Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 D3 account can be hacked via public game, might be explanation to those acc hecked

views
     
TSsammm33
post May 22 2012, 05:53 PM, updated 14y ago

On my way
****
Junior Member
684 posts

Joined: Sep 2007


"an exploit was discovered by duplicating a session ID
basically, if you join a public game with people, they can view your session ID and spoof it to login as you without need for a password or email or anyting
if you play with people, try not to play in public games bro, only with people you know"

"apparently the EU servers went down last night
and when they came back on, many accounts had lost items / gold
lemme find this link for you
http://www.eurogamer.net/articles/2012-05-...nd-items-stolen
here, read that"


SOS = http://us.battle.net/d3/en/forum/topic/5149539239
polarzbearz
post May 22 2012, 05:55 PM

Gracie
*******
Senior Member
4,816 posts

Joined: Apr 2007


Blizzard's official statement/reply makes me go sweat.gif
DrLaboo
post May 22 2012, 05:55 PM

♥ surprised buttsek ♥
******
Senior Member
1,004 posts

Joined: Feb 2011
From: Your House



fark dem shiat!~
luckily i rarely play with them strangers..
Why^Me
post May 22 2012, 06:00 PM

On my way
****
Senior Member
551 posts

Joined: Nov 2004
From: ポンテイアン、 ジョホル。



luckily i not yet buy D3 to play...
sai86
post May 22 2012, 06:02 PM

StilL LearninG
*******
Senior Member
4,934 posts

Joined: Sep 2008
From: Setapak


fk, lucky i only join lyners private game. this is a mega loop hole rclxub.gif no wonder the guys get hacked state even got authenticator still get hacked.

wow, imagine if this happen with RMAH, how blizzard is going to compensate the dmg? shocking.gif

This post has been edited by sai86: May 22 2012, 06:03 PM
DeMoNBLooD
post May 22 2012, 06:02 PM

Getting Started
**
Junior Member
195 posts

Joined: Dec 2009


Fcking hell scary man...imagine u have super rare item and legendary item and a million of gold... And a few max lvl character inside ...holy mother of god...
Y.K.
post May 22 2012, 06:06 PM

Casual
***
Junior Member
371 posts

Joined: Aug 2005


speak of hacking, i m trying to attach mobile authenticator, downloaded the apps but when i input the serial keys it keep saying the serial key is wrong sweat.gif

anyone have this before?
polarzbearz
post May 22 2012, 06:09 PM

Gracie
*******
Senior Member
4,816 posts

Joined: Apr 2007


QUOTE(Y.K. @ May 22 2012, 06:06 PM)
speak of hacking, i m trying to attach mobile authenticator, downloaded the apps but when i input the serial keys it keep saying the serial key is wrong sweat.gif

anyone have this before?
*
Happened to me today. Tried to click the refresh/sync button on left-bottom corner?
kidmad
post May 22 2012, 06:09 PM

Look at all my stars!!
*******
Senior Member
4,482 posts

Joined: Jul 2005
holy cow... no more public games for me.
coldz
post May 22 2012, 06:12 PM

New Member
*
Junior Member
29 posts

Joined: Nov 2007
lol..luckily i m just started smile.gif
CocoMonGo
post May 22 2012, 06:13 PM

Ooo Finally
****
Senior Member
551 posts

Joined: Dec 2006


QUOTE(sai86 @ May 22 2012, 06:02 PM)
fk, lucky i only join lyners private game. this is a mega loop hole  rclxub.gif no wonder the guys get hacked state even got authenticator still get hacked.

wow, imagine if this happen with RMAH, how blizzard is going to compensate the dmg? shocking.gif
*
mayb thats y RMAH still not launch until now
Y.K.
post May 22 2012, 06:14 PM

Casual
***
Junior Member
371 posts

Joined: Aug 2005


QUOTE(polarzbearz @ May 22 2012, 06:09 PM)
Happened to me today. Tried to click the refresh/sync button on left-bottom corner?
*
hmmm? u mean refresh in my iphone or? hmm.gif
alex82
post May 22 2012, 06:15 PM

