Have u Been hacked?

RJMadCat

Well-Known Member
Joined
Jan 11, 2010
Messages
489
Reaction score
0
Location
Sweden
Just something for people to have a look at to prevent being hacked , and if you have been hacked!

* Use a secure password. That means, use both lower and upper case letters and use at least 1 character that is either numeric or non-alphanumeric, ie: # or % or & or $ or something similar. Example of a secure password: IrRulezAtWoW! Note that this is nothing like my password so don't bother trying Suspect
* Start WoW using the Blizzard Launcher. It has a few integrated tricks to block most keylogger type activity.
* Don't enter your password into ANYTHING that isn't either the WoW client or a site that you reached from Blizzard's website. Double-check the security certificate of any such site (you do this by clicking on the little padlock icon, and making sure that the security certificate has actually been issued to Blizzard, and not some other company/individual) before you type in the password.
* People tell you to change your password regularly, this is mostly nonsense. If someone discovers your password, they aren't going to wait a week before they steal your account.
* Never enter your password on a machine that is not continuously under your control, that includes machines belonging to your friends and also public machines Rolling Eyes .
* Very little "hacking" involves doing password scans against your account, ie: Testing many different passwords to see if you can "guess" the right one. 99.99% or more involves finding your password via alternate means such as a keylogger.
* Blizzard's security is watertight. Anyone who says anything about how they got hacked because Blizzard's network is unsecure is trying to hide their own security inadequacy. Nobody is going to steal your password from Blizzard's servers. You'd have less difficulty stealing all the gold from Fort Knox than you would trying to steal the account database on Blizzard's network.
* Get an authenticator. Really. It's cheap and it basically guarantees that even if you get a keylogger on your machine, you are basically unhackable. Anyone who tells you that they were hacked "even with an authenticator" is talking from between their buttocks. The level of technology that would have to be aimed at hacking you when you're using an authenticator is beyond the level available to most governments, let alone some chinese goldfarmer.



A lot of people have reported an increase in their accounts being hacked after converting to Battle.Net. This is NOTHING to do with the security of the Battle.NET system. The problem is that most people have their "Remember Account Name" option turned on. When you switch to Battle.NET, your account name changes to your e-mail address. That means that (possibly for the first time in years), you have to type in your account name when you first log in to WoW after converting your account. If you have a keylogger on your machine at that point, the goldfarmer on the other side has had your password for ages (and probably your email address as well, since you type that a fair number of times), but can't use it because he doesn't know your account name. Suddenly, he now has your account name as well, and that's game over. Moral of the story, make VERY sure your machine is secure before you convert to Battle.NET, and when you do, change your password at the same time.


If u have been hacked please go here https://eu.blizzard.com/support/webform.xml?locale=en_GB&lan=en

If u need aditional information go here http://forums.wow-europe.com/thread.html?topicId=35983697&sid=1


Any tips on being hacked/preventing to be hacked post them here: )

*Edit* will update Q/A here from posts below

Q: What exactly is an authenticator? Can you get one for Steam?
A: A authenticator is a 6 digit number that u need to enter that is a rolling code before you can log into your account, and i dont know if you can get it off steam u should get it on battlenet.

Q:So where else can i get a Autenticator?
A: Got my Authenticator from wantitall.co.za. Took bout half a month for shipping if you dont mind the wait. ( thx to Spawn-X)
 
Last edited:
Nice info.

I got hacked for the first time, Been playing since Public release almost 6 years ago.

First time i got hacked was December, exactly 1 week after migrating to Battle.net.
I wouldn't say their system is insecure, even considering the above sentence.

Was very weird though.
I have my Internet Security package updated daily.

My home network runs through my Linux machine for internet access, which i have spent the money for a powerful packet-sniffing Malware Scanner as well.

But i digress,
The situation occurred, and i got all my stuff back.
Immediately after I got the Mobile Authenticator for my HTC Phone.

My password was already strong, but changed it to now be a 16-character pass with 2 non-alpha-numeric characters and one non-standard character.

Nice write-up though RJ, sure lots of ppl would appreciate.
 
The way I see it is if you have an authenticator you should be unhackable. (In theory) *touch wood*

I think Blizzard should make the authenticators compulsary. I think that would limit 99.99% of the hacking, unless you loose your authenticator and password on the same day :)
 
authenticator = unhackable indeed and is the best possible thing to have if you dont want to be hacked

*edit* but for those who cant get autenticators due to their phones or money or whatever reason, there are still ways to avoid being hacked if u follow some of those. but u wont be unhackable
 
Not all of the OP is true. I have in fact been hacked WHILE I had an authenticator on my account. The hackings on my account stop the day I moved my battle.net account away from my gmail email to another email on another domain.

So in essence, I think my gmail account got compromised before my wow account, because my wow account was never hacked, and the hacking on it only stopped when I changed email address...so go figure.

Also the combination of your password be it caps or not doesn;t matter, as the OP self said, most hackings dont happen with password guessing but instead of actually capturing it one way or another.

And if you don;t believe me that my account really got hacked with an authenticator on, it truly did happen. But the good thing is, they can;t remove your authenticator without entering 2 consecutive passwords on the website so they can do very little with your account.

They did however change my account to some random yahoo email address, only because I was stupid enough to choose my secret question as the town I was born in, and that being the same town as my billing address on my b.net account, so again go figure how they managed to hack that...
 
What exactly is an authenticator? Can you get one for Steam?
 
A authenticator is a 6 digit number that u need to enter that is a rolling code before you can log into your account, and i dont know if you can get it off steam u should get it on battlenet.
 
