Guild Wars Guru Security Notice

Dralspire

Retired

Join Date: Apr 2005

Done, passwords changed.

S{R}Raptor

S{R}Raptor

Academy Page

Join Date: May 2005

Wolves in Exile

W/Mo

what if this breach has not been fixed and the people that did this snuck a root kit onto the server the forums are running on, knowing that the first thing people do is change emails and passwords, then these guys get all your changes to. A gaming league i belong to had this happen to them and it took them over a year to straighten out all the crap that got damaged.

I am glad you guys told us that you had a security breach, but you need to dot every i and cross every t and make darn sure everything is accounted for before you go telling innocent people to reset their stuff and end up them being the ones that get hacked. Rootkits are damn hard to detect unless you have the right scanners for them as most AV will not find them.

Valcion

Frost Gate Guardian

Join Date: Aug 2007

A/

honestly, no use in change my forum info, since if they got it they got it, not much to be done about it. It's much more important to change the OTHER info, like your ncsoft master account password and email and such.

I use a junk mail acct for all game fan sites and completely separate and unique email and pass for my in game stuff, so at the very worst they can hack into my other fan site accounts, but not my actual game accounts.

Inde

Site Contributor

Join Date: Dec 2004

Quote:
Originally Posted by S{R}Raptor View Post
what if this breach has not been fixed and the people that did this snuck a root kit onto the server the forums are running on, knowing that the first thing people do is change emails and passwords, then these guys get all your changes to. A gaming league i belong to had this happen to them and it took them over a year to straighten out all the crap that got damaged.

I am glad you guys told us that you had a security breach, but you need to dot every i and cross every t and make darn sure everything is accounted for before you go telling innocent people to reset their stuff and end up them being the ones that get hacked. Rootkits are damn hard to detect unless you have the right scanners for them as most AV will not find them. Well I guess I could make up a few "what if" theories myself as well (which I have indeed been doing for the last 24 hours now ), but I can tell you we went over our files with a fine tooth comb. They didn't get onto our server from what we can tell but I don't have an answer for you, or if this was a concern, because if you know about rootkits than you know the problems associated with those. I can tell you that even now we continue to work on this but we've always monitored our security, which is how we knew this happened in the first place.

I'm as upset by all this as anyone, it's not an easy problem and there are no easy solutions. We are very disappointed that this happened as well. My own data was compromised as much as yours. Our approach is to try to be as open and honest as possible with all of you.

Inde

Site Contributor

Join Date: Dec 2004

I'll bring everyone up to speed, S{R}Raptor's last line is referring to a virus notice he believes happened from a visit to Guru in December of '09. I contacted him personally by PM as his was the only report. We checked our ad server, tried to replicate and watched the forums closely for any further reports and received none. So no, I do not believe this was related, to answer your question.

Gennadios

Gennadios

Wilds Pathfinder

Join Date: Jun 2009

N/A

Well. At least you didn't wait for the player base to find out and then accuse us of exercising poor security to cover it up.

Ty for the announcement.

Akish Cohor

Academy Page

Join Date: Nov 2009

N/A

Were our dates of birth on the information the hackers received?

Inde

Site Contributor

Join Date: Dec 2004

Yes, we believe so Akish. And just for further information, birthdates are collected for COPPA compliance when you register.

al_capowned

Pre-Searing Cadet

Join Date: Mar 2009

what version of WordPress are/were you running? 2.9.1?

jonnieboi05

jonnieboi05

Forge Runner

Join Date: Mar 2006

Mableton, Georgia

Guild Ancestors Reunited [?????????]

I'm curious... What would you say (in your opinion, Inde) was the most critical bit of information the hackers got (or believed to have gotten)?

Inde

Site Contributor

Join Date: Dec 2004

al_capowned - It was our blogs.guildwars2guru.com that was accessed using Wordpress MU 2.8.6. The next version release was Wordpress MU 2.9.1 on Jan. 14th, then another update on Jan. 18th to 2.9.1.1. So we were behind by 9 days. We had stopped development of the user blogs as we had run into numerous problems.