^_^
***
Junior Member
371 posts

Joined: Sep 2006
i haven't start pub game yet..solo all the way
TiF
post May 22 2012, 06:15 PM

Regular
******
Senior Member
1,192 posts

Joined: Dec 2009


lol, so much for 'always online anti cheat' bla bla
polarzbearz
post May 22 2012, 06:17 PM

Gracie
*******
Senior Member
4,816 posts

Joined: Apr 2007


QUOTE(Y.K. @ May 22 2012, 06:14 PM)
hmmm? u mean refresh in my iphone or? hmm.gif
*
Yeah.. today when I tried to log-in to my Battle.net at their website, the authentication always fail and I wondered why.. clicked the refresh at my phone, numbers updated and can login already sweat.gif
Y.K.
post May 22 2012, 06:21 PM

Casual
***
Junior Member
371 posts

Joined: Aug 2005


QUOTE(polarzbearz @ May 22 2012, 06:17 PM)
Yeah.. today when I tried to log-in to my Battle.net at their website, the authentication always fail and I wondered why.. clicked the refresh at my phone, numbers updated and can login already sweat.gif
*
oh okay, so urs are actually authenticator code but not serial key issue la.

i m trying to attach, the serial code displayed cannot be used n i tried to reset it n still the same sad.gif
polarzbearz
post May 22 2012, 06:29 PM

Gracie
*******
Senior Member
4,816 posts

Joined: Apr 2007


QUOTE(Y.K. @ May 22 2012, 06:21 PM)
oh okay, so urs are actually authenticator code but not serial key issue la.

i m trying to attach, the serial code displayed cannot be used n i tried to reset it n still the same sad.gif
*
sweat.gif Oh wow, sorry I mis-interpreted your message blush.gif

Never had an issue when I linked my device with my account. I did that before Diablo III was released tho.. during the Beta's.
gaeria84
post May 22 2012, 06:30 PM

Enthusiast
*****
Senior Member
837 posts

Joined: Mar 2005
QUOTE(CocoMonGo @ May 22 2012, 06:13 PM)
mayb thats y RMAH still not launch until now
*
After all this, you sure you want to trade in RMAH? There might be some security flaw lurking around in their servers that may compromise your account and your hard earned cash.

This is Blizzard we are talking about. Should anything happen, they take an extremely long time (weeks, sometimes months) to restore your account/items/cash and most of the time, you won't get back all your stuff

This post has been edited by gaeria84: May 22 2012, 06:31 PM
nate_nightroad
post May 22 2012, 06:36 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


luckily is just a GAME and not real life...

phew
bamkai
post May 22 2012, 06:41 PM

Getting Started
**
Junior Member
167 posts

Joined: Jan 2010
luckily i dont know what diablo is
Teddysaur
post May 22 2012, 06:45 PM

Socially cawkward 🦄
***
Junior Member
435 posts

Joined: Oct 2010
Oh crap. I've only started playing public game since yesterday on NA server. Usually I played private game with a friend. Didnt realized hacking account in D3 was so easy.

Hopefully nothing bad happen to my account.

skywardsword
post May 22 2012, 06:45 PM

On my way
****
Junior Member
680 posts

Joined: Sep 2010
server down for maintenance lah... same as WOW somemore... thats why things cannot authenticate.

samlee860407
post May 22 2012, 06:45 PM

Look at all my stars!!
*******
Senior Member
4,631 posts

Joined: Oct 2005


QUOTE(Y.K. @ May 22 2012, 06:21 PM)
oh okay, so urs are actually authenticator code but not serial key issue la.

i m trying to attach, the serial code displayed cannot be used n i tried to reset it n still the same sad.gif
*
i also face the serial number problem now, again actually

both the iphone app and the real authenticator cannot be used. both give me the error of serial number wrong when i want to attach it.



