Hacked accounts (Compare notes page)

Fril Estelin

Fril Estelin

So Serious...

Join Date: Jan 2007

London

Nerfs Are [WHAK]

E/

Quote:
Originally Posted by Brianna
Please explain how it is a Malware Magnet? Are you talking from the side of accepting files from people or an exploit in the program itself?
Mostly the 1st one, but also the 2nd one. MSN is bad IMHO. So is outlook (though it used to be much worse).

Anti-badware (anti-virus, anti-spyware) may be imperfect, it's an absolute necessity nowadays. A reminder about the Security Tips for the Guild Wars (GW) player.

Linksys

Jungle Guide

Join Date: Apr 2006

Here's another thing to NOT do. I'm not sure if it's already been mentioned on this forum somewhere. But something you should never do is register and participate in a website forum that's exclusively run by a guild or alliance.

Let's say you just joined the latest title hunting, Hall of Heroes, town owning, super leet free HFFF alliance. And you find out they have their own website domain and on this site their own forums. Better yet, they actually "require" you to go and register on the forums. So what does an unsuspecting gamer do? Goes to the forums and registers. What does an even more naive gamer do? Use the same email address and password he/she uses in GW for convenience. Not just on any website. But some unknown obscure privately owned domain. You can see where things can go horribly wrong there.

Fril Estelin

Fril Estelin

So Serious...

Join Date: Jan 2007

London

Nerfs Are [WHAK]

E/

Quote:
Originally Posted by Linksys
So what does an unsuspecting gamer do? Goes to the forums and registers. What does an even more naive gamer do? Use the same email address and password he/she uses in GW for convenience. Not just on any website. But some unknown obscure privately owned domain. You can see where things can go horribly wrong there.
Yes, but bear in mind that there's nothing wrong at all with registering to a forum where you have reasons to believe it's legitimate and run by honest people. It's always possible that they'll get your IP address and try to hack into your computer, but then do the best you to keep it protected. But there're even work-arounds for this, use:
1) Firefox add-ons such as TorButton or Tor-Proxy.net toolbar
(it's also good to use trail-removing add-ons such as Stealther or Distrust)
2) use a Firefox conversion such as TorPark

On the other hand, don't use your "normal" email address for this kind of stuff. Use "buffer email addresses" that you can discard at any time, if things turn bad. NEVER, EVER use the same password on different accounts. (see link I posted above)

No need to become paranoid, well you're free to be but usually a common-sense approach with caution is all you need.

Franco Power

Franco Power

Jungle Guide

Join Date: Dec 2006

UK

W/

1: Where you online when you got hacked? if so what happend, where were you?
No, I was offline. Happened over night.
2: Do you use textmod? If you do, where did you download it from?
I don't think Texmod even existed back then.
3: Are you on American or other servers at the time? (And when you loged in what was your location? (Server/Outpost)
Mainly International or Euro servers, I was offline when it happened, logged out in HA ID1 probably.

4: Do you have your account linked to play NC or use the online store?
Yes I did.

5; Was PlayNC or Anet helpful in recovering your Account?

About as helpful as someone slamming a sledge hammer in my head to find out if it hurts.

Tom Swift

Jungle Guide

Join Date: Aug 2007

OK for anyone who changed their Guild Wars log-in email to an email that they use only for Guild Wars and thought that made them more secure - think again.

There were some (very repeatable) glitches in registering one of my accounts for the Xunlai house this month and guildwars.com wound up actually showing me my brothers current email loggin.

What this means is, let's say you originally used your general email address when you first installed guild wars. Now, you realized that was unsafe so you changed it to a new email used only for logging into guild wars. But you continued to use the old one to contact guild wars friends and on these forums. If you registered for xunlai house, any of those people who know your old email (including anyone they may have forwarded one of your emails to) may guess that you had used that email for a GW login at one time (a fairly reasonable assumption) and can find your current logon email in about five minutes. (I don't know whether it makes a difference if it was before or after you changed log-on emails because my brother does not remember exxactly when he registered at xunlai)

Now that does not help them to get your password as far as I can see but it does mean that if you thought changing your email logon for guild wars made you safe - forget it

that bothers me and it needs fixed right now (I am contacting ANet but it will be days before it gets through the automated replies and a human sees it)

In the mean time, if you don't want people knowing your email logon for GW don't register for xunlai.

Fril Estelin

Fril Estelin

So Serious...

