
Originally Posted by
alabamahotpocket
While this Security Token is great for account password protection, its useless against session hijacking type of trojans because of the way ffxi is designed.
Let me explain what i mean with an example. Ill use the windower plugin LightLuggage as example (im not saying LL is a trojan lol, just using it to explain session hijacking).
As plugin developer, i could add some extra code to this plugin that only gets activated if a character named "Somerandomcharacter" sends the plugin user (the victim) a trade request. Once this trade request is sent from the exploiter (in this case me, the developer), the plugin could block all the user input from windower, and start sending keyboard commands to the game. It only takes a few key clicks to accept the trade, put up all your Gil in trade window and hit OK. All trades are final, right?
If the trojan was well written, it could even check players equip and unequip high priced items (like KC) for trading. Same with bazaars.
There's no security code to confirm if the trade was legit or not (unless the "in-game bonus" in announcement means you can use the device to confirm in-game trades, bazaaring, delivery boxing and selling on AH).
The plugin dont even need internet access, so your firewall and antivirus programs would not protect you in this case. Having access to FFXI data in your PC memory is good enough.
Since the source code of the plugin is not open to public, you cant really know if something extra was added to it. You probably wont even know which plugin did it. It could happen while you are afk to eat or just doing overnight bazaaring.
Also, this dont have to be windower plugin. Im just using it as example since many ppl use those. It could be some random virus you picked up from somepage.com or the functionality could be built in the claiming bot you are using.
As long as the FFXI items/gil can be turned into real life money, RMT will be after your stuff, and they dont care what methods are used to get it.
/cheers