Wow Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 12 July 2010

ESRB mistakenly releases player email addresses

Posted on 19:15 by Unknown
Many people have asked me how the bad guys get hold of our battle.net login id's - the same bad guys that inundate us with WoW phishing emails and do dictionary attacks on our battle.net logins.

The team at wow.com have published an article on how the Entertainment Software Rating Board (ESRB) managed to mistakenly release almost 1000 email addresses of wow players that wrote to them to complain about Blizzard's plan to use real names on the official wow forums.

This email list is a gold mine to the bad guys, especially where these email addresses match up with battle.net ID's.  There is little doubt that these 1000 email addresses will end up on WoW phishing lists and that they may also be targets for WoW dictionary attacks.

If you recently wrote to ESRB and you used the same email address as your battle.net ID then please consider changing your battle.net ID to a new, unique email address.

You can read more about the mess-up at Wow.com
Read More
Posted in | No comments

Monday, 7 June 2010

Patch Your Flash!

Posted on 17:41 by Unknown
Blizzard has released an advisory warning all players to update their Adobe Flash Player.  Adobe Flash Player 10.0.45.2 has a vulnerability that may allow an attacker to take control of your machine.

LUCYTR: A critical vulnerability has been discovered in Adobe Flash Player 10.0.45.2 and Adobe Reader/Acrobat 9.x, and could potentially be used to target World of Warcraft players and accounts. The newest available version of Adobe Flash 10.1, Release Candidate 7 (available at http://labs.adobe.com/technologies/flashplayer10/), does not appear to contain this vulnerability, and we recommend that everyone upgrade their Flash player as soon as possible. Earlier versions of Adobe Reader and Acrobat, specifically version 8.x, do not appear to contain this vulnerability, either. 
Adobe reports that it has seen evidence of this vulnerability already being exploited.

Although the technical details are still sketchy, it is likely to require a specially crafted flash or PDF file to trigger the vulnerability.  We have seen this type of attack on Adobe flash before - where you can be infected by a keylogger/trojan by simply visiting a legitimate web page that renders this malicious code or redirects to a malicious site containing the code.

Unfortunately, Adobe don't seem to have this fix on their auto-update system so be sure to visit Adobe's Security Page and patch your machine with v10.1 today.
Read More
Posted in | No comments

Thursday, 3 June 2010

Phishers Ramp Up Their WoW Assault

Posted on 01:30 by Unknown
Phishers have begun targeting the remote auction house and cataclysm betas in the latest wave of WoW account phishing spam.

In the first example, unsuspecting users receive an email promoting the features and benefits of the remote auction house and invite them to participate in the beta by clicking on a download now link. The link takes them to a fake battle.net login site where their game details are captured.

A sample email is shown below:

























A second type of phishing email is targeting the Cataclysm beta opt-in. Users are sent an email reminding them to update their system specifications to be eligible for a beta invite by logging into battle.net. Naturally, the battle.net link is a fake site designed to collect your account credentials:






















Be wary of any email that pretends to come from Blizzard and check the URL of any linked site before entering your account credentials. Visit our anatomy of a phishing site post for information on how to spot phishing emails and better protect your game account.

Let us know if you have received emails scams like these.
Read More
Posted in beta, cataclysm, phishing, remote auction house, scam, warcraft, wow | No comments

Sunday, 30 May 2010

Suffer mortals, as your pathetic password betrays you!

Posted on 20:33 by Unknown
One of the things we often don't put much thought into is password selection. Usually it is a loved-one's name or an easily remembered string of characters. Unfortunately, a poor choice of password can dramatically increase the chance of your game account being hacked.

In an analysis performed by Imperva of 32 million leaked passwords from rockyou.com, it was found that nearly 50% of passwords consist of people's names, slang words, dictionary words or trivial passwords. The study estimates that if a hacker used the top 5000 passwords in a dictionary attack, it would take, on average, only 111 attempts to break into a given account.

World of Warcraft does not have an account or IP address lockout after any number of bad password attempts. This gives the bad guys an opportunity to dictionary attack your account.

Assuming that the WoW account password frequency distribution is similar and that a hacker could try a password every 2 seconds - it would take an average of only 3.7 minutes to hack an account.

Obviously the time required to hack your account is going to vary based on the strength of your game password so choosing an uncommon and complex password is key. The report lists the following as the most commonly used passwords:
  1. 123456
  2. 12345
  3. 123456789
  4. password
  5. iloveyou
  6. princess
  7. rockyou (or 'warcraft' in our case)
  8. 1234567
  9. 12345678
  10. abc123
Other common passwords include monkey, qwerty, 654321 and first names of people.

How can you better protect your WoW account?