previously, i bought 1 from authenticator token from blizzard, but serial number error. Blizzard can't resolve it hence sent me another. this time can attach liao. then after that i din't play WoW anymore, I took away the authenticator.

then now, i want to reattach it back, it says serial number error

then I try to download the iphone app, again, say serial number problem

open a ticket, asked me to call them, but when i tried to call the number, it says "this number had bar all incoming calls" :S
technoraver
post May 22 2012, 06:45 PM

★ ayam watching jew ★
*****
Senior Member
944 posts

Joined: Nov 2006
From: Cheras,Cyberjaya


dafaq!?
Y.K.
post May 22 2012, 07:03 PM

Casual
***
Junior Member
371 posts

Joined: Aug 2005


QUOTE(samlee860407 @ May 22 2012, 06:45 PM)
i also face the serial number problem now, again actually

both the iphone app and the real authenticator cannot be used. both give me the error of serial number wrong when i want to attach it.
previously, i bought 1 from authenticator token from blizzard, but serial number error. Blizzard can't resolve it hence sent me another. this time can attach liao. then after that i din't play WoW anymore, I took away the authenticator.

then now, i want to reattach it back, it says serial number error

then I try to download the iphone app, again, say serial number problem

open a ticket, asked me to call them, but when i tried to call the number, it says "this number had bar all incoming calls" :S
*
wah ur problem sounds serious leh, lol i think i not gonna attach authenticator for now then hmm.gif

anyway i sent a ticket n c how they reply la.
ZeratoS
post May 22 2012, 07:06 PM

Oh you.
******
Senior Member
1,044 posts

Joined: Dec 2008
From: 127.0.0.1


http://us.battle.net/d3/en/forum/topic/5149619846?page=7#124

Apparently. Typical lah, bringing shame to South East Asia.
Deimos Tel`Arin
post May 22 2012, 07:17 PM

The LYN Kondom Man
*******
Senior Member
4,202 posts

Joined: Jan 2003
From: THE ONE AND ONLY CHOO CHOO TRAIN KINGDOM




QUOTE(alex82 @ May 22 2012, 06:15 PM)
i haven't start pub game yet..solo all the way
*
same here only joined friends game few times.will reduce friends now
Seiei5
post May 22 2012, 07:18 PM

New Member
*
Junior Member
39 posts

Joined: Oct 2010
Man they should have put something like and 6 pin code to access your inventory and oso your stash inventory . this alone can solve all this hacking case.....
wodenus
post May 22 2012, 07:52 PM

Tree Octopus
********
All Stars
14,990 posts

Joined: Jan 2003
QUOTE(Seiei5 @ May 22 2012, 07:18 PM)
Man they should have put something like and 6  pin code to access your inventory and oso your stash inventory . this alone can solve all this hacking case.....
*
They would have stolen that too with a keylogger smile.gif


This post has been edited by wodenus: May 22 2012, 07:52 PM
gaeria84
post May 22 2012, 09:57 PM

Enthusiast
*****
Senior Member
837 posts

Joined: Mar 2005
Very typical of Blizzard, now you know why a lot of people quit WoW tongue.gif
Hornet
post May 22 2012, 10:13 PM

What?
*******
Senior Member
4,251 posts

Joined: Jan 2003
From: Malacca, Malaysia, Earth


QUOTE(wodenus @ May 22 2012, 07:52 PM)
They would have stolen that too with a keylogger smile.gif
*
The problem now might not be related to keylogger, but rather, more like piggybacking into your account when you're online. They are not stealing any password or anything.

And in Maplestory, the personal pin can only be key in using graphical keyboard where you click on each character to input. Keyloggers therefore cannot capture it as there's no keystroke to be captured.

Its a very good system.

This post has been edited by Hornet: May 22 2012, 10:14 PM
C-Fu
post May 23 2012, 03:45 AM

Ninja-Fu
******
Senior Member
1,051 posts

Joined: Apr 2005
From: Brisbane, QLD, Ostolia



well Bashiok from Blizzard just pretty much confirmed it.


http://us.battle.net/d3/en/forum/topic/514...846?page=32#633

QUOTE
QUOTE
Posted by MielTicket
It was Wayyyy too many at once and at the same time. It seems the attack was very orchestrated



It seems to me like it's the most logical way to go about it. Build up a list of accounts and passwords, and then hit them in a rapid succession before word can spread and people can change their passwords, add an authenticator, etc.

mr11
post May 23 2012, 03:54 AM

Regular
******
Senior Member
1,017 posts

Joined: Jun 2010
Btw now is ok ...since my account doesn haven any rare items ...just enjoy the game
VinluV
post May 23 2012, 03:56 AM

Regular
******
Senior Member
1,947 posts

Joined: Nov 2005
i replicated the session hijacking theory, and yeap doable without authenticator. but needs some work.
careful guys.

This post has been edited by VinluV: May 23 2012, 03:57 AM
I<3LYN
post May 23 2012, 05:17 AM

On my way
****
Senior Member
614 posts

Joined: Sep 2009


QUOTE(VinluV @ May 23 2012, 03:56 AM)
i replicated the session hijacking theory, and yeap doable without authenticator. but needs some work.
careful guys.
*
really? show us pictures of guys that you hacked... or it didn't happen tongue.gif
d33pbluez
post May 23 2012, 08:51 AM

On my way
****
Senior Member
559 posts

Joined: Mar 2005



Soon it going to be another WoW ...where alot will start quitting due the server security...Thanks blizzard for shorten the game life of diablo for 10 years to 5 years rclxms.gif

This post has been edited by d33pbluez: May 23 2012, 08:56 AM
fubs
post May 23 2012, 10:12 AM

Getting Started
**
Junior Member
201 posts

Joined: Aug 2009
guys, for those who are having trouble with "Invalid Serial" when trying to add the mobile authenticator; try turning off your B.Net SMS notification first.

Worked for me.
khelben
post May 23 2012, 10:18 AM

I love my mum & dad
*******
Senior Member
6,056 posts

Joined: Jan 2003
From: Suldanessellar



QUOTE(gaeria84 @ May 22 2012, 09:57 PM)
Very typical of Blizzard, now you know why a lot of people quit WoW  tongue.gif
*
A lot of people quit WoW because that game is 8 years old la laugh.gif
SweetPuff
post May 23 2012, 10:26 AM

Look at all my stars!!
*******
Senior Member
2,021 posts

Joined: Jan 2003


At least, with LYN members only D3 friends, I always know that I'm within driving distance to punch someone in the face if one of them tries with hack.
Eiensakura
post May 23 2012, 10:30 AM

Getting Started
**
Junior Member
189 posts

Joined: Aug 2008
never the one to play with strangers, hated pugs in WoW, will continue to hate them in D3
gaeria84
post May 23 2012, 10:32 AM

Enthusiast
*****
Senior Member
837 posts

Joined: Mar 2005
QUOTE(khelben @ May 23 2012, 10:18 AM)
A lot of people quit WoW because that game is 8 years old la laugh.gif
*
No doubt, but there were a lot of factors that contributed to WoW's decline

- Game going in the wrong direction - lots of recycled content, game being trivialized
- Long downtimes
- Bad customer service


VinluV
post May 23 2012, 11:54 AM

Regular
******
Senior Member
1,947 posts

Joined: Nov 2005
QUOTE(I<3LYN @ May 23 2012, 05:17 AM)
really? show us pictures of guys that you hacked... or it didn't happen  tongue.gif
*
didn't hack anyone as its complex for automation, i just tested with a friend for over an hour.
you just need to replace some of your session particulars with another person, and for a short time you'll be in control of the other party, then you get errors.

My suspicions are the same as Bashiok, this was well coordinated, and the guys targeted people from the start. Collected the passwords and details. Then they did the "hack at once.
farkinid
post May 23 2012, 12:01 PM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


QUOTE(VinluV @ May 23 2012, 11:54 AM)
didn't hack anyone as its complex for automation, i just tested with a friend for over an hour.
you just need to replace some of your session particulars with another person, and for a short time you'll be in control of the other party, then you get errors.

