Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Got hacked? Account compromised?, Information here

views
     
Rei7
post May 22 2012, 12:12 PM

Game, anime and headphones ❤️
******
Senior Member
1,669 posts

Joined: Apr 2011



This is called session hijacking.
Where hacker get our session key to access our session in game.
If you ever get kicked out in game, reset modem and log-in as quickly as you can.
Before they get all the items.

More info about session hijacking http://en.wikipedia.org/wiki/Session_hijacking

This post has been edited by Rei7: May 22 2012, 12:18 PM
Rei7
post May 22 2012, 12:26 PM

Game, anime and headphones ❤️
******
Senior Member
1,669 posts

Joined: Apr 2011



QUOTE(leongkokloon @ May 22 2012, 12:24 PM)
dafuq? for real?
*
Told you this is session hijacking. Random people get hacked.

QUOTE
just started not long ago...haven't join any public game nor adding people yet. Should be safe right?

For now only add the people you know. Sounds dangerous.


Until Blizzard fix the loophole if this session hijacking, random people will be hacked.

This post has been edited by Rei7: May 22 2012, 12:28 PM
Rei7
post May 22 2012, 12:30 PM

Game, anime and headphones ❤️
******
Senior Member
1,669 posts

Joined: Apr 2011



QUOTE(Walbur @ May 22 2012, 12:27 PM)
yeah, that for real......
they even change my password.
could you explain how they know my secret answer? and my email password.
both are total different.

and I don;t believe that so many keylogger flying around the world.

yes, i have Anti-malware, virus NOD32 every on....
*
That is fairly new. Considering most hacked account doesn't get their password changed.
Have you ever log-in to any suspicious website? Might be a phishing website.

Ermm very dangerous. Any chance you got kicked out of the game?
For now the possible theory is it's a session hijacking but if they change password totally a different story.

This post has been edited by Rei7: May 22 2012, 12:32 PM
Rei7
post May 22 2012, 12:36 PM

Game, anime and headphones ❤️
******
Senior Member
1,669 posts

Joined: Apr 2011



QUOTE(Walbur @ May 22 2012, 12:33 PM)
i don't know how they do it.
byt, when they hack my account, i was playing half way.
then system kick me out, i login again, kick them out.
surprisingly, after few time of "you kick me, I kick you".
they able change my password, without receive a email notification from my email account.
*
Yes. This is session hijacking. Where he gets your session key to go on your session and kicking you out.
The things that you should really do is kick him out, log out and change the password.
Damn I don't think i'll be wasting my time on this game yet. Will wait for Blizzard to close this loophole.

Probably true as well. A loophole in the database might also be a problem here.
They really need to secure it soon or more random people well get their acc hacked.

This post has been edited by Rei7: May 22 2012, 12:38 PM
Rei7
post May 22 2012, 12:43 PM

Game, anime and headphones ❤️
******
Senior Member
1,669 posts

Joined: Apr 2011



QUOTE(Szzz @ May 22 2012, 12:40 PM)
Changing password requires a verification from email right? How does session hijacking change the password then
*
Don't think the current guy problem is session hijacking.
But most people who reported being hack says that their account password hasn't been changed.
Hacker might have access in the database. doh.gif
Rei7
post May 22 2012, 12:49 PM

Game, anime and headphones ❤️
******
Senior Member
1,669 posts

Joined: Apr 2011



QUOTE(leongkokloon @ May 22 2012, 12:47 PM)
Hey guys the authenticator is only from ur mobile phone only right? say i borrow my friends device for the authenticator can it work?
*
Only you. No one else can
Rei7
post May 22 2012, 01:24 PM

Game, anime and headphones ❤️
******
Senior Member
1,669 posts

Joined: Apr 2011



QUOTE(Kissan @ May 22 2012, 01:09 PM)
blink.gif so many kena hack.

btw, Under Communication Preferences>Privacy>Enable Real ID..

that "enable real id" got what use eh?? since i mostly play alone , so disable it better?
*
http://us.battle.net/en/realid/faq
Rei7
post May 22 2012, 03:55 PM

Game, anime and headphones ❤️
******
Senior Member
1,669 posts

Joined: Apr 2011



Damn just now I got disconnected and DDOS'ed
It seems that they plan take our session on later ddos our connection so that we can't re-log.
Luckily a simple restart to the modem fix this.
And was able to relog and logout without them taking over the session again. -.-
Rei7
post May 22 2012, 04:00 PM

Game, anime and headphones ❤️
******
Senior Member
1,669 posts

Joined: Apr 2011



QUOTE(raptar_eric @ May 22 2012, 03:58 PM)
dont worry... server going down now, i think they are patching it
*
Hopefully so. bruce.gif
Rei7
post May 22 2012, 04:03 PM

