[lnkForumImage]
TotalShareware - Download Free Software
Usa Forum
 Home | Login | Register | Search 


 

Forums >

alt.games.warcraft

HACKED!!! so it happened to me, too

evanmac69

7/21/2011 12:01:00 PM

here's the story:

tonight I had insomnia, so around 5:00 a.m. I logged in, after
installing the wowhead prog+addon to send profiles to their site, I
played with my mage a litlle, then I went to bed around 5:30 a.m.

Today's morning at 11:00 a.m. (around) I was in my bike repair shop and,
because there was no customers, I decided to do a round at AH with my
banker...

First strange thing: upon logging in, at char select screen I saw that
my toon were in a strange order, but, oh boy!, I slept a few hours
tonight, maybe I did something while sleeping?

Second strange thing: the banker wasn't mounted and far away from
silvermoon's AH, boh!, surely I sleepwalked around tonight while playing
wow...

3rd s.t. (strange thing): I was unable to post auction because I was too
low in money. WHAT!? I have around 4k gold here... no! a look at my
backpack and I discovered that I... MISS ALL MONEY!!!

oh god, are there my auctions still there? yes
the cracker stolen something from guild bank? yes

ok, I was hacked between 5:30 a.m. and 11:00, further investigation lead
me around 9:00 a.m. as steal time. I immediately opened a ticket about
the thing, then logged out with banker to check other toon... that I
didn't see before this discovery

MY HIGH LVL CHAR WAS ALL NAKED!!!! in the char select screen... the
huntress, the shaman, the rogue, the... ALL!!!!!!

so I logged in with my huntress just to run around in dalaran totally
naked, waiting for a ticket response

interlude: beetwen the awful discovery I downloaded and set up the
authenticator on my android device

end of the story: after around 45 min wait, emptying the banker's guild
tabs to sell all and disband that useless guild, someone from the
blizzard contacted me, we had a short conversation and he mailed to all
char all stolen suff and money

GREAT BLIZZARD!!! many thanks to you :D
--
this is a random signature
13 Answers

S U N risr

7/21/2011 12:44:00 PM

0

On 7/21/2011 8:01 AM, EvanMac wrote:
> here's the story:
>
> tonight I had insomnia, so around 5:00 a.m. I logged in, after
> installing the wowhead prog+addon to send profiles to their site, I
> played with my mage a litlle, then I went to bed around 5:30 a.m.
>
> Today's morning at 11:00 a.m. (around) I was in my bike repair shop and,
> because there was no customers, I decided to do a round at AH with my
> banker...
>
> First strange thing: upon logging in, at char select screen I saw that
> my toon were in a strange order, but, oh boy!, I slept a few hours
> tonight, maybe I did something while sleeping?
>
> Second strange thing: the banker wasn't mounted and far away from
> silvermoon's AH, boh!, surely I sleepwalked around tonight while playing
> wow...
>
> 3rd s.t. (strange thing): I was unable to post auction because I was too
> low in money. WHAT!? I have around 4k gold here... no! a look at my
> backpack and I discovered that I... MISS ALL MONEY!!!
>
> oh god, are there my auctions still there? yes
> the cracker stolen something from guild bank? yes
>
> ok, I was hacked between 5:30 a.m. and 11:00, further investigation lead
> me around 9:00 a.m. as steal time. I immediately opened a ticket about
> the thing, then logged out with banker to check other toon... that I
> didn't see before this discovery
>
> MY HIGH LVL CHAR WAS ALL NAKED!!!! in the char select screen... the
> huntress, the shaman, the rogue, the... ALL!!!!!!
>
> so I logged in with my huntress just to run around in dalaran totally
> naked, waiting for a ticket response
>
> interlude: beetwen the awful discovery I downloaded and set up the
> authenticator on my android device
>
> end of the story: after around 45 min wait, emptying the banker's guild
> tabs to sell all and disband that useless guild, someone from the
> blizzard contacted me, we had a short conversation and he mailed to all
> char all stolen suff and money
>
> GREAT BLIZZARD!!! many thanks to you :D


Nice that you got your stuff back so fast. Glad I have had my
authenticator for quite some time. Not that it's the end-all means to
prevent hacking, but it's definitely discourages most hackers. Why go
through the trouble, when it's easier to hack a unsecured account.
Sure, there will be those that will do it, but there are less of them
then there are of the others.