My suspicions are the same as Bashiok, this was well coordinated, and the guys targeted people from the start. Collected the passwords and details. Then they did the "hack at once.
*
I still don't understand why the game server would pass your session token to other members in the group and vice versa. I haven't done any testing but a wireshark or tcpdump file would interest me very much.
I<3LYN
post May 23 2012, 12:29 PM

On my way
****
Senior Member
614 posts

Joined: Sep 2009


QUOTE(VinluV @ May 23 2012, 11:54 AM)
didn't hack anyone as its complex for automation, i just tested with a friend for over an hour.
you just need to replace some of your session particulars with another person, and for a short time you'll be in control of the other party, then you get errors.

My suspicions are the same as Bashiok, this was well coordinated, and the guys targeted people from the start. Collected the passwords and details. Then they did the "hack at once.
*
record a video... expose blizzard blaming technique....
now blizzard kept blaming the players.
polarzbearz
post May 23 2012, 12:32 PM

Gracie
*******
Senior Member
4,816 posts

Joined: Apr 2007


QUOTE(VinluV @ May 23 2012, 11:54 AM)
didn't hack anyone as its complex for automation, i just tested with a friend for over an hour.
you just need to replace some of your session particulars with another person, and for a short time you'll be in control of the other party, then you get errors.

My suspicions are the same as Bashiok, this was well coordinated, and the guys targeted people from the start. Collected the passwords and details. Then they did the "hack at once.
*
QUOTE(I<3LYN @ May 23 2012, 12:29 PM)
record a video... expose blizzard blaming technique....
now blizzard kept  blaming the players.
*
^ +1 to this. The way blizzard posts the formal announcement is like, blaming players for not being careful/secured enough; and mentions nothing about the exploits.
I<3LYN
post May 23 2012, 12:32 PM

On my way
****
Senior Member
614 posts

Joined: Sep 2009


QUOTE(farkinid @ May 23 2012, 12:01 PM)
I still don't understand why the game server would pass your session token to other members in the group and vice versa. I haven't done any testing but a wireshark or tcpdump file would interest me very much.
*
i am going to try to replicate the exploit as well. doh.gif
ZeratoS
post May 23 2012, 01:57 PM

Oh you.
******
Senior Member
1,044 posts

Joined: Dec 2008
From: 127.0.0.1


http://www.youtube.com/watch?v=8iQoOMJ9n8k

For you.
Deimos Tel`Arin
post May 23 2012, 02:00 PM

The LYN Kondom Man
*******
Senior Member
4,202 posts

Joined: Jan 2003
From: THE ONE AND ONLY CHOO CHOO TRAIN KINGDOM




QUOTE(polarzbearz @ May 23 2012, 12:32 PM)
^ +1 to this. The way blizzard posts the formal announcement is like, blaming players for not being careful/secured enough; and mentions nothing about the exploits.
*
very irresponsible.

it is battle.net server not secured. not the players.
polarzbearz
post May 23 2012, 02:06 PM

Gracie
*******
Senior Member
4,816 posts

Joined: Apr 2007


QUOTE(Deimos Tel`Arin @ May 23 2012, 02:00 PM)
very irresponsible.

it is battle.net server not secured. not the players.
*
True. But I'm not surprised, that's how most of the business organisations AND the government works... play "Tai-chi" (push the blame to end users/citizen/anyone else than themselves)

Sigh, only hope Blizzard will fix this as soon as possible, doesn't matter if they don't want to admit their mistakes.. just fix it before my final exam is over laugh.gif

This post has been edited by polarzbearz: May 23 2012, 02:07 PM
Deimos Tel`Arin
post May 23 2012, 02:10 PM

The LYN Kondom Man
*******
Senior Member
4,202 posts

Joined: Jan 2003
From: THE ONE AND ONLY CHOO CHOO TRAIN KINGDOM




QUOTE(polarzbearz @ May 23 2012, 02:06 PM)
True. But I'm not surprised, that's how most of the business organisations AND the government works... play "Tai-chi" (push the blame to end users/citizen/anyone else than themselves)

Sigh, only hope Blizzard will fix this as soon as possible, doesn't matter if they don't want to admit their mistakes.. just fix it before my final exam is over laugh.gif
*
aye. at least valve admitted.
takkicom
post May 23 2012, 02:20 PM

Casual
***
Junior Member
422 posts

Joined: Sep 2008
QUOTE(Deimos Tel`Arin @ May 23 2012, 02:10 PM)
aye. at least valve admitted.
*
since WOW has this problem, if i give hack i quit, that it
argue they dont give help hand
VinluV
post May 23 2012, 03:43 PM

Regular
******
Senior Member
1,947 posts

Joined: Nov 2005
QUOTE(farkinid @ May 23 2012, 12:01 PM)
I still don't understand why the game server would pass your session token to other members in the group and vice versa. I haven't done any testing but a wireshark or tcpdump file would interest me very much.
*
here's the setup tho a very very simplified one.

2 pc in the same network. By network I mean me and mate using my router.
No opendns, No dns crypt, No authenticator used, firewall and my IPS turned off.
after trading and dropping items left and right for about half an hour and monitoring packets with tcpdump,
i just copied some token values from my friend to my packets (a certain open source scarab javascript packet interceptor i bet you know was used whistling.gif )

For a few seconds, i got him off his account. Then I got the i got kicked of battle net error.

what i can suspect is that my token and session weren't matching the ones on battlenet so i got kicked off, as the next few packets sent from me was using my original values, instead of the "malformed" packet.

Its doable but based on my setup its quite a below basic one, its still a long way for me.
Will try to pass u a dump with better values if i can get some sort of poc.

edit: wouldn't be surprised if chinese have pwned bnet

This post has been edited by VinluV: May 23 2012, 03:45 PM
farkinid
post May 23 2012, 03:58 PM

Enthusiast
*****
Senior Member
997 posts

Joined: Feb 2007


QUOTE(VinluV @ May 23 2012, 03:43 PM)
here's the setup tho a very very simplified one.

2 pc in the same network. By network I mean me and mate using my router.
No opendns, No dns crypt, No authenticator used, firewall and my IPS turned off.
after trading and dropping items left and right for about half an hour and monitoring packets with tcpdump,
i just copied some token values from my friend to my packets (a certain open source scarab javascript packet interceptor i bet you know was used whistling.gif )

For a few seconds, i got him off his account. Then I got the i got kicked of battle net error.

what i can suspect is that my token and session weren't matching the ones on battlenet so i got kicked off, as the next few packets sent from me was using my original values, instead of the "malformed" packet.

Its doable but based on my setup its quite a below basic one, its still a long way for me.
Will try to pass u a dump with better values if i can get some sort of poc.

edit: wouldn't be surprised if chinese have pwned bnet
*
Hmm interesting.

If you have any interesting dumps, please send them my way. But I still don't understand Bliz's need to allow user machines to communicate with each other. I thought all the heavy lifting was done on the servers and the result was sent to the user machines.

Unless somebody has a way to parse token data and reconstruct login values, then this may not work. Still it does sound possible.
neoengsheng
post May 23 2012, 04:01 PM

Getting Started
**
Junior Member
261 posts

Joined: Jul 2009
QUOTE(VinluV @ May 23 2012, 03:43 PM)
here's the setup tho a very very simplified one.

2 pc in the same network. By network I mean me and mate using my router.
No opendns, No dns crypt, No authenticator used, firewall and my IPS turned off.
after trading and dropping items left and right for about half an hour and monitoring packets with tcpdump,
i just copied some token values from my friend to my packets (a certain open source scarab javascript packet interceptor i bet you know was used whistling.gif )

For a few seconds, i got him off his account. Then I got the i got kicked of battle net error.

what i can suspect is that my token and session weren't matching the ones on battlenet so i got kicked off, as the next few packets sent from me was using my original values, instead of the "malformed" packet.

Its doable but based on my setup its quite a below basic one, its still a long way for me.
Will try to pass u a dump with better values if i can get some sort of poc.

edit: wouldn't be surprised if chinese have pwned bnet
*
What you described is the typical man in the middle attack where a hacker sits some where inside the same network as you are and use packet siffer to sniff out the packet s you send and receive to Blizzard server.

This is almost undoable on the open internet.

I have been reading the Diablo 3 official forum and really tempted to try to replicate or some how prove Blizzard is covering up and downplay the whole issue while at the same time keep blaming the users for hacking. This is even worse when combined with fanboys on the forum insulting and accusing people of lying about getting hacked with an authenticator.
VinluV
post May 23 2012, 04:04 PM

Regular
******
Senior Member
1,947 posts

Joined: Nov 2005
QUOTE(farkinid @ May 23 2012, 03:58 PM)
Hmm interesting.

If you have any interesting dumps, please send them my way. But I still don't understand Bliz's need to allow user machines to communicate with each other. I thought all the heavy lifting was done on the servers and the result was sent to the user machines.

Unless somebody has a way to parse token data and reconstruct login values, then this may not work.  Still it does sound possible.
*
probably due to heavy loads on the server.
Wouldn't be surprised that companies would choose the easy and less secure way out of a problem.
I've not played wow but some guys on my d3 public games told me you can use wow hacks on d3. Unproven as i don't play wow or have any knowledge of it.
If u know any hitb/hackerspace fellows, they may have doxed it as well.

edit: just thought of the whisper and message function, not sure if can directly ping user ip/id from whispering. Any thoughts?
I<3LYN
post May 23 2012, 04:09 PM

On my way
****
Senior Member
614 posts

Joined: Sep 2009


QUOTE(VinluV @ May 23 2012, 04:04 PM)
probably due to heavy loads on the server.
Wouldn't be surprised that companies would choose the easy and less secure way out of a problem.
I've not played wow but some guys on my d3 public games told me you can use wow hacks on d3. Unproven as i don't play wow or have any knowledge of it.
If u know any hitb/hackerspace fellows, they may have doxed it as well.

edit: just thought of the whisper and message function, not sure if can directly ping user ip/id from whispering. Any thoughts?
*
with my understanding of the battle.net 1.0 protocol.. nope you cant get any network info by whispering/messaging a player.

not really sure about battle.net 2.0 though.
charlieoscardelta
post May 23 2012, 04:17 PM

Getting Started
**
Junior Member
56 posts

Joined: May 2007
QUOTE(TiF @ May 22 2012, 06:15 PM)
lol, so much for 'always online anti cheat' bla bla
*
they never said it was for social anticheat - it's anti-piracy.
VinluV
post May 23 2012, 04:47 PM

Regular
******
Senior Member
1,947 posts

Joined: Nov 2005
QUOTE(neoengsheng @ May 23 2012, 04:01 PM)
What you described is the typical man in the middle attack where a hacker sits some where inside the same network as you are and use packet siffer to sniff out the packet s you send and receive to Blizzard server.

This is almost undoable on the open internet.

I have been reading the Diablo 3 official forum and really tempted to try to replicate or some how prove Blizzard is covering up and downplay the whole issue while at the same time keep blaming the users for hacking. This is even worse when combined with fanboys on the forum insulting and accusing people of lying about getting hacked with an authenticator.
*
The MITM is very highly dependant on where the hacker location is as well.
Has to be close to Bnet server or piggybacking tmnut in order to capture a proper dump.

edit: just informed that there is a new type of boy/man in the browser attack as well.

This post has been edited by VinluV: May 23 2012, 04:52 PM

 

Change to:
| Lo-Fi Version
0.0290sec    0.23    5 queries    GZIP Disabled
Time is now: 1st December 2025 - 06:51 PM