Wow Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 15 March 2010

Kicking Goals in the World of Warcraft

Posted on 22:03 by Unknown
Is a member of your family or close friend crazy about a game called World of Warcraft? Do they lock themselves in their room, playing the game for hours and refusing to take phone calls or talk to you? It's time to investigate this seemingly strange behavior by drawing parallels to the universal sport of soccer/football.

What is the World of Warcraft?

World of Warcraft (WoW) is a highly popular multi-player online game with over 11 million subscribers. Unlike traditional stand-alone computer games, online games feature interaction with hundreds and sometimes thousands of other real human players. In WoW, these players form 'raid groups' of up to 25 players to tackle an in-game dungeon.

What exactly is a WoW raid group?

Think of a raid group as a soccer team and think of an dungeon as a series of matches where the team plays against computer controlled opponents, also known as "bosses". The raid group works as a team to win these matches - there is a nominated raid leader (the coach and captain) who gives instructions and coordinates the team. The team consists of attackers (DPS members) which are assigned to attack and damage the boss and defenders (tanks and healers) which aim to distract the boss and heal up the team so that the attackers can do their job. Each team member is assigned a specific role and, like any sporting match, all players need to be present for the full game time and perform their assigned duties to the best of their ability. Many raid groups also have reserve players that sit on the bench, waiting to be called in to replace players.

Team members will communicate with each other via a microphone and headphones connected to the PC - you may see your partner sporting a very ugly set of headphones, looking something like a submarine commander. This is the equivalent of the on field communication that happens between players, the captain and the coach.

Each of the matches takes typically between 5-10 mins. During this time, there is no way to pause the game - all raiding takes place in real time. After each match, the raid leader will analyse the performance of the team, make adjustments and then re-engage until the "boss" is defeated - just like any good soccer coach.

A full raid session may consist of many boss kills and can easily go for several hours. Raids are typically scheduled at specific times each week.

So why won't they come and have dinner when they are called?

Players are required to be present for the full duration of the raid. Like any sporting match, you cannot just leave the game whenever you decide. Many of the matches require all members of the raid to play at their best - any single member that steps away from a match and goes 'away from keyboard - AFK' without pre-warning the raid leader will very likely cause the match to be lost - upsetting the other 24 players in the raid.

Why can't I talk to them for 5 mins during a raid?

Players will either be participating in the match or will be listening to the raid leader, taking instructions before the next match. Either way, the player needs to give the raid his/her full attention.

It is best to wait for a "bio" break to speak with them. Bio breaks are scheduled breaks where the player can get a coffee or visit the bathroom.

What happens when all of the bosses are defeated
?

This only occurs for the very elite teams and only for certain periods of the year. The creators of WoW are constantly adding new bosses and content to the game to keep players entertained. Most raiding groups always have something bigger to aim for.

I asked them to go out this weekend but they claim they are rostered. What's the deal?

Just like your weekend soccer games, players announce their availability to play typically 1-2 weeks ahead of the scheduled raid. A team roster is usually published by the raid leader a few days before the raid. Players that made themselves available and subsequently get rostered are expected to play.

Why bother raiding - it's just a computer game? Why don't they go outside and kick a ball instead?

The real thrill of raiding is the feeling of progression, team work and accomplishment - just like the feeling you get after winning a sporting final.

Each completed boss encounter awards the group with several items of equipment, otherwise known as 'loot'. This loot comes in the form of items that the player can wear and may be a new piece of armor, weapon or other similar item. Loot items increase the power of individual players and are highly sought after. Winning loot in a raid is a significant achievement - very similar to that sporting trophy you display with pride on the mantle piece.

So if I have to engage in conversation with my WoW gamer, what should I be asking?

Stun your WoW gamer by asking them any of the following questions:
  • What role do you play in WoW raids? A tank, healer or DPS? Why did you chose that role?
  • What new loot did you get from your raid today? Show me your character.
  • What boss are you currently working on? How did you go?
  • Your dinner is almost ready, when can you take your next extended bio break?
Ask these and your fellow raider is bound to be most impressed with your understanding of their gaming world.

