How do people steal accounts these days?

Anonymous IXl

Anonymous IXl

Lion's Arch Merchant

Join Date: Nov 2009

ON, Canada

Super Galactic Mystery Solvers [Clue]

Mo/Me

This is not another thread with a kid crying cus he got his account hacked. Yes i did get my account hacked and all of my money stolen but i have no clue how they got into my account. I have a password that would be next to impossible to guess and i dont go on any other GW sites other than Wiki and Guru. Nobody knows my password so i have no clue how else anyone would get access to my account.

Zebideedee

Zebideedee

Jungle Guide

Join Date: Sep 2007

55?? 57' 0" N / 3?? 12' 0" W

N/Me

1. I'm scared of Clowns

2. I'm scared after what you said

I'll be honest lately I've been putting my money into titles, if theres nothing to steal then hackers will prolly leave you alone. Sad I think like that but hey!

Anonymous IXl

Anonymous IXl

Lion's Arch Merchant

Join Date: Nov 2009

ON, Canada

Super Galactic Mystery Solvers [Clue]

Mo/Me

Ya... It stinks cus before it happened i was going to spend over 300e on Zkeys to use on chest (I didnt and that was most of my cash) They didnt take my obby edge for some reason... Lol And all my obby sets were still there.

Bob Slydell

Forge Runner

Join Date: Jan 2007

The amount of people getting hacked seemed to have dropped a LOT ever since the character name question was introduced.

The only person who could have hacked you, obviously knew one your character's names.

Did you ever have same email and password assigned to any Guild Wars forums (or Guru, for that matter?) and not have changed it since? Not trying to insult your intelligence, but trying to narrow it down a bit myself... I mean...this person also HAD to know one of your character names.

Anonymous IXl

Anonymous IXl

Lion's Arch Merchant

Join Date: Nov 2009

ON, Canada

Super Galactic Mystery Solvers [Clue]

Mo/Me

I have a randomized password that I copy and paste every time I log in so it couldn't have been from another website because i didn't even have it memorized. The only way i could think of would be if someone scouted me out on guru or it was someone i know. I am kind of suspicious of a guildy of mine but i have no way i could ever prove it... Another reason i think it was someone i know was because i got my obby edge as a drop and said i was going to keep it cus it was kinda special. They didnt take that. As well they didn't delete ANY armour. All my sups vigs are there. So i dont think that they were doing this as gold selling. Also it was hacked soon after i logged off for the night because in the guild roster it said i had been offline for maybe an hour difference to when i actually logged off. So there are many things that make me think it was someone i knew.

Braxton619

Braxton619

Desert Nomad

Join Date: Jul 2008

A/W

It's probably someone who you know that hacked you. Hackers that used brute force can't do it anymore without knowing the account's character names. There has been a TON less hackers now.

i farm baddies

Lion's Arch Merchant

Join Date: Apr 2009

the only way to get "hacked" is if you let the person do it, its your fault and only yours. not just you, everybody that it happens.

Dre

Krytan Explorer

Join Date: Nov 2007

Belgium

Dutch Doom Brigade

W/

Quote:
Originally Posted by Anonymous IXl View Post
I have a randomized password that I copy and paste every time I log in
Stop right there,...

That password is saved on a file on your PC right?

If there's a virus/spyware on your PC and GW remembers your login + a char name, then that's probably how your account has been hacked

Kamatsu

Kamatsu

Moderator

Join Date: May 2005

Australia

Quote:
Originally Posted by Dre View Post
Stop right there,...

That password is saved on a file on your PC right?

If there's a virus/spyware on your PC and GW remembers your login + a char name, then that's probably how your account has been hacked
Possibly, although the file could be encrypted - so without the password/key they could steal the file, but be unable to open it.

There are programs around that can be used to store passwords, key bits of info, etc in an encrypted file that you need a password to open... make the master-password strong enough and 1 you can remember but is not easy to guess... and the stuff should be safe (as long as you trust the encryption used.. and your master-password)

Bill Clinton

Krytan Explorer

Join Date: Mar 2009

Lets not rule out the possibility here that it was someone watching you in real life while you logged in.

Got any mates who play guild wars?

EDIT:
Also, people dont hack eachothers accounts just to piss each other off. Whoever it was didnt delete your armor and stuff because they just want the raw cash.
Hell I bet a good portion of the hacking community dont even know what an obsidian edge is worth, they just take ectos/keys to sell for IRL cash.

