Item Search
     
BG-Wiki Search
+ Reply to Thread
Page 1 of 13 1 2 3 11 ... LastLast
Results 1 to 20 of 244

Thread: New RMT attacks     submit to reddit submit to twitter

  1. #1
    Salvage Bans
    Join Date
    Jan 2007
    Posts
    766
    BG Level
    5
    FFXI Server
    Ragnarok

    New RMT attacks

    Two of my LS members and good friends had their accounts stolen yesterday at around 5:45 PM EST. However these were not ordinary attacks, they were different.

    In about 10 seconds from "Disconnected, this PlayOnline ID was logged in from another Terminal", both of their passwords had been changed. That is impossibly fast for a human to do, so the thieves are using a program to change passwords immediately.

    Both of them managed to call GMs from other characters (or have friends do so), and get their accounts locked, but because it was Sunday and they couldn't phone in, the process took too long, somewhere around 45 minutes, so the damage was definitely already dealt.

    Today both of them called SE and presented their info only to be told, "The name on the account doesn't match, sorry. There is no way to change the name on the account so it must not be you."

    Neither of their accounts were bought, they are the original owners and have been playing for years, their names were definitely on the account prior to the thefts. This means there is a way to change the names on accounts, and now SE is unwilling to return the accounts to them.

    Update: PoL Message is unrelated

    I'll keep you updated with whatever I find out.


    (3:06:23 PM) Caitlyn: ok so SE sucks
    (3:06:35 PM) Caitlyn: they refuse to believe that it is possible that this can happen
    (3:06:54 PM) Caitlyn: but i took my CC off the account and they told me i might get charged for the server transfer
    (3:07:07 PM) Caitlyn: and there is nothing i can do because i can't verify the account
    (3:07:12 PM) Caitlyn: wtf is up with that
    Cliff Notes:
    On Sunday 5:45pm EST 2 people (Servont and Caitlyn) who play on PC in my LS had their accounts stolen. None of their other accounts, or the accounts of anyone who had access to their accounts were compromised. Only these two. Servont and Caitlyn did not have each others info.

    Caitlyn and Servont both exchanged ID/PW info via PM on our LS website. This was how the accounts were compromised.

    The most important thing to note is that the name on the account was changed after the hacking, making Caitlyn and Servont unable to retrieve ownership.

    The main point I am trying to get at here is that there seems to be a method to change the name of the owner of the account, making you unable to get back your account. The PoL message was speculation as it is unknown how the accounts were being compromised, we now know the accounts were compromised via forum PMs, so there is no exploit with PoL Messages to worry about.

  2. #2
    Tottenham 'til I die
    Join Date
    Jan 2008
    Posts
    2,215
    BG Level
    7

    NONONO WILL NEVER HAPPEN TO ME LALALALA

  3. #3

    holy wow, i'm scared.

  4. #4
    Space Pope
    Join Date
    Oct 2006
    Posts
    361
    BG Level
    4
    FFXI Server
    Diabolos

    But... the blinking... drives us mad...

    Was it a POL message or a "new email" message? Does it hurt to open up a POL message in-game?

  5. #5
    CoP Dynamis
    Join Date
    Jul 2007
    Posts
    262
    BG Level
    4
    FFXI Server
    Siren

    Wow, that sucks.

  6. #6
    E. Body
    Join Date
    Jun 2007
    Posts
    2,410
    BG Level
    7
    FFXI Server
    Ragnarok
    WoW Realm
    Haomarush

    Strange Tubbers, I got an empty POL message yesterday too. Just after X told me they were hacked. I guess if my account gets exploded then we can confirm that's the cause.

  7. #7
    Yvonne
    Guest

    Quote Originally Posted by altwight View Post
    Strange Tubbers, I got an empty POL message yesterday too. Just after X told me they were hacked. I guess if my account gets exploded then we can confirm that's the cause.
    I got one too, but I'm on the PS3. Not sure if that means I'm safe from anything, but I'll keep you guys posted.

  8. #8
    TIME OUT MOTHERFUCKER

    Join Date
    Nov 2007
    Posts
    3,897
    BG Level
    7
    FFXI Server
    Ragnarok

    From a programing standpoint, this seems highly improbable.

    Are you sure these people weren't doing something else stupid, like, say, using IE?

  9. #9
    New Spam Forum
    Join Date
    Aug 2008
    Posts
    155
    BG Level
    3

    Well, if you get one of these blank messages change your password asap. Then everyone flood SE's phones and demand they look into this bullshit. >_>

  10. #10
    Salvage Bans
    Join Date
    Jan 2007
    Posts
    766
    BG Level
    5
    FFXI Server
    Ragnarok

    It was a PoL message, Cait said she got two of them, then poof. I just spoke with the other one (Servont), he said he doesn't remember getting any PoL messages, so I'm really really hoping it was a strange coincidence. The fact that they can change names now is bad enough.

