Wow Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 21 May 2010

MMO-Champion hacked

Posted on 17:25 by Unknown
The team at the popular WoW fan site MMO-champion have announced that their site was recently hacked. What happened here and how can you best protect yourself against malicious code on legitimate web pages?

The malicious code was Gumblar - a malicious piece of javascript that was placed on their pages.

How did the malicious code get there?

This is a question that has not been answered by the web site owners. However, it is likely to be one of the following causes:
  1. The mmo-champion.com site was hacked and the code was manually planted there by the attacker. There are multiple ways this could have happened, but one common way is via SQL-Injection.
  2. One of their admins was infected on their own PC and their FTP login details were used by the malware to log in to the mmo-champion.com web servers and automatically infect their files.
Hackers often target legitimate web sites, especially high traffic sites, so that they get the widest exposure to their malware.

What is the malicious code designed to do?

According to a Gumbar Q&A, the malicious code redirects a user to a malicious web site that contains specially crafted PDF or flash files that automatically infect your machine if you do not have your Adobe flash player patched. The malware that it installs can redirect your google searches and replace search results with links to malicious sites. It also harvests FTP information from your machine so that it can try to automatically inject code on other web servers. Finally, it can open a back door so that your machine can be controlled remotely.

Could I have been infected from MMO-champion?

The team at mmo-champion claim that the malicious code was only on their site for 30 mins before it was detected, shut down and subsequently cleaned.

If you browsed the site in that time, you probably would have noticed an attempt to redirect your browser to another web site. Many browsers have in-built blocking mechanisms so you may have seen a big red message on your browser advising you that you are about to visit a malicious web site. If you proceeded, and the malicious web site was online at the time, then you would have been exposed to malicious pdf or flash files. If, and only if, your Adobe flash player was not patched, then these malicious files may have automatically executed. If you were running up-to-date and mainstream antivirus products then it should have been detected and stopped at this stage.

The short answer is, you may have been infected but you would have needed to have no antivirus (or poor antivirus), no recent patching of your Adobe flash player and would have needed to visit the site in the 30 mins when the code was there.

If you think your machine is infected then try this free web-based scanner - Housecall

Does it steal my WoW account info?

No, but if you were infected then you still need to clean it off your machine since it may compromise any FTP sites that you might visit, install a backdoor and your search engine results may be replaced with malicious sites. This is not the type of malware that you want on your PC.

Would the firefox 'noscript' add-on help?

Probably, although if you are a regular mmo-champion visitor then you would have been likely to nominate their site as a trusted site in noscript - resulting in noscript having no effect. Noscript is a great security measure, but it breaks a lot of sites. It is the old security vs usability trade-off.

What can I do to protect myself against these attacks?
  1. Make sure your software is fully patched - this includes your operating system (OS), browser, flash player, javascript, etc. Most people just worry about patching their OS, but there are many other avenues for exploiting software vulnerabilities on your PC.
  2. Make sure you run reputable anti-virus on your system - and make sure it is always updated.
  3. Don't ignore your browser when it tells you that the site you are about to go to is potentially dangerous.
  4. Get yourself an authenticator. Even though this malware is not written to steal WoW information, the next one might be. An authenticator is a last line of defense, and may prove to be your savior should all else fail.
Finally, don't assume you can't get infected by malware without user interaction - you can! You can pick up malware simply by visiting a web page and you won't even know it is happening. This is why you need several defense mechanisms in your security arsenal.


Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in gumblar, hacked, mmo-champion | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Diablo 3 Beta Phishing Season Begins
    The scammers are out in force with the recent Diablo 3 beta opt-in announcement.   Phishing scams are very common around any Blizzard beta ...
  • What would happen if people could trade?
    The question of mirror-ability of strategies often comes up when I post my trading strategy. The 0.01 strategy is clearly mirror-able. If th...
  • Tragedy of commons (and non-TC alliances)
    The tragedy of commons is a well-known economical problem, described by the anecdote: "herders sharing a common parcel of land, on whi...
  • A new approach to fight botting
    Botting is a widespread plague of MMOs. A botter can gain insane amount of game resources since it “farms for free”: the time of the bot cos...
  • The war for Finanar
    Finanar is a 0.5 system in Metropolis with 3 ice anomalies. If you check out my corp killboard you see lot of kills there, about 8B destro...
  • The (total lack of) balance of trade of highsec
    The fact that you can be much more rich in highsec than in the competitive areas of EVE (low, null, WH) is one of my main messages. It can b...
  • Planetary interaction for beginners
    Planetary interaction isn't a really profitable enterprise. However the "newbie-version" is a "printing money" schem...
  • Nullsec-altruism and a free titan
    Imagine that you are an avatar in Diablo 3. You enter New Tristram after defeating some risen dead. The town is clearly in danger. The undea...
  • The myth of the skilled, goodfight-seeking PvP-er
    While no sane man would claim that pilot skill decides large engagement instead of strategic decisions, there is a claim that there are skil...
  • (I'm not) defining lowsec
    This is a rather short post, will be one more today, about my very first PvP action. Sugar reminded me of a problem that I read about a l...

Categories

  • account
  • account theft
  • adobe
  • alpha
  • arena tournament
  • authenticator
  • authenticators
  • battle.net
  • beta
  • blizzard
  • brute force
  • cataclysm
  • diablo 3 phishing scam
  • dictionary attack
  • drive-by
  • email
  • fake
  • flash
  • game
  • Gold
  • guild
  • gumblar
  • hacked
  • hacking
  • hacks
  • Ideas
  • ISK
  • keylogger
  • march
  • mmo-champion
  • New
  • password
  • password stealing
  • patching
  • phishing
  • raiding
  • Random
  • ranks
  • remote auction house
  • scam
  • scams
  • security
  • security checklist
  • soccer
  • strong password
  • trojan
  • vulnerability
  • warcraft
  • wow
  • wowarmory
  • wowmatrix

Blog Archive

  • ►  2013 (242)
    • ►  November (15)
    • ►  October (25)
    • ►  September (24)
    • ►  August (21)
    • ►  July (24)
    • ►  June (22)
    • ►  May (22)
    • ►  April (22)
    • ►  March (20)
    • ►  February (21)
    • ►  January (26)
  • ►  2012 (261)
    • ►  December (24)
    • ►  November (21)
    • ►  October (24)
    • ►  September (21)
    • ►  August (26)
    • ►  July (25)
    • ►  June (20)
    • ►  May (25)
    • ►  April (23)
    • ►  March (23)
    • ►  February (23)
    • ►  January (6)
  • ►  2011 (4)
    • ►  September (1)
    • ►  April (1)
    • ►  March (1)
    • ►  January (1)
  • ▼  2010 (17)
    • ►  November (1)
    • ►  September (2)
    • ►  August (1)
    • ►  July (1)
    • ►  June (2)
    • ▼  May (2)
      • Suffer mortals, as your pathetic password betrays ...
      • MMO-Champion hacked
    • ►  April (1)
    • ►  March (2)
    • ►  February (2)
    • ►  January (3)
  • ►  2009 (4)
    • ►  December (1)
    • ►  October (1)
    • ►  September (1)
    • ►  July (1)
Powered by Blogger.

About Me

Unknown
View my complete profile