Page 5 of 14 FirstFirst ...
3
4
5
6
7
... LastLast
  1. #81

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    If they steal one of your authenticator codes, they can logon to account management and change ur pw. Doesnt help them nothing, seeing as they dont have any more codes to logon the game itself. Or, they can logon the game and try to take stuff, and get immideatly dc'd by the user trying to logon again, because user still have his password. They will need the user to enter a new auth code every 30sec to even stay online. Sounds like the hacker needs to be online and communicate with ur computer within seconds, to even successfully logon to any character. I dont see this being a commonly used method amongst hackers. Im curious to see what Bizzards actions will be, to counter this.

  2. #82

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    Quote Originally Posted by bbr
    If there's one virus that does it, there will be more.

    Hope blizzard's login application will get smarter soon, to prevent viruses from snatching stuff like this.
    Blizzard can be vigilant with updating their encryption, but there's not a whole lot they can do when you let a virus onto your system and that virus reads information from your memory and redirects traffic however it likes.

    It's more like players need to understand that an authenticator is only a part of the solution. People who think 'I have an authenticator, I am invincible" are about as stupid as the people who say "I never go to suspicious sites, I am invincible" or "I have anti virus software, I am invincible."

    The only way to be safe is to take multiple precautions. Have a firewall, have an updated anti virus, have an authenticator, and pay attention to what you click and where you browse. If you think that only one or two of those things will be enough, well, eventually you'll be wrong.

  3. #83

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    Quote Originally Posted by Guinss
    If they steal one of your authenticator codes, they can logon to account management and change ur pw. Doesnt help them nothing, seeing as they dont have any more codes to logon the game itself. Or, they can logon the game and try to take stuff, and get immideatly dc'd by the user trying to logon again, because user still have his password. They will need the user to enter a new auth code every 30sec to even stay online. Sounds like the hacker needs to be online and communicate with ur computer within seconds, to even successfully logon to any character. I dont see this being a commonly used method amongst hackers. Curious to see what Bizzards action will be, regarding this.
    The hacker does need to be "online" when you try to log in in order to use the authenticator code, but that part can be automated, and for such a sophisticated attack, that's trivial to do. You could even run a sweat shop like most of these gold seller/hackers already do. Joe Chinaman or Joe Russki is sitting at a terminal waiting for the trojan to pass him an account, and when it does, he's logged in automatically, and all he has to do is to quickly get the loot off the account onto a friendly mule. The guy robbing the account doesn't need to even know the account name or password.

    There is no chance of the actual user kicking the hacker off, because the actual user's correct information is never going to get to the Blizzard servers. The user doesn't even know that he's being hacked, per se, only that he can't log on. The server only knows that the user successfully logged on (actually the hacker, but the server doesn't know that).

  4. #84

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    Quote Originally Posted by Guinss
    If they steal one of your authenticator codes, they can logon to account management and change ur pw. Doesnt help them nothing, seeing as they dont have any more codes to logon the game itself. Or, they can logon the game and try to take stuff, and get immideatly dc'd by the user trying to logon again, because user still have his password. They will need the user to enter a new auth code every 30sec to even stay online. Sounds like the hacker needs to be online and communicate with ur computer within seconds, to even successfully logon to any character. I dont see this being a commonly used method amongst hackers. Curious to see what Bizzards action will be, regarding this.
    Indeed, even if they hack someone with authenticator, you can just try to log in again, no need to go through authenticator code step, just your normal password and that will result in dc + 24h ban on account, plenty of time to sort things out.

  5. #85

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    Quote Originally Posted by Mystoman
    Indeed, even if they hack someone with authenticator, you can just try to log in again, no need to go through authenticator code step, just your normal password and that will result in dc + 24h ban on account, plenty of time to sort things out.
    Only if you log in from a different PC. If you log in from the infected PC, you never connected to the Blizzard server the first time, and you won't on the second or third try either.

    As far as the server knows, you tried to log in one time, and you succeeded.

  6. #86

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    Quote Originally Posted by Drizzay
    No one is safe!
    Everyone can be safe. Since the game launched my account has never been hacked. I never bought an Authenticator, and I never will. Wanna know why? Because I can play without a ton of mods. I don't visit porn sites and other websites that are filled with viruses.

  7. #87

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    where does it come from?

    I guess the usual free wow mount here and update your patch with our superfast dl...
    Time waits for no one.
    Aoccdrnig to rscheearch at Cmabrigde uinervtisy, it deosn't mttaer waht oredr the ltteers in a wrod are, the olny iprmoetnt tihng is taht the frist and lsat ltteres are at the rghit pclae. The rset can be a tatol mses and you can sitll raed it wouthit a porbelm. Tihs is bcuseae we do not raed ervey lteter by it slef but the wrod as a wlohe.

  8. #88

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    What is more worrying is not that this virus can hack WoW accounts but that these authenticators are industry standard for a lot of online banking authenticators also. That is much more of an issue that a WoW account as far as I am concerned. This is as far as I know, correct me if I am wrong though.

  9. #89

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    Quote Originally Posted by CaptainArlong
    Everyone can be safe. Since the game launched my account has never been hacked. I never bought an Authenticator, and I never will. Wanna know why? Because I can play without a ton of mods. I don't visit porn sites and other websites that are filled with viruses.
    Not all porn sites have viruses...

