Guild Wars Guru Security Notice
Dralspire
Done, passwords changed.
S{R}Raptor
what if this breach has not been fixed and the people that did this snuck a root kit onto the server the forums are running on, knowing that the first thing people do is change emails and passwords, then these guys get all your changes to. A gaming league i belong to had this happen to them and it took them over a year to straighten out all the crap that got damaged.
I am glad you guys told us that you had a security breach, but you need to dot every i and cross every t and make darn sure everything is accounted for before you go telling innocent people to reset their stuff and end up them being the ones that get hacked. Rootkits are damn hard to detect unless you have the right scanners for them as most AV will not find them.
I am glad you guys told us that you had a security breach, but you need to dot every i and cross every t and make darn sure everything is accounted for before you go telling innocent people to reset their stuff and end up them being the ones that get hacked. Rootkits are damn hard to detect unless you have the right scanners for them as most AV will not find them.
Valcion
honestly, no use in change my forum info, since if they got it they got it, not much to be done about it. It's much more important to change the OTHER info, like your ncsoft master account password and email and such.
I use a junk mail acct for all game fan sites and completely separate and unique email and pass for my in game stuff, so at the very worst they can hack into my other fan site accounts, but not my actual game accounts.
I use a junk mail acct for all game fan sites and completely separate and unique email and pass for my in game stuff, so at the very worst they can hack into my other fan site accounts, but not my actual game accounts.
Inde
I'll bring everyone up to speed, S{R}Raptor's last line is referring to a virus notice he believes happened from a visit to Guru in December of '09. I contacted him personally by PM as his was the only report. We checked our ad server, tried to replicate and watched the forums closely for any further reports and received none. So no, I do not believe this was related, to answer your question.
Gennadios
Well. At least you didn't wait for the player base to find out and then accuse us of exercising poor security to cover it up.
Ty for the announcement.
Ty for the announcement.
Akish Cohor
Were our dates of birth on the information the hackers received?
Inde
Yes, we believe so Akish. And just for further information, birthdates are collected for COPPA compliance when you register.
al_capowned
what version of WordPress are/were you running? 2.9.1?
jonnieboi05
I'm curious... What would you say (in your opinion, Inde) was the most critical bit of information the hackers got (or believed to have gotten)?
Inde
al_capowned - It was our blogs.guildwars2guru.com that was accessed using Wordpress MU 2.8.6. The next version release was Wordpress MU 2.9.1 on Jan. 14th, then another update on Jan. 18th to 2.9.1.1. So we were behind by 9 days. We had stopped development of the user blogs as we had run into numerous problems.
JonnieBoi05 - emails
JonnieBoi05 - emails
SithLord2064
This is the sort of thing that makes my sphincter shrink. Thank Balthazar the GWG team caught it quickly and informed the users immediately.
jonnieboi05
Quote:
Originally Posted by Inde
JonnieBoi05 - emails
Ah, okay. Thank you, Inde.
al_capowned
mrmango
Thank you for the notification.
Raven Wing
+1 thank you for informing us.
I wonder if we will see a lot of old guru users like myself having their account used for RMT etc spam on this forum and then get banned by guru? I hope not
I wonder if we will see a lot of old guru users like myself having their account used for RMT etc spam on this forum and then get banned by guru? I hope not
Gill Halendt
karlik
I think as a result we might see many forum members getting one of those phishing emails? Seems to me like one of the best uses for the info they got.
As said before, this kind of thing happens, and the best thing the site can do is be open, honest, and tell us what happened.
A hobby forum I used to frequent was recently hacked, most members got a spam email that was said to have come from the forum (looked like an endorsement from the forum). They (the forum) denied it happened and said it was unrelated to their site. A few of us posted the header info showing it was sent through the forum mail system, including the ip address of the forums mail server. They eventually did some research and admitted that somehow it did come through their mail system, but it would never happen again, and no damage was done.
Being told "somehow" means they don't have any idea what happened or how it happened, and yet they can assure us nothing bad happened (none of our info was compromised) and it'll never happen again?
Thx for handling this right way guys.
As said before, this kind of thing happens, and the best thing the site can do is be open, honest, and tell us what happened.
A hobby forum I used to frequent was recently hacked, most members got a spam email that was said to have come from the forum (looked like an endorsement from the forum). They (the forum) denied it happened and said it was unrelated to their site. A few of us posted the header info showing it was sent through the forum mail system, including the ip address of the forums mail server. They eventually did some research and admitted that somehow it did come through their mail system, but it would never happen again, and no damage was done.
Being told "somehow" means they don't have any idea what happened or how it happened, and yet they can assure us nothing bad happened (none of our info was compromised) and it'll never happen again?
Thx for handling this right way guys.
JR
Quote:
Originally Posted by Gill Halendt
Is there any chance they could match e-mails and passwords if passwords are succesfully decrypted?
Do you think they have got to GWGuruAuction as well?
*sigh* I have my IGN in that profile.
The Auction page was also compromised, though I find it very unlikely that they managed to get your character name from there. Inde might be able to confirm that either way.
[EDIT: Character names are in the AH user table, which was accessed by the hackers.]
Quote: