Wow Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Sunday, 4 September 2011

Diablo 3 Beta Phishing Season Begins

Posted on 19:59 by Unknown
The scammers are out in force with the recent Diablo 3 beta opt-in announcement.  

Phishing scams are very common around any Blizzard beta release announcement so it is time to be especially on your guard.


I received the following in my in-box today:

Greetings from Blizzard Entertainment!
We’re gearing up for the forthcoming launch of Diablo III and would like to extend you an invitation toparticipate in the beta test. If you are interested in participating, you need to have a Battle.net account, which you can create on our Battle.net website.
We will flag you for access to the Diablo III beta test when we begin admitting press. You do not need to go through the opt-in process.
To secure your place among the first of Sanctuary’s heroes,Please use the following template below to verify your account and information via email.
* Name:
* Battle.account name:
* Password:
* Country:
* E-mail Address:
Thanks and see you all in the Burning Hells!

The email claims to give you an express beta invite without having to go through the formal opt-in process. Naturally, this is a phishing attempt aimed at getting hold your valuable battle.net account details. The reply email address resolves into a d3-blizzard.com domain which, not-so-surprisingly, is registered in China:

Domain Name: D3-BLIZZARD.COM
Registrar: HICHINA ZHICHENG TECHNOLOGY LTD.
Whois Server: grs-whois.hichina.com
Referral URL: http://www.net.cn
Name Server: DNS27.HICHINA.COM
Name Server: DNS28.HICHINA.COM
Status: ok
Updated Date: 29-aug-2011
Creation Date: 29-aug-2011
Expiration Date: 29-aug-2012

Remember, Blizzard will never ask your for your battle.net password - be wary of any communications that requests this.
Read More
Posted in diablo 3 phishing scam | No comments

Tuesday, 5 April 2011

Top WoW Phishing Scams for March 2011

Posted on 22:20 by Unknown
I have established a WoW phishing honeypot and I see a lot of active phishing scams.  I thought I would take the time to cover off the top two WoW phishing scams for March :

#1 Titled "Too Many Attempts Warning No.x" - 37% of WoW scams

The most common phishing scam for March comes in the form of a straight text email that warns you that your account has been locked due to too many login attempts. It provides a link to restore your account, but naturally points to a fake battle.net site, where your account details are captured.

-----------------------------------------------------------------------------
Dear customer, 
Due to suspicious activity, your Battle.net account has been locked. You tried to login your account too many times (403). We are concerned about whether your account has been stolen. In order to guarantee the legitimacy of your account, we need you follow these steps:

Step 1: Secure Your ComputerIn the event that your computer has been infected with malicious software such as a keylogger or trojan, simply changing your password may not deter future attacks without first ensuring that your computer is free from these programs. Please visit our Account Security website to learn how to secure your computer from unauthorized access.

Step 2: Secure Your E-mail AccountAfter you have secured your computer, check your e-mail filters and rules and look for any e-mail forwarding rules that you did not create. For more information on securing your e-mail account, visit our Support page.

Step 3: Restore access to Your accountWe now provide a secure link for you to verify whether you have taken the appropriate steps to secure the account, your computer, and your email address. Please follow this site to restore the access to your account: xxxxxxxxxxxxxxxxxxxxxxxxxxxx

If you still have questions or concerns after following the steps above, feel free to contact Customer Support at xxxxxxxxxxxxxxxxxxx.

Sincerely, 
The Battle.net Account Team 
Online Privacy Policy
-----------------------------------------------------------------------------


#2 Titled "Account Change" - 26% of WoW scams

This scam attempts to scare you into thinking that your contact information has been illegally modified and entices you to log in to a fake site to verify your account information.

-----------------------------------------------------------------------------
Hello,
This is an automated notification regarding your Battle.net account. Some or all of your contact information was recently modified through the Account Management website.

*** If you made recent account changes, please disregard this automatic notification.
*** If you did NOT make any changes to your account, we recommend you log in to xxxxxxxxxxxxxxxxxxxx review your account settings.

If you cannot sign into Account Management using the link above, or if unauthorized changes continue to happen, please contact Blizzard Billing & Account Services for further assistance.

Billing & Account Services can be reached at 1-800-59-BLIZZARD (1-800-592-5499 Mon-Fri, 8AM-8PM Pacific Time) or at billing@blizzard.com.

Account security is solely the responsibility of the accountholder. Please be advised that in the event of a compromised account, Blizzard representatives will typically lock the account. In these cases the Account Administration team will require faxed receipt of ID materials before releasing the account for play.

Regards,
The Battle.net Support Team 
Blizzard Entertainment
www.blizzard.com/support 
Online Privacy Policy
-----------------------------------------------------------------------------

Other active scams including a "7 days free access offer", "investigations on the sale/trade of your game account" and various "compensation" emails.  I have also started to see scams for LOTRO and RIFT.  You know that you have made it as an MMO when you see active phishing scams - sad, but true.

