d2jsp
Log InRegister
d2jsp Forums > Diablo II > Diablo 2 Discussion > Regarding The Recent D2 Hacking Wave
Prev1234Next
Add Reply New Topic New Poll
Member
Posts: 3,623
Joined: Aug 28 2014
Gold: 13.45
Mar 30 2020 01:25pm
Interesting.
Member
Posts: 62,647
Joined: Aug 15 2012
Gold: 30.00
Mar 30 2020 01:28pm
Cry
Member
Posts: 17,273
Joined: Jul 29 2010
Gold: 10,709.66
Warn: 70%
Mar 30 2020 01:38pm
Quote (KRR @ 29 Mar 2020 23:24)
There’s a guy hacking B.net server to DDOS me directly through the game’s ports.. and he knows my cd keys somehow despite never telling any1.
I don’t think its something you can prevent once targetted


Call your network provider and tell them you have been compromised to an extent you don't know and you suspect you are being ddos. They will help take care of the situation in a legal manner.

Quote (Taylor_Swift @ 30 Mar 2020 08:06)
Updated Again:

Recommended Actions:

1) 2 Factor Authenticate your bnet account. It's easy and only takes a minute to download/set up. Don't reveal your CD key to anyone. Change your secret question/answer. Change your bnet account password.
2) Change your diablo 2 password, especially if you have had the same one for a long time (years). Make it different from any other one you use for any other account (jsp, gd, etc). Password length is more important than complexity in regards to safety.
3) Try to minimize publicizing your Diablo 2 in game identities. When trading on jsp/gd, use a mule account with no valuable items. Move your existing high value items to a mule account not known to the public and that you do not duel on. Refrain from showing high value items to strangers in game.
4) If you were hacked, buy a new CD key pair from Blizzard and create a new bnet account with 2 Factor Authentication. Make your new D2 accounts using this new CD key.



Might it be good idea for people to change there passwords for other things like email, etc? Ya know, incase one is same for another game or service?

Thank you for sharing awareness and whatnot.

This post was edited by treezin on Mar 30 2020 01:44pm
Member
Posts: 6,114
Joined: Mar 30 2018
Gold: 255.00
Mar 30 2020 02:18pm
Quote (KRR @ 30 Mar 2020 01:24)
There’s a guy hacking B.net server to DDOS me directly through the game’s ports.. and he knows my cd keys somehow despite never telling any1.
I don’t think its something you can prevent once targetted


You obviously have zero idea how Battle.net's server work in this day and age. There is zero way anyone can obtain your IP address via Battle.net. The only way they could get it is if you yourself have been using 3rd party programs which in that case you deserve it.
Member
Posts: 19,438
Joined: Aug 11 2011
Gold: 33.00
Mar 30 2020 02:20pm
Quote (zetsubl @ 30 Mar 2020 17:20)
have you already reported this to blizzard?


I have not, but plan to. You're welcome to copy paste what I wrote there. The more complaints they get, the more likely they are to look into it. I'd suggest going the ticket route vice forum posting.

Quote (treezin @ 30 Mar 2020 19:38)
Call your network provider and tell them you have been compromised to an extent you don't know and you suspect you are being ddos. They will help take care of the situation in a legal manner.




Might it be good idea for people to change there passwords for other things like email, etc? Ya know, incase one is same for another game or service?

Thank you for sharing awareness and whatnot.



Yes, it's a good idea to change your 1) registered recovery email pw and 2) bnet account pw in addition to your 3) d2Acc pw.

Two factor authentication should be used for both emails. These two passwords should be unique, that is, your recovery email, bnet, and d2 accounts should be three distinct, (long) passwords not used anywhere else.

The reason for this is that the Hackers have access to multiple tables within the breached database: one that lists d2AccName/pw pairs (we know this for sure), and at least another that lists d2AccName/hashedCD-Key/emailThaHashedCD-KeyIsRegisteredOn(bnetAcc)/bnetPW (not 100% certain but extremely likely) The recoveryEmailforD2AccName is also very likely to be on one of these two tables.

If your password is the same for one of these three identifiers, the hacker can try the same password for your other unhashed (not encrypted) data and gain full control.
Member
Posts: 19,438
Joined: Aug 11 2011
Gold: 33.00
Mar 30 2020 02:26pm
Okay, the post I wrote above is confusing so let me clarify:

There are two emails used to identify you and one d2Acc. Change your d2Acc pw now. Make it unique and long.

For your two emails, one is your recovery email and the other is the email you use to log into bnet. Make sure these both have 2FA on them. Also make sure that the passwords to each of these emails is unique and long.

Hopefully that's clear.
Member
Posts: 3,623
Joined: Aug 28 2014
Gold: 13.45
Mar 30 2020 02:50pm
Quote (hehexd @ Mar 30 2020 04:18pm)
You obviously have zero idea how Battle.net's server work in this day and age. There is zero way anyone can obtain your IP address via Battle.net. The only way they could get it is if you yourself have been using 3rd party programs which in that case you deserve it.


LOL good post there sir. I have to agree with you.
Member
Posts: 26,747
Joined: Apr 18 2007
Gold: 1,246.69
Mar 30 2020 04:38pm
hehexd and maximillionCohen are known 3rd party hack users and are friends with the guy that claims to hack. Don’t listen to them trying to cover up.
My ISP confirmed i’m being DDOS but couldn’t fix it and recommended I call blizzard. Blizzard confirmed it also on their side and resolved the issue as of today and FBI is now involved.


Sadly these hackers messing with a 20 year old game are going to make Blizzard shut down D2 due to liability issues.


This post was edited by KRR on Mar 30 2020 04:41pm
Member
Posts: 6,114
Joined: Mar 30 2018
Gold: 255.00
Mar 30 2020 04:47pm
Quote (KRR @ 30 Mar 2020 17:38)
hehexd and maximillionCohen are known 3rd party hack users and are friends with the guy that claims to hack. Don’t listen to them trying to cover up.
My ISP confirmed i’m being DDOS but couldn’t fix it and recommended I call blizzard. Blizzard confirmed it also on their side and resolved the issue as of today and FBI is now involved.


Sadly these hackers messing with a 20 year old game are going to make Blizzard shut down D2 due to liability issues.


You're an idiot. There is zero way your ISP would be able to even link an attack on your IP to Blizzard or Battle.net and if you are claiming they did you are lying and again it's because you have zero clue how the internet works.

So let's see some screenshots from Blizzard "confirming" they fixed your issue lmaoo.. What could Blizzard even do if "hackers" obtained your homenet IP?? They can't mitigate the DDoS attacks on YOUR IP address :wallbash: :rofl:
Member
Posts: 19,438
Joined: Aug 11 2011
Gold: 33.00
Mar 30 2020 04:53pm
Hey guys, I would appreciate it if you didn't spam this thread, as my previous one on jsp was closed due to spam.

If you have some beef with each other you can always pm instead of trying to show off publicly.
Go Back To Diablo 2 Discussion Topic List
Prev1234Next
Add Reply New Topic New Poll