First, buy yourself an authenticator and add another layer of security to your account. A dictionary attack is largely rendered useless with the addition of a hardware token.

Second, if you don't have an authenticator or wish to be more secure then choose a strong password. Strong passwords contain numeric and non-standard characters and do not have any strings that contain dictionary words. They should be at 12-14 characters in length. However, don't bother too much with upper and lower case characters since the battle.net authentication service does not differentiate between upper/lower case. An example of strong WoW password would be something like "sdm#6wua2pa9jk".

If you have trouble remembering a strong password (and most of us will) then try to create something similar from a memorable saying. For example, Professor Putricide's "Bad news everyone! I don't think I'm going to make it" becomes "bne!idtig2mi" as your password. Such a password will be close to impossible to dictionary attack and will take a long time to brute force attack. Don't share this password with anyone and don't use this password on any other service - keep it unique to WoW only.

Finally, create a unique email address as your battle.net login. Hackers need to be able to guess or steal your username so making this complex will certainly hinder their efforts.

Update: If you want to read more about hackers stealing account usernames and passwords, check out the Symantec article where they recently discovered 44 million stolen gaming credentials.

A little bit of effort with your password selection will make hacking your precious account significantly more difficult... and don't forget to get yourself an authenticator.
Read More
Posted in brute force, dictionary attack, password, strong password, warcraft, wow | No comments

Friday, 21 May 2010

MMO-Champion hacked

Posted on 17:25 by Unknown
The team at the popular WoW fan site MMO-champion have announced that their site was recently hacked. What happened here and how can you best protect yourself against malicious code on legitimate web pages?

The malicious code was Gumblar - a malicious piece of javascript that was placed on their pages.

How did the malicious code get there?

This is a question that has not been answered by the web site owners. However, it is likely to be one of the following causes:
  1. The mmo-champion.com site was hacked and the code was manually planted there by the attacker. There are multiple ways this could have happened, but one common way is via SQL-Injection.
  2. One of their admins was infected on their own PC and their FTP login details were used by the malware to log in to the mmo-champion.com web servers and automatically infect their files.
Hackers often target legitimate web sites, especially high traffic sites, so that they get the widest exposure to their malware.

What is the malicious code designed to do?

According to a Gumbar Q&A, the malicious code redirects a user to a malicious web site that contains specially crafted PDF or flash files that automatically infect your machine if you do not have your Adobe flash player patched. The malware that it installs can redirect your google searches and replace search results with links to malicious sites. It also harvests FTP information from your machine so that it can try to automatically inject code on other web servers. Finally, it can open a back door so that your machine can be controlled remotely.

Could I have been infected from MMO-champion?

The team at mmo-champion claim that the malicious code was only on their site for 30 mins before it was detected, shut down and subsequently cleaned.

If you browsed the site in that time, you probably would have noticed an attempt to redirect your browser to another web site. Many browsers have in-built blocking mechanisms so you may have seen a big red message on your browser advising you that you are about to visit a malicious web site. If you proceeded, and the malicious web site was online at the time, then you would have been exposed to malicious pdf or flash files. If, and only if, your Adobe flash player was not patched, then these malicious files may have automatically executed. If you were running up-to-date and mainstream antivirus products then it should have been detected and stopped at this stage.

The short answer is, you may have been infected but you would have needed to have no antivirus (or poor antivirus), no recent patching of your Adobe flash player and would have needed to visit the site in the 30 mins when the code was there.

If you think your machine is infected then try this free web-based scanner - Housecall

Does it steal my WoW account info?

No, but if you were infected then you still need to clean it off your machine since it may compromise any FTP sites that you might visit, install a backdoor and your search engine results may be replaced with malicious sites. This is not the type of malware that you want on your PC.

Would the firefox 'noscript' add-on help?

Probably, although if you are a regular mmo-champion visitor then you would have been likely to nominate their site as a trusted site in noscript - resulting in noscript having no effect. Noscript is a great security measure, but it breaks a lot of sites. It is the old security vs usability trade-off.

What can I do to protect myself against these attacks?
  1. Make sure your software is fully patched - this includes your operating system (OS), browser, flash player, javascript, etc. Most people just worry about patching their OS, but there are many other avenues for exploiting software vulnerabilities on your PC.
  2. Make sure you run reputable anti-virus on your system - and make sure it is always updated.
  3. Don't ignore your browser when it tells you that the site you are about to go to is potentially dangerous.
  4. Get yourself an authenticator. Even though this malware is not written to steal WoW information, the next one might be. An authenticator is a last line of defense, and may prove to be your savior should all else fail.
Finally, don't assume you can't get infected by malware without user interaction - you can! You can pick up malware simply by visiting a web page and you won't even know it is happening. This is why you need several defense mechanisms in your security arsenal.