Learn more about the mechanics of these scams.
Read More
Posted in march, phishing, scams, wow | No comments

Sunday, 27 March 2011

Trust Me, I am a Security Pro

Posted on 20:04 by Unknown
Everyone you talk to seems to have their own special advice on how to avoid having your game account hacked. Unfortunately, there is both good and bad advice given. While I normally blog about the good advice, I decided to take some time and dispel some of the common IT security myths out there.



Myth: You can't get hacked by simply visiting a web site

People often claim that you can't be hacked by just visiting a web site and that you need to download and install something by clicking on it.

This is false. You can indeed pick up a trojan/keylogger simply by browsing to a web site that has malicious content which takes advantage of a vulnerability and, depending on the vulnerability, you may not even know that you have been infected.

Vulnerabilities can be found in the operating system, your browser, your flash player, your media player and in any piece of software that runs on your machine. Many of these vulnerabilities, if exploited, allow remote code execution which can be used to automatically download malicious software without your interaction or knowledge.

Myth: Running Firefox/Mozilla means I am safe

Internet Explorer has traditionally been one of the most exploited browsers, mainly because of its historical prevalence. These days, Firefox is the most popular browser amongst WoW users (44%), with IE (22%) and Chrome (21%) coming next... and the hackers have followed. Many vulnerabilities and exploits have been discovered with Firefox.

Other browsers are not perfect either. For example, a competition at a security conference found that most browsers could be easily compromised with Google's Chrome being the last one standing.

Myth: Run 'noscript' and you will be fine

Noscript is an addon for firefox that allows you to block flash and javascript on web pages. It helps alleviate issues such as flash vulnerabilities that are often announced. 

Noscript is a very good idea in concept but it breaks most web sites, especially modern web sites that require flash and javascript (which is nearly all of them).  This is the traditional trade-off you get with security.  Noscript provides some excellent protection but you will not get the full functionality from web sites without extensive whitelisting.

Myth: I run a Mac and Macs don't get malware

Yes they do - just not as much malware as what Windows users can expect.

However, you can still get phished.  Given that many of the account hacks are a result of phishing attacks, Mac users need to remember that they are just as vulnerable to these as any other user.

Myth: Pick up free anti-virus software and you will be right

Honestly, you get what you pay for.  As someone that comes from the anti-virus industry, I know the investment required to produce a top-quality anti-virus solution.  Free AV is good, but paid-for AV is better. It ultimately comes down to your tolerance of risk and whether you are prepared to pay for better protection. You can see a list of AV products and their ratings at avtest.org.

Myth: I have an Authenticator therefore I am protected 100%

No security will provide 100% protection. Whenever you hear someone say that something is 100% secure then don't believe a word of it.

The authenticator recently fell victim to some malware that intercepted the authenticator's code and sent it off to the hacker. But don't despair - the authenticator is still one of the best prevention mechanisms you can buy.

I don't have an authenticator, I don't run AV, I don't have a firewall and I have never been hacked.

You should go and buy yourself a lottery ticket. Seriously, you are very lucky.

As discussed earlier, you can get infected simply by surfing a page that features some malformed objects designed to exploit a vulnerability in some piece of software on your PC.

But you avoid bad sites such as hack sites or porn sites, right? 

Well, even the good sites get hacked to become a source of malware. This is becoming a much more common method of malware propagation.

Visit our 10 Easy WoW Security Steps post to learn more about securing your WoW account.

Read More
Posted in | No comments

Wednesday, 5 January 2011

NETGEAR TECH SUPPORT SETUP SCAM!! WOW $60.00 TO SETUP CONFIGURATION PROBLEMS.

Posted on 09:16 by Unknown
BEWARE OF NETGEAR SCAM. I PURCHASE A NETGEAR ROUTER ONE YEAR AGO AND TECH SUPPORT WON'T FIX THEIR CONFIGURATION.!!!!!BEWARE  WE SHOULD NOT HAVE TO PAY FOR TECH SUPPORT $60.00 IF IT IS A PROBLEM WITH THEIR WIZARD OR CONFIGURATION PROBLEM. THIS IS AN INTERNAL MATTER OF THE COMPANY.

