Guild Wars Forums - GW Guru
 
 

Go Back   Guild Wars Forums - GW Guru > The Inner Circle > The Riverside Inn

Notices

Closed Thread
 
Thread Tools Display Modes
Old Nov 28, 2009, 04:53 PM // 16:53   #1
Ascalonian Squire
 
Rainen_Fyre's Avatar
 
Join Date: May 2007
Location: USA, central time zone
Guild: TRP
Profession: W/
Advertisement

Disable Ads
Default Account Hacked, not a QQ.

This is just a note to other GW users. I was hacked while on my account last night. Someone logged into my NCSoft master account and changed the passwords for it as well as my log in password. I was immediately booted out of GW and could not log on. I then logged onto one of my other accounts to see someone else logged into my main account. I started the ball rolling trying to get a quick response from Anet, with no prevail.
It seems to me that NCSoft has some issues with Brute Force hacking.
I have no Trojans, KeyLoggers or have I downloaded any unsafe programs, I am running Kespersky total security.
The only thing I have downloaded recently was GWML, I do not know if this is the culprit or not but it was recent.
Yes when I first started GW I bought gold for real money, stupid I know, but I was not aware of the pitfalls at the time and I didnt know it was wrong.
I just wanted everyone to be aware, change your NCSoft Master account passwords regularly, it might have saved me a large headache.
Rainen_Fyre is offline  
Old Nov 28, 2009, 05:16 PM // 17:16   #2
Wilds Pathfinder
 
Join Date: Aug 2005
Guild: BEN
Profession: R/N
Default

make your password 10 chars + next time.. don't use words in the dictionary or names/slang words and add some numbers, you'll be fine

or you can make your pass really random- use a pattern on your keyboard, like start at g and press the keys to make a circle around it, last letter in caps then add your favorite number after.. just an example of ways to make your pass totally random and still remember it
Mustache Mayhem is offline  
Old Nov 28, 2009, 05:40 PM // 17:40   #3
Lion's Arch Merchant
 
Razon's Avatar
 
Join Date: Nov 2008
Profession: Mo/
Default

Lol if someone actually brute-forced your password, it must really suck. A password with just letters/numers alone ain't the best idea.
Razon is offline  
Old Nov 28, 2009, 05:53 PM // 17:53   #4
Krytan Explorer
 
Laraja's Avatar
 
Join Date: Dec 2007
Location: Somewhere over the rainbow
Guild: Descendents of Honor
Profession: Rt/
Default

Being an ex-Unix engineer with a specialty in hacked systems, I can tell you that making up good passwords is actually pretty easy.

The random Star Wars name generator is perfect. Type in some random crap, you cousin's best friend's dog's name, a made-up prescription drug name, whatever, replace some of the letters in the generated name with corresponding numbers on your phone, such as 2 for abc, 3 for def and so on, and you have a password that is impossible to hack. It has no ties to anything that's remotely familiar to you. Write it down, remember it, tape it to the bottom of a desk drawer or somewhere in case you forget.

No one would brute force a GW password unless they're so bored, that they have nothing else to do. Hackers brute force a system that actually is worth the time and has something worth stealing. I would expect it's something that you've accidently downloaded.

Anyway, my two cents worth.
Laraja is offline  
Old Nov 28, 2009, 06:58 PM // 18:58   #5
Forge Runner
 
Iuris's Avatar
 
Join Date: Nov 2006
Guild: Crazy ducks from the Forest
Profession: W/
Default

Brute forcing would also hit the failed attempt login delay GW is supposed to have.

Hacked, hacked, hacked... who believes this crap? You don't get hacked in GW. Somehow, somewhere security slips. Answer a wrong email, change pass on an NCsoft imitation page - bang. Use strong GW password and download nothing - and someone gets into the Email used for login, resets password, and gets it sent to him. Stuff like that is what really happens.

But noooo - everyone is SOOOO secure.

I sometimes actually wonder whether half the "hacking" reports are false complaints from gold sellers angry that Anet shut their accounts down, trying to make it seem GW is insecure.
Iuris is offline  
Old Nov 28, 2009, 07:50 PM // 19:50   #6
Ascalonian Squire
 
Join Date: May 2005
Location: Dallas, TX
Guild: Escape the [FATE]
Profession: R/
Angry

This also just happened to me early this morning..

I use a non-dictionary alpha-numeric password that would take years to brute force and they were still able to reset my password... Perhaps the forgot password function was exploited or something similar. Any update on your account Rainen_Fyre?
fritz300 is offline  
Old Nov 28, 2009, 08:20 PM // 20:20   #7
Desert Nomad
 
shoyon456's Avatar
 
Join Date: Jul 2006
Profession: D/
Default

Quote:
Originally Posted by Iuris View Post
Brute forcing would also hit the failed attempt login delay GW is supposed to have.

Hacked, hacked, hacked... who believes this crap? You don't get hacked in GW. Somehow, somewhere security slips. Answer a wrong email, change pass on an NCsoft imitation page - bang. Use strong GW password and download nothing - and someone gets into the Email used for login, resets password, and gets it sent to him. Stuff like that is what really happens.

But noooo - everyone is SOOOO secure.

I sometimes actually wonder whether half the "hacking" reports are false complaints from gold sellers angry that Anet shut their accounts down, trying to make it seem GW is insecure.
I'm sure the majority of people this happened to have had some security slip. However, you need to stop drinking the Anet kool-aid. No security system is flawless. If a hacker really wanted to get your account without a security slip, I'm sure they could.

Hell, I think Anet is even secretly aware of some sort of exploit for this, hence why guru now has the no IGN in profile policy as requested by Anet.

Just my 2 cents.
shoyon456 is offline  
Old Nov 28, 2009, 08:47 PM // 20:47   #8
Krytan Explorer
 
Join Date: Feb 2009
Guild: your just a meatsheild to me
Profession: N/Mo
Default

ive had i think 4 but for sure 3 friends who were looking up how to hack guild wars and the next day they were hacked so you might want to stay away from hacking sites to
snowman relic is offline  
Old Nov 28, 2009, 08:52 PM // 20:52   #9
Pre-Searing Cadet
 
Join Date: Jan 2007
Guild: Ravn
Profession: W/N
Default

Posting about this is a waste of time. I have made a couple of posts about this and had one deleted. With 3 years of grinding to only have my stuff gone is pure bs.

Stop drinking the Anet kool-aid... no kidding.

To anyone else whos been hacked, the Kool-aid really don't taste good anymore anyway so move on.

For the ones who love this Kool-aid let them be happy with Anet ops I meant Jim Jones.
sirsterm is offline  
Old Nov 28, 2009, 09:03 PM // 21:03   #10
Lion's Arch Merchant
 
damkel's Avatar
 
Join Date: Nov 2005
Profession: W/
Default

What everyone has been saying, stay away from suspect e-mails, downloads, websites etc. There is real money to be made in hacking peoples accounts and taking their gold (like the OP who admits to buying in-game gold with real $$). Sorry for your loss dude. Thanks for putting this warning out too.
damkel is offline  
Old Nov 28, 2009, 09:21 PM // 21:21   #11
Ascalonian Squire
 
The build master's Avatar
 
Join Date: Nov 2009
Unhappy

Quote:
Originally Posted by Rainen_Fyre View Post
Yes when I first started GW I bought gold for real money
Karma always gets you.
But really you cant do much for keeping your account safe. Random passwords regular virus scans and try to avoid weird gw related web sites.
The build master is offline  
Old Nov 28, 2009, 09:24 PM // 21:24   #12
Krytan Explorer
 
mlandry's Avatar
 
Join Date: Jul 2006
Profession: W/Me
Default

I just logged on for the first time in months today because I felt like restarting. Noticed a few items are missing (I thankfully customize everything and they left those) + all my armors have had their vigors runes taken off, no more cash in stash, all my chaos gloves + destroyer gloves have been salvaged as well.

Guess I'm permanently done with this game after 2200 hours played. Thanks hackers.

P.S : I only use this + GWwiki as sites.
mlandry is offline  
Old Nov 28, 2009, 09:26 PM // 21:26   #13
Ascalonian Squire
 
Join Date: Nov 2009
Default

Quote:
Originally Posted by shoyon456 View Post
Hell, I think Anet is even secretly aware of some sort of exploit for this, hence why guru now has the no IGN in profile policy as requested by Anet.
I've been wondering about that. Friend/ignore lists in this game are account wide (someone can log in on an alt and still show up), I wonder if someone figured out how to use this to get account emails. Doesn't explain how they get the password, but it does solve half the "battle" right there.
Blobbob is offline  
Old Nov 28, 2009, 09:27 PM // 21:27   #14
Krytan Explorer
 
Deviant Angel's Avatar
 
Join Date: Apr 2006
Location: On a boat!
Guild: Homeless.
Profession: Mo/
Default

Quote:
Originally Posted by Rainen_Fyre View Post
Yes when I first started GW I bought gold for real money, stupid I know, but I was not aware of the pitfalls at the time and I didnt know it was wrong.
*coughs*

Majority of the people that have made "omg I just got hacked" threads recently have been told by support that RMT companies were responsible. They don't need a keylogger if you used the same email and password (hell, even a similar one) to register on their website.
Deviant Angel is offline  
Old Nov 28, 2009, 10:08 PM // 22:08   #15
Ascalonian Squire
 
Rainen_Fyre's Avatar
 
Join Date: May 2007
Location: USA, central time zone
Guild: TRP
Profession: W/
Default

Quote:
Originally Posted by fritz300 View Post
This also just happened to me early this morning..

I use a non-dictionary alpha-numeric password that would take years to brute force and they were still able to reset my password... Perhaps the forgot password function was exploited or something similar. Any update on your account Rainen_Fyre?
No as of right now just waiting on Anet to reset password. Probably be on Monday, I get jacked out of farming Pie..........so sad.

And after reading all the above emails I believe my password was on the weak side. As Deviant Angel pointed out, I could have used the same password or something similar at that sight. I know it was the same email. And now in the crunch wars against gold sellers they picked my account out of the hat.