  10. #90
    I am Murloc! Nienniora's Avatar
    Join Date
    Mar 2009
    Location
    Quebec
    Posts
    5,161

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    the tabard its missing his thumb because of the symetry.. :
    and
    lol at authentificator

  11. #91

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    So is it wise to hit send on your authenticator code right before the code changes, to give any hacker the least amount of time possible to hack your account?

  12. #92

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    I am wildly offended by the use of "ass" in this announcement. Please keep in mind that this is a game for ages 12 and up. WHY WON'T ANYONE THINK OF THE CHILDREN?!
    This is my signature. You will now remember me.

  13. #93

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    Quote Originally Posted by CaptainArlong
    Everyone can be safe. Since the game launched my account has never been hacked. I never bought an Authenticator, and I never will. Wanna know why? Because I can play without a ton of mods. I don't visit porn sites and other websites that are filled with viruses.
    *sigh* this is ignorance at its finest.

    I played for 3 years, never got hacked. Know why? I don't visit suspicious sites, have anti virus software, don't give out my information yada yada yada.

    Then one day I got hacked. Know why? Because I visited a Blizzard fan site, which was linked to by a blue post, from the official blizzard forums. I read a totally legitimate article about the upcoming Wrath of the Lich King expansion, and while I did that, my browser was being exploited by a flash vulnerability through an advertisement embedded in the page. All of my software was fully updated, but they got me during a window where a vulnerability was discovered and not yet corrected.

    Saying "I've never been hacked, so I am safe" is like saying "I've never had cancer, so I'll never get it." No one gets cancer until they get cancer. No one gets hacked until they get hacked. I hope you won't get hacked, but with your ignorant attitude, you probably will hacked some day.

  14. #94

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    Quote Originally Posted by Collected
    So is it wise to hit send on your authenticator code right before the code changes, to give any hacker the least amount of time possible to hack your account?

    After all im affraid that all is going in a matter of seconds , automaticly. Well at least login on b.net account and changing pass, dunno what about WoW itself coz it will dc after beign afk too long anyway ? But yeh, prolly im going to wait with sending code till last seconds.

  15. #95

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    Is nothing unique in this game anymore? Why does everyone need to be able to ride a deathcharger. This game has fallen pray the commercialization band wagon since they joined with activision.

  16. #96

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    Quote Originally Posted by Tang
    Only if you log in from a different PC. If you log in from the infected PC, you never connected to the Blizzard server the first time, and you won't on the second or third try either.

    As far as the server knows, you tried to log in one time, and you succeeded.
    What you dont understand is that you are indeed connected to Blizzard. The hack just send your code to them and switches it with a fake code which goes to Blizzard. Therefore the fail on login.

    You can pretty much just spam login and they wont be able to do nothing. Even if the same auth code is still valid. Unless, ofcourse wont work if they change your password. Something that is a risk for them seeing as they then use one of the recieved codes and its no longer useable.

  17. #97

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    Quote Originally Posted by Slipper
    Just curious - Im about to start playing WoW again, well was thinking about it - but my account isnt attached to an authenticator and im extrememly tight on money etc - even a WoW subscription is pushing it. Taking into account all of hte following, should I really buy an authenticator and be short on money, or just wait till next payday?

    The internet I use is extremely secure.
    The computer I will be using has just been rebuilt and uses AVG.
    Nothing gets downloaded onto the computer in terms of torrents etc.

    I have 4 years playing experience and have only been hacked once, and that was when I logged into my account at a friends house.

    So what im asking is, is the authenticator that important if you are a sensible, knowledgable computer user?

    Physical authenticator is like 6 bucks. Skip Mcdonalds one day and get one.
    Mobile authenticator is free.

  18. #98

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    Quote Originally Posted by Tang
    *sigh* this is ignorance at its finest.

    I played for 3 years, never got hacked. Know why? I don't visit suspicious sites, have anti virus software, don't give out my information yada yada yada.

    Then one day I got hacked. Know why? Because I visited a Blizzard fan site, which was linked to by a blue post, from the official blizzard forums. I read a totally legitimate article about the upcoming Wrath of the Lich King expansion, and while I did that, my browser was being exploited by a flash vulnerability through an advertisement embedded in the page. All of my software was fully updated, but they got me during a window where a vulnerability was discovered and not yet corrected.

    Saying "I've never been hacked, so I am safe" is like saying "I've never had cancer, so I'll never get it." No one gets cancer until they get cancer. No one gets hacked until they get hacked. I hope you won't get hacked, but with your ignorant attitude, you probably will hacked some day.
    This is too true, wendsday I was hacked, lost everything, never did anything reckless or went to any unsafe sites, don't be an ass just because it hasn't happened to you, because kharma has a way of taking you down a notch
    How much bone could a bonestorm storm if a bonestorm could BOOOOOOOOONESTOOOOOOOOOOOORM!!
    http://www.mmo-champion.com/character-bios/'almega'-nara-draconus/ - my RP character

  19. #99

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    The Blizz authenticator is pointless, the REAL authenticator should be two factor. Its based on something you have (Authenticator) and something you know (a pin). I will never own the Blizz kind, as its been proven not effective.

  20. #100

    Re: Authenticator Accounts Hacked, ICC Quests, Crimson Deathcharger

    Gee. I recall members calling me down as retarded and not understanding things at all for describing this exact method of hacking your account some months ago. mmo=champion forums ftw.


    http://www.mmo-champion.com/general-discussions-22/if-you-do-not-have-a-authenticator-read-this!/msg1875413/#msg1875413

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •