Guild Wars Guru Security Notice

Gun Pierson

Gun Pierson

Forge Runner

Join Date: Feb 2006

Belgium

PIMP

Mo/

Thanks for the heads up and keep up the good work!

Inde

Site Contributor

Join Date: Dec 2004

No one is happy about this, and I wouldn't expect them to be. I apologize we were a week behind on a security update for a piece of software. Nowhere have we had a "relaxed" attitude towards our user's security. As for a web software "notorious for security holes" that's highly debatable. I'm sure I could link you to many top name sites who use that software if that is what you would like. You seem to be intentionally trying to get a rise out of either us or the players, I appreciate and will continue to respond to legitimate questions or concerns. But you don't seem to have asked anything in your previous post that you care to hear a response to. If that's not the case please let me know and I'll be happy to answer.

al_capowned

Pre-Searing Cadet

Join Date: Mar 2009

Quote:
Originally Posted by Inde
View Post
No one is happy about this, and I wouldn't expect them to be. I apologize we were a week behind on a security update for a piece of software. Nowhere have we had a "relaxed" attitude towards our user's security. As for a web software "notorious for security holes" that's highly debatable. I'm sure I could link you to many top name sites who use that software if that is what you would like. You seem to be intentionally trying to get a rise out of either us or the players, I appreciate and will continue to respond to legitimate questions or concerns. But you don't seem to have asked anything in your previous post that you care to hear a response to. If that's not the case please let me know and I'll be happy to answer.
It's not my intention at all. I, like the rest of the users here, appreciate the honesty the team has displayed by letting us know what happened. But I'm not about to applaud you for a job well done. The hard fact of it is that it wasn't a job well done....it was a job poorly done. Whether you can supply a list of websites currently using the software is almost a moot point as many of the versions in between 2.1.x and 2.8.x have had serious issues with root access exploits not to mention a number of backdoor issues in numerous version updates. As with any open-source project it is almost essential to be on top of every daily release of the software when working with a large vulnerable community. I make no effort to insult anyone affiliated with the site...I'm just not so quick to thank you for informing us of your f-up.

Inde

Site Contributor

Join Date: Dec 2004

Yep, and I can appreciate that attitude actually al_capowned. I'll tell you that I also had a few choice words when I found out. Informing my other admins they also said similar about the "f-up". (Except it was more detailed, with more curse words and name dropping.) Your response is honest and I can only tell you it fell through the cracks as we had dropped the project a month back so weren't actively watching for the update.

Loralai_gw

Pre-Searing Cadet

Join Date: Mar 2007

Well being that i used a unique email and password for this site, I'm not worried. Gotta say you guys worked fast, informed us in a timely manner, have answered our questions and been really honest about it all. So for that I thank you. Seems like more than what a lot of sites would do, not even referring to anything guild wars related there.

This sites been open for a long time and with everything happening in WoW and Aion lately, and still happening it seems, nice to know that maybe someone at least knows or will fess up to what's going on. Pretty sure if we're all flooded with spam mail soon at least we'll now have some knowledge. Right now it just seems like everyone's fishing around for answers.

Maybe that's why some people are so grateful, referring to al_capowned there, because at least we know. No speculation, no assumptions.

I still don't think this could hack any guild wars account considering our character names weren't in there. I'll be watching my email though, let you know if something pops up since I don't use it for anything but this site.

Sir Skullcrasher

Sir Skullcrasher

Furnace Stoker

Join Date: Jun 2005

California

15 over 50 [Rare]

W/Mo

I would imagine no amount of security features will deter the hackers. (in no way am I saying we shouldn't have any) I mean if they REALLY want the information, they might as well take their sweet time to hack away until they got it. Either way, I know all security features can and WILL be compromised at any given time. Still, it's kind of weird how the hackers came here for emails instead of other big sites!

drunk n angry

drunk n angry

Lion's Arch Merchant

Join Date: Jul 2009

in a quiet little town that i love.

Ancient Dragoons [AGED]

W/

thank you for the transparency involved in the hack. as a community member it is VERY appreciated. so ty.

cosyfiep

cosyfiep

are we there yet?

Join Date: Dec 2005

in a land far far away

guild? I am supposed to have a guild?

Rt/

yes thanks for the information!
(and people laugh at my tinfoil hat, HA!)

PuppyEater

PuppyEater

Frost Gate Guardian

Join Date: Nov 2005

I'm on the left...

Guilds? Where we're going we don't need guilds...

R/Rt

Exactly how much did they get? The whole package or just a few emails?

Artemis Alexandrae

Artemis Alexandrae

Ascalonian Squire

Join Date: Nov 2009

Descendants of Honor

R/

Thanks for the heads up.

wilson

Krytan Explorer

Join Date: May 2005

aggro bubble

[RD];[FW];[GOTS];[baed];[kiSu]

Thanks for the warning! I changed my info on all the guru related sites.

pumpkin pie

pumpkin pie

Furnace Stoker

Join Date: Jul 2006

behind you

bumble bee

E/

I am inclined to ask, change passwords and email address (actually open yet another new email account just for guru, hehehehe) that is all I could do, right?

