Account hacked, guild bank gone

2»

Comments

  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    I'm guessing brute force.

    Here's one thing not a lot of people know about battle.net passwords: They suck. They are NOT case sensitive and they are length-capped - only the first (12?) characters of a password are counted.

    So if your password is something "Strong" like:

    DevilCard99FOUR!!33--

    Any brute force of:

    devilcard99f

    DEVILCARD99F

    DeviLCaRD99f

    will work. The rest is truncated.

    If they JUST made their passwords case-sensitive, that would go a long way towards preventing this from happening.

    (Don't believe me? Try your password with various caps, etc.)
  • RyderRyder Kalamazoo, Mi Icrontian

    ....They are NOT case sensitive and they are length-capped - only the first (12?) characters of a password are counted.

    16 characters, because I changed mine to be safe and it should have been 18, but entering 16 works just fine.

  • MyrmidonMyrmidon Baron von Puttenham California Icrontian
    @Lincoln This. I even did a bunch of research on it at my last job (to prove to my bosses that their password system was BS. Did not get promotion. Teach me to busybody).

    Also, brute force must be done using an offline version of something that might required your password to work - in the case of a linux operating system, for instance, if you had the shadow password, you'd be set. For an encryption key, all you'd need is a small encrypted packet. I'm not sure any vulnerability like that exists on battle.net's systems, because they're BIG HONKING OBVIOUS PROBLEMS... I don't think they can brute force your password. They CAN, however, catch you with a keylogger or rootkit - social engineering is TREMENDOUSLY easier than any other method.

    Another important thing to note that sadly Randall Munroe doesn't talk about in his comic is the use of dictionary crackers (but he DOES mention this in the mouseover text) - you can use something like Cain and Abel to try it yourself, but if your password is made up of common dictionary words (or even common misspellings or substitution), brute forcing suddenly becomes much easier. Many password cracking dictionaries include things proper names, text-speech, or leetspeak. Sadly, CorrectHorseBatteryStaple is easily cracked with a dictionary, but C0rrectHorseBttryStaple would thwart dictionaries that didn't include "C0rrect" or "Bttry"... which is most of them.
  • UPSLynxUPSLynx :KAPPA: Redwood City, CA Icrontian



    (Don't believe me? Try your password with various caps, etc.)

    Well holy crap. Who woulda thunk it.
  • UPSLynx said:



    (Don't believe me? Try your password with various caps, etc.)

    Well holy crap. Who woulda thunk it.
    The Chinese?
    BlackHawkCantiBHHammyUPSLynx
  • CycloniteCyclonite Tampa, Florida Icrontian
    UPSLynx said:



    (Don't believe me? Try your password with various caps, etc.)

    Well holy crap. Who woulda thunk it.
    Just tested myself. Are you fucking kidding me?!
    JBoogaloo
  • ChoochChooch K-Pop authority™, Pho King Madison Heights, MI Icrontian

    UPSLynx said:



    (Don't believe me? Try your password with various caps, etc.)

    Well holy crap. Who woulda thunk it.
    The Chinese?
    image
    BHHammyRahnalH102
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
  • CantiCanti =/= smalltime http://www.youtube.com/watch?v=y9K18CGEeiI&feature=related Icrontian
    "Thus, they breached the country’s regulations banning invasive access of “ordinary computer information systems”."

    Theses guys will probably spend a good part of their sentence trying to hack stuff for the Chinese government.
  • fatcatfatcat Mizzou Icrontian

    So here's the thing:

    If you're playing WoW and suddenly, for no reason, it immediately logs out and goes back to the title screen, DO NOT LOG BACK IN.

    Go to worldofwarcraft.com and immediately change your password and add an authenticator.

    just had this happen. didn't take any chances and changed pw
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    Same exact thing just happened to me again. Game froze, logged out. I powered down and re-scanned for malware (nothing found). I have an authenticator now so I don't know.
  • ChoochChooch K-Pop authority™, Pho King Madison Heights, MI Icrontian
    It happened to me too. I changed my pw just in case. Something is going on.
  • Someone (and by someone I mean some group of Chinese hackers) probably have a zero day exploit for WoW itself. Malware scanners won't detect something that they don't know to look for.
  • ThraxThrax 🐌 Austin, TX Icrontian
    Yeah. I imagine that's why nobody's ever been able to conclusively find something with a scanner.
  • primesuspectprimesuspect Beepin n' Boopin Detroit, MI Icrontian
    I'm convinced that the WoW client itself is compromised somehow.
  • TushonTushon I'm scared, Coach Alexandria, VA Icrontian
    Look at that finishing line: An authenticator protects your account 99% of the time

    The authenticator coupled with their beta client launcher thing ... it's awesome.
    oni_delsChooch
  • oni_delsoni_dels Drunk French Canadian Montréal, Québec. Icrontian
    i know i use to have the app thingy on my phone when i was playing...
    never got hacked.
  • RahnalH102RahnalH102 the Green Devout, Veteran Monster Hunter, Creature Enthusiast New Mexico Icrontian
    oni_dels said:
    Update: Turns out it was packaged in a fake Curse Client some people had downloaded from a fake Curse site.
  • pseudonympseudonym Michigan Icrontian
    FYI, make sure you write down the serial number and such for your phone code on the authenticator (Like they tell you to) or else you are not getting back into your account without a photo id. Make sure you do the SMS Protect as well.

    Sincerely, guy who can't get into his battle.net account right now.
    Tushon
  • midgamidga "There's so much hot dog in Rome" ~digi (> ^.(> O_o)> Icrontian
    pseudonym said:

    FYI, make sure you write down the serial number and such for your phone code on the authenticator (Like they tell you to) or else you are not getting back into your account without a photo id. Make sure you do the SMS Protect as well.

    Sincerely, guy who can't get into his battle.net account right nowwon't send Blizzard a photo of his ID.

  • d3k0yd3k0y Loveland, OH Icrontian
    midga said:

    pseudonym said:

    FYI, make sure you write down the serial number and such for your phone code on the authenticator (Like they tell you to) or else you are not getting back into your account without a photo id. Make sure you do the SMS Protect as well.

    Sincerely, guy who can't get into his battle.net account right now won't send Blizzard the NSA a photo of his ID.

    oni_delsRahnalH102JBoogaloo
  • pseudonympseudonym Michigan Icrontian
    Exactly. I had to do it, but the last thing I want to do is send Blizzard a copy of my id.
  • BobbyDigiBobbyDigi ? R U #Hats ! TX Icrontian
    I presume the issue is with Blizzard having your ID? Because thinking the NSA doesn't already have a copy of your government issued ID would just be... silly.

    So what is the concern there?

    -Digi
  • d3k0yd3k0y Loveland, OH Icrontian
    edited January 2014
    He could be using cash paid game time cards and using a fake name on his account while using a laptop at a random internet bar, the NSA might not know how much sugar he likes in his coffee quite yet.

    THEY KNOW EVERYTHING!
  • pseudonympseudonym Michigan Icrontian
    BobbyDigi said:

    I presume the issue is with Blizzard having your ID? Because thinking the NSA doesn't already have a copy of your government issued ID would just be... silly.

    So what is the concern there?

    -Digi

    The concern being the less people having my id the better. Because we all know companies never make a mistake and lose our info to the darkest corner of the web. Right? Guys?

  • JBoogalooJBoogaloo This too shall pass... Alexandria, VA Icrontian
    I ran into this same issue and wasn't going to send my ID. I hopped on the chat function, ten minutes later after answering a couple questions, boom...done. I'm assuming you already tried this and it wasn't successful huh? Bleh...bummer.
  • pseudonympseudonym Michigan Icrontian
    JBoogaloo said:

    I ran into this same issue and wasn't going to send my ID. I hopped on the chat function, ten minutes later after answering a couple questions, boom...done. I'm assuming you already tried this and it wasn't successful huh? Bleh...bummer.

    Bummer is right. Oh well.
Sign In or Register to comment.