佳礼资讯网

 找回密码
 注册

ADVERTISEMENT

楼主: poisonsoup

小心!不要进入任何public game

  [复制链接]
发表于 23-5-2012 06:56 PM | 显示全部楼层
其实blizzard应该做一个system是 就算frdlist的朋友要join 也需要被 leader approve
回复

使用道具 举报


ADVERTISEMENT

发表于 23-5-2012 07:16 PM | 显示全部楼层
其实blizzard应该做一个system是 就算frdlist的朋友要join 也需要被 leader approve
snak3e 发表于 23-5-2012 06:56 PM


里面可以设定啊....
回复

使用道具 举报

发表于 23-5-2012 07:56 PM | 显示全部楼层
里面可以设定啊....
whistle1984 发表于 23-5-2012 07:16 PM



    有么? 怎样怎样
回复

使用道具 举报

发表于 4-6-2012 10:44 PM | 显示全部楼层
刚刚有朋友中hack了 =.="
barbarian一进game就全裸... :S
干嘛这个game 那么容易hack的 =.="
回复

使用道具 举报

发表于 5-6-2012 04:54 AM | 显示全部楼层
刚刚有朋友中hack了 =.="
barbarian一进game就全裸... :S
干嘛这个game 那么容易hack的 =.="
dannytoh_1985 发表于 4-6-2012 10:44 PM



  树大招风,hacker都抓D3来开刀~
回复

使用道具 举报

 楼主| 发表于 6-6-2012 11:55 AM | 显示全部楼层
本帖最后由 poisonsoup 于 6-6-2012 11:57 AM 编辑

How You Got Hacked 你是怎样被hack

The "hackers" are doing this by rolling through a database they've built up over the last 10+ years of username/email/password combos.

These lists are compiled from the following sources:
- Phishing scams*
- Fake fansite fronts
- Hacked fansites
- Hacked online games that have been compromised
- Hacked email and social sites
- "Powerleveling" services
- Keylogging trojans (rarest form)

Any of these are almost assuredly NOT related to Diablo 3, this list was made over the last several years.  It could even be the pokemon fansite account you created for your kid 4 years ago.

*  Regarding phishing scams, ask yourself if, in the last 10 years, you have ever signed up for a beta, responded to a support ticket, or kept your account from being locked after unauthorized use...for ANY game, Blizzard or otherwise.

Your email address/username may be connected to several passwords spread over many such databases.  Hackers/phishers compile these lists and sell them to gold selling sites for pennies per name.  These gold sellers often are working from several different compiled lists.

What they all count on is that you use the same password or few passwords over and over again to do various things around the nets.  They use this to get access to your account easily, or to your email where they can reset your password and again get access to your account easily.

What Happens Now?
Now here is where the bot scripting sets in.  Once they access your account, the following happens in order by use of a very easy botting macro program.

1) A level 1 character is added to your friend's list.  This character is on a second computer than the one running the script.

2) This character creates a session in a town with a fixed location for the stash, etc.

3) Your character is invited to the session, the macro accepts the invite.

4) The macro (still in control of your character) proceeds to give the Level 1 all your stuff, all your gold, and walks your character to the stash where everything is cleaned out of the first tab and handed to the level 1.

Recently (in the last day or so) they've just been taking gold instead of totally stripping a character.  This can cut precious seconds or even a full minute off their hack time.

5) The macro runs fast, and not very thoroughly, ergo usually its just the last character you played that gets cleaned out in this manner.  It ensures they get the gold.

5b) if they're babysitting the macro and notice you have multiple characters, they'll clean it out by hand instead of letting the macro run, this is rare though.

6) Profit.

7) If they're feeling ballsy, a second macro will run, creating a first level character and then continuously spamming ads for gold sites on the trade/chat channels until the account gets reported enough.

Update - Watch in the video as an account thief actually demonstrates:
http://www.youtube.com/watch?v=sxVM06owyuk&feature=related

Things It Was Not
There is no actual hacking or "session hijacking" involved in this process, you are simply being logged in from another location.  If you were online at the time, you'll be kicked.  This is not a "session hijacking".  There was also no "monkey in the middle" attack or other assault on the English language that a hacker used to get your stuff.  They had your password, end of story.  The passwords are also not being brute-forced, people who believe so are idiots.

