Originally Posted by Hissy
Don't know if this is relevant, but I checked my firewall logs a little while ago, and two things were weird:
a) it was blocking (yay) outgoing attempts to connect to a particular IP address. "whois" identified that IP address as belonging to "Lewt Inc." and Googling that name revealed them to be exactly what they sound like - a gold selling site (and I might add, I have never used or visited any gold selling sites). b) My firewall was blocking repeated attempts to connect to my PC, from an IP Address that appeared to be PlayNC.com. I suspect this to be a spoof, since why would PlayNC attempt to connect to my PC? Perhaps the hope is that I will trust PlayNC and let them through my firewall (Yeah right. As if. Like even) I run a truly absurd amount of security, anti-virus, anti-spyware, anti-rootkit, anti-suspicious behaviour, anti-everything software... always on, and multiple full scans per day. Nothing is detected. I use texmod downloaded from a "trusted" source, and Ventrillo for voice chat - but I've never used any other 3rd party software for GW. I've never visited or used any gold selling sites. So why am I seeing a) above? My suspicion is malware on GW related sites/forums eg. adverts b) is worrying because it suggests someone knows I have a PlayNC game, and I am on a hitlist of people to be specifically targeted. Is anyone else seeing similar activity? |
Any ideas on what this 3-way handshake thing is? After all these hacking reports... I'm kind of worried mine will be targeted (even though I only have about 100k of stuff).