d2jsp
Log InRegister
d2jsp Forums > Diablo > Diablo 3 > D3 Discussion >
Poll > Has Your Account Been Hacked?
Prev167891028Next
Add Reply New Topic New Poll
  Guests cannot view or vote in polls. Please register or login.
Member
Posts: 7,726
Joined: Nov 21 2009
Gold: 2,630.00
May 23 2012 06:20pm
Only game I've ever been hacked in... Diablo 3. Sad times.
Member
Posts: 32
Joined: Jan 23 2011
Gold: 0.00
May 23 2012 06:21pm
Quote (Sanity @ May 23 2012 06:23pm)
Has anyone considered the possibility that the majority of people that were hacked have perhaps been tracked over the course of several months? Although Diablo III was only released a week ago, it's possible that the people hacked could have been targeted before release and the hackers have been waiting. I can't see how such a massive security flaw could exist with a company as experiences as blizzard. It's easy enough to be on something like a botnet for several months without knowing assuming you don't know what to look for.

I just can't see how hackers could acquire emails and password in order to hack accounts.


They use a MitM attack. MitM's are getting a lot more common now and the pressing issue is that the exploit is extremely hard to fix. Basically what it does is use a malware agent on a victim's computer to steal the victim's session, thereby circumventing authenticators entirely. Hackers do not actually obtain the victim's password nor do they need it or anything similar like email addresses. Given that MitM attacks are extremely common nowadays (there are dozens of programs out there that can steal people's passwords just by being on the same WiFi network with MitM using ARP poisoning and other such exploits, http://code.google.com/p/subterfuge being one such program) it isn't surprising that it's been applied to the newest, multi-million dollar computer game by the scourge that is Chinese gold farmers. Anyways, patching this would be extremely difficult.
Member
Posts: 13,125
Joined: Jan 27 2007
Gold: 17,500.00
May 23 2012 06:21pm
Quote (Buffalo_Soldier @ May 23 2012 08:20pm)
Only game I've ever been hacked in... Diablo 3. Sad times.


this
Member
Posts: 74,815
Joined: Nov 21 2002
Gold: 387.51
May 23 2012 06:23pm
No mine hasnt. COMMON SENSE!
Member
Posts: 1,110
Joined: Sep 24 2006
Gold: 2,500.01
May 23 2012 06:24pm
Quote (Buffalo_Soldier @ May 23 2012 05:20pm)
Only game I've ever been hacked in... Diablo 3. Sad times.


just lost everything couple hours ago
Member
Posts: 11,136
Joined: May 7 2006
Gold: 0.01
May 23 2012 06:26pm
Quote (fearless2009 @ May 23 2012 07:21pm)
They use a MitM attack.  MitM's are getting a lot more common now and the pressing issue is that the exploit is extremely hard to fix.  Basically what it does is use a malware agent on a victim's computer to steal the victim's session, thereby circumventing authenticators entirely.  Hackers do not actually obtain the victim's password nor do they need it or anything similar like email addresses.  Given that MitM attacks are extremely common nowadays (there are dozens of programs out there that can steal people's passwords just by being on the same WiFi network with MitM using ARP poisoning and other such exploits, http://code.google.com/p/subterfuge being one such program) it isn't surprising that it's been applied to the newest, multi-million dollar computer game by the scourge that is Chinese gold farmers.  Anyways, patching this would be extremely difficult.


So it basically comes down to the user doing something to put their account at risk.
Member
Posts: 24,639
Joined: Jun 27 2008
Gold: 0.00
May 23 2012 06:28pm
Mayyyybe.... Njaguar is going through account/passes from jsp and trying them on D3. Someone confirm me, this might be true.
Member
Posts: 32
Joined: Jan 23 2011
Gold: 0.00
May 23 2012 06:28pm
Quote (Sanity @ May 23 2012 07:26pm)
So it basically comes down to the user doing something to put their account at risk.


Yes and no. There is some sort of fault in the user himself in that they have acted somehow to inadvertently obtain the malware in the first place. It is mostly unavoidable however, as the user does not actually need to download any files for the virus to be put on his/her computer.
Member
Posts: 759
Joined: Jul 21 2010
Gold: 951.00
May 23 2012 06:29pm
I didn't get a notice or anything, not even suspicious activity on my account. I haven't even joined any public games, I either play with my brother and uncles or solo. Only thing I can think of is me using the Auction House. I woke up this morning though, and my stash and Witch Doctor were wiped clean. Pretty disappointing...


This post was edited by BuffaloBillyBob on May 23 2012 06:29pm
Member
Posts: 2,562
Joined: Jan 21 2009
Gold: 0.00
May 23 2012 06:30pm

Quote (simpleforce @ May 23 2012 07:28pm)
Mayyyybe.... Njaguar is going through account/passes from jsp and trying them on D3. Someone confirm me, this might be true.


Sounds interesting, my Malwarebytes blocks an IP from JSP a LOT. why?

Still unsure of this but if it's true makes sense.
Go Back To D3 Discussion Topic List
Prev167891028Next
Add Reply New Topic New Poll