branwen (Melmond): Lv12 LNC9 CON7 THM6 MNR6 ALC4

                          Comment


                          • #28
                            Re: MAJOR Password Logging Scheme

                            Originally posted by hongman View Post
                            Not always stupidity, not having the knowledge is not the users fault.
                            Heh that's like saying "I didn't know Bush was gonna turn out to be this bad when I held my nose & voted for him.."
                            Host of irc.gamesurge.net #FF14 - TheAfterLife XI & XIV LS
                            Olorin (Ramuh): BLM75 BRD78 WHM75 RDM75
                            Olorin Branwen (Melmond): Lv12 LNC9 CON7 THM6 MNR6 ALC4

                            Comment


                            • #29
                              Re: MAJOR Password Logging Scheme

                              You don't necessarily have to download the file yourself, nor do you have to unzip it yourself.

                              If the person/people running this scheme have any amount of talent, they probably wrote cookies, ActiveX controls and/or Javascript into the webpage itself that would automate all that action behind the scenes.
                              So use an incredibly insecure browser and let that do the work for you. Got it.

                              And seriously, if this uses ActiveX, you're just plain stupid for having that enabled. The .05% of sites that require it can screw off. Seriously, I'd like to know how the hell these people got it downloaded AND running without some sort of security prompt from their browser or anti-virus

                              And that person from ramuh is an idiot. It doesn't take a "genius" to use a keylogger to get accounts. it takes someone with a keylogger and a place to download it from. A 10 year old could steal accounts if they wanted to.

                              Trust me, really awsam hackers wouldn't be targetting an MMO, they'd be targetting banks. This is user stupidity, simple as that. There's plenty of guides out there on how to stay secure on the intarwebs, it's your fault for not following them.

                              Comment


                              • #30
                                Re: MAJOR Password Logging Scheme

                                Originally posted by Theyaden View Post
                                I've found everyone ends up getting burned sooner or later, just a question of when and how. I get a kick out of people that go on about how others that get screwed deserve it since they are usually the ones wailing the loudest when it happens to them in an area they are less knowledgeable about.
                                Thanks for the heads up I haven't seen it myself, but I can warn my younger brother who also uses my terminal just in case.
                                BTW Yes a person should be careful but I don't think it's good to react with glee to someone getting nailed either.
                                I don't think anyone is reacting with glee. They are simply saying "That sucks, but honestly, you should have known better." And I can assure you that if I were ever stupid enough to fall for something like this, I sure as hell wouldn't be telling other people about it. I don't know the first thing about PCs, but I do know not to randomly click on links sent to me by strangers. I guess that's too much to expect from some people now?

                                Comment

                                Working...
                                X