Announcement

Collapse
No announcement yet.

New RMT Attacks, take caution

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • New RMT Attacks, take caution

    One of my hnmls officers found it on BG and post it on our forum, just relaying here.
    New RMT attacks - Order of the Blue Gartr
    Originally posted by Tubbers on BG
    Two of my LS members and good friends had their accounts stolen by RMT yesterday at around 5:45 PM EST. However these were not ordinary attacks, they were different. Smarter, faster, and at this point they don't seem to be from keyloggers (though that is still the most likely case).

    In about 10 seconds from "Disconnected, this PlayOnline ID was logged in from another Terminal", both of their passwords had been changed. That is impossibly fast for a human to do, so they are using a program to change passwords immediately now.

    Both of them managed to call GMs from other characters (or have friends do so), and get their accounts locked, but because it was Sunday and they couldn't phone in, the process took too long, somewhere around 45 minutes, so the damage was definitely already dealt.

    Today both of them called SE and presented their info only to be told, "The name on the account doesn't match, sorry. There is no way to change the name on the account so it must not be you."

    Neither of their accounts were bought, they are the original owners and have been playing for years, their names were definitely on the account prior to the hackings. This means the RMT have found a way to change the names on accounts, and now SE is unwilling to return the accounts to them.

    Other peculiarities were that one of them received a PoL message immediately prior to the attack, upon looking at it, it was empty. Completely empty, no from, no message at all, just completely blank. I'm asking the other if it was the same case, but if it is, this spells for an extremely deadly new form of attack. If that was how they were hacked, there is a vulnerability in PoL messages to buffer overflow attacks (maybe). I'm not the greatest with PoL.exe, but considering Taj's malformed character exploit which DC'd players, I'm inclined to believe it is possible.

    If you get a PoL message, I would urge you not to open it until this is resolved as either impossible or fixed.

    I'll keep you updated with whatever I find out.

    ------

    Finished reading whats already up. Seems somewhat fishy, but best to take to the side of caution nonetheless.
    Adventures of Akashimo Hakubi & Nekoai Nanashi



  • #2
    Re: New RMT Attacks, take caution

    Exactly ten seconds?

    Comment


    • #3
      Re: New RMT Attacks, take caution

      No, that sounds like a pretty ordinary keylogger attack.

      "received a PoL message immediately prior to the attack, ... If that was how they were hacked, ... considering Taj's malformed character exploit which DC'd players, I'm inclined to believe it is possible."
      I'm not.
      I use a Mac because I'm just better than you are.

      HTTP Error 418 - I'm A Teapot - The resulting entity body MAY be short and stout.

      loose

      Comment


      • #4
        Re: New RMT Attacks, take caution

        What the hell is up with this whole "Something bad happened, you should be careful" mentality people have, anyway?

        "Some celebrity has lung cancer. You should stop smoking.", even though everyone already knows smoking causes cancer. "Some woman was raped last night. You should keep your eyes open.", even though everyone already knows you're at risk anywhere. "There's some new virus going around. You should use anti-virus software and be careful where you go online", even though everyone already knows that you need to either use secure software or not connect to the internet.

        Comment


        • #5
          Re: New RMT Attacks, take caution

          [ame=http://en.wikipedia.org/wiki/Culture_of_fear]Culture of fear - Wikipedia, the free encyclopedia[/ame]

          Also with things like this people like to try and make a name for themselves by being 'first' to notice, mention, diagnose etc the problem.
          I use a Mac because I'm just better than you are.

          HTTP Error 418 - I'm A Teapot - The resulting entity body MAY be short and stout.

          loose

          Comment


          • #6
            Re: New RMT Attacks, take caution

            Originally posted by Feba View Post
            "Some woman was raped last night. You should keep your eyes open for suspicious people."
            Otherwise it just sounded like this:

            O_O
            {New Sig in the works}
            -----------------------
            "There will come a day when the world will realize that Superman can no longer create miracles. If my name was Superman, that day would be today." 4/29/2009 - Me

            Originally posted by Aksannyi
            "Hello! 100+3 Leathercrafting, your materials, 5k! Mention code LTH74 for a special discount!" - they'd get blisted by everyone they sent that to.
            Originally posted by Solymir
            What do you have against Ants? Is iVirus some new Apple product?