Read More
Posted in gumblar, hacked, mmo-champion | No comments

Sunday, 25 April 2010

Beware 2010 Arena Tournament scams

Posted on 15:28 by Unknown
Scammers are increasing their efforts with the recent announcement of the 2010 Arena Tournament. I am starting to see phishing emails that tell you all about the new arena tournament and provides you with a convenient "Register Now" link. This link takes you to a fake login page and steals any details that you enter.

The fake login page will capture your username and password. The site then redirects you to the genuine US battle.net login page and tournament registration. Like an ATM skimming device attack, the user rarely detects that a scam has taken place until their account is stripped.

An example of these emails:

























Want to learn more about how to spot phishing scams? Check out our post covering the anatomy of a WoW phishing site.
Read More
Posted in arena tournament, email, phishing, scam | No comments

Monday, 15 March 2010

Kicking Goals in the World of Warcraft

Posted on 22:03 by Unknown
Is a member of your family or close friend crazy about a game called World of Warcraft? Do they lock themselves in their room, playing the game for hours and refusing to take phone calls or talk to you? It's time to investigate this seemingly strange behavior by drawing parallels to the universal sport of soccer/football.

What is the World of Warcraft?

World of Warcraft (WoW) is a highly popular multi-player online game with over 11 million subscribers. Unlike traditional stand-alone computer games, online games feature interaction with hundreds and sometimes thousands of other real human players. In WoW, these players form 'raid groups' of up to 25 players to tackle an in-game dungeon.

What exactly is a WoW raid group?

Think of a raid group as a soccer team and think of an dungeon as a series of matches where the team plays against computer controlled opponents, also known as "bosses". The raid group works as a team to win these matches - there is a nominated raid leader (the coach and captain) who gives instructions and coordinates the team. The team consists of attackers (DPS members) which are assigned to attack and damage the boss and defenders (tanks and healers) which aim to distract the boss and heal up the team so that the attackers can do their job. Each team member is assigned a specific role and, like any sporting match, all players need to be present for the full game time and perform their assigned duties to the best of their ability. Many raid groups also have reserve players that sit on the bench, waiting to be called in to replace players.

Team members will communicate with each other via a microphone and headphones connected to the PC - you may see your partner sporting a very ugly set of headphones, looking something like a submarine commander. This is the equivalent of the on field communication that happens between players, the captain and the coach.

Each of the matches takes typically between 5-10 mins. During this time, there is no way to pause the game - all raiding takes place in real time. After each match, the raid leader will analyse the performance of the team, make adjustments and then re-engage until the "boss" is defeated - just like any good soccer coach.

A full raid session may consist of many boss kills and can easily go for several hours. Raids are typically scheduled at specific times each week.

So why won't they come and have dinner when they are called?

Players are required to be present for the full duration of the raid. Like any sporting match, you cannot just leave the game whenever you decide. Many of the matches require all members of the raid to play at their best - any single member that steps away from a match and goes 'away from keyboard - AFK' without pre-warning the raid leader will very likely cause the match to be lost - upsetting the other 24 players in the raid.

Why can't I talk to them for 5 mins during a raid?

Players will either be participating in the match or will be listening to the raid leader, taking instructions before the next match. Either way, the player needs to give the raid his/her full attention.

It is best to wait for a "bio" break to speak with them. Bio breaks are scheduled breaks where the player can get a coffee or visit the bathroom.

What happens when all of the bosses are defeated
?

This only occurs for the very elite teams and only for certain periods of the year. The creators of WoW are constantly adding new bosses and content to the game to keep players entertained. Most raiding groups always have something bigger to aim for.

I asked them to go out this weekend but they claim they are rostered. What's the deal?

Just like your weekend soccer games, players announce their availability to play typically 1-2 weeks ahead of the scheduled raid. A team roster is usually published by the raid leader a few days before the raid. Players that made themselves available and subsequently get rostered are expected to play.

Why bother raiding - it's just a computer game? Why don't they go outside and kick a ball instead?

The real thrill of raiding is the feeling of progression, team work and accomplishment - just like the feeling you get after winning a sporting final.

Each completed boss encounter awards the group with several items of equipment, otherwise known as 'loot'. This loot comes in the form of items that the player can wear and may be a new piece of armor, weapon or other similar item. Loot items increase the power of individual players and are highly sought after. Winning loot in a raid is a significant achievement - very similar to that sporting trophy you display with pride on the mantle piece.

So if I have to engage in conversation with my WoW gamer, what should I be asking?