Join Date: Jan 2007

London

Nerfs Are [WHAK]

E/

Quote:
Originally Posted by Tom Swift
There were some (very repeatable) glitches in registering one of my accounts for the Xunlai house this month and guildwars.com wound up actually showing me my brothers current email loggin.
If I understood correctly what you explained, it's simply the browser remembering the form information you typed in, including your email. If you clean your cookies regularly, you won't have this problem.

And Anet can't do anything about the fact that your friends know your email address. It's more a problem of you realising too late that you wanted to use a different email address. If your password is strong (see this guide), you won't have a problem because of that!

Tom Swift

Jungle Guide

Join Date: Aug 2007

Quote:
Originally Posted by Fril Estelin
If I understood correctly what you explained, it's simply the browser remembering the form information you typed in, including your email. If you clean your cookies regularly, you won't have this problem.
NO -it's not anything to do with browsers and cookies. Xunlai House actually showed me my brothers current email log-in name even though I have never sent him an email at that address, I have never entered that email into any form on this computer and he has never entered it into any form or in any manner on this computer (he lives in a different state)

And again, this only reveals the email logon - it does not reveal the password. but there are a lot of people who though making a new email only for logging in to Guild Wars would make them safer. They need to know it does not.

And no, ANet can not do anything about your friends knowing your email address. But that does not mean they should be handing out your current log in name to them.

Yes - make sure your passwords are secure - that is doubly important because your email log-in name is not.

Gli

Forge Runner

Join Date: Nov 2005

Quote:
Originally Posted by Tom Swift
NO -it's not anything to do with browsers and cookies. Xunlai House actually showed me my brothers current email log-in name even though I have never sent him an email at that address, I have never entered that email into any form on this computer and he has never entered it into any form or in any manner on this computer (he lives in a different state)

And again, this only reveals the email logon - it does not reveal the password. but there are a lot of people who though making a new email only for logging in to Guild Wars would make them safer. They need to know it does not.

And no, ANet can not do anything about your friends knowing your email address. But that does not mean they should be handing out your current log in name to them.

Yes - make sure your passwords are secure - that is doubly important because your email log-in name is not.
Of all the possible thousands upon thousands of e-mail adresses in their database, they glitched and showed your brother's?

No offense, but I'm kinda 100% convinced you're looking at a problem at your end, not theirs.

Tom Swift

Jungle Guide

Join Date: Aug 2007

Quote:
Originally Posted by Gli
Of all the possible thousands upon thousands of e-mail adresses in their database, they glitched and showed your brother's?

No offense, but I'm kinda 100% convinced you're looking at a problem at your end, not theirs.
lol - no - it is definitely at theirs (maybe glitch was a bad choice of words). But I don't think its a wise idea to list the steps to repeat it here. I've told ANet how it happened and for once got a fast response from support (escalated in less than 20 minutes). So hopefully it will be fixed soon.

SuTiH

Wilds Pathfinder

Join Date: Jul 2006

Whats Going On [sup]

Mo/

1: Wasn't online, my internet was dead almost all day, when it finaly worked again I lost almost everything (just items [expensive ones tho><], hapily no character loss..)

2: Nope, don't use it

3: Nope

4: linked to play NC yes

therangereminem

therangereminem

Jungle Guide

Join Date: Jan 2007

R/Mo

we in my allince think it is guildwars/prediction s sign up every hacked in allince happened after sign up of that

Snow Bunny

Snow Bunny

Alcoholic From Yale

Join Date: Jul 2007

Strong Foreign Policy [sFp]

Quote:
Originally Posted by therangereminem
we in my allince think it is guildwars/prediction s sign up every hacked in allince happened after sign up of that
a. stop with your conspiracy theory

b. can't you type correctly?

Tom Swift

Jungle Guide

Join Date: Aug 2007

Ach - turns out my my brother used my name when he signed up for Xunlai predictions (he thought he had to register under the name originally on the GW account), which is why guildwars.com showed me his current email log-in.

Still, I do not I do not feel comfortable with the fact that xunlai house showed me his current email when I logged into it using my email address.

Jhadur

Jhadur

Desert Nomad

Join Date: Jul 2005

Glob of Ectospasm [GoE]

Well I've now been the victim of an account hack.
Still have all my chars just lost a couple of stacks of ectos,fissure armour from my main and all the items on the char that I had last played. Even the customised weapons.

To answer the questions in first post.

1. Nope I was at work

2. I have used textmod before but not for about 6 months, downloaded through a link in the canthan explorer thread on this site.

