Announcement

Collapse
No announcement yet.

MAJOR Password Logging Scheme

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • MAJOR Password Logging Scheme

    Tonight on Ramuh Server, there must have been hundreds of people who received a /tell from a user named Tenthmoonlight telling them to check out a game-related website. This link was also passed around by secondary users, so just in case if you have a grudge with anyone be careful.

    Going to that link will install a password logging trojan horse into your Playonline software and your account WILL be hacked. Do NOT go to ANY website unless you know the person well.

    If you have been victimized by this incident, you need to call the Information Center IMMEDIATELY to have your password changed and you probably will also need to reinstall & reupdate your entire POL and FFXI installation.

    If anyone has any other information in regards to this (file names, users to watch out for), or news that it has occurred on another server please post it here.
    Host of irc.gamesurge.net #FF14 - TheAfterLife XI & XIV LS
    Olorin (Ramuh): BLM75 BRD78 WHM75 RDM75
    Olorin Branwen (Melmond): Lv12 LNC9 CON7 THM6 MNR6 ALC4


  • #2
    Re: MAJOR Password Logging Scheme

    ...or just use Firefox/Opera/Konqueror/Safari/ANYTHING OTHER THAN IE to prevent these problems.

    Anyways, thanks for the warning, you can never be too careful.
    MisterCookie: Alla refugee since May 2006

    MisterCookie: Writing poor signatures since January 1999

    http://www.songbirdnest.com - OSS Media Player

    Comment


    • #3
      Re: MAJOR Password Logging Scheme

      This happened on Fairy server too, last week. At least a couple people I know of lost their accounts.
      The tells were sent by a couple different names, and the website address ended with .zip.
      There's a thread on KI :link

      edit: I hope its ok to post the link there; I've never posted a link before. -_-;

      second edit: fixed link
      Last edited by Chveya; 05-15-2007, 08:06 AM. Reason: fixed link
      Nibblonian: "You are the last hope of the universe."
      Fry: "So I really am important? How I feel when I'm drunk is correct?"
      Nibblonian: "Yes, except the Dave Matthews Band doesn't rock."'

      Sisqi ~Fairy~WHM 75
      PLD 60 RDM 54 BLM 48

      Comment


      • #4
        Re: MAJOR Password Logging Scheme

        Anyone who is honestly that stupid deserves to have their account hacked. It would teach them a valuable lesson about the internet, and maybe life in general.
        Read my blog.
        ffxibrp.livejournal.com
        Currently: Entry #32, August 31/07.
        Entry 32: Death to Castro

        Comment


        • #5
          Re: MAJOR Password Logging Scheme

          Originally posted by Legal Fish View Post
          Anyone who is honestly that stupid deserves to have their account hacked. It would teach them a valuable lesson about the internet, and maybe life in general.
          I agree. Not that warning people not to fall for this is a bad idea, but seriously, if they don't already know not to visit/download any links that some complete stranger suggests, then they are probably already beyond help.

          Comment


          • #6
            Re: MAJOR Password Logging Scheme

            third'd. If you're stupid enough to be using an insecure browser AND not run a good antivirus, it's your own damn fault.

            Hell, you deserve it for using IE at all. It's just asking for problems.

            And website address ending in .ZIP? Are you fsking joking? That means that, not only did they let their computer download something extremely obviously, but they also apparently opened it. Honestly, not only do I not have pity for them, but if this is as insanely obvious as you're claiming it, I actually find this hilarious. You wouldn't let some random guy on the street mess with your car, why would you let some random guy on the internet mess with your computer?!

            Comment


            • #7
              Re: MAJOR Password Logging Scheme

              I had a guy send me a tell the other night in Al Zhabi, saying he was quitting FFXI and to check out his website <insert obvious virus link here> and i sent a tell back telling him to **** the hell off and he was set to away so i got the auto reply lol.. This was just before beseiged, three of my friends in my party in Al Zhabi also got the same tell.

              pshhh.

              How rude.



              http:// cerberusatemycookies.blogspot.com

              Comment


              • #8
                Re: MAJOR Password Logging Scheme

                Originally posted by Chveya View Post
                This happened on Fairy server too, last week. At least a couple people I know of lost their accounts.
                The tells were sent by a couple different names, and the website address ended with .zip.
                There's a thread on KI here
                edit: I hope its ok to post the link there; I've never posted a link before. -_-;
                It's fine to post a link, though it wasn't posted right so I fixed it for you.

                Reading that thread is a real heads-up. Seems like they caught the guy who was running the scheme too (if it's only one person that is)...
                Host of irc.gamesurge.net #FF14 - TheAfterLife XI & XIV LS
                Olorin (Ramuh): BLM75 BRD78 WHM75 RDM75
                Olorin Branwen (Melmond): Lv12 LNC9 CON7 THM6 MNR6 ALC4

                Comment


                • #9
                  Re: MAJOR Password Logging Scheme

                  Originally posted by Feba View Post
                  And website address ending in .ZIP? Are you fsking joking? That means that, not only did they let their computer download something extremely obviously, but they also apparently opened it.
                  That's the part that gets no sympathy from me. You brought this all upon yourself when you went to an untrusted/unknown URL ending in .ZIP and then proceeded to download and open said file. I hope these people that actually went to these URLs learn something; they won't though. >.>




                  PLD75 DRK60 lots of other levels.
                  ------
                  Shackle their minds when they're bent on the cross
                  When ignorance reigns, life is lost


                  Comment


                  • #10
                    Re: MAJOR Password Logging Scheme

                    Apperently the website ended in .zip.

                    How. In. Gods. Stupid. Name....

