Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Got hacked? Account compromised?, Information here

views
     
farkinid
post May 21 2012, 02:18 PM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


QUOTE(VinluV @ May 21 2012, 01:06 PM)
copy paste doesnt work.
Keyloggers tap into your system key typing function. Copy pasting doesn't work.
The best practise is to use authenticator to add 2 factor security.
If you feel like challenging yourself, install diablo on ubuntu, block all outgoing ports except 80 and 443, encrypt your pc and dns traffic, and play diablo tongue.gif
*
shakehead.gif

Asking a newbie to get D3 to run on a linux distro without explaining the complications of wine........

Although, if a newbie really does try it, it would be interesting to see the tears of frustration and rage.


farkinid
post May 21 2012, 03:06 PM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


You know, I see alot of posts being thrown around about some super hackers and some equally strange pieces of advice to avoid being hacked. As somebody who has been lucky enough to avoid these misfortunes, there are a few rules to adhere to.

Basic principle to avoid being hacked socially engineered
  1. Emails. Don't click the links in them! Yes you just won a trip to Blizzard City but calm down and verify by independently going to your account. Some of you would be surprised how many people actually fall for this.
  2. Passwords. Its not about password complexity. Its about password repetition. So many people use the same password or variation of the same password. Ironically, a notebook and a pen is a better password manager than any other digital locker.
  3. Usernames are just as bad. People use the same username for everything. For example, xXHackMeXx@hotmail.com is attached to a xXHackMeXx at forum.suckerd3user.com and is also attached to a battlenet account.
  4. Networks. ok, this is a little more technical. Public wireless networks, public VPN-s or proxies all are dangerous. So next time you sit at Starbucks on their public wifi showing off your Macbook, somebody is sniffing all the traffic on that wireless network.

Most of the time, its the small things that get you hacked, rather than your computer being compromised. And for god's sake, get an authenticator.
farkinid
post May 21 2012, 03:14 PM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


QUOTE(memphiz_zero88 @ May 21 2012, 03:09 PM)
but, but... i use same username for all accounts on internet. am I in the bad position? unsure.gif  unsure.gif
*
It just means that you are easier to track.
farkinid
post May 21 2012, 03:47 PM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


QUOTE(patienceGNR @ May 21 2012, 03:39 PM)
I know several people who do this doh.gif I wanted to do the same but not so free to buy one coffee costing 15 bucks then later cannot sniff anything. Besides, I'm not interested lah, use my phone can sniff people's Facebook sessions already.

But eh guys, don't lah, people's hard work gone just like that :/ *except for Facebook*
*
Err... I'm guilty of sniffing in public places too. Sometimes, waiting for ppl and I have laptop in hand so just busybody and see what ppl are doing.
farkinid
post May 22 2012, 09:35 AM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


I don't want to sound like a fanboi but on a balance of probabilities, it is far more likely that the account was compromised from the end user's side. However, I am somewhat curious about the state of Blizzard security now.
farkinid
post May 22 2012, 10:57 AM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


QUOTE(I<3LYN @ May 22 2012, 10:47 AM)
I will take back my words stated that it is a rumors.

My character is compromised as well... my level 49 barbarian. all the golds and items were gone. It was alright yesterday night before i went to sleep. Today morning all gone. I played a public game yesterday morning. As most suspected, public game maybe the cause.

It seems like the technique used to gain access to your character doesn't involve login at all. Many suspected that, the hackers can clone the session they played with you and through that gaining full access to your character.
*
I really feel for you man. I am starting to think its more than just end user compromise. If its a session hijack, then this is really serious. Who want to play with me while I packet sniff? I'm curious.
farkinid
post May 22 2012, 12:27 PM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


Hmm, the high occurrence of hacking complains seems to suggest something is up. I think this has officially gone beyond end user compromise. Its really quite disturbing.
farkinid
post May 22 2012, 02:15 PM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


QUOTE(Walbur @ May 22 2012, 12:33 PM)
i don't know how they do it.
byt, when they hack my account, i was playing half way.
then system kick me out, i login again, kick them out.
surprisingly, after few time of "you kick me, I kick you".
they able change my password, without receive a email notification from my email account.

I mean, when they change my email account from battle net, they need to answer the secret question. > sent email to my email address.

unless, they could access to Battlenet Database.
*
This doesn't sound like a session hijack. More keylogger/engineered type of compromise
farkinid
post Jun 8 2012, 09:32 AM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


Interstingly, last night, after dinner I realized I had about an hour or so of free time. So I decided to boot up my D3. After patching, I logged in with my username, password and then mobile authenticator (set to ask every log in) only to be greeted with a "your account is locked...... unusual activity" message.

Man, that was annoying. So I went to the Bnet website and then proceeded to initiate a new password. Armed with a new password, I logged back in and everythign was in place. The only thing I want to know is, what exactly was the "unusual activity"?
farkinid
post Jun 8 2012, 09:55 AM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


QUOTE(shootkk @ Jun 8 2012, 09:43 AM)
Perhaps they were trying to log in to your account and brute force the password or maybe they even have your password but was stopped by the authenticator?

I'll bet that's along the lines of what "unusual activity" means.
*
Perhaps. Its quite worrying because my passwords are unique and should not be cracked easily. Also, doesn't Bliz have a limit to login attempts? That should stop brute forcing.

Oh also, basic password generation technique.

» Click to show Spoiler - click again to hide... «


This post has been edited by farkinid: Jun 8 2012, 09:58 AM
farkinid
post Jun 20 2012, 02:33 PM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


If anybody is still interested, an interesting story on account compromise.

http://blogs.avg.com/news-threats/chatted-hacker-virus/

 

Change to:
| Lo-Fi Version
0.0232sec    1.53    7 queries    GZIP Disabled
Time is now: 27th November 2025 - 06:52 AM