I just wanted to share this story as a warning to others that Gold Buying online is as Dumb as it comes. Hind sight 20/20.
Rainen_Fyre is offline  
Old Nov 29, 2009, 01:18 AM // 01:18   #16
Krytan Explorer
 
Feathermoore Rep's Avatar
 
Join Date: Nov 2006
Location: PM me for JACT Invite
Guild: Feathermoore Clan
Profession: R/Mo
Default

They still needed you NCsoft username first.

And if they hacked through your GW account, they need to know your account name. Player names can not get you account names. One way or another your info got tapped.
Feathermoore Rep is offline  
Old Nov 29, 2009, 02:26 AM // 02:26   #17
Forge Runner
 
Join Date: Jan 2007
Default

Quote:
Originally Posted by Falynn Firestorm View Post
Being an ex-Unix engineer with a specialty in hacked systems, I can tell you that making up good passwords is actually pretty easy.

The random Star Wars name generator is perfect. Type in some random crap, you cousin's best friend's dog's name, a made-up prescription drug name, whatever, replace some of the letters in the generated name with corresponding numbers on your phone, such as 2 for abc, 3 for def and so on, and you have a password that is impossible to hack. It has no ties to anything that's remotely familiar to you. Write it down, remember it, tape it to the bottom of a desk drawer or somewhere in case you forget.

No one would brute force a GW password unless they're so bored, that they have nothing else to do. Hackers brute force a system that actually is worth the time and has something worth stealing. I would expect it's something that you've accidently downloaded.

Anyway, my two cents worth.
This. 100%. And @ passwords: I don't understand why people can't grasp the concept that if you use passwords that don't contain any common dictionary names, your chances of getting hacked with bruteforce are literally 0. On the other hand, you are never safe from a keylogger. I guess people overall are just too lazy to take their online safety seriously, so it comes down to making their password part of their username or their pet dog's name.
Bob Slydell is offline  
Old Nov 29, 2009, 02:35 AM // 02:35   #18
Forge Runner
 
Karate Jesus's Avatar
 
Join Date: Apr 2008
Location: Texas
Guild: Reign of Judgment [RoJ]
Profession: Me/
Default

Quote:
Originally Posted by Iuris View Post
Brute forcing would also hit the failed attempt login delay GW is supposed to have.
Actually, it doesn't have one (at least, not on the website where he claims he was hacked).

And even Gaile has admitted that these recent influxes in hacked accounts were no coincidence. Support is actually trying to add some more anti-hacking protocols, because of these problems (as per Gaile's talk page).

These hacks are a real problem and I personally tell everyone I know in game to avoid buying from the NCSoft website and to avoid using the NCSoft website for anything other than increasing the strength of their passwords.
Karate Jesus is offline  
Old Nov 29, 2009, 02:53 AM // 02:53   #19
Departed from Tyria
 
Shayne Hawke's Avatar
 
Join Date: May 2007
Guild: Clan Dethryche [dth]
Profession: R/
Default

Sure is pretty risky to be playing Guild Wars these days, eh?

Good lord, I hope we don't have to use the PlayNC account to transfer things from GW to GW2.
Shayne Hawke is offline  
Old Nov 29, 2009, 03:24 AM // 03:24   #20
Krytan Explorer
 
Hyperventilate's Avatar
 
Join Date: Nov 2007
Location: Somewhere in California
Guild: I Gots A Crayon [Blue]
Profession: Me/Mo
Default

Quote:
Originally Posted by Iuris View Post
Brute forcing would also hit the failed attempt login delay GW is supposed to have.

Hacked, hacked, hacked... who believes this crap? You don't get hacked in GW. Somehow, somewhere security slips. Answer a wrong email, change pass on an NCsoft imitation page - bang. Use strong GW password and download nothing - and someone gets into the Email used for login, resets password, and gets it sent to him. Stuff like that is what really happens.

But noooo - everyone is SOOOO secure.

I sometimes actually wonder whether half the "hacking" reports are false complaints from gold sellers angry that Anet shut their accounts down, trying to make it seem GW is insecure.

My boyfriend's ex-guildie stopped playing Guild Wars for a few months. When he recently logged in (A few days ago), his account was gone.

Since he doesn't play anymore, how could he have slipped up his password? A-net confirmed it was a Chinese Money Trader.

I admit, the majority of people probably responded to a fake e-mail or somehow gave out their information, I don't think -everyone- has fallen for that.


Even Gaile has addressed this is a very real problem and it is hacking in one form or another.


Very scary times, these are.
Hyperventilate is offline  
Closed Thread

Share This Forum!  
 
 
           

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 11:29 AM // 11:29.


Powered by: vBulletin
Copyright ©2000 - 2016, Jelsoft Enterprises Ltd.
jQuery(document).ready(checkAds()); function checkAds(){if (document.getElementById('adsense')!=undefined){document.write("_gaq.push(['_trackEvent', 'Adblock', 'Unblocked', 'false',,true]);");}else{document.write("