> Forest of True Sight > Questions & Answers Reload this Page Possible account stealing
Reply
Old Jun 20, 2005, 07:19 AM // 07:19   #1
Tech Monkeh Mod
 
cannonfodder's Avatar
 
Join Date: May 2005
Location: Good Old North East of England
Profession: Mo/Me
Advertisement

Disable Ads
Default Possible account stealing

Hey guys, this is just to advise all who play on the european servers about a worrying incident that happened to me on saturday evening..

A Character "whispered me" to advise that he was from the Guild wars admin team, and that there was a serious problem, and someone had accused me of "scamming them", he requested my email address and password and said "we will sort this out for you, and if you have done nothing wrong, you will get your account back", he would not say who had complained about me, only that I had scammed this guy out of 8 platinum. I said he could have my email address only, and that should be sufficient. He then replied "please comply with my request or you will be banned", I just replied "ban, i'll take it to your manager"....

This went on for about 10 minutes or so. I just kept replying "ok then ban my account", in the end he said "lol, was only messin with ya, your the only one who hasn't gave me the details.."

My parting shot to this person was "email is going to guild wars admin team, as we speak, lets see who's account is banned.."

So I have mailed the support team and I am awiating a reply...

If anyone wants this character name pm me, and i'll supply it(thats if I am allowed to?)...

Maybe this can be turned into a sticky? Mods. As I think it is A topic people need to be wary of...
cannonfodder is offline   Reply With Quote
Old Jun 20, 2005, 07:25 AM // 07:25   #2
Lion's Arch Merchant
 
Join Date: Apr 2005
Guild: Death Infernal Evil
Profession: Mo/R
Default

no worries anet will take care of him no problem. no need to spread his name- and good going! you're smarter than some people! and NObody is a dev- I think Devs has their own avatars- like gaile gray's avatar (maybe? haven't seen her avatar at all)looks so different than any other run of the mill characters.
Jwh6913 is offline   Reply With Quote
Old Jun 20, 2005, 07:26 AM // 07:26   #3
Academy Page
 
Join Date: May 2005
Location: south korea
Guild: Angels of Anarchy
Profession: W/R
Default

um, this the world's oldest form of social engineering. no way anyone should ever fall for that.
King of Fools is offline   Reply With Quote
Old Jun 20, 2005, 07:32 AM // 07:32   #4
Lion's Arch Merchant
 
Madjik's Avatar
 
Join Date: May 2005
Location: Somewhere, U.S.A.
Guild: Gold Pheonix
Default

Even so a reminder is needed:

No dev team for any game will ever ask for your account info (password and such) and anyone who does is obviously trying to steal from you.

Smart move on your part cannonfodder.

Last edited by Madjik; Jun 20, 2005 at 07:36 AM // 07:36..
Madjik is offline   Reply With Quote
Old Jun 20, 2005, 07:36 AM // 07:36   #5
Tech Monkeh Mod
 
cannonfodder's Avatar
 
Join Date: May 2005
Location: Good Old North East of England
Profession: Mo/Me
Default

Quote:
Originally Posted by Madjik
Even so a reminder is needed:

No dev team for any game will ever ask for your account info (password and such) and anyone who does is obviously trying to steal from you.

Smart move on your part cannonfodder.
Thanx dude, never once believed him though......
cannonfodder is offline   Reply With Quote
Old Jun 20, 2005, 04:01 PM // 16:01   #6
Frost Gate Guardian
 
Join Date: Apr 2005
Location: Puget Sound area, WA State
Guild: KnightMare Brigade [KB]
Profession: E/R
Default

Think about it... all of your account details are on THEIR servers. They wouldn't need to get the information from you. They just do a database query.

Good Job on skunking him out. Most need to learn that they don't need to get that data from you, they can look it up based on your unique characters names.
Oni No Arashi is offline   Reply With Quote
Old Jun 20, 2005, 04:11 PM // 16:11   #7
Wilds Pathfinder
 
Kuku Monk's Avatar
 
Join Date: Jun 2005
Profession: Me/E
Default

Quote:
Originally Posted by cannonfodder
Thanx dude, never once believed him though......
Then why'd u give him your email address? He woulda got nothing from me.
Kuku Monk is offline   Reply With Quote
Old Jun 20, 2005, 04:23 PM // 16:23   #8
Ascalonian Squire
 
