Jan 04, 2010, 04:04 AM // 04:04
|
#2
|
Desert Nomad
Join Date: Jul 2006
Profession: D/
|
I've been getting the same spam emails about my WoW account (hint, I do not have a WoW account now or ever).
It's just fishing for someone to hit their fake link and put in their account info. Notice how the url is "ncsofts" not "ncsoft." You're just one of many that's getting them. All they need are a few people who have accounts to click on the link and put in their info to make sure their account is ok, then its gone.
I've forwarded them to Blizzard, but I get so many now, its just easier to delete them all.
|
|
|
Jan 04, 2010, 04:05 AM // 04:05
|
#3
|
Krytan Explorer
Join Date: Dec 2006
Profession: W/
|
If this really is a hacker email you really shouldn't post a link to the website.
|
|
|
Jan 04, 2010, 04:31 AM // 04:31
|
#4
|
Lion's Arch Merchant
Join Date: Feb 2009
Profession: R/
|
Good thing you pointed out the extra s on ncsoft. Someone might panic if they receive an email saying their account info has been changed, and overlook that small detail.
|
|
|
Jan 04, 2010, 05:36 AM // 05:36
|
#5
|
Older Than God (1)
Join Date: Aug 2006
Guild: Clan Dethryche [dth]
|
Nasty.
I agree that you should take the URL code out, or at least break it so it doesn't work.
|
|
|
Jan 04, 2010, 05:56 AM // 05:56
|
#6
|
Grotto Attendant
Join Date: May 2005
Location: The Netherlands
Guild: Limburgse Jagers [LJ]
Profession: R/
|
Quote:
Originally Posted by furpigs
**********The Email Below***************
Password Reset Success
From: NCsoft Support ( [email protected])
Sent: Sun 1/03/10 5:31 AM
To: (my email address)
Someone at 210.259.232.57 has reset your Aion Game Account password for account xxxxxx. If you did not make this change, please contact support immediately.
|
Did you just post your accountname?
|
|
|
Jan 04, 2010, 06:11 AM // 06:11
|
#7
|
Forge Runner
|
Quote:
Originally Posted by Arduin
Did you just post your accountname?
|
I think he said he doesn't even own an Aion account. These hackers are getting desperate now just shooting out random emails to random people hoping to get a bite.
LOL..I also just noticed the IP is totally fake. 259 is an impossible range. its 0-255, (preferably 0-254).
Last edited by Bob Slydell; Jan 04, 2010 at 06:16 AM // 06:16..
|
|
|
Jan 04, 2010, 06:54 AM // 06:54
|
#8
|
Grotto Attendant
Join Date: Jun 2006
Location: Europe
Guild: The German Order [GER]
Profession: N/
|
Did you use email address that this was sent to for something aion or gw related? Fansite, etc.
|
|
|
Jan 04, 2010, 07:41 AM // 07:41
|
#9
|
Furnace Stoker
Join Date: Jul 2006
Location: behind you
Guild: bumble bee
Profession: E/
|
210.259.232.57
on one IP lookup, says the ip address is invalid
another one says the ip is from SOFTBANK TELECOM CORP, Yokohama, Japan,
|
|
|
Jan 04, 2010, 10:33 AM // 10:33
|
#10
|
Guest
|
I expect a lot more people will be getting hit this way. In their hack panic, they will give away their account(s) info.
|
|
|
Jan 04, 2010, 12:13 PM // 12:13
|
#11
|
So Serious...
Join Date: Jan 2007
Location: London
Guild: Nerfs Are [WHAK]
Profession: E/
|
Quote:
Originally Posted by flubber
I expect a lot more people will be getting hit this way. In their hack panic, they will give away their account(s) info.
|
In particular if they've been reading the security threads on Guru. Everyone must be feeling like everyone else is a potential hacker by now ;P.
EDIT: Security-induced brain explosion: what if the OP is a hacker attempting to cause more trouble by pointing to a fake phishing attempt?
Last edited by Fril Estelin; Jan 04, 2010 at 12:16 PM // 12:16..
|
|
|
Jan 04, 2010, 12:20 PM // 12:20
|
#12
|
Desert Nomad
|
General advice:
Use a text-only email client, do not enable html or any kind of executable.
Don't click links in emails, forum posts etc. Ever. Use your own favourites/bookmarks, to make sure you land on genuine sites - or carefully type the URL's yourself (beware of fake sites created using common mispellings of URLs).
If you MUST click on links...
...Use Firefox with Noscript, Adblock, Flashblock (or an equivelent browser setup), to help prevent infection by malware
...Do not enable script, or flash for ANY site unless you absolutely HAVE to, and even then - only after you are sure the site is genuine and trustworthy.
...Make sure you are running respectable anti-malware (firewall, antivirus, antispyware, antirootkit)
...Double-check the spelling of URL's - especially if the site is asking for any information.
Does that sound inconvenient or complicated? It really isn't. Make it a habit, and it's like driving a car - you won't even notice you're doing it.
|
|
|
Jan 04, 2010, 12:23 PM // 12:23
|
#13
|
Krytan Explorer
Join Date: Aug 2007
Location: The Netherlands
Profession: W/
|
Use an email filter and get rid of the garbage before it ever hits your pc.
|
|
|
Jan 04, 2010, 03:32 PM // 15:32
|
#14
|
Desert Nomad
Join Date: Dec 2005
Location: The Edge
Guild: Tormented Weapons [emo]
|
Quote:
Originally Posted by pumpkin pie
210.259.232.57
on one IP lookup, says the ip address is invalid
another one says the ip is from SOFTBANK TELECOM CORP, Yokohama, Japan,
|
One quick glance will tell an IT guy this isn't a valid IP address. The second octet is invalid. It's outside of any IP range.
|
|
|
Jan 04, 2010, 04:34 PM // 16:34
|
#15
|
Ascalonian Squire
|
Sorry, I realize that I should not have posted the bad link. I was trying to help.
I do not own an Aion account and the account name in the email was not any account that I have for anything.
The email address they sent it to was at one time associated to an NCSoft master account, but no longer. The email address was not the login to the gw's account.
|
|
|
Jan 07, 2010, 05:21 PM // 17:21
|
#16
|
Guest
|
Quote:
Originally Posted by Fril Estelin
In particular if they've been reading the security threads on Guru. Everyone must be feeling like everyone else is a potential hacker by now ;P.
|
Well, if they have any sort of sense, NO. Logging into/out of a site and obtaining a random's account info, isn't hacking. It is site failure. no matter what the thundercat team thinks.
Quote:
Originally Posted by Fril Estelin
EDIT: Security-induced brain explosion: what if the OP is a hacker attempting to cause more trouble by pointing to a fake phishing attempt?
|
I don't think anyone would waste the time, unless trolling.
|
|
|
Jan 07, 2010, 05:41 PM // 17:41
|
#17
|
Grotto Attendant
Join Date: Mar 2006
Location: Done.
Guild: [JUNK]
|
A mail I received today:
Quote:
Subject: Aion Account Check
When you receive this message at the same time means that you have a routine account of our recent examination, was checking your account we have the evidence to prove that involved in the controversial game currency transaction so we had to take the necessary measures.
Please visit our web site XXXXXXXX as soon as possible to activate your account or we will suspend your account.
The NCsoft Team
|
(Removed the link and replaced it with XXXXXXXX.)
Forwarded it to support - got this back:
Quote:
Greetings,
Thank you for writing in this report. This is a scam email used to steal account information. Please do not follow any links that are listed in that email. If you have anymore in-game questions or concerns please let me know. Thank you.
Regards,
GM Redcommander
|
I know one of more person that got it today also. Neither of us has an AION account.
Last edited by upier; Jan 07, 2010 at 05:51 PM // 17:51..
Reason: More info.
|
|
|
Jan 07, 2010, 05:46 PM // 17:46
|
#18
|
Older Than God (1)
Join Date: Aug 2006
Guild: Clan Dethryche [dth]
|
I also got the e-mail that upier received. I don't play Aion either, and the odd thing about it was that it was sent to a forwarding e-mail address I almost never give to anyone.
Pretty poor phish attempt if you ask me. At least the Nigerian prince had a reason for his English being so poor.
|
|
|
Jan 07, 2010, 05:48 PM // 17:48
|
#19
|
Forge Runner
Join Date: Dec 2006
Guild: The Overacheivers [Club]
Profession: Mo/
|
Have you got your email address linked on any fansites or commonly used usernaes? Also lol at that IP address
|
|
|
Jan 07, 2010, 06:15 PM // 18:15
|
#20
|
Ascalonian Squire
Join Date: Jul 2009
Location: Somewhere in Ascalon
Profession: Me/E
|
These must be just mass emails going out. Because I received a WoW one on an email account that has never been registered anywhere on any site.
|
|
|
Thread Tools |
|
Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is On
|
|
|
All times are GMT. The time now is 09:22 PM // 21:22.
|