  11. #11

    fuck, the Chinese are this smart? :D

  12. #12
    Salvage Bans
    Join Date
    Jan 2007
    Posts
    766
    BG Level
    5
    FFXI Server
    Ragnarok

    Quote Originally Posted by Tarage View Post
    From a programing standpoint, this seems highly improbable.

    Are you sure these people weren't doing something else stupid, like, say, using IE?
    Both of then use Firefox + NoScript. Servont has/had the block <IFRAME> checked, Caitlyn did not; however both of them only visited FFXIAH, otherWiki, and our LS (my) website. I've thoroughly checked my website for any invasion, and there's nothing there. Which means It's either FFXIAH, otherWiki (RMT Vandalism?), or a new form of attack.

    Also from a programming standpoint it is not that improbable. If there are vulnerabilities in POL (which there most definitely are) they may be able to be exploited like this. It's very unlikely, but it's possible.

  13. #13
    Yvonne
    Guest

    Quote Originally Posted by Tarage View Post
    From a programing standpoint, this seems highly improbable.

    Are you sure these people weren't doing something else stupid, like, say, using IE?
    Yeah, I can see PC users might be affected by this, but not sure how a blank message would do it. I haven't changed any routines on my PS3 or shared my account info with anyone.

  14. #14
    Sea Torques
    Join Date
    Feb 2008
    Posts
    580
    BG Level
    5
    FFXI Server
    Phoenix

    need to get the Security Token out already!

  15. #15
    Falcom is better than SE. Change my mind.
    Join Date
    Jun 2006
    Posts
    17,291
    BG Level
    9

    Do you know who sent the POL messages? Since something just seems off about them getting an invisible message then getting their account hacked. Unless the RMT found a way around the "Lets be friends!" invite message.

  16. #16
    New Spam Forum
    Join Date
    Mar 2008
    Posts
    190
    BG Level
    3

    Wait so if i'm reading this right, Servont got hacked with little/no evidence of what he did in any case?

    Im scared, tell me this isn't true.

  17. #17
    Salvage Bans
    Join Date
    Jan 2007
    Posts
    766
    BG Level
    5
    FFXI Server
    Ragnarok

    @ Corr : No, according to Caitlyn it was "completely blank" with nothing in it whatsoever.

  18. #18
    Falcom is better than SE. Change my mind.
    Join Date
    Jun 2006
    Posts
    17,291
    BG Level
    9

    Quote Originally Posted by Tubbers View Post
    @ Corr : No, according to Caitlyn it was "completely blank" with nothing in it whatsoever.
    So there wasn't even a sender's name... okay now I am scared...

  19. #19
    Hydra
    Join Date
    Oct 2006
    Posts
    97
    BG Level
    2
    FFXI Server
    Diabolos

    I'm not sure about any of you, but I don't use my POL Mail for anything, at all. Pretty sure there are much safer/better e-mail services out there. The only crap I get in that box is RMT mail, so I fiddled with those mail filter settings. No more junk mail or blinking in the top right corner cause of their mail. Just take a few minutes to configure your mail filter to prevent getting mail from anyone you do not list (I believe it's called white listing).

    Regardless, thanks for the heads up.

  20. #20
    My Little Ixion
    Join Date
    Aug 2007
    Posts
    8,069
    BG Level
    8
    FFXIV Character
    Olorin Bustyoas
    FFXIV Server
    Sargatanas
    FFXI Server
    Ramuh

    Did they ask SE for the affidavit & provide the original reg codes when they called? From what I understand those are both the easiest way to get their accounts back from RMT shenanigans.

+ Reply to Thread
Page 1 of 13 1 2 3 11 ... LastLast

Similar Threads

  1. New RMT spam, yay -_-
    By Auspice in forum FFXI: Everything
    Replies: 32
    Last Post: 2010-08-04, 14:55
  2. New RMT Tactic - Phishing Messages Ingame
    By Yvonne in forum FFXI: Everything
    Replies: 38
    Last Post: 2009-09-11, 07:57
  3. New RMT exploit or gimmick?
    By DAKPluto in forum FFXI: Everything
    Replies: 153
    Last Post: 2009-07-03, 16:44
  4. New RMT method of account hijacking?
    By AneyuS in forum FFXI: Everything
    Replies: 58
    Last Post: 2008-10-23, 16:32
  5. New RMT methods?
    By lilfoo in forum FFXI: Everything
    Replies: 4
    Last Post: 2008-09-11, 02:15
  6. New RMT conspiracy
    By bulk in forum FFXI: Everything
    Replies: 76
    Last Post: 2008-01-28, 17:47
  7. New RMT Tactic?
    By Max™ in forum FFXI: Everything
    Replies: 35
    Last Post: 2007-09-17, 09:35
  8. New law in China possibly will hinder RMT?
    By Charitwo in forum FFXI: Everything
    Replies: 35
    Last Post: 2007-04-15, 10:21
  9. New RMT army?
    By knifebait in forum FFXI: Everything
    Replies: 51
    Last Post: 2006-07-29, 09:57