Item Search
     
BG-Wiki Search
Page 12 of 47 FirstFirst ... 2 10 11 12 13 14 22 ... LastLast
Results 221 to 240 of 931
  1. #221
    Cerberus
    Join Date
    Dec 2004
    Posts
    469
    BG Level
    4
    FFXI Server
    Quetzalcoatl

    Quote Originally Posted by sixstitches View Post
    this is where I am now, I live in fear, to the point where am thinking about setting up a computer just to play game only, no browsing or any other activities. Also super paranoid about anytime i feel like the virus is back, if my calc opens a little slower my mind is racing.

    But i also think if we are force to live in fear, then really am i really having fun anymore? I pay 30$/month to SE to provide me with entertainment, I hardly slept lastnight anxious about contacting SE monday morning. Currently i am on the path of "i'd feel so sickly violated by both the RMT and SE's inaction that i'd just cut my losses and give up." I am not having fun anymore, y play. I use FF to get away from the RL, now I am right smack back in RL with the same types of worries.

    I wonder how they deal with inflation when they restore, they pump more gils into the economy. I blame gil buyers!
    SEEK HELP

  2. #222
    Yoshi P
    Join Date
    Jun 2007
    Posts
    5,144
    BG Level
    8
    FFXIV Character
    Fitz Everleigh
    FFXIV Server
    Excalibur

    Quote Originally Posted by Gere View Post
    No because the same keylogger will work whether or not you have a token. Plus the token restricts them to only stealing your sellable items and gil rather than your entire account.
    I admit I didn't keep a whole lot with the last string of serious hacks other than where to stay away from, but wouldn't passwords saved, prevent this particular string of hackings from happening? (obviously assume no security token here)

  3. #223
    Neb
    Neb is offline
    New Spam Forum
    Join Date
    Jul 2006
    Posts
    152
    BG Level
    3
    FFXI Server
    Bahamut

    I'm all freaked out now I have been alomst dced many times in the past week but have never fully dced. Whenever i catch it I spam tells to myself (old School pray that I reconnect to the server style) and I always seem to reconnect. These random DC have never happened to me before. I'm screwed I hope someone finds some sort of fix or preventative tactic for this soon.

  4. #224
    Cerberus
    Join Date
    Jun 2007
    Posts
    409
    BG Level
    4

    Quote Originally Posted by Spekkio View Post
    if this is sophisticated enough to hijack a session live (again, i'm guessing not, but that's the only viable method i can think of to explain the partial DC and recover effect that was described above) would it be that much of a surprise to find out that they're using RK style obfuscation techniques to avoid detection? hooking the OS kernel to hide RK processes and files has been around for a decade, but most of the prior attacks appeared to be sloppy hack jobs by an attacker with limited expertise. if instead the RMT hired "professionals" to engineer this attack, it would not surprise me if they added the usual packing/RK tricks to minimize the threat of detection.

    as for if session relocation is possible, if the above poster was able to action on their session from a different IP, that tends to indicate that it is possible to pull it off, if you can keep the server from firing a disconnect. if it's just checking for a keepalive from the original IP, either the attacker's software on the victim PC could deliver that or they might even be able to forge the keepalive to keep the session running till they can pilfer the contents of the account. without seeing any kind of connection logs, traffic capture, or anything beyond vague symptoms at this point though, this is all wild speculation.
    Userland RK methods, and even most of the "professionals" ones are easily detected nowadays. Most can't even hide it's HANDLE usage and that's an extremely basic method of detection, imagine all the detectors that are out to the public these days.

    To be fair, I'm rather skeptical towards use of such sophisticated methods by gil mongering chinamen. If this is what's currently happening to FFXI, then it should be going on in other games -- I don't go out of my way to track the hackings in regards to WoW and such. So hopefully someone can point out if there are similar outbreaks in the realms of MMO.

    Edit: http://technet.microsoft.com/en-us/s.../bb897445.aspx , post log/screenshot please.

  5. #225
    Banned.

    Join Date
    Aug 2009
    Posts
    2,516
    BG Level
    7
    FFXI Server
    Fenrir

    I'm having connection problems recently where, for no reason, FFXI loses its connection but all my other internet-using applications keep chugging on.

    A friend of mine 2boxed me all through Dynamis on Saturday without issue so I'm pretty sure it's my connection/copy of the game/computer, and not RMT.

    Before freaking out over disconnects, check it on a different computer/connection.

