Item Search
     
BG-Wiki Search
Page 4 of 16 FirstFirst ... 2 3 4 5 6 14 ... LastLast
Results 61 to 80 of 304
  1. #61
    23 years old
    Rating: total douchebag

    Join Date
    May 2005
    Posts
    8,371
    BG Level
    8

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by rydiu
    it's not "my" argument... its the argument of every security-minded person who's posting.

    <Ryko> No you're dumb! har har! it's better to store your password in a text file and copy + paste it into POL every time you log in


    <Everyone> Umm.. no?
    By everyone you mean yourself, right? I called you stupid for a very specific reason, I sure as hell didn't drag anyone else into this "har har" exchange. You have yet to respond to the actual point since I debunked your last little spew of bullshit. Do yourself a favor and stuff it if you're going to keep going down this road instead of addressing the fact that multiple accounts have been lost to keyloggers and yet not one has been attributed to remote access. This is ignoring the fact that I, once again, never stated that it was a keylogger in the first place.

  2. #62
    Sea Torques
    Join Date
    Jun 2007
    Posts
    682
    BG Level
    5
    FFXI Server
    Odin

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by Sykes
    Quote Originally Posted by Zero Serenity
    Yes...you do. Whenever you visit a page you download something let it be a simple HTML file or a JPG file. But downloading a virus just by being there? Not happening. Besides, how would it execute without being an ActiveX object? ColdFusion? No. It doesn't work that way.
    Microsoft Internet Explorer JPEG rendering library vulnerable to buffer overflow

    (old, but some people don't patch ... and just a single of many counter-examples)
    If you don't patch you're just asking for trouble, so I'm not going to even bother helping those folks.

    Spira, Bullet 3: Yes, this can be done, but leaves a few problems associated with it, especialy when using a proxy of somesort. Like if I'm at work (Syracuse, NY) I use a proxy in Rochester, NY.

    Sevilla: We use a program at work that not only keylogs, mouselogs, clipboard logs (and other things) but it's like running Fraps on the whole computer, meaning we have recordings of our entire sessions.

  3. #63
    bzs
    bzs is offline
    Melee Summoner
    Join Date
    Jul 2007
    Posts
    38
    BG Level
    1

    Re: Recent Hackings and Steps to Insure Account Safety.

    What is wrong with the saved login/password feature?
    I don't get it
    I have 4 accounts saved on my POL with login and pwd, saves me from typing them again
    of course I have pwd protection, an universal pwd to access all 4 of those accounts
    the universal pwd I have is completely different from the pwds to the accounts

    Only reason I see ppl not wanting to use it is if many dumb ppl put their POL pwd for the layer security that is suppose to be on your PC only
    I seen many ppl do that because they thought you were suppose to input your POL pwd for it only

  4. #64
    New Odin
    Join Date
    Jul 2006
    Posts
    8,659
    BG Level
    8
    FFXIV Character
    Sparthia Abysseant
    FFXIV Server
    Excalibur
    FFXI Server
    Lakshmi

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by Spira
    I would think the only way that you can protect yourself is if Square Enix does something about this..
    This is the winner of the thread.

    Protecting your computer from threats is great and all, and everyone should be versed on at least basic defense against web threats and the sort but the fact of the matter is that what SE could do is far more than what we could do security wise in protecting an account. (At least if you dont wanna be put at risk for other ways of being hacked.)

    Anyone who plays FFXI knows that having no resource site is like playing with blinders on and having half the playerbase worry they are gonna be e-hijacked because of RMT activities is why i will continue to blame this on SE. Getting your account compromised is probably the individuals fault but SE not doing anything and letting RMT live is the bigger fault at hand.

    Take SEs advice, dont use anything. Dont even open a Web Browser when you play this game. Buy a seperate computer just to play the game.

  5. #65
    Cerberus
    Join Date
    Aug 2006
    Posts
    486
    BG Level
    4

    Re: Recent Hackings and Steps to Insure Account Safety.

    ryko:

    you say people don't want to take the trouble to use RDP when hacking someone's account....but the account owners should use a copy-paste method to put their password into POL.

    your justification for this is that if POL stores the password, they are more likely to get hacked since the password is stored in POL.

    if someone is too lazy to use RDP and only uses a keylogger (most of which scan clipboard and mouse-clicks) are they going to go through the trouble of cracking the POL decoding and decryption scheme for passwords?

    can someone other than me explain what is wrong with this picture, plz

  6. #66
    23 years old
    Rating: total douchebag

    Join Date
    May 2005
    Posts
    8,371
    BG Level
    8

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by ronin sparthos
    Quote Originally Posted by Spira
    I would think the only way that you can protect yourself is if Square Enix does something about this..
    This is the winner of the thread.
    It's not SE's fault someone with access to your girlfriend's account was a moron and somewhere they shouldn't have been.

    Quote Originally Posted by rydiu
    utter crap
    Is it hard to understand that a person's motivation to not be lazy when it comes to their own personal single set of information is obviously much higher than someone else's attempting to get into thousands of peoples' information and lucking out with a handful? Do I have to explain that? What are you, twelve?

  7. #67
    E. Body
    Join Date
    Mar 2006
    Posts
    2,333
    BG Level
    7

    Re: Recent Hackings and Steps to Insure Account Safety.

    a viable strategy for an account theft application would be to look for the launching of POL if it finds no saved password file. upon that trigger, it can either log keystrokes or read clipboard information or take screenshots, or even change your password from your own machine.

    in addition, your password probably stored in memory in plaintext somewhere when logging on. it's not uncommon for applications to obfuscate the password with dots, but store the actual password in memory without any form of protection. revelations is an app probably edging on 8 years old that still works on many windows applications to this day to pull the actual contents of an obfuscated text box object from memory. i doubt that this application would work for POL since it's not exactly a standard windows dialog, but the lesson is still valid.

    you can take steps to make it harder for an automated password stealing tool to get your account details, but the only sure fire way to prevent yourself from getting hijacked is to not get infected in the first place. i'm not saying i don't condone the steps above as viable strategies to mask your password from a trojan, but these solutions are really just "security through obscurity" which is never a good choice for your only defense. in days i'm sure the RMT will make actions to counter our detection schemes. the names of their executables can be changed easily. they could be generated at each install. they could infect POL.EXE directly, thus even circumventing a software firewall. an off the shelf rootkit could have this malware integrated into it, not only stealing your POL info, but allowing them to sell off your PC to a botnet operator. this is the opening volley. it's caught us off guard and done very significant damage due to the surprise nature of their attack, but make no mistake, this is only the first of many attacks of increasing severity. take precautions with your password, but don't fool yourself into thinking it's enough that you can be caviler in your behavior. virus authors have been defeating defenses for over 30 years, and the sophistication of this attack is primitive compared.

    while SE's response is by almost any measure, horrifically inadequate, we can't just sit on our laurels and wait for our benevolent providers to defend us. while surely SE shares in the blame to a significant degree, that's hardly consolation when an account is stolen. the most important thing to take away from this thread is how we, as users, can protect ourselves. don't bury your head in the sand and hope till SE solves this problem, take a proactive stance and ensure your computer is properly protected with the latest patches, antivirus software, firewalls, and common sense.

  8. #68
    E. Body
    Join Date
    Jul 2006
    Posts
    2,184
    BG Level
    7

    Re: How to protect your computer against BAD THINGS.

    Quote Originally Posted by Zero Serenity
    DO NOT EVER USE A REGISTRY CLEANER!!!
    I've used registry cleaners for years... never had any problems and they help your computer to run best..
    Ccleaner is fine, also been using RegistryBooster with very good results.
    Reg cleaners get all of the leftover files from uninstallations and misc. problems in the registry. Certain regcleaners can cause problems but have yet to experience a problem with ccleaner or registrybooster.

  9. #69
    Cerberus
    Join Date
    Aug 2006
    Posts
    486
    BG Level
    4

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by Ryko
    Is it hard to understand that a person's motivation to not be lazy when it comes to their own personal single set of information is obviously much higher than someone else's attempting to get into thousands of peoples' information and lucking out with a handful? Do I have to explain that? What are you, twelve?

    And with this, you fail at the internet.

    I must be leaving now to attend my distributed/parallel computing final exam now. If ryko is still posting this crap when I get back I'm gonna kill everyone in IRC!

  10. #70
    23 years old
    Rating: total douchebag

    Join Date
    May 2005
    Posts
    8,371
    BG Level
    8

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by rydiu
    Quote Originally Posted by Ryko
    Is it hard to understand that a person's motivation to not be lazy when it comes to their own personal single set of information is obviously much higher than someone else's attempting to get into thousands of peoples' information and lucking out with a handful? Do I have to explain that? What are you, twelve?

    And with this, you fail at the internet.
    This coming from the guy who didn't even know you could right click paste into POL. Next time try a little harder to seem smarter than you actually are, either that or save your effort and don't say anything in the first place.

  11. #71
    New Odin
    Join Date
    Jul 2006
    Posts
    8,659
    BG Level
    8
    FFXIV Character
    Sparthia Abysseant
    FFXIV Server
    Excalibur
    FFXI Server
    Lakshmi

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by Ryko
    It's not SE's fault someone with access to your girlfriend's account was a moron and somewhere they shouldn't have been.
    So you think its perfectly fine that we have to fend for ourselves when its SE escalating the issue between them and the RMT? Are we not the customers that pay to play?

    Logic. Where.

  12. #72
    Sea Torques
    Join Date
    Jun 2007
    Posts
    682
    BG Level
    5
    FFXI Server
    Odin

    Re: How to protect your computer against BAD THINGS.

    Quote Originally Posted by Seditedi
    Quote Originally Posted by Zero Serenity
    DO NOT EVER USE A REGISTRY CLEANER!!!
    I've used registry cleaners for years... never had any problems and they help your computer to run best..
    Ccleaner is fine, also been using RegistryBooster with very good results.
    Reg cleaners get all of the leftover files from uninstallations and misc. problems in the registry. Certain regcleaners can cause problems but have yet to experience a problem with ccleaner or registrybooster.
    I just spoke from a more general populice. I usualy have more problems with them than they do good. Like I said before, the registry isn't much datasize to begin with, so having it cleaned is a placebo effect.

  13. #73
    23 years old
    Rating: total douchebag

    Join Date
    May 2005
    Posts
    8,371
    BG Level
    8

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by ronin sparthos
    Quote Originally Posted by Ryko
    It's not SE's fault someone with access to your girlfriend's account was a moron and somewhere they shouldn't have been.
    So you think its perfectly fine that we have to fend for ourselves when its SE escalating the issue between them and the RMT? Are we not the customers that pay to play?

    Logic. Where.
    Jesus christ you people today.

    For one: SE is escalating the issue between them and RMT because we asked them to. Don't sit there, bitch, and cry foul that after years of complaining about RMT having server balls in a vice grip of monopolization that they actually did something about it. The players begged for RMT bannings, they got them.

    Secondly: It doesn't have to be RMT stealing your account for what I said originally to be the case. It is not SE's fault someone with access to your girlfriend's account was on a website they shouldn't have been on and picked something up. SE warns your asses not to go to those third party sites left and right, how the fuck is it their fault when you don't listen?

  14. #74
    E. Body
    Join Date
    Jul 2006
    Posts
    2,184
    BG Level
    7

    Re: Recent Hackings and Steps to Insure Account Safety.

    Stop trying to use an advanced vocabulary to act smart Ryd lol.
    In all honesty, accounts getting hacked are those of people that are not even educated properly to maintain and secure a windows based computer. I have my password saved into POL from day 1 since I started playing and guess how many times I've been hacked. A whopping 0 times.
    I maintain my computer with a virus scan, firewall and 2 scans for spyware as well as countless other maintenance tools. As long as you aren't retarded and open up random email attachments from people you don't even know minimal maintenance will keep your computer running well and free from hackers... its not rocket science.

  15. #75
    Final Fantasy XI Music Devotee

    Join Date
    Dec 2005
    Posts
    723
    BG Level
    5
    FFXIV Character
    Vianne Nys
    FFXIV Server
    Excalibur
    FFXI Server
    Quetzalcoatl

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by Zero Serenity
    If you don't patch you're just asking for trouble, so I'm not going to even bother helping those folks.
    Whose fault is it that a product isn't safe upon release?

  16. #76
    Ridill
    Join Date
    Oct 2005
    Posts
    10,210
    BG Level
    9
    FFXI Server
    Asura

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by ronin sparthos
    Quote Originally Posted by Ryko
    It's not SE's fault someone with access to your girlfriend's account was a moron and somewhere they shouldn't have been.
    So you think its perfectly fine that we have to fend for ourselves when its SE escalating the issue between them and the RMT? Are we not the customers that pay to play?

    Logic. Where.
    What's SE's fight with RMTs have to do with responsibility for hackings? Even if it were the very RMT they're fighting that's hacking us? You should be glad SE is trying so hard to remove them.

    I bet you're the kind of person who thinks 911 wasn't the terrorists' fault, but our own because of our foreign policy.

