Guild Wars Guru Security Notice

4 pages Page 4
JR
JR
Re:tired
#61
Quote: Originally Posted by Gill Halendt View Post How about passwords?

Is there any chance they could match e-mails and passwords if passwords are succesfully decrypted?

Do you think they have got to GWGuruAuction as well?

*sigh* I have my IGN in that profile. They can match them up, yes. This is why we are advising people to change their passwords as soon as possible.

The Auction page was also compromised, though I find it very unlikely that they managed to get your character name from there. Inde might be able to confirm that either way.

[EDIT: Character names are in the AH user table, which was accessed by the hackers.]

Quote:
Originally Posted by Raven Wing View Post
+1 thank you for informing us.

I wonder if we will see a lot of old guru users like myself having their account used for RMT etc spam on this forum and then get banned by guru? I hope not Change your password and you should be fine.
D
DutchSmurf
Krytan Explorer
#63
Thanks for letting us now this fast. Not that I'm worried myself. I only use the password here for unimportant things. So in the worst case they can now access many of my forum accounts.
Auron of Neon
Auron of Neon
cool story bro
#64
Thanks JR! I live in constant fear of my Guild Wars account being compromised, but I'm given a modicum of peace knowing that the Guru Mods are on the case and working diligently.

I'm not quite sure what I'd do if I woke up one day and was unable to play my favorite game.
Yol
Yol
Wilds Pathfinder
#65
Thanks for letting us know so quickly, and being open about it.

I wanted to raise a point for the members on this forum who are using the same e-mail address and password as their GW log-in details....have you posted anything in the "show off your titles in progress" thread, or maybe offered help in the PUGS forums? Not a good idea to post screenshots of your hero panel with your character name in it, and don't put your IGN in the post if you're offering to help someone asking for help with vanquishing Elona, for example. It may sound like a bit of stretch, but basically, the hackers would now have your e-mail address, password, and a character name.

Inde said earlier that character names were removed from member profiles (which was a perfectly acceptable and understandable move), but that doesn't mean that character names aren't available on the forum to anyone with a few minutes and a bit of patience to do the searches.
MithranArkanere
MithranArkanere
Underworld Spelunker
#66
I use the trash email here, so there is no harm done, all they will get is my spam email.
Just.nl
Just.nl
Krytan Explorer
#68
Quote: Originally Posted by Rampage View Post Shit happens. I'm very glad to see that you aren't pulling an NCSoft and just denying everything. Thanks for informing the community, good job guys. /Agree.

Im glad to read this:
Quote:
We've spent the 24 last hours tirelessly investigating what happened, patching up the exploit, and further strengthening security. Hopefully you can all sort it soon out & it will be back as normal.
Good job & Thanks!
Bobby2
Bobby2
Furnace Stoker
#69
Props. Not worried, but you guys rock.
Sha Noran
Sha Noran
Desert Nomad
#71
Wow.

Guild Wars and all its affiliates must just be easy prey, considering the sheer volume of hacking attacks I've seen the game and its biggest site's experience. I had a white hat hacker friend (and some black hats frankly) in-game for quite some time and they always had a chuckle over the general ease with which the whole system could be pwned, but as things have panned out its clear they were quite right. Sad.
C
Curin Derwin
Frost Gate Guardian
#74
What about date of birth? Was that accessed? Can we choose to delete it and remove it ENTIRELY (and not just "hide it from public", please? It's used as a security measure for GW and other services.

Also, is there a way to view all posts that you account has posted on this website?

Thanks,
Destructor
JR
JR
Re:tired
#75
Quote: Originally Posted by Destructor View Post What about date of birth? Was that accessed? Can we choose to delete it and remove it ENTIRELY (and not just "hide it from public", please? It's used as a security measure for GW and other services. We are required by COPPA to keep dates of birth.

[EDIT: Birthdays, as has been mentioned earlier in the thread, were indeed accessed.]

Quote:
Originally Posted by Destructor View Post
Also, is there a way to view all posts that you account has posted on this website? Go to your profile page, and you will find that option under statistics.
I
Inde
Site Contributor
#77
Birth dates were indeed accessed. We answered that here as well for reference:

http://www.guildwarsguru.com/forum/g...50#post5028750

And just to let everyone know, birth dates are used for recovery of your Guild Wars/NCSoft account and password along with the following information:

NCsoft master account name: ENTER ACCOUNT NAME HERE
First and last name: ENTER FIRST AND LAST NAME HERE
Physical Address: ENTER POSTAL MAILING ADDRESS (not e-mail address) HERE
Date of birth: ENTER DATE OF BIRTH HERE
Serial codes/access keys: ENTER CODES/KEYS HERE
Unique Account ID(s): ENTER UNIQUE ACCOUNT ID(s) HERE

http://help.ncsoft.com/cgi-bin/ncsof...i=&p_topview=1
http://help.ncsoft.com/cgi-bin/ncsof...i=&p_topview=1
http://help.ncsoft.com/cgi-bin/ncsof...i=&p_topview=1

So a birth date alone is not going to (or shouldn't be able to) recover a Guild Wars or NCSoft account without other identifying information that we do not collect.
Braxton619
Braxton619
Desert Nomad
#78
Thanks for letting me know. I changed all my passwords associated to my email and Guild Wars accounts.
Lord Dagon
Lord Dagon
Desert Nomad
#79
great job guys top notch job. NCSoft could learn a thing or two from you.
novawhiz
novawhiz
Desert Nomad
#80
wait... people still wanna steal gw accounts??


o.0