I'm all freaked out now I have been alomst dced many times in the past week but have never fully dced. Whenever i catch it I spam tells to myself (old School pray that I reconnect to the server style) and I always seem to reconnect. These random DC have never happened to me before. I'm screwed I hope someone finds some sort of fix or preventative tactic for this soon.
Userland RK methods, and even most of the "professionals" ones are easily detected nowadays. Most can't even hide it's HANDLE usage and that's an extremely basic method of detection, imagine all the detectors that are out to the public these days.
To be fair, I'm rather skeptical towards use of such sophisticated methods by gil mongering chinamen. If this is what's currently happening to FFXI, then it should be going on in other games -- I don't go out of my way to track the hackings in regards to WoW and such. So hopefully someone can point out if there are similar outbreaks in the realms of MMO.
Edit: http://technet.microsoft.com/en-us/s.../bb897445.aspx , post log/screenshot please.
I'm having connection problems recently where, for no reason, FFXI loses its connection but all my other internet-using applications keep chugging on.
A friend of mine 2boxed me all through Dynamis on Saturday without issue so I'm pretty sure it's my connection/copy of the game/computer, and not RMT.
Before freaking out over disconnects, check it on a different computer/connection.
You may try a program called "threatfire" I've found it to effectively find "unknown" keylogger type activity (even the kind that hide process from taskmanager/system services) Even ones hidden in devices.
Narse's logs have a few files with strange spaces in them, probably just a byproduct of pasting the log files, but might be worth investigating. e.g.:
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.e xe
C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUt il.exe -p
Is everyone that's been hacked a windower user? It seems to be the one common thread in all these incidents.
It's funny how people will go to great lengths to lock down their browser with noscript, run an AV scanner, buy a security token, and all that, yet they'll allow a closed-source, TOS-breaking third party app to hook into the game's memory every time they log on. Not pointing any fingers, just pointing out the cognitive dissonance there.
I contacted SE and they will be starting a restore process.
I am pretty sure I will be quitting after the restore, liquidate, give gils to friend and quit. it's sorta seeking help i guess. one less thing to worry about now that I don't play. lmao.
in a way this was good, it was a wake up call. If they can do this with ffxi, then my desktop is not safe to do secure transaction. so i am planning on setting up a linux system for use with online banking/paypal and such. I am not saying linux is safe, but it's less targetted.
Another friend who recently joined our LS just posted that he's on Hades server and his sellables are gone.
Really hope SE's staff isn't going to flake out on this like they had so many times before when accounts had been hacked.
fair enough. comparing hooking 98's DOS based kernel to hide nasty behavior to xp's kernel is like comparing repairing a car's engine to a jet turbine. there's still always the threat of an RK hooking the bootloader and basically running the OS in a hypervisor that can jack control or some similarly complicated method, but now we're assuming a lot more creativity than i'd be inclined to believe. still, with packer apps out there that literally automate stealthing applications against AV threats, it would be very surprising to me if each round of malware doesn't come with new tricks and traps to slow us down.
Windower has nothing to do with this. Everyone that posts on this forum just happens to use it. There's a thread over on alla about the same thing, where they're all anti-windower.
True, that's what I was getting at. If these guys are really using such complicated hooks, then we should be seeing it used elsewhere. They wouldn't waste such an exploit that would cost them a lot of time and/or money to produce on a single entity when it can be used for untold gains in its regards.
@windowerguys, you should add a setting that blocks IE from being loaded while Windower is up to force terrible people to not be terrible.
They did a pretty cool thing awhile ago for ppl to put on their websites to prevent it from loading if they were using IE.
Operation Spring Cleaning - Bring down IE6 - Windower
Anyone who was using IE6 would be redirected to:
Operation Spring Cleaning
ok, so i wanted to post keylogger notification image i've been getting but it seems i cant post url till i have 10 post...
In the days of pXI, and the near-complete rending of the source code that makes XI tick, is it really that surprising that someone could come up with a means to hijack an active session of the game?
I don't mean this as a slant against pXI, just pointing it out...if they can make the world work by reverse engineering, someone nefarious can certainly "fake it".
Anyone w/ firefox + the goodies been hit yet?