Dunno if it matters but did they have their passwords saved? After seeing this I remembered getting a blank message that I opened up in game a month or so ago but never lost my account.
Dunno if it matters but did they have their passwords saved? After seeing this I remembered getting a blank message that I opened up in game a month or so ago but never lost my account.
*Lights the Tsuki signal*
This happened to a friend of mine and almost happened to another friend of mine who was able to catch it in time to lock the character. They both ran numerous scans and found nothing and both use Firefox with add-ons.
Very scary indeed...
Third LS member just got hacked, just now...
[Edit: He was able to stop the hacking, he's also kind of >.> so we're not sure if he was really hacked at all]
Is there something on your linkshells website? >_>
No, he uses Xbox360 to play, doesn't have a PC with XI installed.
It's a trick by SE! They're scaring everyone into buying SecurityToken!
If one LS is getting hit repeatedly, I'd definitely also look at potential alternate mechanisms. Did you have anyone quit/get kicked under questionable circumstances in the last few months, and might they have had pw info for other members/ability to hack LS site?
I'm not trying to be at all rude, just a suggestion and hope this is helpful. Gorilla in the room etc etc.
[also /wave at Toyo/Uryuu]
i might have missed it, but how long from them opening the blank message did it take to them getting kicked off?
the 10 seconds was how long it took them to try to log back in from the black screen of death if i understand correctly. wondering how long it took for it to be compromised from the time they opened the phony message
Haven't seen a single response from the OP regarding the questions asking whether or not these people shared their info. Since the common factor in all these cases is the social group, I'm gonna guess someone they knew probably fucked them over.
even if it was somebody they knew, it does not explain how their names were changed on their accounts
did he share his info w/ anyone? did he receive the mysterious blank message? for clarification, did the blank message have to be OPENED or was it sufficient to receive it to trigger the assumed exploit?
it's even possible that they've done something far more clunky than reverse engineering the entire database mechanism. if you replaced the first/last name in the local computer's memory (or just unlocked the field if it's just a dressed up windows dialogue) then sent the update string to the server. if the server doesn't do a sanity check on the update request (and this is SE. they do everything lazy.) it may very well overwrite the "unchangable" information on the account.
the application of the blank message is open to speculation at this point. if i had to guess though, it's probably some sort of database injection attack based on the speed of execution. the malformed message presses a new password and contact info into the database in place of the current data which is then shortly thereafter used to log in. this could easily be mechanized to allow the kinds of smash and grab behaviors we've seen where the account is lost entirely before the user is even aware that they are being targeted.
assuming that the attacker has not found a way to inject POL messages directly into the system for processing and delivery (they have to use one of the "approved" channels such as the ffxi client or POL viewer) what methods could be used to send the message? what information is needed to address the message to the player? would they need my account number? player name? obviously they have to address it SOMEHOW, so if we can properly control access to that information, we should be able to mitigate the threat by reducing the chances that the messages can reach us.
the fortunate thing is that if SE reacts quickly, they can disable the mechanism the CGF are using to transmit these poison messages and then plug the hole at their leisure. the question is, will SE react quickly if at all? also, the security token may not protect us if the "uses token" field is in the same table they have managed to find a way to gain access to (assuming that they have even got actual access to the database) as they could simply update that field to be false at the same time as they overwrite your account information and contact info.
one thing is for sure, if this attack is using database code injection, it's a new evolution in the capacity of the attacks of the cgf on accounts. previously they only attempted to attack client machines and intercept the login credentials at that point. if they have engineered a powerful server side attack like this, even the vigilant could be at risk.
Anyone else start getting the gil messages again via tell the last two days? Just started again for a lot of people i talked to lol
To the OP: Do you have any affiliation with Taj? He's the only one I know of that can change the name on accounts and this kind of seems like his style, of course this is a stab in the dark.
You can't change names on accounts, it's not possible.(I started this game at like age 14 years ago and the name on my old account wasn't mine, so I tried forever trying to get the name changed. I spoke to everyone I could, and they told me there is no possible way for ANYONE (read ANYONE, not even THEM) to change the name on an account, ever.) Someone is either reading PM's or like Drwaffles said: Someone knew their info, and fucked them over. But I doubt they will admit it.
There is some side of the story not being told...