                    /wow
                    -Baka Inu!
                    Nejiko - Mithra Current: [ 70 THF / 35 NIN ]
                    Basic Jobs: [ 70 THF / 20 MNK / 11 WHM / 18 BLM / 22WAR / 05 RDM]
                    Advance Jobs: [ 04 BST / 37 NIN / 02 SMN / 05RNG / 07 SAM / 07 PLD / 00 DRK / 31 BRD / 00 DRG]
                    Aht Jobs: [07 COR / 00 BLU / 00 PUP]

                    Comment


                    • #11
                      Re: MAJOR Password Logging Scheme

                      Starving, to me, from studying keyloggers, it seems to be a self extracting zip, meaning, it extracts as soon as it's downloaded no matter what.

                      I don't even think the zip is a zip, I think it's got a hidden extension. I'll look into it when I get home, more updates comming later, but for now, I got class.
                      -Baka Inu!
                      Nejiko - Mithra Current: [ 70 THF / 35 NIN ]
                      Basic Jobs: [ 70 THF / 20 MNK / 11 WHM / 18 BLM / 22WAR / 05 RDM]
                      Advance Jobs: [ 04 BST / 37 NIN / 02 SMN / 05RNG / 07 SAM / 07 PLD / 00 DRK / 31 BRD / 00 DRG]
                      Aht Jobs: [07 COR / 00 BLU / 00 PUP]

                      Comment


                      • #12
                        Re: MAJOR Password Logging Scheme

                        A friend of me got hacked too lately. He never gives his password to anyone, and changes it every month. I don't remember him saying anything about having received a /tell though.

                        These are his 2 characters:
                        *Removed Link*
                        From FFXIAH: Bierzwerg & Icequeen

                        All his items got sold, and his password changed back to what it was before, it all took about 3 days before he could login again, with no equipment and no gil. He called PlayOnline, but after a long phone call, the only result was "We're sorry for the inconvenience but we can't help you."
                        Last edited by Arctic Wolf; 05-15-2007, 05:40 AM. Reason: URL's

                        In wilderness is the preservation of the world.

                        Comment


                        • #13
                          Re: MAJOR Password Logging Scheme

                          Originally posted by StarvingArtist
                          Some people in my LS also got this message. "/sarcasm dl it and open it, because nothing bad ever comes from teh intarweb"
                          Seriously though, at what point does this Trojan actually install/activate?
                          -Just visiting the link? I would imagine you get prompted for a download, unless your browser is set to automatically dl/open .zip files (which would be a bad idea).
                          -If the file is downloaded, is it self installing? Not running a scan at this point is going further into bad internet habits.
                          -Is there an actual program inside the zip that has to be activated by the user? If that's the case, they have stumbled beyond faux pas.
                          Well I suppose that's the trick here.. You don't necessarily have to download the file yourself, nor do you have to unzip it yourself.

                          If the person/people running this scheme have any amount of talent, they probably wrote cookies, ActiveX controls and/or Javascript into the webpage itself that would automate all that action behind the scenes. Even if someone visited the website out of curiosity, and knew enough not to get the file on their own, you would still get compromised and not know until it was too late.
                          Host of irc.gamesurge.net #FF14 - TheAfterLife XI & XIV LS
                          Olorin (Ramuh): BLM75 BRD78 WHM75 RDM75
                          Olorin Branwen (Melmond): Lv12 LNC9 CON7 THM6 MNR6 ALC4

                          Comment


                          • #14
                            Re: MAJOR Password Logging Scheme

                            Except that any well-designed web browser won't allow a website to do that kind of monkeying with your local machine without user approval. There are security restrictions placed on web content running on local machines for exactly that reason.

                            Which sort of brings us back to "don't use IE".
                            Defeated: Maat, Divine Might, Fenrir, Kirin, Cactrot Rapido, Xolotl, Diabolos Prime, Kurrea, 9/10 Dynamis Bosses (missing Tav), Promathia, Proto-Ultima, Proto-Omega, 4 Jailers, Apocalypse Nigh, 6/6 Nyzul Bosses
                            RDM90, PLD90, DRG90, COR90, SCH90, BLU54
                            All Nations Rank 10, ZMs & PMs Complete, AUMs Complete, Captain, Nyzul Floor 100 (5 Weapons, 4 WS), Medal of Altana, WotG Mission 15, 1/3 Addons Complete, 9/9 Abyssea Main Quests, 6/6 Caturae

                            Comment


                            • #15
                              Re: MAJOR Password Logging Scheme

                              Kar, Just because you don't use IE, dosn't automaticly make you safe, There are workarounds in old Firefox (1.5.x) as well which have been found and fixed in 2.0 (which you should upgrade to). Also, a simple setting turned on in Firefox (which can be programed to by a simple click of a button) makes it auto run scripts, <b>WITHOUT USER APPROVIAL</b> because you already have it.

                              Also, this keylogger isn't jsut targeting your POL ID (common misconception), it's infact logging everything you type, including windows, and what not. This is an old scam which can easilly be used to steal your idenity.
                              -Baka Inu!
                              Nejiko - Mithra Current: [ 70 THF / 35 NIN ]
                              Basic Jobs: [ 70 THF / 20 MNK / 11 WHM / 18 BLM / 22WAR / 05 RDM]
                              Advance Jobs: [ 04 BST / 37 NIN / 02 SMN / 05RNG / 07 SAM / 07 PLD / 00 DRK / 31 BRD / 00 DRG]
                              Aht Jobs: [07 COR / 00 BLU / 00 PUP]

                              Comment

                              Working...
                              X