
Originally Posted by
Okuza
Just heard a story from a person in our linkshell that claimed to have been hacked. Had a happy ending. She was gone from shell for about 3 days. She was kinda sporadic for online time, so we didn't really wonder too much. Here's what she said happend:
She was AFK for the evening in Promvyon-Mea.
When she came back in morning, she was logged out with no content-IDs.
Contacted tech-support, got redirected. Contacted another SE rep (not quit sure who).
After "a big hassle" got her account restored.
Seems a friend sent her a tell shortly after getting hacked, got a really weird response, called a GM. The GM froze the account right away. Not sure what the "big hassle" involved, but it was probably proof of identity stuff and being given a bit of a run-around while they figured out what to do. Account had all it's gear intact. "Looked like whoever was on the way to Windy when frozen", which makes sense for someone without warp exiting from Mea.
I asked a bunch of questions to try to narrow things down a bit for the potential cause:
She was using a wi-fi connection. 'Dunno if it was configured properly or not, but she says it was.
She was online when compromised. So far, all the reports these days are of people being online when attacked.
She does NOT use a firewall. Her connection and comp are up 24x7.
She has used the Linkshell Community, but not recently (not in past 3 months or so).
My hunch here is that it's either a man-in-the-middle attack using the wifi connection -- PW sniff or packet injection -- or it's subversion of the OS via one of the many holes open on non-firewalled windows systems.