  17. #77
    Relic Horn
    Join Date
    Oct 2005
    Posts
    3,132
    BG Level
    7
    FFXI Server
    Unicorn
    WoW Realm
    Shattered Hand

    Re: Recent Hackings and Steps to Insure Account Safety.

    The keylogger I ran into way back when Totien's account got stolen watched the clipboard, took screenshots to get POLIDs and snagged incoming instant messages.

  18. #78
    E. Body
    Join Date
    Jul 2006
    Posts
    2,184
    BG Level
    7

    Re: How to protect your computer against BAD THINGS.

    [quote=Zero Serenity]
    Quote Originally Posted by Seditedi
    Quote Originally Posted by "Zero Serenity":3knnbpi5
    DO NOT EVER USE A REGISTRY CLEANER!!!
    I've used registry cleaners for years... never had any problems and they help your computer to run best..
    Ccleaner is fine, also been using RegistryBooster with very good results.
    Reg cleaners get all of the leftover files from uninstallations and misc. problems in the registry. Certain regcleaners can cause problems but have yet to experience a problem with ccleaner or registrybooster.
    I just spoke from a more general populice. I usualy have more problems with them than they do good. Like I said before, the registry isn't much datasize to begin with, so having it cleaned is a placebo effect.[/quote:3knnbpi5]

    Actually it is rather large, just exported my reg to see and find it is 103MB. Pretty large considering its mainly text/binary codes/hex codes etc. Invalid entries just bog down the performance of the system when accessing the registry.

  19. #79
    23 years old
    Rating: total douchebag

    Join Date
    May 2005
    Posts
    8,371
    BG Level
    8

    Re: Recent Hackings and Steps to Insure Account Safety.

    Quote Originally Posted by Viena
    Quote Originally Posted by Zero Serenity
    If you don't patch you're just asking for trouble, so I'm not going to even bother helping those folks.
    Whose fault is it that a product isn't safe upon release?
    You could say the programmers but if you think any product is immediately safe upon release as opposed to fixing antagonizing issues as they come up you'd be wrong. Accepting the fact that no product is safe upon release should be your reason to patch and update and if you don't then it's your fuckup, sorry.

  20. #80
    E. Body
    Join Date
    Jun 2006
    Posts
    2,181
    BG Level
    7
    FFXIV Character
    Bro Teampill
    FFXIV Server
    Gilgamesh
    FFXI Server
    Ifrit

    Re: Recent Hackings and Steps to Insure Account Safety.

    Here's some of what I've gathered based on some of the threads here, and other info:

    1) First off, SE will do nothing for you at present. They have pretty much explicitly stated that account security is up to us, not them. That doesn't meant they won't plug the holes in their dam (constructed by beavers), but who knows how much damage will be done first.

    2) It seems that browsing the web is the most likely scenario that people are getting malicious code running on their machines.

    3) It is very possibly code that specifically targets FFXI. If that's the case, then more than likely the code is going to be found on FFXI related sites. Chances are you won't get it from something like MSNBC.com.

    4) Nobody at this point has any idea exactly what the code is doing. It may be a simple key logger. It might be a key logger that also finds the file where POL passwords are stored, and cracks them. It may also be able to recognize attempts to circumvent simple password input via the keyboard, ala cut & paste, by scanning the contents of the clipboard.

    5) Some of the steps outlined in the OP aren't half bad ideas, and won't cause any more harm than is being done right now.

    I mentioned before that it wouldn't be a bad idea to decouple your web surfing and game playing to separate pieces of hardware, aka PC for browsing, Xbox 360 for playing, or separate PC's for game play and web browsing. Until this is all ironed out, you really can't be too careful, unless you don't have any sort of attachment to your account.

Page 4 of 16 FirstFirst ... 2 3 4 5 6 14 ... LastLast

Similar Threads

  1. Additions and Adjustments to Chocobo Raising (25/09/2006)
    By spooky in forum FFXI: Everything
    Replies: 64
    Last Post: 2006-09-27, 10:43
  2. Mijin Gakure damage and how to boost it
    By Benadar in forum FFXI: Everything
    Replies: 63
    Last Post: 2006-08-04, 22:52
  3. Hacking FFXI registry to up the back buffer
    By Russta in forum FFXI: Everything
    Replies: 28
    Last Post: 2006-03-24, 10:35
  4. I think the FFXI dev team gave up and left to play WoW
    By Razz in forum FFXI: Everything
    Replies: 10
    Last Post: 2005-04-24, 15:58