Finally, just remember that calling your WoW player for dinner or asking them to do chores in the middle of the raid is likely to be met with some serious resistance. Would David Beckham or Ronaldo leave the field mid-game to put the trash out? At least wait for half-time.
Read More
Posted in raiding, soccer, warcraft, wow | No comments

Monday, 1 March 2010

Update: Keylogger websites shut down

Posted on 18:13 by Unknown
The main infection source of the recent anti-authenticator keylogger/trojan appears to have been shut down. The main places of infection - the fake site wowmatrixf._com and other associated fake addon sites, including cursea._com and deadlybossmodss._com - are no longer online. (Victims were lured to these fake sites via Google advertisements)

We can breathe a sigh of relief but don't become complacent. This trojan/keylogger is likely to spring up somewhere else. Be cautious of what you download and execute from any web site. Addons should not require an installer package to execute. Be very suspicious of anything that asks you to "run a program". Follow our 10 Easy Steps to increase protection.

If you notice that these fake sites pop up in another spot then let us know.
Read More
Posted in | No comments

Sunday, 28 February 2010

Authenticator hack - is your account still safe?

Posted on 18:18 by Unknown
The big security news of the weekend is that Blizzard has confirmed a man-in-the-middle attack that is being used to hack accounts that are using an authenticator.

Let me state up front that this is not a reason to throw your authenticator away nor should it be an excuse for not getting one. The authenticator is a very sound device - but it is, and will always be, just one of many security mechanisms that you should use to help secure your account. It is what us IT security guys call "layered security" - more on this in a moment.

The attack itself requires a keylogger/trojan. The keylogger, once installed on your system, logs your game user name, password AND authenticator code. It proceeds to post this information off to a rogue server so that the attacker can use this information in near real-time to access your game account. In the meantime, it sends an incorrect code to the battle.net authentication server from your machine - resulting in an "incorrect login" type message from the game. It does this so that you don't consume the one-time-use code that the authenticator provides.

Now it was only a matter of time before we saw this kind of attack. More and more people have been using authenticators. In a survey of over 90 gamers at securingwow.blogspot.com, 84% of them claim to have an authenticator attached to their game account. This tells us that more and more people are now running with an authenticator - reducing the pool size of "easy" victims.

The bad guys are now being forced to step up the sophistication of their attacks and have started targeting those with authenticators. We are bound to see many more keyloggers with this capability in the near future. Additionally, phishing attacks will also begin to operate in the same fashion - asking you to type in your authentication code, along with your other game account details, posting the info off to the attacker - who uses them in real time - leaving you with a "system unavailable" message and a soon-to-be-stripped game account. If we don't have these mechanisms in WoW phishing sites already then I can assure you that they are not far away.

So how do you prevent it from happening? It all comes down to minimizing the chance of being infected with a keylogger in the first place. One of the many tenets of IT Security is that "no sercurity system is 100% effective". Anyone that tells you otherwise does not know what they are preaching or they are trying to sell you some snake-oil. In this case, we can't rely on authenticators to be the only defense mechansim - here are ten simple steps you can do to reduce the chance of your game account being compromised:
  1. Don't share your game password with anyone and pick a password that is not easily guessed
  2. Don't use the same password for subscribing to fan sites
  3. Keep your operating system, browser and other software (especially Adobe Flash) fully patched - start with Windows Update
  4. Run a reputable antivirus product, preferably a full internet security suite with a firewall and keystroke encryption
  5. Don't click on email attachments, especially when you don't know the sender
  6. Don't download and run executable files from web pages
  7. Don't enter your game password into any web site other than the official game sites
  8. Don't enter your game password to a legitimate Blizzard web site from a PC that may be compromised
  9. Be very suspicious if an addon requires some form of install package to be run
  10. Invest in a Blizzard authenticator or install the Battlenet authenticator application on your phone
Try to follow all of these recommendations - not just one or two points.