Also - you need to check your PC if you haven't already to find out if
any keyloggers are there to see if that's how they hacked in. I also am
careful on visiting sites for WoW info. I use google for the search,
then always use the goggle cached version of that site. It's usually
only a few hours or a day behind what the actual site is, unless I
require live data (wow armory, wow-heroes, etc).

Still not sure about the new authenticator procedure. So far, so good
but I'd still like an opt out check box that forces me to enter my auth.
code each time. I'd feel better....

BTW - On that note, last week I was asked out of the blue for the first
time on my main PC since the new procedure went into effect for my auth
code. I'll have to keep a mental note of how often it asks for
verification. So far, once now in 3 weeks, and it did ask for it when I
went on a trip and accessed my account while I was on my laptop at a
hotel. Come to think of it, it also said something like I was playing
outside of my usual schedule (during a weekday, when I normally am at
work). Is Bliz tracking our playing history/frequency/time to help
combat hacking? Not sure I like that as I just don't like being tracked
or watched in general from credit card usage history, to traffic light
cameras, GPS tracking. Not a conspiracy person or anything...just
private and don't like it. But I understand as far as Bliz is concerned
that I agree to it when I choose to play the game, and can leave if I
don't like it. Can't so much with the other type of surveillance...

evanmac69

7/21/2011 2:22:00 PM

0

IYM <"S U N risr"@optonline.net> wrote:

> Also - you need to check your PC if you haven't already to find out if
> any keyloggers are there to see if that's how they hacked in. I also am
> careful on visiting sites for WoW info.

I have a macintosh with osx snow lepoard updated, I'm pretty sure that
the problem began when I installed that damned wow-head-related stuff,
but can't figure how it happened; plus, I have a program called "little
snitcher" who alerts me when some entity in my computer wants to connect
with something over the internet

so, again, I can't figure how it happened :D


--
this is a random signature

Neil Cerutti

7/21/2011 2:52:00 PM

0

On 2011-07-21, EvanMac <evanmac69@gmail.com> wrote:
> so, again, I can't figure how it happened :D

That's been one of the two commonalities between the hacking
stories I've seen.

How careful the person is, how knowledgable of computers I
believe them to be, and what protective software they have
installed has been seemingly irrelevant.

The other commonality is they don't have an authenticator
instealled.

--
Neil Cerutti

evanmac69

7/21/2011 3:39:00 PM

0

Neil Cerutti <neilc@norwich.edu> wrote:

> On 2011-07-21, EvanMac <evanmac69@gmail.com> wrote:
> > so, again, I can't figure how it happened :D
>
> That's been one of the two commonalities between the hacking
> stories I've seen.
>
> How careful the person is, how knowledgable of computers I
> believe them to be, and what protective software they have
> installed has been seemingly irrelevant.
>
> The other commonality is they don't have an authenticator
> instealled.

just about the second point, since authenticator came out I always had
the opportunity to install a software on my phone (either was an iphone
or an android), but I strongly refused to do it, not because I'm lazy,
eh :D

in this four years I played wow, I never had issue like this, obviously
I never buyed gold, nor powerlevel, etc. and all things went good until
this morning :D

as you too said, isn't important how much carefully and protective you
are, crackers are always just around the corner, thanks god blizzard is
just a step behind them :D

btw, I felt exactly like sheldon:
<http://www.youtube.com/watch?v=K5GHA... :D

"all that time spent clicking on my mouse, simply vanished", and "a
game? angry birds maybe a game! warcraft is a complex mmporg in which
you interact... ok, technically speaking it's a game"


AHAHAHAHAHAHA


--
this is a random signature

dburne

7/21/2011 4:29:00 PM

0

On Thu, 21 Jul 2011 14:01:16 +0200, evanmac69@gmail.com (EvanMac)
wrote:

>here's the story:
>
>tonight I had insomnia, so around 5:00 a.m. I logged in, after
>installing the wowhead prog+addon to send profiles to their site, I
>played with my mage a litlle, then I went to bed around 5:30 a.m.
>
>Today's morning at 11:00 a.m. (around) I was in my bike repair shop and,
>because there was no customers, I decided to do a round at AH with my
>banker...
>
>First strange thing: upon logging in, at char select screen I saw that
>my toon were in a strange order, but, oh boy!, I slept a few hours
>tonight, maybe I did something while sleeping?
>
>Second strange thing: the banker wasn't mounted and far away from
>silvermoon's AH, boh!, surely I sleepwalked around tonight while playing
>wow...
>
>3rd s.t. (strange thing): I was unable to post auction because I was too
>low in money. WHAT!? I have around 4k gold here... no! a look at my
>backpack and I discovered that I... MISS ALL MONEY!!!
>
>oh god, are there my auctions still there? yes
>the cracker stolen something from guild bank? yes
>
>ok, I was hacked between 5:30 a.m. and 11:00, further investigation lead
>me around 9:00 a.m. as steal time. I immediately opened a ticket about
>the thing, then logged out with banker to check other toon... that I
>didn't see before this discovery
>
>MY HIGH LVL CHAR WAS ALL NAKED!!!! in the char select screen... the
>huntress, the shaman, the rogue, the... ALL!!!!!!
>
>so I logged in with my huntress just to run around in dalaran totally
>naked, waiting for a ticket response
>
>interlude: beetwen the awful discovery I downloaded and set up the
>authenticator on my android device
>
>end of the story: after around 45 min wait, emptying the banker's guild
>tabs to sell all and disband that useless guild, someone from the
>blizzard contacted me, we had a short conversation and he mailed to all
>char all stolen suff and money
>
>GREAT BLIZZARD!!! many thanks to you :D

And thank you, I went off to the Blizz store and bought an
authenticator. I've been meaning to do it for a while. That was the
push I needed :)
Eddy

Debbie

7/21/2011 8:36:00 PM

0


>
> The other commonality is they don't have an authenticator
> instealled.
>

Did anyone with an authenticator ever get hacked?
I got mine the day after I got hacked.

Matthew

7/21/2011 8:38:00 PM

0


"Shammy" <none@nothing.com> wrote in message
news:j0a2iv$p2j$1@sunce.iskon.hr...
>
>>
>> The other commonality is they don't have an authenticator
>> instealled.
>>
>
> Did anyone with an authenticator ever get hacked?
> I got mine the day after I got hacked.

Only way I believe is if your computer is already compromised on your side


John Gordon

7/21/2011 8:45:00 PM

0

In <j0a2iv$p2j$1@sunce.iskon.hr> "Shammy" <none@nothing.com> writes:

> Did anyone with an authenticator ever get hacked?

I believe there have been cases where hackers contacted customer service
and impersonated their victim to get an authenticator removed, and *then*
hacked someone.

And it's theoretically possible to make a "man-in-the-middle" attack where
the hackers infect your Wow client so that it sends your password and
authenticator code directly to the hacker instead of actually logging you
in, so the authenticator code is (briefly) still good for the hacker to
use. But I haven't heard of that actually happening.

Those are the only two ways I know of for an authenticator to get hacked.

--
John Gordon A is for Amy, who fell down the stairs
gordon@panix.com B is for Basil, assaulted by bears
-- Edward Gorey, "The Gashlycrumb Tinies"

John Gordon

7/21/2011 8:48:00 PM

0

In <4e288e44$0$30052$9a6e19ea@unlimited.newshosting.com> "Matthew" <iamacatslaveand@proudtoserve.com> writes:

> > Did anyone with an authenticator ever get hacked?

> Only way I believe is if your computer is already compromised on your side

Actually an authenticator will protect against most hacking even if your
PC is compromised. That's kind of the point. (along with email phishing)

--
John Gordon A is for Amy, who fell down the stairs
gordon@panix.com B is for Basil, assaulted by bears
-- Edward Gorey, "The Gashlycrumb Tinies"

Debbie

7/21/2011 8:54:00 PM

0


>
> I believe there have been cases where hackers contacted customer service
> and impersonated their victim to get an authenticator removed, and *then*
> hacked someone.

Dont I need to send them a copy of my driver's license or passport or
something for them to act on what I say?

>
> And it's theoretically possible to make a "man-in-the-middle" attack where
> the hackers infect your Wow client so that it sends your password and
> authenticator code directly to the hacker instead of actually logging you
> in, so the authenticator code is (briefly) still good for the hacker to
> use. But I haven't heard of that actually happening.

As far as I know you cant log into wow while someone else is logged in
already and the authenticator code isnt active a long time. Only way they
could do this is that I use my authenthenticator code log in and out
immediately so they have the time to use it... but since blizz looks at the
IP address now it they might want a different authenticator code if someone
logs in from a different IP like 3 min after logging the first time so the
code wouldnt be worth much.