WARNING: Possible Hacker attack

A place for The Mana World players to discuss game-related topics outside the scope of development including guilds, player interactions, game meta and more.


User avatar
Nard
Knight
Knight
Posts: 1113
Joined: 27 Jun 2010, 12:45
Location: France, near Paris

WARNING: Possible Hacker attack

Post by Nard »

:evil: WARNING: Possible Hacker attack :evil:

Two of my good friends have had their accounts hacked last week. Tezer had is main char deleted twice and password changed, lvledzero had items in his storage stolen. :( Both of them swear they did not tell their password to anybody. Hacker attack from their computer is likely to have happened though I have no element to be sure of it.
Anyway Both of them use Windows and had no antivirus/spyware protection.
I wonder where they can have catched such malware and which player can be stupid enough to do such things as he would have had much more fun to get the items by himself (or herself). :evil:

Anyway I find the news sufficiently important to make an announcement and to remind everybody to turn on their protection software, and firewalls.

Additionally if devs could be kind enough to complete this warning....
"The language of everyday life is clogged with sentiment, and the science of human nature has not advanced so far that we can describe individual sentiment in a clear way." Lancelot Hogben, Mathematics for the Million.
“There are two motives for reading a book; one, that you enjoy it; the other, that you can boast about it.” Bertrand Russell, Conquest of Happiness.
"If you optimize everything, you will always be unhappy." Donald Knuth.
User avatar
Chicka-Maria
TMW Adviser
TMW Adviser
Posts: 1562
Joined: 19 Feb 2010, 02:10
Location: Internet

Re: WARNING: Possible Hacker attack

Post by Chicka-Maria »

reminder to never give away your information EVEN your username lol
Yubaba
TMWC Member of The Mana World
Leader of The Mana Empire (TME)
[19:41] Ladysugar: he told me to push a setzer up his rear
www.deviantart.com/comfycheeks - Old Deviant Art
William James wrote:Act as If what you do make's a difference, because It does.
User avatar
natsuki3
Novice
Novice
Posts: 222
Joined: 04 Jul 2010, 17:32
Location: /bin/manaplus

Re: WARNING: Possible Hacker attack

Post by natsuki3 »

i can remember yesterday was a n00b asking me about my login and my password , he was saying he will give me items and lvl .
lol but i didnt give to him
Its blue like the sea.
Frost
TMW Adviser
TMW Adviser
Posts: 851
Joined: 09 Sep 2010, 06:20
Location: California, USA

Re: WARNING: Possible Hacker attack

Post by Frost »

There are some fairly elaborate scams around to get your login information. I and each of my alts has been approached (by alts of the same person) on several occasions with the following cover stories:

"If you join my party, I'll give you items. I must log into your account to get you into my party."

"Download manabot from this web site: blahblah. (The web site prompted for my TMW login and password.)

"I found this great web site that will get you level 99. Log in and see for yourself." (web site wanted my TMW login and password, of course.)

"I know a cheat to get to level 99. I won't tell anyone, but I'll run it on your account if you let me log in."


lvledzero says he didn't give away his login info, and I believe him. Still, the grade of idiot who steals accounts in this game is far below the sort of person who can use malware to steal accounts. Frankly, those people have bigger things to attack.

I suspect the thief has been able to guess some passwords. There's a good summary of how to choose secure passwords at https://isc.sans.edu/diary.html?storyid=1528

Briefly:
1) Don't use a word, a name, or all numbers. Base it on a sentence or lyrics to a song. "Mana World is fun, I play it every day!" becomes "MWif,Ipied!" (Yeah, guess that one baby!) (Do NOT use my example as your password!)
2) Write it down or store it in a secure program like Password Safe. Yes, I said write it down. Otherwise you'll end up choosing easy passwords, which is worse.
3) Use a different password for each site. If someone gets your TMW password, do you want them to log into your bank account? Your FaceBook account? Your Paypal account?
4) Don't tell anyone else your password. All reputable sites are designed specifically so that only you need your password, not them. If someone says they need your login info, they're up to no good. Just like in real life, you might trust some friends. If you do, it might be awkward if you discover things are missing from your account -- just like if your friend had a key to your home and your TV got stolen.
5) Changing your password every 30 days or whatever is not nearly as important as making it hard to guess (and hard for you to lose) in the first place. Most people change "g@rb@ge123" to "g@rb@ge456" anyway, which is useless.

Sources: SANS articles, Bruce Schneier's excellent Crypto-Gram, various vendor whitepapers and "best practices" documents, and my own experience in IT security.
You earn respect by how you live, not by what you demand.
-unknown
Frost
TMW Adviser
TMW Adviser
Posts: 851
Joined: 09 Sep 2010, 06:20
Location: California, USA

Re: WARNING: Possible Hacker attack

Post by Frost »

natsuki3 wrote:i can remember yesterday was a n00b asking me about my login and my password , he was saying he will give me items and lvl .
lol but i didnt give to him
Natsuki, aka s-mack, superbuster, heinz guro, and chiribo
You earn respect by how you live, not by what you demand.
-unknown
Matt
Grand Knight
Grand Knight
Posts: 1759
Joined: 07 Aug 2004, 10:47
Location: Germany->Bavaria

Re: WARNING: Possible Hacker attack

Post by Matt »

If you want to make your account resistent to all kinds of attacks and spoofes just pm me your account name and account password, I can activate the alpha-hacking-protection for your account then.

Its not rolled out yet because its still in its alpha phase, but it works like a charm :)
User avatar
argul
Novice
Novice
Posts: 237
Joined: 08 Aug 2010, 18:43

Re: WARNING: Possible Hacker attack

Post by argul »

Matt wrote:If you want to make your account resistent to all kinds of attacks and spoofes just pm me your account name and account password, I can activate the alpha-hacking-protection for your account then.

Its not rolled out yet because its still in its alpha phase, but it works like a charm :)
Please do so with my account Matt! Help me getting it secure!

Here is my account: gonzalio
and my password: passw0rD
---
Matt
Grand Knight
Grand Knight
Posts: 1759
Joined: 07 Aug 2004, 10:47
Location: Germany->Bavaria

Re: WARNING: Possible Hacker attack

Post by Matt »

Your account is now unhackable secured!

Bind to your machine, like this one:

http://watchplayread.com/gabe-newell-pu ... eam-guard/
The Steam Guard feature links your user account for Steam to your computer’s specific identifiers. So if someone were to know your user/pass and tried to access it from any computer that isn’t authorized under the Steam account, it wouldn’t work and the user would be immediately notified, which is pretty damn cool.
User avatar
Crush
TMW Adviser
TMW Adviser
Posts: 8046
Joined: 25 Aug 2005, 16:08
Location: Germany

Re: WARNING: Possible Hacker attack

Post by Crush »

It's an interesting concept, but unfortunately with one big drawback: when your computer breaks down due to a hardware failure in one of the components used for fingerprinting it, there is no way to get back into your account.

Accidently frying my processor or mainboard is more likely for me than leaking my steam password.
  • former Manasource Programmer
  • former TMW Pixel artist
  • NOT a game master

Please do not send me any inquiries regarding player accounts on TMW.


You might have heard a certain rumor about me. This rumor is completely false. You might also have heard the other rumor about me. This rumor is 100% accurate.
User avatar
Crush
TMW Adviser
TMW Adviser
Posts: 8046
Joined: 25 Aug 2005, 16:08
Location: Germany

Re: WARNING: Possible Hacker attack

Post by Crush »

Ah, and to get the discussion back to TMW: Although I don't think that we can have something like that on tmwAthena, we could do something like that on ManaServ without even needing a server change.

On Manaserv, the client hashes the passwords locally before sending them to the server. This is to make sure that no cleartext passwords are sent through the net.

We could add an option at account creation to create a "secured account". In that case the password gets salted with some hardware information from the system before sending it. This makes sure that the account can only be accessed from the same machine.

A potential attack to this system would be to obtain the hardware identifiers of the user in some way together with its password, but I am quite sure Steam is vulnerable to this attack, too.
  • former Manasource Programmer
  • former TMW Pixel artist
  • NOT a game master

Please do not send me any inquiries regarding player accounts on TMW.


You might have heard a certain rumor about me. This rumor is completely false. You might also have heard the other rumor about me. This rumor is 100% accurate.
User avatar
Big Crunch
TMW Adviser
TMW Adviser
Posts: 1056
Joined: 16 Dec 2009, 22:52

Re: WARNING: Possible Hacker attack

Post by Big Crunch »

Frost wrote:There are some fairly elaborate scams around to get your login information. I and each of my alts has been approached (by alts of the same person) on several occasions with the following cover stories:

"If you join my party, I'll give you items. I must log into your account to get you into my party."

"Download manabot from this web site: blahblah. (The web site prompted for my TMW login and password.)

"I found this great web site that will get you level 99. Log in and see for yourself." (web site wanted my TMW login and password, of course.)

"I know a cheat to get to level 99. I won't tell anyone, but I'll run it on your account if you let me log in."


lvledzero says he didn't give away his login info, and I believe him. Still, the grade of idiot who steals accounts in this game is far below the sort of person who can use malware to steal accounts. Frankly, those people have bigger things to attack.

I suspect the thief has been able to guess some passwords. There's a good summary of how to choose secure passwords at https://isc.sans.edu/diary.html?storyid=1528

Briefly:
1) Don't use a word, a name, or all numbers. Base it on a sentence or lyrics to a song. "Mana World is fun, I play it every day!" becomes "MWif,Ipied!" (Yeah, guess that one baby!) (Do NOT use my example as your password!)
2) Write it down or store it in a secure program like Password Safe. Yes, I said write it down. Otherwise you'll end up choosing easy passwords, which is worse.
3) Use a different password for each site. If someone gets your TMW password, do you want them to log into your bank account? Your FaceBook account? Your Paypal account?
4) Don't tell anyone else your password. All reputable sites are designed specifically so that only you need your password, not them. If someone says they need your login info, they're up to no good. Just like in real life, you might trust some friends. If you do, it might be awkward if you discover things are missing from your account -- just like if your friend had a key to your home and your TV got stolen.
5) Changing your password every 30 days or whatever is not nearly as important as making it hard to guess (and hard for you to lose) in the first place. Most people change "g@rb@ge123" to "g@rb@ge456" anyway, which is useless.

Sources: SANS articles, Bruce Schneier's excellent Crypto-Gram, various vendor whitepapers and "best practices" documents, and my own experience in IT security.
Thanks for posting solid advice Frost.
sexy red bearded GM
User avatar
Chicka-Maria
TMW Adviser
TMW Adviser
Posts: 1562
Joined: 19 Feb 2010, 02:10
Location: Internet

Re: WARNING: Possible Hacker attack

Post by Chicka-Maria »

Big Crunch wrote:
Frost wrote:There are some fairly elaborate scams around to get your login information. I and each of my alts has been approached (by alts of the same person) on several occasions with the following cover stories:

"If you join my party, I'll give you items. I must log into your account to get you into my party."

"Download manabot from this web site: blahblah. (The web site prompted for my TMW login and password.)

"I found this great web site that will get you level 99. Log in and see for yourself." (web site wanted my TMW login and password, of course.)

"I know a cheat to get to level 99. I won't tell anyone, but I'll run it on your account if you let me log in."


lvledzero says he didn't give away his login info, and I believe him. Still, the grade of idiot who steals accounts in this game is far below the sort of person who can use malware to steal accounts. Frankly, those people have bigger things to attack.

I suspect the thief has been able to guess some passwords. There's a good summary of how to choose secure passwords at https://isc.sans.edu/diary.html?storyid=1528

Briefly:
1) Don't use a word, a name, or all numbers. Base it on a sentence or lyrics to a song. "Mana World is fun, I play it every day!" becomes "MWif,Ipied!" (Yeah, guess that one baby!) (Do NOT use my example as your password!)
2) Write it down or store it in a secure program like Password Safe. Yes, I said write it down. Otherwise you'll end up choosing easy passwords, which is worse.
3) Use a different password for each site. If someone gets your TMW password, do you want them to log into your bank account? Your FaceBook account? Your Paypal account?
4) Don't tell anyone else your password. All reputable sites are designed specifically so that only you need your password, not them. If someone says they need your login info, they're up to no good. Just like in real life, you might trust some friends. If you do, it might be awkward if you discover things are missing from your account -- just like if your friend had a key to your home and your TV got stolen.
5) Changing your password every 30 days or whatever is not nearly as important as making it hard to guess (and hard for you to lose) in the first place. Most people change "g@rb@ge123" to "g@rb@ge456" anyway, which is useless.

Sources: SANS articles, Bruce Schneier's excellent Crypto-Gram, various vendor whitepapers and "best practices" documents, and my own experience in IT security.
Thanks for posting solid advice Frost.

lol
Yubaba
TMWC Member of The Mana World
Leader of The Mana Empire (TME)
[19:41] Ladysugar: he told me to push a setzer up his rear
www.deviantart.com/comfycheeks - Old Deviant Art
William James wrote:Act as If what you do make's a difference, because It does.
User avatar
yourmistakes
Knight
Knight
Posts: 695
Joined: 05 Dec 2009, 06:08
Location: North Korea
Contact:

Re: WARNING: Possible Hacker attack

Post by yourmistakes »

how long will it take until people begin using such basic security practices?
User avatar
Hello=)
The Mana World
The Mana World
Posts: 701
Joined: 11 Jun 2009, 12:46

Re: WARNING: Possible Hacker attack

Post by Hello=) »

Crush wrote:Ah, and to get the discussion back to TMW: Although I don't think that we can have something like that on tmwAthena
From what I seen in login server code, eA actually supports hashed passwords as well (so they do not have to be sent as plain text). However it does not looks like if this mode used and I'm not even aware if client supports this mode at all.
User avatar
Eragon
Peon
Peon
Posts: 47
Joined: 13 Aug 2010, 10:04
Location: Somewhere in a hidden place in Planet Earth

Re: WARNING: Possible Hacker attack

Post by Eragon »

Nice thread but isn't it possible to add a chat filter just like most online games do?
For example my password is PeaceWorld.
And when I enter PeaceWorld in chat, it shows like **********?
I don't know if that is possible, but its still nice ^^
Post Reply