Thanks JR!

Tullzinski

Tullzinski

Jungle Guide

Join Date: Mar 2006

Trying to stay out of Ryuk's Death Note

N/R

ROFL @ hackers, good luck with my email and password from this site and
GWG2 site. One thing about being in the military is that you constantly move. The email address associated with this site was from being stationed in Hawaii and the GWG2 site has an email I created specifically for that site only.

I will keep an eye on it to see if any spam happens.

Thanks for the heads up!

Another Felldspar

Lion's Arch Merchant

Join Date: Sep 2006

Alchemy Incorporated

Mo/E

I can't tell you how much I appreciate you letting us know. It has increased my respect for Guru.

Jk)Phoenix

Jk)Phoenix

Wilds Pathfinder

Join Date: Apr 2006

Pizza's Town

I've Quit GW ^^

E/

changed all passwords,

thx a lot for letting us know it, great community!

Painbringer

Painbringer

Furnace Stoker

Join Date: Jun 2006

Minnesota

Black Widows of Death

W/Mo

Bad thing is many have listed our character names so one less security block for them to worry about

As said before Crap happens

milan

Desert Nomad

Join Date: Nov 2005

BONE

N/

Thanks for letting us know. Good job on the communication, much appreciated.

Lycan Nibbler

Forge Runner

Join Date: Sep 2006

AZ

Inde, JR and team.. luv you guys <3

If only NCSoft would look and learn from your actions rather than more likely look and go "see"....

JR

JR

Re:tired

Join Date: Nov 2005

W/

Quote:
Originally Posted by Painbringer View Post
Bad thing is many have listed our character names so one less security block for them to worry about

As said before Crap happens Character names were wiped from the forum two months or so ago, when the change to remove them was first implemented.

If you are concerned about posts you made containing your character names, that can be resolved too. Simply do a search on the forum for your character name, and edit the posts that come up.

[EDIT: If you can't edit your post because the thread is closed (and only if the thread is closed) PM me with direct links to the posts and I will remove them.]

nologic

nologic

Frost Gate Guardian

Join Date: Jul 2006

Sweden

E/

glad i changed my mail to a fake none that forwards my mail adress to the real one.. Same goes on another forum.

But I do think its good to keep the website up and running with newest builds released for the forums and wordpress in the future also inform wordpress about it so they wont make the same mistake in the future.

lilDeath

Krytan Explorer

Join Date: Sep 2006

Treehouse #1

W/

I applaud Guru for their open communications, working in the Internet business for 10 years now - I know it is not easy to be so brutally honest, with the potential of being ripped apart by your clients.

Luckily, I have practiced good security and none of passwords are the same, and I also deleted my char names on forums / posts / screens ever since the security breaches became known.
I will go ahead and change the passwords on Guru / Guru2 anyway - I am not worried about the e-mail address, since if it was used in a Spam attack there are ways to take this further and find out the source.

Also, people should not be fooled about 'just getting e-mail addresses' - SPAM is big business, for every 1 million (very small number) SPAM mails sent, even a 0.5-1% uptake is significant, especially if it is a phishing attempt, that is 5000-10000 people more that have been affected and potentially spreading the attack even wider themselves - yes, it is the ripple-effect.

I won't be as harsh as a previous poster about being late with security patches, it can easily get out of control... I know how things can happen and projects get stopped for whatever reason, and again shit does happen... that is true.

I myself (and my team ofc) am responsible for 250+ servers, which is our own and also our clients, and I am personally very diligent to view any security releases and I must assess what needs to be done and IF it needs to be done.
Luckily, we work on a steady release-cycle, and we patch our systems within 12-24 hours of release and the out-of-band (0-day) stuff is done ASAP.

So, I can certainly appreciate what it takes to keep your systems up to date and somehow... I am sure the Guru folks won't be waiting that long again and that they would have put 'something' in place to prevent this from reoccuring.

Thanks again, Guru guys and gals!

Gigashadow

Gigashadow

Jungle Guide

Join Date: Aug 2005

Bellevue, WA

W/

FYI AionSource also had a trojan on it (confirmed by AionSource webmaster in the thread below) that nailed some people. Looks like fansites are under heavy attack these days.

http://www.aionsource.com/forum/aion...appen-you.html

4thVariety

Krytan Explorer

Join Date: Jun 2005

European Union

ADL

E/

Wartower got hacked as well, so it appears that somebody is trying all angles right now.

Tullzinski

Tullzinski

Jungle Guide

Join Date: Mar 2006

Trying to stay out of Ryuk's Death Note

N/R

Not suprising to see the increase in hacking attempts referenced above. Looks like the recent security improvements to NCsoft Master Hub and GW had an impact.

Inde

Site Contributor

Join Date: Dec 2004

Can anyone get me the german translation of wartower's message please?

http://www.wartower.de/news/

And yes, I can google translate too We are debating a line in the google translation though. Thanks!

