I just quoted Slashdot, the NYtimes link is better.
I just quoted Slashdot, the NYtimes link is better.
You'd think that if someone had the means to use those types of keyloggers, they'd target something with a little more value than an MMORPG. Like a bank account. I wouldn't think we'd have to worry about that, for a while. But I dunno.
Just experienced this myself, to an extent. Game crashed, and when I tried to log back in, POL crashed again before I could. I'm just glad I had found this thread earlier tonight. I'd had no idea what was going on and I wouldn't have known a thing to prevent a hacking if I hadn't but. luckily I knew to reboot immediately, log onto a different pc and change my se pw. Doing a scan now and I'll let you know if I find anything interesting. :/
Right now, my infected pc is acting a little wierd; ever so often the applications that I have open will stop responding for a couple seconds. I notice this mainly when I'm typing something or switching between windows. I've only had wiki, wiki forum, BG, my ls's private forum, and windower forum up so it must have come in through one of them. I'm using firefox with keyscrambler, ad block plus, flashblock, no script. Also been using avast antivirus, adaware antispyware, and zonealarm firewall. Not sure how it got past the firewall, it usually gives me a pop up anytime something's going on with the system.![]()
Don't forget the fact that there's an almost 0% chance of being prosecuted for stealing MMO items whereas there's a almost 100% chance of being prosecuted for stealing real money from someone's bank account if you get caught.
Was your character moved at all? Did FFXI just crash or did you get the "this account has logged in from another location" message? There's a chance there's just something wrong with your computer.
didnt notice a "this account has been logged in from another location" message, but I'd been afk browsing the internet too so there's a chance I didn't notice it at the time. My character hadn't been moved, but I haven't checked any of my mules. Just my main.
Question:
Does anyone in here play FFXI on Mac pc?
Do Mac owners go thru these key loggers issues?
Reason i ask because I’ am planning to invest on a Mac pc and a Mac notebook. For the time been I am playing FFXI on my play station 3.
I apologize if I’ am off topic.
Aikar I was considering to send a heads up notification letter to SE customer service online support or STF. It would be on behalf of the user base who I have seen posting their compromised account info.
What way do you think I should describe a summary of what has been going on in the users accounts that have posted here?
I mean the type of attack it appears to be. So I can point it out to them.
I want to write a technical description of it without overly garbling it with words like I normally do. Is there some kind of name for these kind of attacks you can tell me or advise where I can read up?
I plan to look at all of the forums and get a general head count of who has been hit and the similarities, all with the token being the common denominator. While I do not need their names, I will need to describe the occurrences in a general format that STF can understand.
I am asking you because I know you know your shit and how to protect it.
Any info is appreciated.![]()
Same here I got hack after 1:00 am PST on Sunday morning Aug23. (late saturday night) None of my password was changed, with the account already strip, the account is useless unless they physically have the token.
Thinking about this, I can make a few suggestions for other, maybe it would help.
1) I use the same ID/Passwd for POL and SE for the main account, because I didn't want to track yet another ID/Passwd. I believe this is a big mistake, it just makes it easier for them.
2) my second account has POL different than SE password, and it wasn't hacked. I ran both accounts on windowers with one computer, I play simultaneously on one computer. So i makes me wonder if the POL/SE passwd differences kept that account from being stripped.
My main account crash first... try to log back in and hung, few minutes later, my second account started doing wierd laggy stuff and eventually crashed too. I rebooted try to log into main a few times (i think 3) gave up. I try to log into second account 1 time didn't work. I gave up and went to bed at like 2am. I woke up and my main account was stripped. I check all the Dboxes and they don't have names where stuff is being sent.
3) I setup my lap top for FFXI now and have it on hot standby with windower started and ready to go. I figure if i see windower crash again without messages, and POL hangs just like I was being hacked. I would jump on to my laptop and log in, with bad token in the hopes that it DCs them. Once it DCs them, the hacked token is useless because it's already been used once by them.
4) I have a theory that they do this at 1am on saturday because
a) it's a busy time, so GM queue would be huge and they are busy
b) POL information center is unavailable
c) no staff to do a live investigation of the hack, SE is close till monday
d) possibly, maybe they know that SE only keeps transaction log for 24 hours, so as to avoid SE from looking at the Dbox logs to figure out the blood trail
I hope that d) isn't true though, I hope they keep longer logs. They should also keep a log of IP address that logons with account ID. They should do stuff like if you got DCed from colorado, and try to login from China ISP or Russian ISP, then the server don't let you for 30mins. Only way to get back in right away is to do it from same IP, or at lease from same ISP block/geographic region.
just a thought.
Does anyone with a token ever log out and come back later to realise they've been hacked while they were offline? Or does it just take place while they're actually logged on. Probably a stupid question but was just wondering.
Pretty much, if you're running FFXI on Mac-branded hardware, you're doing so by running Windows on it in some fashion (most likely Boot Camp). That Windows install is just as susceptible to malware as any other.
Mac OS X has very little malware that actually targets/affects it, but that has a lot more to do with market share than it does lack of vulnerability.
Did you attempt to log back in from the same PC and were unable to immediately after crashing when you were getting hacked? I imagine, with a token, if your POL just crashes, the best thing to do is to just log on from another computer and change PW, or at least reboot the system you're on first.
Also, has anyone done any rootkit scans yet that has been hacked?
SSL would be about as effective as a cardboard hammer in this case. remember, SSL requires both computers to have aBb in memory to function since SSL is a symmetric key. the attacker has full access to the PC most likely and as such could pilfer the key straight out of memory.
in addition, if the attacker had malware on the computer, they could simply inject commands into POL to control it. this would require the PC to stay on and web connected throughout the entire pilfering, but could explain the "DCless" thefts we're seeing. rather than actually killing POL, it closes out the window keeping parts of it alive and blocking a new instance from loading while the RMT use your computer as a proxy of sorts to very very rapidly take everything. moreover, if you change your source IP (such as changing from 1 wireless network to another) would you drop your connection? i'd assume as much, but if not, could the RMT hijack the components necessary to effectively transfer your entire session to one of their machines? if so, this would be the endgame i'd anticipated where no security policies or token mechanics could really protect the user as either of the above would in essence completely do away with the need for any authentication information.
The person who mentioned this is Iulus, concerning the husband of a member in our LS. I talked to her yesterday about this, and she stated that her husband's POL crashed, he was unable to log back in. During this time, she was unaware that he was crashing. She noted that he was red-dotting, but that he recovered, never dropping from PT. After he recovered, he warped out of Salvage. She asked him why he warped, and he stated that he crashed and wasn't even online.
A friend plays FFXI through Parallels/VMWare Fusion (uses both if one of the two crashes) and in fullscreen mode. He doesn't use the virtual machine to browse for websites because, in his words, he calls Windows an "insecure pile of crap" and he only needs Parallels/Fusion for FFXI. He only browses the internet through Safari in Mac OSX, and uses Mac-only IRC and IM client.
Since he doesn't visit websites through Internet Explorer in virtualized Windows 7 RTM (his current virtualized OS), he feels he's not at risk. On top of which, any keylogger he may get through Safari in Mac will be only able to run in a Windows environment anyhow and not smart enough to traverse all the way to the virtual hard disks where the guest OS is installed.
He tells me himself, even if using Bootcamp to install a full Windows OS is much more insecure than using virtualized Windows OS so long as he doesn't use Internet Explorer, which he calls a "shoddy program by Microsoft."
He's fun to talk to and listen whenever virtual Windows crashes on him because it isn't perfect in Parallels/Fusion, and thus he starts cursing about Windows when he IMs me. ^^;
By the way, Aikar mentioned PlayOnline Viewer uses SSL connection, yes it is true. All you have to do is look for the key icon in the corner of the Viewer.