JonnieBoi05 - emails

SithLord2064

SithLord2064

Academy Page

Join Date: Jul 2008

Phoenix, AZ

From the Ashes Rise the Pheonix

E/Me

This is the sort of thing that makes my sphincter shrink. Thank Balthazar the GWG team caught it quickly and informed the users immediately.

mrmango

mrmango

Desert Nomad

Join Date: Oct 2006

Southern California

Charter Vanguard [CV]

Me/Rt

Thank you for the notification.

Raven Wing

Jungle Guide

Join Date: Nov 2005

The Imperial Guards of Istan [TIGI]

N/

+1 thank you for informing us.

I wonder if we will see a lot of old guru users like myself having their account used for RMT etc spam on this forum and then get banned by guru? I hope not

karlik

Banned

Join Date: Sep 2009

I think as a result we might see many forum members getting one of those phishing emails? Seems to me like one of the best uses for the info they got.

As said before, this kind of thing happens, and the best thing the site can do is be open, honest, and tell us what happened.

A hobby forum I used to frequent was recently hacked, most members got a spam email that was said to have come from the forum (looked like an endorsement from the forum). They (the forum) denied it happened and said it was unrelated to their site. A few of us posted the header info showing it was sent through the forum mail system, including the ip address of the forums mail server. They eventually did some research and admitted that somehow it did come through their mail system, but it would never happen again, and no damage was done.

Being told "somehow" means they don't have any idea what happened or how it happened, and yet they can assure us nothing bad happened (none of our info was compromised) and it'll never happen again?

Thx for handling this right way guys.

JR

JR

Re:tired

Join Date: Nov 2005

W/

Quote:
Originally Posted by Gill Halendt View Post
How about passwords?

Is there any chance they could match e-mails and passwords if passwords are succesfully decrypted?

Do you think they have got to GWGuruAuction as well?

*sigh* I have my IGN in that profile.
They can match them up, yes. This is why we are advising people to change their passwords as soon as possible.

The Auction page was also compromised, though I find it very unlikely that they managed to get your character name from there. Inde might be able to confirm that either way.

[EDIT: Character names are in the AH user table, which was accessed by the hackers.]

Quote: /Agree.

Im glad to read this:
Quote:
Originally Posted by Raven Wing View Post
+1 thank you for informing us.

I wonder if we will see a lot of old guru users like myself having their account used for RMT etc spam on this forum and then get banned by guru? I hope not Change your password and you should be fine.

DutchSmurf

Krytan Explorer

Join Date: Jun 2006

Thanks for letting us now this fast. Not that I'm worried myself. I only use the password here for unimportant things. So in the worst case they can now access many of my forum accounts.

Auron of Neon

Auron of Neon

cool story bro

Join Date: Apr 2006

Mililani

yumy

Thanks JR! I live in constant fear of my Guild Wars account being compromised, but I'm given a modicum of peace knowing that the Guru Mods are on the case and working diligently.

I'm not quite sure what I'd do if I woke up one day and was unable to play my favorite game.

Yol

Yol

Wilds Pathfinder

Join Date: Feb 2007

GameAmp Guides [AMP]

E/

Thanks for letting us know so quickly, and being open about it.

I wanted to raise a point for the members on this forum who are using the same e-mail address and password as their GW log-in details....have you posted anything in the "show off your titles in progress" thread, or maybe offered help in the PUGS forums? Not a good idea to post screenshots of your hero panel with your character name in it, and don't put your IGN in the post if you're offering to help someone asking for help with vanquishing Elona, for example. It may sound like a bit of stretch, but basically, the hackers would now have your e-mail address, password, and a character name.

Inde said earlier that character names were removed from member profiles (which was a perfectly acceptable and understandable move), but that doesn't mean that character names aren't available on the forum to anyone with a few minutes and a bit of patience to do the searches.