  6. #226
    Mithra Ero-Sensei
    Sex Manthra

    Join Date
    Nov 2005
    Posts
    10,160
    BG Level
    9
    FFXIV Character
    Erosensei Gulkeeva
    FFXIV Server
    Gilgamesh
    FFXI Server
    Cerberus
    WoW Realm
    Magtheridon

    You may try a program called "threatfire" I've found it to effectively find "unknown" keylogger type activity (even the kind that hide process from taskmanager/system services) Even ones hidden in devices.

  7. #227
    Sea Torques
    Join Date
    Oct 2006
    Posts
    731
    BG Level
    5

    Quote Originally Posted by Gulkeeva View Post
    You may try a program called "threatfire" I've found it to effectively find "unknown" keylogger type activity (even the kind that hide process from taskmanager/system services) Even ones hidden in devices.
    Hey that looks like it might work.

  8. #228
    Cerberus
    Join Date
    Dec 2004
    Posts
    469
    BG Level
    4
    FFXI Server
    Quetzalcoatl

    Narse's logs have a few files with strange spaces in them, probably just a byproduct of pasting the log files, but might be worth investigating. e.g.:

    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.e xe
    C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUt il.exe -p

    Is everyone that's been hacked a windower user? It seems to be the one common thread in all these incidents.

    It's funny how people will go to great lengths to lock down their browser with noscript, run an AV scanner, buy a security token, and all that, yet they'll allow a closed-source, TOS-breaking third party app to hook into the game's memory every time they log on. Not pointing any fingers, just pointing out the cognitive dissonance there.

  9. #229
    Melee Summoner
    Join Date
    Jun 2009
    Posts
    29
    BG Level
    1
    FFXI Server
    Quetzalcoatl

    Quote Originally Posted by Solefald View Post
    SEEK HELP
    I contacted SE and they will be starting a restore process.
    I am pretty sure I will be quitting after the restore, liquidate, give gils to friend and quit. it's sorta seeking help i guess. one less thing to worry about now that I don't play. lmao.

    in a way this was good, it was a wake up call. If they can do this with ffxi, then my desktop is not safe to do secure transaction. so i am planning on setting up a linux system for use with online banking/paypal and such. I am not saying linux is safe, but it's less targetted.

  10. #230
    Melee Summoner
    Join Date
    Jun 2009
    Posts
    29
    BG Level
    1
    FFXI Server
    Quetzalcoatl

    kicks to the groin

    Quote Originally Posted by Solefald View Post
    Is everyone that's been hacked a windower user? It seems to be the one common thread in all these incidents.
    yes, i for one used windower. i guess if you really want to eliminate this threat, then you can also move to consoles. alot safer than PCs. or quit, which is 100% safe.

    Quote Originally Posted by Solefald View Post
    It's funny how people will go to great lengths to lock down... yet they'll allow a closed-source,TOS-breaking third party app... Not pointing any fingers, just pointing out the cognitive dissonance there.
    and thanks for the additional kicks to the groin.

  11. #231
    We wear wine red on Wednesdays

    Join Date
    Sep 2006
    Posts
    2,241
    BG Level
    7
    FFXIV Character
    Marius Krieg
    FFXIV Server
    Balmung
    FFXI Server
    Fenrir

    Another friend who recently joined our LS just posted that he's on Hades server and his sellables are gone.

    Really hope SE's staff isn't going to flake out on this like they had so many times before when accounts had been hacked.

  12. #232
    E. Body
    Join Date
    Mar 2006
    Posts
    2,333
    BG Level
    7

    Quote Originally Posted by Kaces View Post
    Userland RK methods, and even most of the "professionals" ones are easily detected nowadays. Most can't even hide it's HANDLE usage and that's an extremely basic method of detection, imagine all the detectors that are out to the public these days.

    To be fair, I'm rather skeptical towards use of such sophisticated methods by gil mongering chinamen. If this is what's currently happening to FFXI, then it should be going on in other games -- I don't go out of my way to track the hackings in regards to WoW and such. So hopefully someone can point out if there are similar outbreaks in the realms of MMO.

    Edit: RootkitRevealer , post log/screenshot please.
    fair enough. comparing hooking 98's DOS based kernel to hide nasty behavior to xp's kernel is like comparing repairing a car's engine to a jet turbine. there's still always the threat of an RK hooking the bootloader and basically running the OS in a hypervisor that can jack control or some similarly complicated method, but now we're assuming a lot more creativity than i'd be inclined to believe. still, with packer apps out there that literally automate stealthing applications against AV threats, it would be very surprising to me if each round of malware doesn't come with new tricks and traps to slow us down.