Stun your WoW gamer by asking them any of the following questions:
  • What role do you play in WoW raids? A tank, healer or DPS? Why did you chose that role?
  • What new loot did you get from your raid today? Show me your character.
  • What boss are you currently working on? How did you go?
  • Your dinner is almost ready, when can you take your next extended bio break?
Ask these and your fellow raider is bound to be most impressed with your understanding of their gaming world.

Finally, just remember that calling your WoW player for dinner or asking them to do chores in the middle of the raid is likely to be met with some serious resistance. Would David Beckham or Ronaldo leave the field mid-game to put the trash out? At least wait for half-time.
Read More
Posted in raiding, soccer, warcraft, wow | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Diablo 3 Beta Phishing Season Begins
    The scammers are out in force with the recent Diablo 3 beta opt-in announcement.   Phishing scams are very common around any Blizzard beta ...
  • What would happen if people could trade?
    The question of mirror-ability of strategies often comes up when I post my trading strategy. The 0.01 strategy is clearly mirror-able. If th...
  • Tragedy of commons (and non-TC alliances)
    The tragedy of commons is a well-known economical problem, described by the anecdote: "herders sharing a common parcel of land, on whi...
  • A new approach to fight botting
    Botting is a widespread plague of MMOs. A botter can gain insane amount of game resources since it “farms for free”: the time of the bot cos...
  • The war for Finanar
    Finanar is a 0.5 system in Metropolis with 3 ice anomalies. If you check out my corp killboard you see lot of kills there, about 8B destro...
  • The (total lack of) balance of trade of highsec
    The fact that you can be much more rich in highsec than in the competitive areas of EVE (low, null, WH) is one of my main messages. It can b...
  • Planetary interaction for beginners
    Planetary interaction isn't a really profitable enterprise. However the "newbie-version" is a "printing money" schem...
  • Nullsec-altruism and a free titan
    Imagine that you are an avatar in Diablo 3. You enter New Tristram after defeating some risen dead. The town is clearly in danger. The undea...
  • The myth of the skilled, goodfight-seeking PvP-er
    While no sane man would claim that pilot skill decides large engagement instead of strategic decisions, there is a claim that there are skil...
  • (I'm not) defining lowsec
    This is a rather short post, will be one more today, about my very first PvP action. Sugar reminded me of a problem that I read about a l...

Categories

  • account
  • account theft
  • adobe
  • alpha
  • arena tournament
  • authenticator
  • authenticators
  • battle.net
  • beta
  • blizzard
  • brute force
  • cataclysm
  • diablo 3 phishing scam
  • dictionary attack
  • drive-by
  • email
  • fake
  • flash
  • game
  • Gold
  • guild
  • gumblar
  • hacked
  • hacking
  • hacks
  • Ideas
  • ISK
  • keylogger
  • march
  • mmo-champion
  • New
  • password
  • password stealing
  • patching
  • phishing
  • raiding
  • Random
  • ranks
  • remote auction house
  • scam
  • scams
  • security
  • security checklist
  • soccer
  • strong password
  • trojan
  • vulnerability
  • warcraft
  • wow
  • wowarmory
  • wowmatrix

Blog Archive

  • ▼  2013 (242)
    • ▼  November (15)
      • There is no "respect number"
      • Mobile vending machine
      • My big problem with EVE
      • Highsec POCO ownership
      • No way I go to WH space
      • Representation of women in MMOs
      • The failure of altruism
      • Thinking about highsec POCOs
      • My project failed
      • The largest awox in the history of EVE
      • Don't Fleet up!
      • Respect: the holy grail of MMOs
      • Talons of the Talos
      • Morons of the week
      • October ganking report
    • ►  October (25)
    • ►  September (24)
    • ►  August (21)
    • ►  July (24)
    • ►  June (22)
    • ►  May (22)
    • ►  April (22)
    • ►  March (20)
    • ►  February (21)
    • ►  January (26)
  • ►  2012 (261)
    • ►  December (24)
    • ►  November (21)
    • ►  October (24)
    • ►  September (21)
    • ►  August (26)
    • ►  July (25)
    • ►  June (20)
    • ►  May (25)
    • ►  April (23)
    • ►  March (23)
    • ►  February (23)
    • ►  January (6)
  • ►  2011 (4)
    • ►  September (1)
    • ►  April (1)
    • ►  March (1)
    • ►  January (1)
  • ►  2010 (17)
    • ►  November (1)
    • ►  September (2)
    • ►  August (1)
    • ►  July (1)
    • ►  June (2)
    • ►  May (2)
    • ►  April (1)
    • ►  March (2)
    • ►  February (2)
    • ►  January (3)
  • ►  2009 (4)
    • ►  December (1)
    • ►  October (1)
    • ►  September (1)
    • ►  July (1)
Powered by Blogger.

About Me

Unknown
View my complete profile