In this specific case, the keylogger was reportedly delivered via a fake site for the Wowmatrix addon manager. The site was created to look and feel like wowmatrix.com but, instead of downloading and installing the addon manager, the keylogger was installed instead. Our recommendations #6 and #9 talk about being "very suspicious" of add-ons that require an installer to run and avoid running executable files from web sites.

The bottom line is that keyloggers and phishing sites are here to stay. Don't rely on your authenticator to protect you 100% of the time - but don't throw it out either. It still forms a very strong part of your layered defense against the bad guys.

Post a comment - we would like to hear from you if you have fallen victim to this attack.
Read More
Posted in account, authenticator, blizzard, fake, game, hacked, keylogger, phishing, wow, wowmatrix | No comments

Friday, 12 February 2010

Adobe Flash Vulnerability Fix

Posted on 14:47 by Unknown
Adobe has released a patch for the latest Flash vulnerability. Adobe Flash is used by the majority of browsers to display dynamic content on web pages. This vulnerability can potentially lead to automatic keylogger downloads by visiting a web site that has a specially crafted flash file embedded in its pages. This is known as a 'drive-by download' - one in which malware can be downloaded and installed without you knowing.

While I am yet to see this specific vulnerability exploited, it is only a matter of time before it is. I have seen previous Flash vulnerabilities exploited to download keyloggers from popular WoW fan sites.

So - play it safe - visit the official Adobe Flash download site and update your flash player.

Be sure to visit our 10 Easy Steps page to further protect your WoW account.
Read More
Posted in adobe, drive-by, flash, keylogger, vulnerability | No comments

Friday, 29 January 2010

Blizzard Launches Battle.Net Security Site

Posted on 17:45 by Unknown
Blizzard has launched their official security awareness page offering helpful advice on what you can do to safeguard your computer, how to spot scams, info on the adverse effects of buying gold, and tried-and-true methods to help prevent account compromises.

The specifically provide:
  • A Security Checklist - covering preventative measures that you should be taking
  • Type of Account Thefts - listing the common methods used to hack accounts
  • Advice on what to do if you get hacked
Be sure to check it out at http://us.battle.net/security/

As always, having a Blizzard Authenticator is one of the best methods of hack prevention.
Read More
Posted in account, account theft, battle.net, blizzard, hacked, security, security checklist | No comments

Friday, 15 January 2010

The Armory Phishing Scam

Posted on 16:39 by Unknown
The new and improved wowarmory has brought with it opportunity for scammers seeking to trick you into disclosing your wow game passwords. Check out the full coverage at wow.com on this latest scam:

http://www.wow.com/2010/01/15/beware-of-wow-armory-phishing-scams/

As always, never enter your game username/password into a site that is not "blizzard.com" or "worldofwarcraft.com" and get yourself an authenticator today!

If you have had a close encounter with a wow phishing scam then post and comment and let us know about it.
Read More
Posted in phishing, security, wowarmory | No comments

Tuesday, 12 January 2010

Beware of Cataclysm Phishing Scams

Posted on 18:04 by Unknown
With the recent announcement of the Catalysm alpha, users are warned not to fall victim to phishing scams.

Be aware that if you receive an email inviting you to join the Cataclysm testing cycle then it will most likely be a scam. Cataclysm open beta does not exist as yet.

Do not enter your game username and password into any sites that may link from any email claiming to be an official Blizzard invite to Cataclysm.