Painbringer

Painbringer

Furnace Stoker

Join Date: Jun 2006

Minnesota

Black Widows of Death

W/Mo

Just an FYI I got spooked after reading this and went on GW to change my password and I kept getting a code 11 error. It never said I changed anything, but now I can not log in at all. One of the passwords I tired worked for last night but today I am locked out. Not sure if many other people have had the same issue but Now I have no GW at all

Inde

Site Contributor

Join Date: Dec 2004

Painbringer, you'll want to contact Support definitely, but I don't know if this is exactly related to the Guru issues. In your previous post you said you logged into Guild Wars and then couldn't change your password from that point. To log into Guild Wars you need your IGN (which is not stored on Guru). Then you stated that your Guild Wars had stopped responding and needed to force to close it. After that you stated "I can not sign into GW with old password but the intial one I tried that code 11 on me works".

This could be a technical issue or a simple case of mistyping since I haven't seen anyone have the exact problem you've described. But please let us know what support tells you and if you can get that resolved.

glacialphoenix

glacialphoenix

Desert Nomad

Join Date: Jul 2008

Singapore

Royal Order of Flying Lemmings [ROFL]

Mo/

Quote:
Originally Posted by Painbringer
One of the passwords I tired worked for last night but today I am locked out Have you tried logging in using the new password?

Painbringer

Painbringer

Furnace Stoker

Join Date: Jun 2006

Minnesota

Black Widows of Death

W/Mo

This is exactly what happened

I logged in to my GW account and got to character selection screen then I went to change password option. The screen came up (enter old password enter new password re enter new password). I did this and added a new password nothing happened and I got a-code 11 error. I backed out and re tried the new password again nothing happened-code 11. I then thought maybe I need to add some numbers so I tried a new password with numbers added and nothing happened again – code 11. I tired it a couple more times and I got fed up. I selected the Ncsoft link address on the code 11 message and went to there site. Could not log on (not totally sure what to log on with since I do not remember ever going here with my account.) After a couple attempts I gave up. Went back to the GW window it was locked on me. Closed it with task manager and reopened it tried to log on and my old password did not work. I then tried the first new password I tried that code 11 on me and it worked. I played last night then shut it down. I had a bad feeling something was screwy so I tried to log on again this morning and none of the passwords I used work. Old / new / new with numbers… nothing works.

Keep in mind I am only 5 % worried about a hacker getting me. I really think it was a mess up on GW site maybe too many people trying at once to change passwords. Remember the issues with the free storage pane-too much flow at once.

I sent a ticket this morning and will let you know, but I bet I miss the Redo winterfest

I should have sticked to my "If it aint broke Don’t Touch IT" motto when it comes to electronical things

Earth

Earth

Always Outnumbered

Join Date: Jul 2006

Quote:
Originally Posted by Inde View Post
Can anyone get me the german translation of wartower's message please?

http://www.wartower.de/news/

And yes, I can google translate too We are debating a line in the google translation though. Thanks!
Rough translation:

Currently a lot of game fansites are under attack from outside parties. After Guru was attacked, Wartower was also targeted.

We have closed the security hole. The attackers have managed to steal encrypted passwords of Wartower-Forum accounts. We suggest that you change your forum passwords immediately. It may be possible for the attackers to log on to your forum account under certain circumstances and abuse it. This also includes accounts on other websites, if you use the same account name and password on multiple sites.

Last part is just an explanation about how to change your password.


Hope this helps.

I guess you were debating the "It may be possible for the attackers to log on to your forum account under certain circumstances" line? I'm not too sure what they mean with that to be honest, so don't entirely trust my translation . What they probably mean is that the attackers are able to log in to the forum accounts.



EDIT: German isn't my first language, so I'm happy to see our translations are more or less the same Guess all those lessons are good for something

Wheel of time

Ascalonian Squire

Join Date: Sep 2009

I can give it a try (german is my first language so the english may not be perfect):

At the moment fansites are obviously under heavy attacks from the outside. After the attack of GWG the wartower has been targeted as well.

We closed the security gap. But the attackers managed to steal encyphered passwords of the wartower forum accounts. We therefore ask you to change your forumpasswords. The attackers may under these circumstances be able to log in with your accounts and abuse them. This includes accounts somewhere else where you used the same data.




My opinion: Im truly worried about all that bad attention gw forums seem to get recently and i sincerely hope for the consequences to be as few as possible.


E: hmmm i should translate faster i guess^^

still we seem to agree more or less on the translation

Inde

Site Contributor

Join Date: Dec 2004

Thank you both so much!

frinoh

Ascalonian Squire

Join Date: Feb 2006

About the wartower.de incident:

I'm german and I skimmed through the thread on their forums, the admin mentioned that their passwords are md5/salt protected, so their message that passwords were stolen might be a bit over the top. It seems the attackers merely aquired the encrypted password file.

I'd still recomend changing your password of course.