  13. #233
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    Windower has nothing to do with this. Everyone that posts on this forum just happens to use it. There's a thread over on alla about the same thing, where they're all anti-windower.

  14. #234
    Cerberus
    Join Date
    Jun 2007
    Posts
    409
    BG Level
    4

    Quote Originally Posted by Spekkio View Post
    fair enough. comparing hooking 98's DOS based kernel to hide nasty behavior to xp's kernel is like comparing repairing a car's engine to a jet turbine. there's still always the threat of an RK hooking the bootloader and basically running the OS in a hypervisor that can jack control or some similarly complicated method, but now we're assuming a lot more creativity than i'd be inclined to believe. still, with packer apps out there that literally automate stealthing applications against AV threats, it would be very surprising to me if each round of malware doesn't come with new tricks and traps to slow us down.
    True, that's what I was getting at. If these guys are really using such complicated hooks, then we should be seeing it used elsewhere. They wouldn't waste such an exploit that would cost them a lot of time and/or money to produce on a single entity when it can be used for untold gains in its regards.

    @windowerguys, you should add a setting that blocks IE from being loaded while Windower is up to force terrible people to not be terrible.

  15. #235
    Relic Shield
    Join Date
    Oct 2006
    Posts
    1,599
    BG Level
    6
    FFXI Server
    Odin

    Quote Originally Posted by Kaces View Post
    True, that's what I was getting at. If these guys are really using such complicated hooks, then we should be seeing it used elsewhere. They wouldn't waste such an exploit that would cost them a lot of time and/or money to produce on a single entity when it can be used for untold gains in its regards.

    @windowerguys, you should add a setting that blocks IE from being loaded while Windower is up to force terrible people to not be terrible.
    They did a pretty cool thing awhile ago for ppl to put on their websites to prevent it from loading if they were using IE.

    Operation Spring Cleaning - Bring down IE6 - Windower

    Anyone who was using IE6 would be redirected to:

    Operation Spring Cleaning

  16. #236
    n3wbr33d
    Guest

    ok, so i wanted to post keylogger notification image i've been getting but it seems i cant post url till i have 10 post...

  17. #237
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,065
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    Quote Originally Posted by n3wbr33d View Post
    ok, so i wanted to post keylogger notification image i've been getting but it seems i cant post url till i have 10 post...
    PM it to me.

  18. #238
    Canada
    Join Date
    Oct 2006
    Posts
    1,482
    BG Level
    6
    FFXIV Character
    Mlle Skjie
    FFXIV Server
    Hyperion
    FFXI Server
    Sylph
    WoW Realm
    Madoran

    Quote Originally Posted by Aikar View Post
    theres one way to protect against this if SE would implement it, but it puts more hassle on us to login and would be too hard for idiots.

    User pushes button, gets 6 digit code.

    However, use only types in the first 4 digits and memorizes first 2.
    SE then receives code, Performs some hashing, and sends back a 2 digit #
    User is prompted for a 2nd code, which you then push the button for a 2nd code and prepend with the last 2 of the first code and append the 2 SE supplied back.

    This would be unhackable, but will be a little tedious to login.
    Couldn't this be defeated by a man in the middle?

  19. #239
    YOU ARE SEARED
    Dungeon Master of the House of Weave

    Join Date
    May 2007
    Posts
    4,453
    BG Level
    7
    WoW Realm
    Kilrogg

    In the days of pXI, and the near-complete rending of the source code that makes XI tick, is it really that surprising that someone could come up with a means to hijack an active session of the game?

    I don't mean this as a slant against pXI, just pointing it out...if they can make the world work by reverse engineering, someone nefarious can certainly "fake it".

  20. #240
    I'm more gentle than I look.
    Mr. Feathers AKA Mr. Striations
    All hail Lord Yamcha

    Join Date
    Aug 2007
    Posts
    17,539
    BG Level
    9

    Anyone w/ firefox + the goodies been hit yet?

Page 12 of 47 FirstFirst ... 2 10 11 12 13 14 22 ... LastLast

Similar Threads

  1. What in the fuck is going on with Ancient Currency prices?
    By Avarice in forum FFXI: Everything
    Replies: 22
    Last Post: 2009-01-12, 05:21
  2. Ok what the hell is up with Roc?
    By S N K in forum FFXI: Everything
    Replies: 49
    Last Post: 2008-06-28, 21:00
  3. Oldschool players with JP Accounts & The new Expansion
    By Lyramion in forum FFXI: Everything
    Replies: 39
    Last Post: 2007-11-24, 01:31