3. Euro servers and the char was still in the same place that I'd left him. Euro servers, great temple of Balth

4. Yes account is linked to plaync and I've used the store.

Nothing was taken from other characters and my Ranger still has his fissure armour.

For everyone that will say it's because I've downloaded something then can they explain why my 2nd account that isn't linked to PlayNC or the store hasn't been touched.

Queenie

Queenie

Forge Runner

Join Date: Jul 2005

1: Where you online when you got hacked? if so what happend, where were you? Nope

2: Do you use textmod? If you do, where did you download it from?
No

3: Are you on American or other servers at the time? (And when you loged in what was your location? (Server/Outpost) Yes, Great Temple of Balthazar

4: Do you have your account linked to play NC or use the online store?
No

codyty

codyty

Ascalonian Squire

Join Date: Jul 2008

The guild Hall

Legendary Sinz of the Underworld [SINZ]

A/

my account master of all ty was also hacked can u help me get it back

Accursed

Accursed

Wilds Pathfinder

Join Date: Sep 2007

Question: Should you use a fake/unused e-mail to use for your Guild Wars account along with a a bad/password that you don't use?

Should I change it if I use the same information for my e-mail and Guild Wars account?

Kamakazi112

Kamakazi112

Jungle Guide

Join Date: Feb 2008

W/

1: Where you online when you got hacked? if so what happend, where were you?

Sleeping

2: Do you use textmod? If you do, where did you download it from?

GWwiki

3: Are you on American or other servers at the time? (And when you loged in what was your location? (Server/Outpost)

Ended up in Kanieng

4: Do you have your account linked to play NC or use the online store?

Nope

Lost:

1500 Ectos
4 Tormented Weapons
1000k Cash
Unded Yeti
500 Bday Cakes
Fow Armor
500 Candy Canes
R8 15^50 Weapons

Toxage

Krytan Explorer

Join Date: Nov 2005

Blizzard is on the right track again as usual.... http://www.blizzard.com/store/details.xml?id=1100000182

Sadly Arena Net only care about Guild Wars 2 and have abandoned us plus they are really lazy.

BLOODGOAT

BLOODGOAT

Wilds Pathfinder

Join Date: Jun 2007

long a

Mo/

1: Where you online when you got hacked? if so what happend, where were you?
No.

2: Do you use textmod? If you do, where did you download it from?
No.

3: Are you on American or other servers at the time? (And when you loged in what was your location? (Server/Outpost)
From AD ToA to ID Balthazar's Temple.

4: Do you have your account linked to play NC or use the online store?
No.

Lost 250k and a dedicated Mini Gwen, big deal.

Would like to add: I told no one my e-mail, password, or engaged in use of mods, or even attempted to. The only GW websites I ever visited were GWG, unofficial Wiki, and PvXwiki.
My password was at the time was however relatively weak.

pumpkin pie

pumpkin pie

Furnace Stoker

Join Date: Jul 2006

behind you

bumble bee

E/

ermmmmmmmm

for so long i've try to avoid using texmod, and its the correct move, because I downloaded texmod several days ago, unzip the contents onto my desktop, and proceed to get the cartography map, I guess I am lucky the map took a long time to download, which discourages me to use texmod, and also i have no idea how to run the thing lol. so phewwww... chuck it into the trash as soon as i found the trojan, it was listed as high risk

so this morning I scan my computer for possible threat and guess what I found

trojan.onlinegame.asai

I am one of those paranoid and have lots of time on their hand people who scan their computer alot. and i am sure that wasn't there before texmod was downloaded.

Download link was from Guild Wars Official Wiki.

Just thought you want to know.

oh and Tor Button is unsafe to use with Firefox 3 see picture

Fril Estelin

Fril Estelin

So Serious...

Join Date: Jan 2007

London

Nerfs Are [WHAK]

E/

Quote:
Originally Posted by pumpkin pie
so this morning I scan my computer for possible threat and guess what I found

trojan.onlinegame.asai
What AV did you use?

Gli

Forge Runner

Join Date: Nov 2005

I'd never download anything linked from a wiki unless it's from a protected page. Any idiot could replace the link with a link to his own 'enhanced' version of the download.

Joseph Rejekt

Joseph Rejekt

Frost Gate Guardian

Join Date: Jun 2006

Absence Of Light

R/D

Anyone I've ever talked to has usually signed up to a website with the same email and password as their GW login.

Tips: Never use the email from your GW account to sign up to a webbie, ALWAYS use another. I have several emails myself.
A firewall and antivirus software are a must!