I JUST MOVED TO NEW LOCATION AND HAD PROBLEM WITH NETGEAR CONFIGURATION, BECAUSE WIZARD COULD NOT FIX THE PROBLEM NOR THE CD PROVIDED. CONTACT NETGEAR TO HELP WITH THIS PROBLEM BEING THAT IT IS A PRODUCT SERVICE THAT CAN ONLY BE FIX BY ONE OF THEIR TECH. NO TECH WOULD HELP WITH THE PROBLEM UNLESS THE CLIENT PAY 60 DOLLAR FOR THEM TO FIX AN INTERNAL CONFIGURATION. AFTER SPEAKING TO OVER 10 DIFFERENT TECH AND SENDING E MAIL TO TECH TO FIX THE PROBLEM THEY HAVE NOT RESOLVE THE ISSUE AND DEMAND THAT YOU PAY FOR TECH SUPPORT TO FIX IT. TO ME THIS IS A SCAM AND CLIENT SHOULD BE ADVISED THAT IF THEY HAVE PROBLEM IN THE FUTURE THAT THERE IS NO TECH SUPPORT TO FIX THE PROBLEM WITHOUT RENEWING YOUR WARRANTY FOR THE PRODUCT. WHICH HAS NOTHING TO DO WITH THEIR CONFIGURATION OR WIZARD PROBLEM.
I ADVISE USER TO BEWARE THIS SCAM AND SELECT A MORE RELIABLE SERVICE AS LYNKSYS ROUTER. BIRKLIN IS SLOW AND HAS ISSUE TOO YET THEY PROVIDE SERVICE IF YOU HAVE SETUP PROBLEM.
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Comments (Atom)

Popular Posts

  • Suffer mortals, as your pathetic password betrays you!
    One of the things we often don't put much thought into is password selection. Usually it is a loved-one's name or an easily remembe...
  • (I'm not) defining lowsec
    This is a rather short post, will be one more today, about my very first PvP action. Sugar reminded me of a problem that I read about a l...
  • The big EVE trick
    What is an easy game: where everyone can achieve what he wants easily. What is a hard game: where you can only advance by becoming better an...
  • You must station trade what you haul
    Well, actually you don't if you are fine with hauling for buy orders. This case you lose serious profit. If you are the station trader o...
  • The (total lack of) balance of trade of highsec
    The fact that you can be much more rich in highsec than in the competitive areas of EVE (low, null, WH) is one of my main messages. It can b...
  • Thinking about highsec POCOs
    In the next EVE patch, Rubicon, highsec customs offices will be capturable by players (actually you destroy and build your own, but it's...
  • What would happen if people could trade?
    The question of mirror-ability of strategies often comes up when I post my trading strategy. The 0.01 strategy is clearly mirror-able. If th...
  • October ganking report
    October was a great month for my corporation , We Gank Because We Care. You can see the results on the killboard but since October was 31 d...
  • The proper profit metric
    Live moron of the weekend post . Did they spent the last month under a rock? People having trouble making ISK with trading. Some rather go m...
  • ur a kid!
    The title is a troll comment I get often. It doesn't make much sense. It's clearly not an argument. While we know that socials don...

Categories

  • account
  • account theft
  • adobe
  • alpha
  • arena tournament
  • authenticator
  • authenticators
  • battle.net
  • beta
  • blizzard
  • brute force
  • cataclysm
  • diablo 3 phishing scam
  • dictionary attack
  • drive-by
  • email
  • fake
  • flash
  • game
  • Gold
  • guild
  • gumblar
  • hacked
  • hacking
  • hacks
  • Ideas
  • ISK
  • keylogger
  • march
  • mmo-champion
  • New
  • password
  • password stealing
  • patching
  • phishing
  • raiding
  • Random
  • ranks
  • remote auction house
  • scam
  • scams
  • security
  • security checklist
  • soccer
  • strong password
  • trojan
  • vulnerability
  • warcraft
  • wow
  • wowarmory
  • wowmatrix

Blog Archive

  • ►  2013 (242)
    • ►  November (15)
    • ►  October (25)
    • ►  September (24)
    • ►  August (21)
    • ►  July (24)
    • ►  June (22)
    • ►  May (22)
    • ►  April (22)
    • ►  March (20)
    • ►  February (21)
    • ►  January (26)
  • ►  2012 (261)
    • ►  December (24)
    • ►  November (21)
    • ►  October (24)
    • ►  September (21)
    • ►  August (26)
    • ►  July (25)
    • ►  June (20)
    • ►  May (25)
    • ►  April (23)
    • ►  March (23)
    • ►  February (23)
    • ►  January (6)
  • ▼  2011 (4)
    • ▼  September (1)
      • Diablo 3 Beta Phishing Season Begins
    • ►  April (1)
      • Top WoW Phishing Scams for March 2011
    • ►  March (1)
      • Trust Me, I am a Security Pro
    • ►  January (1)
      • NETGEAR TECH SUPPORT SETUP SCAM!! WOW $60.00 TO SE...
  • ►  2010 (17)
    • ►  November (1)
    • ►  September (2)
    • ►  August (1)
    • ►  July (1)
    • ►  June (2)
    • ►  May (2)
    • ►  April (1)
    • ►  March (2)
    • ►  February (2)
    • ►  January (3)
  • ►  2009 (4)
    • ►  December (1)
    • ►  October (1)
    • ►  September (1)
    • ►  July (1)
Powered by Blogger.

About Me

Unknown
View my complete profile