It has nothing to do with anyone seeing you in game, your friends list, whether you played alone or in a group, or used the auction house.

It also has nothing to do with how fancy or long your password was, Blizzard's security, game session security, how new your comp is, how much antivirus you run, or how many years you've been a clown working as IT.

Make Yourself a Hard Target
Like I tell my classes when I do security training, you don't need to outrun the bear, you just need to outrun your buddy.

2 main lines of defense to make yourself a hard target:

1 - Change your password for Bnet AND the attached email account to something you have never used before.  It doesn't need to be anything too fancy, just not a complete real word is good enough with a character and number mixed in somewhere, and don't do the obvious like names and dates or, god forbid, your bank card PIN (seen this a lot).  DO IT NOW.

2 - Get an authenticator that actually works for D3.

http://us.battle.net/d3/en/forum/topic/5642267887?page=2


总结是account info被出卖,然后用bot大量的侵略帐号
回复

使用道具 举报

Follow Us
发表于 6-6-2012 12:53 PM | 显示全部楼层
回复 26# poisonsoup

原来你就是这样中hack的。
回复

使用道具 举报

 楼主| 发表于 6-6-2012 01:49 PM | 显示全部楼层
回复  poisonsoup

原来你就是这样中hack的。
权少帅 发表于 6-6-2012 12:53 PM



   你自己小心啦

没有sms和authenicator是100%中
回复

使用道具 举报


ADVERTISEMENT

发表于 6-6-2012 02:08 PM | 显示全部楼层
How You Got Hacked 你是怎样被hack

The "hackers" are doing this by rolling through a database they ...
poisonsoup 发表于 6-6-2012 11:55 AM
所以非常強烈鼓勵使用 ymail 的 disposable email 服務~~~
如此一來,
你用一個 MAIN email 來 login,
這個 MAIN email 只有你一個人懂,
也只是單純拿來 login ymail,
過後再由這個 MAIN email,
你可以 create 超多個小小的 sub email~
可以 MAYBANK 一個 sub email,
Diablo 一個 sub email,
Facebook 一個 sub email,
男朋友女朋友一個 email 等等等等~
全部 sub email 放出去給人知道的 sub email,
都歸納為 MAIN email 來總控制。

在確定你自己的電腦沒有中毒的前提下,
使用這個 disposal email 服務後,
當你收到了 spam mail 等可疑的郵件時,
你可以隨時都知道到底是哪一個 TMD 的公司或遊戲,
出賣了你的 email third party 公司~
因為那個 sub email 你只註冊和讓那個公司或遊戲知道而已~

所以也同樣的,
這個服務也絕對可以預防你遊戲的 email 因為和其他遊戲共用,
而被洩露出去
回复

使用道具 举报

发表于 6-6-2012 02:35 PM | 显示全部楼层
所以非常強烈鼓勵使用 ymail 的 disposable email 服務~~~
如此一來,
你用一個 MAIN email 來 login, ...
超级丑八怪[-_-] 发表于 6-6-2012 02:08 PM



gmail hotmail 有这种功能吗?
回复

使用道具 举报

发表于 6-6-2012 02:54 PM | 显示全部楼层
Disposable Email Service一年US19.90。

本帅也是用着。
回复

使用道具 举报

发表于 6-6-2012 02:59 PM | 显示全部楼层
gmail hotmail 有这种功能吗?
kitkatlow 发表于 6-6-2012 02:35 PM

印像中 gmail & hotmail 貌似沒有,
沒讀過他們有類似的服務和廣告~

ymail 也是兩三年前不小心 register 後,
隔了好久才收到廣告說他們剛開始新的 disposal email 的服務,
過後就開始把 ymail 當成主要 email 來使用了~
BTW,
如果是 yahoo.com 的 domain email 戶口,
是需要升級付費後才能用這個 disposal email 的服務,
暫時只懂 ymail.com domain 是可以免付費來使用 disposal email
回复