            Comment


            • #7
              Re: New RMT Attacks, take caution

              I don't buy that it was dished out through a POL message. But, once we thought this shit was (mostly) over, and here it goes again. /sigh.
              sigpic
              ~Aksannyi~~Hades~~75WHM~75RDM~75BLM~75SMN~73WAR~67SCH~47BRD~
              ~Mama Gamer~~Quitted July 2009/Bannt October 2009~~Excellence LS~
              ~I has a blog~~http://aksannyi.livejournal.com/~
              ~~ ~~ ~~ ~~ ~~ ~~ ~~ ~~ ~~




              Comment


              • #8
                Re: New RMT Attacks, take caution

                Originally posted by Aksannyi View Post
                I don't buy that it was dished out through a POL message. But, once we thought this shit was (mostly) over, and here it goes again. /sigh.
                So true. They don't have anything better to do but to hack our accounts. I wonder what the world would be like without RMT.....




                Anyways, I never want to have my account stolen again. The less I have to deal with SE/Playonline the better.
                Last edited by Durahansolo; 03-30-2009, 03:44 PM.
                {New Sig in the works}
                -----------------------
                "There will come a day when the world will realize that Superman can no longer create miracles. If my name was Superman, that day would be today." 4/29/2009 - Me

                Originally posted by Aksannyi
                "Hello! 100+3 Leathercrafting, your materials, 5k! Mention code LTH74 for a special discount!" - they'd get blisted by everyone they sent that to.
                Originally posted by Solymir
                What do you have against Ants? Is iVirus some new Apple product?

                Comment


                • #9
                  Re: New RMT Attacks, take caution

                  If there weren't any RMT we'd be playing My Little Unicorn: Master Chief edition?
                  sigpic

                  Comment


                  • #10
                    Re: New RMT Attacks, take caution

                    There's a similar "warning" going around at the moment that ffxiclopedia has been "infected with a virus that steals pol passwords". I take both warnings with a pinch of salt, some people just like starting a scare fest.



                    Comment


                    • #11
                      Re: New RMT Attacks, take caution

                      Originally posted by Feba View Post
                      What the hell is up with this whole "Something bad happened, you should be careful" mentality people have, anyway?
                      9

















                      Wait for it.













                      11
                      I RNG 75 I WAR 37 I NIN 38 I SAM 50 I Woodworking 92+2

                      PSN: Caspian

                      Comment


                      • #12
                        Re: New RMT Attacks, take caution

                        Originally posted by fallenintoshadows View Post
                        There's a similar "warning" going around at the moment that ffxiclopedia has been "infected with a virus that steals pol passwords". I take both warnings with a pinch of salt, some people just like starting a scare fest.
                        Now this one is possible (though technically it wouldn't be a virus) and it wouldn't be the first time they were compromised.
                        I use a Mac because I'm just better than you are.

                        HTTP Error 418 - I'm A Teapot - The resulting entity body MAY be short and stout.

                        loose

                        Comment


                        • #13
                          Re: New RMT Attacks, take caution

                          Originally posted by Mhurron View Post
                          Now this one is possible (though technically it wouldn't be a virus) and it wouldn't be the first time they were compromised.
                          I know it's possible but its also possible someone just thought they'd say it was. It's times like this I wonder why google flags ffxionline as a threat for every little thing and ffxiclopedia and other websites which have been compromised in the past go unnoticed.



                          Comment


                          • #14
                            Re: New RMT Attacks, take caution

                            I have a question: Is that new 'software keyboard' actually any better then just typing it in?
                            Originally posted by Ellipses
                            Really, it's just like pretty much every question about this game that begins with "Why." The answer is "Because."
                            Originally posted by MCLV
                            A subjob is like sex, you shouldn't have it untill your 18 but if you don't have it after 21 everyone laughs at you.
                            More Sig:

                            Comment


                            • #15
                              Re: New RMT Attacks, take caution

                              Originally posted by Neomage View Post
                              I have a question: Is that new 'software keyboard' actually any better then just typing it in?
                              If you have a keylogger, yes it would be, but that's like saying you're much safer with a seatbelt on when you're driving drunk.
                              I use a Mac because I'm just better than you are.

                              HTTP Error 418 - I'm A Teapot - The resulting entity body MAY be short and stout.

                              loose

                              Comment

                              Working...
                              X