MithranArkanere

MithranArkanere

Underworld Spelunker

Join Date: Nov 2006

wikipedia.org/wiki/Vigo

Heraldos de la Llama Oscura [HLO]

E/

I use the trash email here, so there is no harm done, all they will get is my spam email.

Just.nl

Just.nl

Krytan Explorer

Join Date: Nov 2007

The Netherlands, Noord-Brabant

Mu-Tants [MU]

Me/

Quote:
Originally Posted by Rampage View Post
Shit happens. I'm very glad to see that you aren't pulling an NCSoft and just denying everything. Thanks for informing the community, good job guys.
We've spent the 24 last hours tirelessly investigating what happened, patching up the exploit, and further strengthening security. Hopefully you can all sort it soon out & it will be back as normal.
Good job & Thanks!

Bobby2

Bobby2

Furnace Stoker

Join Date: Jun 2007

Delayed in order to meet ANet's high standards

[MaSS]

W/E

Props. Not worried, but you guys rock.

Sha Noran

Sha Noran

Desert Nomad

Join Date: Nov 2005

http://tinyurl.com/2jlusq

Idiot Savants [iQ]

R/

Wow.

Guild Wars and all its affiliates must just be easy prey, considering the sheer volume of hacking attacks I've seen the game and its biggest site's experience. I had a white hat hacker friend (and some black hats frankly) in-game for quite some time and they always had a chuckle over the general ease with which the whole system could be pwned, but as things have panned out its clear they were quite right. Sad.

Curin Derwin

Frost Gate Guardian

Join Date: Dec 2005

Mo/E

What about date of birth? Was that accessed? Can we choose to delete it and remove it ENTIRELY (and not just "hide it from public", please? It's used as a security measure for GW and other services.

Also, is there a way to view all posts that you account has posted on this website?

Thanks,
Destructor

JR

JR

Re:tired

Join Date: Nov 2005

W/

Quote:
Originally Posted by Destructor View Post
What about date of birth? Was that accessed? Can we choose to delete it and remove it ENTIRELY (and not just "hide it from public", please? It's used as a security measure for GW and other services.
We are required by COPPA to keep dates of birth.

[EDIT: Birthdays, as has been mentioned earlier in the thread, were indeed accessed.]

Quote:
Originally Posted by Destructor View Post
Also, is there a way to view all posts that you account has posted on this website? Go to your profile page, and you will find that option under statistics.

Inde

Site Contributor

Join Date: Dec 2004

Birth dates were indeed accessed. We answered that here as well for reference:

http://www.guildwarsguru.com/forum/g...50#post5028750


And just to let everyone know, birth dates are used for recovery of your Guild Wars/NCSoft account and password along with the following information:

NCsoft master account name: ENTER ACCOUNT NAME HERE
First and last name: ENTER FIRST AND LAST NAME HERE
Physical Address: ENTER POSTAL MAILING ADDRESS (not e-mail address) HERE
Date of birth: ENTER DATE OF BIRTH HERE
Serial codes/access keys: ENTER CODES/KEYS HERE
Unique Account ID(s): ENTER UNIQUE ACCOUNT ID(s) HERE

http://help.ncsoft.com/cgi-bin/ncsof...i=&p_topview=1
http://help.ncsoft.com/cgi-bin/ncsof...i=&p_topview=1
http://help.ncsoft.com/cgi-bin/ncsof...i=&p_topview=1

So a birth date alone is not going to (or shouldn't be able to) recover a Guild Wars or NCSoft account without other identifying information that we do not collect.

Braxton619

Braxton619

Desert Nomad

Join Date: Jul 2008

A/W

Thanks for letting me know. I changed all my passwords associated to my email and Guild Wars accounts.

Lord Dagon

Lord Dagon

Desert Nomad

Join Date: Jul 2009

Inside the Oblivion Gate

The Imperial Guards of Istan[TIGE]

E/Me

great job guys top notch job. NCSoft could learn a thing or two from you.

novawhiz

novawhiz

Desert Nomad

Join Date: Mar 2006

A/

wait... people still wanna steal gw accounts??


o.0