使用道具 举报

发表于 6-6-2012 03:01 PM | 显示全部楼层
Disposable Email Service一年US19.90。

本帅也是用着。
权少帅 发表于 6-6-2012 02:54 PM

真的超好用的~
也從這裡被我發現幾個 company 亂賣我的 email 給 third party!
Cari 就是其中一個!(不過還在疑惑會不會我有一次在 CC login cari 後中的)。

你可以轉來用 ymail,
disposable 服務甭錢
回复

使用道具 举报

发表于 6-6-2012 03:06 PM | 显示全部楼层
How You Got Hacked 你是怎样被hack

The "hackers" are doing this by rolling through a database they ...
poisonsoup 发表于 6-6-2012 11:55 AM


问题是... 这也是一些“仙家”自己的猜测
更何况,已经不少人用了Battle.net Authenticator 也中招。

我本身,使用dual boot 进入一个专用于玩游戏的Windows... 而且Battle.net的户口也是在D3推出当天换了新密码.

理论上,他的猜测根本不能套用在我身上。
回复

使用道具 举报

发表于 6-6-2012 03:10 PM | 显示全部楼层
什么被hack 不被hack,关键就是玩家对电脑的认识程度有多资深。误上了钓鱼网站,假的battle.net 地址不一样可是网页炒得跟真的一样。如果你不知道就输入username和 password。你的资料就被hacker盗用了。
回复

使用道具 举报

发表于 6-6-2012 03:11 PM | 显示全部楼层
gmail hotmail 有这种功能吗?
kitkatlow 发表于 6-6-2012 02:35 PM


gmail 其实最简单,而且是免费的。

比如说

你的email 是
wangahgou@gmail.com

你可以在后面加 +battlenet
wangahgou+battlenet@gmail.com 来注册battle.net  

你可以在后面加 +cari
wangahgou+cari@gmail.com  来注册cari.


这样你就可以轻易分辨谁出卖你的电邮地址了。
回复

使用道具 举报


ADVERTISEMENT

发表于 6-6-2012 03:19 PM | 显示全部楼层
什么被hack 不被hack,关键就是玩家对电脑的认识程度有多资深。误上了钓鱼网站,假的battle.net 地址不一样 ...
junclj 发表于 6-6-2012 03:10 PM


看得懂就看吧.
http://www.cinemablend.com/games/Diablo-3-Session-Spoofing-Real-Do-Join-Public-Games-43162.html
回复

使用道具 举报

发表于 6-6-2012 03:25 PM | 显示全部楼层
gmail 其实最简单,而且是免费的。

比如说

你的email 是


你可以在后面加 +battlenet
wang ...
megablue 发表于 6-6-2012 03:11 PM


这么明显,人家一看就自动辨识。比如一看 wangahgou+cari@gmail.com 就会自动把 +cari 给remove,用wangahgou@gmail.com
回复

使用道具 举报

发表于 6-6-2012 03:37 PM | 显示全部楼层
本帖最后由 megablue 于 6-6-2012 03:40 PM 编辑
这么明显,人家一看就自动辨识。比如一看 wangahgou+ 就会自动把 +cari 给remove,用wangahgou
kitkatlow 发表于 6-6-2012 03:25 PM


跟简单... 只要做一个filter... 后面没有+的都进入spam 或 label 成 "possible spam".

以后你填写电邮时, 就记得放+something就好了


刻意拿掉你的+something 就很大可能是spam/phishing了
回复

使用道具 举报

发表于 6-6-2012 03:58 PM | 显示全部楼层
How You Got Hacked 你是怎样被hack

The "hackers" are doing this by rolling through a database they ...
poisonsoup 发表于 6-6-2012 11:55 AM


酝酿10多年的db用在d3有什么好处...
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

本版积分规则

 

ADVERTISEMENT



ADVERTISEMENT



ADVERTISEMENT

ADVERTISEMENT


版权所有 © 1996-2023 Cari Internet Sdn Bhd (483575-W)|IPSERVERONE 提供云主机|广告刊登|关于我们|私隐权|免控|投诉|联络|脸书|佳礼资讯网

GMT+8, 25-10-2025 12:48 PM , Processed in 5.430365 second(s), 21 queries , Gzip On.

Powered by Discuz! X3.4

Copyright © 2001-2021, Tencent Cloud.

快速回复 返回顶部 返回列表