Item Search
     
BG-Wiki Search
Page 46 of 47 FirstFirst ... 36 44 45 46 47 LastLast
Results 901 to 920 of 931
  1. #901
    RIDE ARMOR
    Join Date
    Oct 2007
    Posts
    11
    BG Level
    1

    I had been playing for a long time yesterday, and at some time during the wee hours (I think it was around 1am) I was booted with the same message a lot of victims receive about being logged in from another terminal. Unlike others that have been hacked, POL didn't crash to boot up a compromised password entry. I was using Windower 3.3 at the time, and when I was booted back to the Playonline client the same window was still up, and it let me simply click to log back in and allowed me to do so without any problem. I soon changed my passwords on another PC.

    I have the security token, Firefox, NoScript (IFRAMES disabled, settings applied to trusted sites), and Adblock. What's odd, also, is that I VERY rarely play FFXI. Maybe once every couple weeks, but when I do it's for a long time. If it were a case of SE's servers being hacked, then it's strange that the attempt would only happen during the rare time when I was playing.

    So, thinking it's compromised security on my side, I've been scanning with all manner of anti-virus, anti-root-kit, anti-malware, etc., only to turn up nothing. One thing I did get was that Housecall 7.0 flagged launcher.exe from Windower 3.3 as possibly being malicious software, but it didn't do so on the other PC. This PC had version 3.3 while the other has 3.4 (according to the Readme.txt, the launcher.exe file actually says it's 3.3 also).

    So far I've run full system scans with Avast, Windows Defender, Housecall 7.0, Rootkit Buster, Anti-Malware, Spybot S&D, Avira AntiVir, and Avira AntiRootkit. Nothin' other than the flag on launcher.exe. I might pick up BitDefender or NOD32 tomorrow to scan deeper. Anyone have any more suggestions on what I should check with? Anybody still reading HJT logs here?

    Also, have any of the people that've reported being hacked actually managed to find proof of infection on their PC? Thus far I haven't seen anyone reporting what, exactly, is doing this.

  2. #902
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,514
    BG Level
    6

    Are you absolutely certain the "Playonline client" was the real one when you saw it was still up?

  3. #903
    RIDE ARMOR
    Join Date
    Oct 2007
    Posts
    11
    BG Level
    1

    Yeah, when I received the message and was booted from FFXI it sent me straight back to POL as it normally would in the event of a DC, and the window said PlayOnline Viewer Ver.1.18.12b - Windower Enabled, just as it normally does. I was able to log back in immediately; so far everyone that's had their client compromised notes that it crashes completely before loading a new client. This didn't appear to be the case from what I can tell.

  4. #904
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,514
    BG Level
    6

    Sounds like you were booted and your "ghost" (irc term) was still on the server so it saw you as the second instance of your account when you logged in too soon for the other to log out completely. Sorry I do not know the actual terms for this related to pol/xi disconnects but this has happened to me before though it was way back before this wave of hackings started.

  5. #905
    RIDE ARMOR
    Join Date
    Oct 2007
    Posts
    11
    BG Level
    1

    Unfortunately, that wasn't the case. I was online and then suddenly, out of nowhere, it went to a black screen with the "account logged in from another terminal" message. So it wasn't from me trying to log back in after a regular DC. The logging back in part went fine (surprisingly) and seemingly without interference.
    Edit:
    I've read nearly the entire thread now, and my scenario most closely matches Narse on page 3: booted with "logged in from another terminal" message, no problem logging back on and nothing lost, no sign of infection.
    The "no sign of infection" fact is pretty troubling. I can't log in again until I know it's clean. I'm thinking my best course of action would be to back up my important things to an external HD (hopefully without backing up the keylogger) and reformat.

  6. #906
    New Spam Forum
    Join Date
    Jul 2007
    Posts
    197
    BG Level
    3
    FFXI Server
    Gilgamesh

    When the security token first came out it was verified that if someone were to login to your POL account and not the SE account it would kick you off. This seems to be the case in your situation. Most likely your POL account information was compromised but not your security token. If you were already online the one-time key you had used had already been consumed and could not have been reused again.

    This mechanic seems to be done by design. Most likely to help the user identify that 1 part of their 3 part security has been compromised. 3 parts including: POL account information, SE account information, and one time password Token.