Not all of the OP is true. I have in fact been hacked WHILE I had an authenticator on my account. The hackings on my account stop the day I moved my battle.net account away from my gmail email to another email on another domain.

So in essence, I think my gmail account got compromised before my wow account, because my wow account was never hacked, and the hacking on it only stopped when I changed email address...so go figure.

Also the combination of your password be it caps or not doesn;t matter, as the OP self said, most hackings dont happen with password guessing but instead of actually capturing it one way or another.

And if you don;t believe me that my account really got hacked with an authenticator on, it truly did happen. But the good thing is, they can;t remove your authenticator without entering 2 consecutive passwords on the website so they can do very little with your account.

They did however change my account to some random yahoo email address, only because I was stupid enough to choose my secret question as the town I was born in, and that being the same town as my billing address on my b.net account, so again go figure how they managed to hack that...

Indeed the weirdest thing, but your right nothing in this world is 100 % unstealable unhackable , but as you said after you changed your email u had no issues, meaning they could not get past the authenticator issue they needed dif ways of doing it, aka allowing blizzard to send the info to them via your email.
 
Indeed the weirdest thing, but your right nothing in this world is 100 % unstealable unhackable , but as you said after you changed your email u had no issues, meaning they could not get past the authenticator issue they needed dif ways of doing it, aka allowing blizzard to send the info to them via your email.

Yeah it was the most bizarre thing ever.

1. Got hacked
2. Reinstalled windows
3. Got items back, was pretty mad so got myself authenticator and though, cool np now.
4. 2 days later got hacked again, thought WTF#(*$#@($(*$@($@$&%@(@
5. This time I jumped on to the phone to blizzard via skype and told the 1st guy to answer WTF #*W#*$#*$#*$#*#.
6. He fixed my b.net account on to a new email address after asking me 200 questions about details on my account like last 4 digits on my CC attached to it ect and so on

After that no more hacks, so was interesting. At least the second time I didn't lose any items. But here is the interesting, even using the tools specified on the one thread which even blizzard refer to now, (hijacthis I think?) nothing was found on my pc. Also how on earth can you say I had a virus/trojan/keylogger on my pc even after a complete re-install?

Well I think the entry point to my account was via my email address, even till today I still get 5 fake emails from china every day asking for details and wanting me to go to random websites.
 
they prolly got your details as u said a while ago and from reinstalling it was removed, but they already had all the info they needed to send fake emails to blizzard allowing them to enter your account somehow, just glad your sorted, and if you get hacked again. i will eat my socks :P
 
Having an authenticator does not mean you're unhackable, trust me I know, it's merely more protection against being hacked. Secondly people who don't have authenticators should genuinely consider getting one as hackers are now using authenticators on hacked accounts making the retrieval process that much more of a pain and making it a lengthy process too.

Rumours are Cataclyms itself may ship with an authenticator in the box.
 
i'll give you my password just because I have the authenticator on it as well... plus my password is randomly generated by blizzard, decided to have one password out of the 6 I usually use that's not my own just to **** with anyone trying to get into my account. plus the email address I use for my account nobody knows anyway
 
One question though. If I use the authenticator on my phone, and I use my phone as a modem. Would I be able to get the code?

My phone can only connect to either 3G itself, or work as a modem for the pc. It won't allow both connections at the same time. (Very odd because it used to)
 
Mobile Authenticator only connects to the internet first time you install it to get certificate and sync to auth server.

After that it will only connect to internet when you tell it to re-sync.
(Yes it sometimes falls out of sync and needs to be re-synced. You will know when u have to coz your key will be continuously wrong. Its only like 50KB to re-sync it.)
 
Thing is the passwords aren't case sensitive which is already not a good thing.

I've never been hacked. You need to be more paranoid :p It helps...

Have a decent anti virus and anti spyware program, don't click on links on WoW related sites (or forums). Don't click on links emailed to you with WoW related info in and if anything asks for password other than the www.wow-europe.com site, don't enter it :p
 
Mobile Authenticator only connects to the internet first time you install it to get certificate and sync to auth server.

After that it will only connect to internet when you tell it to re-sync.
(Yes it sometimes falls out of sync and needs to be re-synced. You will know when u have to coz your key will be continuously wrong. Its only like 50KB to re-sync it.)

Thanks! :) I'm definitely getting it. As Method said, be Paranoid. :p
 
Thing is the passwords aren't case sensitive which is already not a good thing.

I've never been hacked. You need to be more paranoid :p It helps...

Have a decent anti virus and anti spyware program, don't click on links on WoW related sites (or forums). Don't click on links emailed to you with WoW related info in and if anything asks for password other than the www.wow-europe.com site, don't enter it :p
Trust me I have done all those, in fact I pride myself into knowing a bit about security. Yet it still somehow happened.

Always used firefox + noscript and some other addons, never used links from emails or entered my details on the web. Worse, it was actually an email address I never use on websites, only for WoW and some personal stuff. I have a seperate email address I sign up with on forums and other websites and so on.

Still I got hacked, via my email account somehow.

But I will say this, the authenticator is a damn good idea, even if just to prevent the hackers from adding one to your account and save yourself a lot of trouble is already enough incentive.
 
But I will say this, the authenticator is a damn good idea, even if just to prevent the hackers from adding one to your account and save yourself a lot of trouble is already enough incentive.

Ye...I'm getting one as soon as they start selling them here/allow imports to here.
 
Search around for my previous forum posts, I can get the authenticator on ANY Windows Mobile phone, regardless of compatibility.
 
Top
Sign up to the MyBroadband newsletter
X