However, the memory where PlayOnline stores itself isn't secure, only the connection between the Viewer and the server is. And, like with Windower which requires a hook to find the memory location of the FFXI process to make it windowed and allow it to use plug-ins, the same can feasibly be done to PlayOnline viewer if someone knew how to do the same thing. But, that in and of itself would take a lot of work and programming skill. I'm only good with HTML, PHP and Flash ActionScript. I see C++ as the equivalent of trying to learn Russian (yeah, bad analogy). Therefore, the attacker would have to know how to have the program to do two or three things:1. Interrupt the connection of the playerI am not saying Windower is the cause of this, but wouldn't a knowledgeable programmer do the same method for POL Viewer to allow themselves access to whatever you enter? Hook.dll for Windower is about 512 kiB in size and launcher is 377 kiB in size, thus if a script unbeknown to the user sent two files of similar size, it'd be sent fast enough and be made to hide itself from the user disguised as a rootkit, since these are hard to detect unless you have a scanner to find them specifically.
2. Bypass the information entered by the player to the attacker's computer
3. Read that information in memory as it is entered and send it to the attacker
It's absolutely scary that either RMT companies have resorted to this tactic or are hiring programmers/hackers to do this. It sounds a lot like an act of desperation if this is what's actually happening. They're already spamming tells to us and even fooling players into visiting phishing websites to steal our account info. Players on PS2/PS3, 360, and those not using Windower's Chatmon plug-in are getting spammed each day by tells to buy/sell Gil or pay hundreds of dollars for a power level from 1 to 75. Another friend sent me a screenshot of him getting 9 tells within 15 minutes. A friend on another server told me an RMT "spam bot" glitched and sent him the same tells repeatedly for five minutes. He got pissed because typing /blist add so-and-so was difficult because how they spell out their names, and he just logged out for an hour.
And, yet, here we are about a year after the first group of hackings occurred through iFrame/Flash/Javascript exploits before the security key was introduced, and we are introduced to a new form of attacks by the RMT. It makes me wonder if Square-Enix has their thumbs up their asses, or are just unwilling to do anything to stop this. If they can't stop these now or make an effort to do something to better secure an account, what will it be like for Final Fantasy XIV then? Will the same thing happen there as well?
the big problem here is not that we're being attacked. attacks are a fact of life. with as much real money equal as flows through here without the same risk of legal recourse if detected as say an attack on a bank, we will always be targets. the most important thing is mitigation, which SE has horribly dropped the ball on.
first the rule was if you don't have the cc number, we're not doing business with you anymore. buh bye. draconian and terrible. then they gave us the ability to recover the stripped accounts which is an improvement but still terrible. then they gave us the ability to roll back our accounts which is good, but the restrictions, the hoops we have to jump through, the occasional claims that the account wasn't hijacked and that they wouldn't help us, the one time restore across our entire ffxi career; the list of reasons why this still isn't good enough is staggering.
SE needs to stop thinking of account restoration like they do item restoration: a favor. they're not doing us a favor. they're not being nice. they're doing their JOB to keep us paying them. if i'd lost every sellable item on my account and every gil in my inventory and i couldn't get it restored, i'm done. i have a relic horn, i could continue playing with nothing more than that, but i think i'd feel so sickly violated by both the RMT and SE's inaction that i'd just cut my losses and give up.
players who have been attacked once and had their accounts rolled back should not be forced to live in fear that the next compromise of their account becomes terminal. players who have just been attacked the first time should not have to be concerned if their account will be returned to them or if SE will simply declare without recourse that they didn't feel there was enough evidence and dismiss the player. when SE realizes that they can't blame the victim (no matter how many of the victims carelessly use IE) we'll be in a much better place.
I can confirm that switching wireless networks will kick you off, I've tried at house I was renting a room at because one was being really slow, it seemed to recover, then booted me off without going through normal DCing % drops, just a straight boot, sometimes it took a few minutes though, so that might not stop it
Hahah, of course you're going to get DC'd if your IP changes.