    Addition: Let me clarify... It would kick you off with the terminal message but they would not really be able to fully login.

  7. #907
    RIDE ARMOR
    Join Date
    Oct 2007
    Posts
    11
    BG Level
    1

    When the security token first came out it was verified that if someone were to login to your POL account and not the SE account it would kick you off.
    Hmm, so that's true? I'll test that when I get home. That actually raises as many questions as it answers on my end. It's also been confirmed that only a correct POL password will kick someone off.

    I scanned thoroughly with NOD32 and turned up nothing. I'll have it scan again tonight. So far it seems like my system is squeaky-clean, much to my surprise if it holds true (provided that the detection on Windower was a false positive). If it's the same old POL ID and password stealer, then it should have been detected by now. If I truly haven't been infected, then that means my POL ID and password were stolen by some other method. Others have theorized that attackers have managed to pull info from SE's registration servers or the LS community site somehow... At this point, I would have to consider that as a possibility. I actually did log in to the LS community site a few weeks ago to remove my all of my characters' info due to paranoia (how ironic if by doing so I handed over my POL ID and password).

    Would running Firefox in Sandboxie provide near-immunity from being infected? I previously always ran FFXIAH in Sandboxie, which supposedly saves all files to a partitioned area where they can't infect the rest of the drive, allowing you to clear out all of those files instantly. After I got the token, I got slack on using Sandboxie, and trusted NoScript and Adblock to do the job.

  8. #908
    New Spam Forum
    Join Date
    Jul 2007
    Posts
    197
    BG Level
    3
    FFXI Server
    Gilgamesh

    Quote Originally Posted by Pepperblix View Post
    Hmm, so that's true? I'll test that when I get home. That actually raises as many questions as it answers on my end. It's also been confirmed that only a correct POL password will kick someone off.

    I scanned thoroughly with NOD32 and turned up nothing. I'll have it scan again tonight. So far it seems like my system is squeaky-clean, much to my surprise if it holds true (provided that the detection on Windower was a false positive). If it's the same old POL ID and password stealer, then it should have been detected by now. If I truly haven't been infected, then that means my POL ID and password were stolen by some other method. Others have theorized that attackers have managed to pull info from SE's registration servers or the LS community site somehow... At this point, I would have to consider that as a possibility. I actually did log in to the LS community site a few weeks ago to remove my all of my characters' info due to paranoia (how ironic if by doing so I handed over my POL ID and password).

    Would running Firefox in Sandboxie provide near-immunity from being infected? I previously always ran FFXIAH in Sandboxie, which supposedly saves all files to a partitioned area where they can't infect the rest of the drive, allowing you to clear out all of those files instantly. After I got the token, I got slack on using Sandboxie, and trusted NoScript and Adblock to do the job.
    I know you're hoping for the glimpse chance that your systems clean and that the SE LS community servers were hacked and that your POL information was lost in that manner. However, the probability of SE's server's being hacked with almost no response from the community (of being many people being hacked) is very low. Furthermore, it doesn't serve any purpose for you to suspect that in your current position. The fact of the matter is that someone tried to login to your account from another terminal.

    The reliance on software scanning utilities to find specialized exploits after you've been compromised is not good self assurence. I feel you should reformat and do a clean install to verify that you have eliminated any threats. Then change your POL credentials and refrain from using LS community if you fear it being hacked.

    Good luck.

  9. #909
    RIDE ARMOR
    Join Date
    Jan 2009
    Posts
    21
    BG Level
    1

    my mule just got hacked too, lost my nana great katana off pw and other items (blm related: novio, etc)....

    if anyone has seen something within the last 2-3 weeks, let me know please.

  10. #910
    RIDE ARMOR
    Join Date
    Oct 2007
    Posts
    11
    BG Level
    1

    Sound advice, AoshiZ, thanks. I haven't reformatted yet, but I haven't played FFXI either. Everything's still safe at the moment.

    Sorry to hear about that Ars5, have you done any scans yet? If not, please download any of the free scanning software out there such as Avast, Windows Defender, Housecall 7.0, Rootkit Buster, Anti-Malware, Spybot S&D, Avira AntiVir, Avira AntiRootkit, Threatfire, etc., these are all free, and all of the paid AV software also have trials you can use. If you already have anti-virus software and it hasn't found anything, then I'd strongly suggest downloading more scanning tools, or reformatting just as AoshiZ recommended... it's the only way to (possibly) eliminate infection if nothing can detect it.

    If we can identify FFXI-specific keyloggers we'll be able to figure out how to remove and prevent infections. The problem is that FFXI-specific malware are all new and unknown to most anti-virus programs, so they have to be detected by behavior (heuristics scanning), and each scanner's detection spectrum varies.

    I scanned the PC I previously presumed to be safe and found an LSP Hijacker using Malwarebytes Anti-Malware. It only found a registry entry, and I haven't found the files that correspond to it. The malicious entry was in HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\W inSock2\Xstudio_Packet_Capture, but unfortunately Anti-Malware didn't show me what .dll files might have been associated with it. Anti-Malware removed the entry and it hasn't resurfaced, but I'll be running further tests. This may have been the infection I was looking for all along.

    I can't post relevant links about this yet, but on Malwarebytes' entry about LSP hijackers it mentions that it was first discovered on August 11th of this year. Funny how we saw many new incidents of account theft popping up around that time (for example, this thread started on August 22nd). If you Google the registry entry above it should point to a thread with info about dealing with such an infection.

    I also scanned my presumed unsafe PC with G Data Antivirus 2010, a monster of a program (it's huge and the first run of updates takes ages) which boasts an incredible detection rate according to the most recent report from AV-Comparatives. I'm going to have it scan the other previously assumed safe PC to see what it detects. Oh, and I had NOD32 scan that PC a few days ago and it didn't find anything.

  11. #911
    Relic Shield
    Join Date
    Jul 2006
    Posts
    1,857
    BG Level
    6

    lolGoogleChrome too, I guess.

    My mule account was hacked tonight as I was playing on 360. Got kicked out with the message the account was logged in from another console, by the time I got back to the login page, the password had already been changed. I use FFXIAH and Wiki within Google Chrome (With Privoxy), trojan found was UpxGui.exe. Fun facts: I logged onto that account exactly once from PC, I ordered my security token two weeks ago, and the idiot Chinaman chose the account with little more than 8 million gil and a set of HQ staves instead of my main.

    GM was reasonably fast at freezing, so probably all it did was derail my Astralburn group.

  12. #912
    A. Body
    Join Date
    Jul 2008
    Posts
    4,046
    BG Level
    7
    FFXI Server
    Caitsith

    Quote Originally Posted by Weeks View Post
    lolGoogleChrome too, I guess.

    My mule account was hacked tonight as I was playing on 360. Got kicked out with the message the account was logged in from another console, by the time I got back to the login page, the password had already been changed. I use FFXIAH and Wiki within Google Chrome (With Privoxy), trojan found was UpxGui.exe. Fun facts: I logged onto that account exactly once from PC, I ordered my security token two weeks ago, and the idiot Chinaman chose the account with little more than 8 million gil and a set of HQ staves instead of my main.

    GM was reasonably fast at freezing, so probably all it did was derail my Astralburn group.
    I wouldn't call the ones who did the hacking an 'idiot chinaman' even if they chose a less than spectacular character to strip. If you had 8 million and HQ staves (couple mil?) with gil going @ $29/mil or so last tell I got in game..they aren't that dumb as they just got paid.

    Also, Google Chrome is basically IE, and I don't recall much of any ad-blocking and script removal features of said browser.

  13. #913
    Sea Torques
    Join Date
    Jan 2007
    Posts
    527
    BG Level
    5
    FFXI Server
    Asura

    Google Chrome is pretty but worthless. When it first came out I posted a question to their message boards about add-ons similar to noscript and adblock like we have for firefox and my post was deleted. They don't even want to admit that it's not secure lol.

  14. #914
    Melee Summoner
    Join Date
    Dec 2007
    Posts
    24
    BG Level
    1

    sorry for bringing back a dead post but I didn't see a current one, so I will reply here.

    2 years ago my wife and me were hacked took 8 months to get our accounts back now on march 27th 2010 her account was hacked again through a security token, and they deactivated the token on the account making is so SE tells us they have to "investigate" in order to do a roll back because the token is no longer linked.

    has anyone had this issue and how long did it take to have token issue fixed? :/ it's been 2 months and they keep telling us all we can do is wait for these people who are supposedly looking into the token issue.

    This seems all too familiar to the last time we were hacked :/

    on her account she lost millions in gear over 10mil in gil and about 70mil+ in dynamis currency she was saving for relic...

    thanks for any info

    also before it gets posted we have been using firefox with no script and ad block and haven't even went to any ffxi or ffiv sites with our gaming systems since the last hack 2 years ago, so we have no idea how this could have happened though she did get the issue with being DC then not being able to log in until she rebooted, I am guessing the attempted logon token keys that did not log on were used to disable her token and that's how they took over the account.

  15. #915
    If you stopped to actually learn something you might not post these uninformed posts.
    Join Date
    Oct 2006
    Posts
    1,493
    BG Level
    6

    there is most likely a virus on your computer that intercepted the token key.

    When you logged in to see that account hacked, how many times did you try to log in?

  16. #916
    Melee Summoner
    Join Date
    Dec 2007
    Posts
    24
    BG Level
    1

    twice, which is enough to log onto SE accounts and disable token I know.

    we scanned system with a few programs then decided to format because of no results

    was just wondering if anyone else had this happen and how long it took SE to "investigate" if the token was deactivated by us or hacker.

  17. #917
    You fall, we haul. Saving your Ass is my business
    Join Date
    May 2008
    Posts
    488
    BG Level
    4
    FFXI Server
    Sylph

    Actually, I just had this happen to me and Im pissed. I havent logged on the game since feb. Have token activated etc etc. Everythings changed and Someone ingame told me they sawq me running around like a month ago. I use chrome( used ) and I did find a virus on my comp sadly Fresh formated etc etc firefox blah blah now. But still able to get on with a token activated on the account? Anyway on the chat support with SE now. YAY to putting up with their bs trying to get my shit back...

  18. #918
    Melee Summoner
    Join Date
    Dec 2007
    Posts
    24
    BG Level
    1

    so SE determined the token was not active when the account was hacked. which it was so I guess they just fail at reading IP logs.

    so because of that they refuse to do a restore after 2 months of making us wait to do this "investigation" on the token...

  19. #919
    Hydra
    Join Date
    Sep 2009
    Posts
    112
    BG Level
    3
    FFXI Server
    Siren

    Not sure if this is new but here goes...

    I normally play ffxi on my pc and browse the internet on my laptop because its annoying swapping back and forth in windowed mode.

    I accidentally clicked one of the ads on ffxiah and my computer started to spaz out. Some fake antivirus thing installed itself and it disabled my ctrl alt delete. I couldn't even force it to stop.

    Might be some way they use to get control of accounts for people who play in windowed mode/windower and bypass token.

    TL/DR:
    No script + firefox = good

  20. #920
    E. Body
    Join Date
    Nov 2008
    Posts
    2,048
    BG Level
    7
    FFXI Server
    Bismarck

    Quote Originally Posted by Jado818 View Post
    Not sure if this is new but here goes...

    I normally play ffxi on my pc and browse the internet on my laptop because its annoying swapping back and forth in windowed mode.

    I accidentally clicked one of the ads on ffxiah and my computer started to spaz out. Some fake antivirus thing installed itself and it disabled my ctrl alt delete. I couldn't even force it to stop.

    Might be some way they use to get control of accounts for people who play in windowed mode/windower and bypass token.

    TL/DR:
    No script + firefox = good
    I had the same situation last week. Was driving me nuts. Any program that might have terminated it, like ctrl+alt+del, msconfig, as well as firefox, vent, etc, was infected and wouldn't allow it. I had to go under a different username on the PC and terminate the program, then locate the root startup files and delete them. Was a pain in the ass

Page 46 of 47 FirstFirst ... 36 44 45 46 47 LastLast

Similar Threads

  1. What in the fuck is going on with Ancient Currency prices?
    By Avarice in forum FFXI: Everything
    Replies: 22
    Last Post: 2009-01-12, 05:21
  2. Ok what the hell is up with Roc?
    By S N K in forum FFXI: Everything
    Replies: 49
    Last Post: 2008-06-28, 21:00
  3. Oldschool players with JP Accounts & The new Expansion
    By Lyramion in forum FFXI: Everything
    Replies: 39
    Last Post: 2007-11-24, 01:31