Join Date: May 2005
Default

Quote:
Originally Posted by Jwh6913
no worries anet will take care of him no problem. no need to spread his name- and good going! you're smarter than some people! and NObody is a dev- I think Devs has their own avatars- like gaile gray's avatar (maybe? haven't seen her avatar at all)looks so different than any other run of the mill characters.
even though it's not necessarily posted within the game itself, the general rule is pretty much the same as what valve/steam has been posting regarding account stealing: no one from valve/steam will ever ask you for your account name or password. this message isn't verbatim, but the idea is pretty clear.
mthegreatone is offline   Reply With Quote
Old Jun 20, 2005, 06:25 PM // 18:25   #9
Frost Gate Guardian
 
Join Date: Apr 2005
Default

A while back, Mythic (the makers of DAoC) actually emailed people for a beta and requeted their account info. The email looked like a scam.. "Congrats you are now in the beta for xxxx.. Please email us with your account info".

Was funny that 4 years into a game and 100's of posts about "Mythic will never ask for your info" they turn around and ask for it.

They made a post on the front page after nobody replied so they had no beta testers.
ChristopherKee is offline   Reply With Quote
Old Jun 20, 2005, 08:18 PM // 20:18   #10
Frost Gate Guardian
 
Join Date: Apr 2005
Profession: N/R
Default

Well you gave him your email address so it should be relatively easy to brute force your GW account now and get your password. Just a heads up.
EvilWizard is offline   Reply With Quote
Old Jun 20, 2005, 11:00 PM // 23:00   #11
Krytan Explorer
 
Jelloblimp's Avatar
 
Join Date: May 2005
Guild: [KCHS]
Profession: W/N
Default

Quote:
Originally Posted by King of Fools
um, this the world's oldest form of social engineering. no way anyone should ever fall for that.
I agree this is the oldest trick there is. Also after they get the email address they start sending emails from Anet_at_hotmail.com or some other free/unknown email address (so they can get password).

Also brute force method is very rare (YCantUDie has pointed out the flaws already), but you would be surprised how many people use simple passwords. Password could be pet/family/friends names, animals or some other password can be gotten after some "friendly chatting" with the victim.

First time I heard about this was for usenet accounts for "entertainment directory" since those where payed access (& Kevin Mitnicks adventures who actually got caught & wrote a book on social engineering).
Jelloblimp is offline   Reply With Quote
Old Jun 21, 2005, 02:01 AM // 02:01   #12
Ascalonian Squire
 
Join Date: May 2005
Profession: W/N
Default

Quote:
Originally Posted by cannonfodder
Hey guys, this is just to advise all who play on the european servers about a worrying incident that happened to me on saturday evening..

A Character "whispered me" to advise that he was from the Guild wars admin team, and that there was a serious problem, and someone had accused me of "scamming them", he requested my email address and password and said "we will sort this out for you, and if you have done nothing wrong, you will get your account back", he would not say who had complained about me, only that I had scammed this guy out of 8 platinum. I said he could have my email address only, and that should be sufficient. He then replied "please comply with my request or you will be banned", I just replied "ban, i'll take it to your manager"....

This went on for about 10 minutes or so. I just kept replying "ok then ban my account", in the end he said "lol, was only messin with ya, your the only one who hasn't gave me the details.."

My parting shot to this person was "email is going to guild wars admin team, as we speak, lets see who's account is banned.."

So I have mailed the support team and I am awiating a reply...

If anyone wants this character name pm me, and i'll supply it(thats if I am allowed to?)...

Maybe this can be turned into a sticky? Mods. As I think it is A topic people need to be wary of...

Its totally a part of Identity theft prevention basics to recognize that a company, group, or whatever will NEVER ask for your info like that. But it is amazing how many still fall for it
Nosajio is offline   Reply With Quote
Old Jun 26, 2005, 01:57 AM // 01:57   #13
Frost Gate Guardian
 
Join Date: Apr 2005
Profession: N/R
Default

Umm why is brute forcing a password difficult with an account name. Why can't I just write a script that either uses a dictionary or random generator to guess the account pw? Unless GW has a lockout then it is fairly simple to do (even with a 10 character password).
EvilWizard is offline   Reply With Quote
Reply


Share This Forum!  
 
Thread Tools
Display Modes

Similar Threads
Thread Thread Starter Forum Replies Last Post
WTT- GW account for STEAM account le91688 Sell 1 Oct 10, 2005 05:08 AM // 05:08
Name Stealing Illusion Of Ender Off-Topic & the Absurd 23 Sep 01, 2005 03:33 AM // 03:33
Creating Account through PlayNC Account Stellus Technician's Corner 4 Apr 30, 2005 05:49 PM // 17:49


All times are GMT. The time now is 09:59 PM // 21:59.