If you see a Cataclysm phishing scam then feel free to share your comments on it.
Read More
Posted in alpha, beta, cataclysm, phishing, wow | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Diablo 3 Beta Phishing Season Begins
    The scammers are out in force with the recent Diablo 3 beta opt-in announcement.   Phishing scams are very common around any Blizzard beta ...
  • What would happen if people could trade?
    The question of mirror-ability of strategies often comes up when I post my trading strategy. The 0.01 strategy is clearly mirror-able. If th...
  • Tragedy of commons (and non-TC alliances)
    The tragedy of commons is a well-known economical problem, described by the anecdote: "herders sharing a common parcel of land, on whi...
  • A new approach to fight botting
    Botting is a widespread plague of MMOs. A botter can gain insane amount of game resources since it “farms for free”: the time of the bot cos...
  • The war for Finanar
    Finanar is a 0.5 system in Metropolis with 3 ice anomalies. If you check out my corp killboard you see lot of kills there, about 8B destro...
  • The (total lack of) balance of trade of highsec
    The fact that you can be much more rich in highsec than in the competitive areas of EVE (low, null, WH) is one of my main messages. It can b...
  • Planetary interaction for beginners
    Planetary interaction isn't a really profitable enterprise. However the "newbie-version" is a "printing money" schem...
  • Nullsec-altruism and a free titan
    Imagine that you are an avatar in Diablo 3. You enter New Tristram after defeating some risen dead. The town is clearly in danger. The undea...
  • The myth of the skilled, goodfight-seeking PvP-er
    While no sane man would claim that pilot skill decides large engagement instead of strategic decisions, there is a claim that there are skil...
  • (I'm not) defining lowsec
    This is a rather short post, will be one more today, about my very first PvP action. Sugar reminded me of a problem that I read about a l...

Categories

  • account
  • account theft
  • adobe
  • alpha
  • arena tournament
  • authenticator
  • authenticators
  • battle.net
  • beta
  • blizzard
  • brute force
  • cataclysm
  • diablo 3 phishing scam
  • dictionary attack
  • drive-by
  • email
  • fake
  • flash
  • game
  • Gold
  • guild
  • gumblar
  • hacked
  • hacking
  • hacks
  • Ideas
  • ISK
  • keylogger
  • march
  • mmo-champion
  • New
  • password
  • password stealing
  • patching
  • phishing
  • raiding
  • Random
  • ranks
  • remote auction house
  • scam
  • scams
  • security
  • security checklist
  • soccer
  • strong password
  • trojan
  • vulnerability
  • warcraft
  • wow
  • wowarmory
  • wowmatrix

Blog Archive

  • ▼  2013 (242)
    • ▼  November (15)
      • There is no "respect number"
      • Mobile vending machine
      • My big problem with EVE
      • Highsec POCO ownership
      • No way I go to WH space
      • Representation of women in MMOs
      • The failure of altruism
      • Thinking about highsec POCOs
      • My project failed
      • The largest awox in the history of EVE
      • Don't Fleet up!
      • Respect: the holy grail of MMOs
      • Talons of the Talos
      • Morons of the week
      • October ganking report
    • ►  October (25)
    • ►  September (24)
    • ►  August (21)
    • ►  July (24)
    • ►  June (22)
    • ►  May (22)
    • ►  April (22)
    • ►  March (20)
    • ►  February (21)
    • ►  January (26)
  • ►  2012 (261)
    • ►  December (24)
    • ►  November (21)
    • ►  October (24)
    • ►  September (21)
    • ►  August (26)
    • ►  July (25)
    • ►  June (20)
    • ►  May (25)
    • ►  April (23)
    • ►  March (23)
    • ►  February (23)
    • ►  January (6)
  • ►  2011 (4)
    • ►  September (1)
    • ►  April (1)
    • ►  March (1)
    • ►  January (1)
  • ►  2010 (17)
    • ►  November (1)
    • ►  September (2)
    • ►  August (1)
    • ►  July (1)
    • ►  June (2)
    • ►  May (2)
    • ►  April (1)
    • ►  March (2)
    • ►  February (2)
    • ►  January (3)
  • ►  2009 (4)
    • ►  December (1)
    • ►  October (1)
    • ►  September (1)
    • ►  July (1)
Powered by Blogger.

About Me

Unknown
View my complete profile