Riot Narita

Desert Nomad

Join Date: Apr 2007

Quote:
Originally Posted by i farm baddies View Post
the only way to get "hacked" is if you let the person do it, its your fault and only yours. not just you, everybody that it happens.
The recent NCsoft vulnerabilities proved that this kind of "head in the sand" attitude is foolish, and not always true. It was possible to steal accounts through NCsoft master accounts, no matter how secure or careful the user was, or what measures they took.

They have mostly closed those vulnerabilities (eg. require character name to login, require old GW password before allowing new one to be set using NCsoft master account), but who is to say there aren't more attack methods like that, waiting to be discovered and exploited?

Most people who lose their accounts probably were indeed stupid - inadeqate or non-existent anti-malware, using same email/login/password on multiple sites and forums, posting IGN's in public places, visiting dodgy websites, downloading dodgy software, sharing accounts, buying gold, falling for phishing, scams etc etc.

However, anyone who thinks a lost account is and always will be the user's own fault... is equally stupid. As proved by the NCsoft master account "hacks".

Elephantaliste

Krytan Explorer

Join Date: Nov 2008

adblockplus.or

Quote:
Originally Posted by Dre View Post
Stop right there,...

That password is saved on a file on your PC right?

If there's a virus/spyware on your PC and GW remembers your login + a char name, then that's probably how your account has been hacked
getting hacked because one's own computer is compromised is the worst and best scenario.
Worst case because, indeed, the best password won't help you, but in that case saving it in a file does not make you more or less safe. (Stop false security and let people save their passwords on their home PC...)
Best case because, it is something you can get control on, contrary to fansites.

@OP ; you didn't mention your ncsoft account
did you share same password with it ?

(Now it is no more a problem if your ncsoft account gets compromised, since you characters names aren't mentioned on it...)

jonnieboi05

jonnieboi05

Forge Runner

Join Date: Mar 2006

Mableton, Georgia

Guild Ancestors Reunited [?????????]

Probably from a "friend" or someone who knows you. Submit a ticket to Support if you haven't already. They will be able to check the iP logs and cross check to see where else that iP has been used and they will give him/her his deserving punishment.

gremlin

Furnace Stoker

Join Date: Oct 2006

GWAR

Me/Mo

If there is honestly no way for anyone to know your details, computer never used by anyone else never logged on using another computer friend enemy at work or cybercafe etc.

If your password is really a random sequence not your name etc then I guess we have to believe one of two things.

Either the servers are not safe and hackers are able to get the account details of players or they choose targets based on observation.

I really don't think hackers spend time and trouble hacking random accounts to see what they will get.

Anonymous IXl

Anonymous IXl

Lion's Arch Merchant

Join Date: Nov 2009

ON, Canada

Super Galactic Mystery Solvers [Clue]

Mo/Me

My PW is not used for any other sites but yes it is saved to my computer so that is the only way i could think of.

Braxton619

Braxton619

Desert Nomad

Join Date: Jul 2008

A/W

Quote:
Originally Posted by Anonymous IXl View Post
My PW is not used for any other sites but yes it is saved to my computer so that is the only way i could think of.
That's the problem. Some malicious software can actually run your PC through a remote connection. When they are running your PC, they can view all your files and install things.

Kamatsu

Kamatsu

Moderator

Join Date: May 2005

Australia

Anonymous IXl - is the password stored on a plain text file? Because then yes, that could be how they got your password

If your going to store passwords and such on a file on your comp - always use an encrypted file, or a program that auto-encrypts the file..you'll still need to know a masterpassword.. but at least this way without knowing the masterpassword your info will be safe (good software lets you use an on-screen keyboard to defeat keyloggers)

You might want to scan your pc for viruses, spyware, etc. Try spybot S&D, Malwarebytes Anti-Malware, Ad-Aware.. as well as online scanners (such as Trend Micro, PandaSoft, BitDefender, etc) for viruses and spyware. Online scanners can take awile, but can be useful (some only scan, but at least you'd still know if you had anything that scanner could find).

Emunator

Emunator

Frost Gate Guardian

Join Date: Dec 2006

DVDF

Mo/E

I store passwords on my computer also, i use roboform to do that.
It uses a master password and encrypts the password files.
I also use the on screen keyboard in roboform to input my master password.
After that i copy paste my password into guildwars.

So storing passwords can be safe.

gremlin

Furnace Stoker

Join Date: Oct 2006

GWAR

Me/Mo

Maybe online games need to go the way online banking is moving.

According to friends who use such services there is a device called Pinsafe I understand this creates a number that's used to log into your account but which is only valid for a short time 15 minutes was quoted to me.

If they had that you would be logging in using a different password each time, one that was only valid for that login.

Seems safe to me but would it work with a game and what would be the cost to implement it.