Game, anime and headphones ❤️
******
Senior Member
1,669 posts

Joined: Apr 2011



QUOTE(polarzbearz @ May 22 2012, 04:00 PM)
Session hijacking requires the victim to be online for them to target right? So if I never log-in = safe? lol.. laugh.gif
*
Yeah pretty much. Like me just now restart modem because they ddos my internet.
Then relog in and logout to close session icon_rolleyes.gif

Safe if it's really a session hijacking. If database sql injection and stuff, pretty much nothing we can do.
Rei7
post May 22 2012, 04:15 PM

Game, anime and headphones ❤️
******
Senior Member
1,669 posts

Joined: Apr 2011



Official statement by Blizzard Staff. http://us.battle.net/d3/en/forum/topic/5149619846#1

QUOTE
We'd like to take a moment to address the recent reports that suggested that Battle.net® and Diablo® III may have been compromised. Historically, the release of a new game -- such as a World of Warcraft® expansion -- will result in an increase in reports of individual account compromises, and that's exactly what we're seeing now with Diablo III. We know how frustrating it can be to become the victim of account theft, and as always, we're dedicated to doing everything we can to help our players keep their Battle.net accounts safe -- and we appreciate everyone who's doing their part to help protect their accounts as well. You can read about ways to help keep your account secure, along with some of the internal and external measures we have in place to help us achieve our security goals, at our account security website here: www.battle.net/security.

We also wanted to reassure you that the Battle.net Authenticator and Battle.net Mobile Authenticator (a free app for iPhone and Android devices) continue to be some of the most effective measures we offer to help players protect themselves against account compromises, and we encourage everyone to take advantage of them. In addition, we also recently introduced a new service called Battle.net SMS Protect, which allows you to use your text-enabled cell phone to unlock a locked Battle.net account, recover your account name, approve a password reset, or remove a lost Authenticator. Optionally, you can set up the Battle.net SMS Protect system to send you a text message whenever unusual activity is detected on your account, keeping you aware of important (and possibly unwanted) changes.

For more information on the Authenticator, visit http://us.battle.net/support/en/article/ba...thenticator-faq

For more on the Battle.net Mobile Authenticator, visit http://us.battle.net/support/en/article/ba...thenticator-faq

For more on Battle.net SMS Protect, visit http://us.battle.net/support/en/article/ba...net-sms-protect

We also have other measures built into Battle.net to help protect players. Occasionally, when Battle.net detects unusual login activity that differs from your normal behavior -- such as logging in from an unfamiliar location -- we may prompt you for additional information (such as the answer to one of your security questions) and/or require you to perform a password reset through the Battle.net website. World of Warcraft players might be familiar with this security method already, and Diablo III players may begin to encounter it as well.

As always, if you think you've been the victim of an account compromise, head to the "Help! I've Been Hacked!" tool at http://us.battle.net/en/security/help for assistance.
This post has been edited by Rei7: May 22 2012, 04:17 PM
Rei7
post May 22 2012, 07:37 PM

Game, anime and headphones ❤️
******
Senior Member
1,669 posts

Joined: Apr 2011



QUOTE(polarzbearz @ May 22 2012, 05:39 PM)
Seems that they are trying to avoid from officially admitting an issue while trying to give a "response" to overwhelm complaints from users (especially those that got hacked). sweat.gif
*
Well at least what from I heard they roll back some accounts that kena hack.
Rei7
post May 22 2012, 07:56 PM

Game, anime and headphones ❤️
******
Senior Member
1,669 posts

Joined: Apr 2011



QUOTE(nightshade_nova @ May 22 2012, 07:49 PM)
I think its easy for bystanders to just say that.
But if you put yourself in the shoes of those who got hacked, Im sure the feeling would be furious+mood spoiled to play+feels like boycotting Blizzard.

My own experience my gold was in limbo on the auction house, after I used all of my gold on a buyout, not getting item, not getting gold back.
Luckily it was sorted out now.
I think its to be expected for an online game to have these kind of problems, but trust me experiencing them is hellish.
*
Experienced it before bro. A few times already. Played a few games like Rakion, Eve, Maplestory, Gunz and Risk Your Life.
Comparing what happen to Maplestory Sea which their database got hacked this is still ok because they roll back for some users.
Asiasoft never actually rolled back when their server got compromised and you were left naked and poor which is much worst.

I wanna see if this maintenance will stop all this hacking. I hope there will be less report or none at all.

QUOTE
How you gone with the process. After you kena what you do? I just submit a ticket to blizzard.

http://us.battle.net/en/security/help

This post has been edited by Rei7: May 22 2012, 07:58 PM

 

Change to:
| Lo-Fi Version
0.0163sec    0.26    7 queries    GZIP Disabled
Time is now: 26th November 2025 - 08:04 AM