You are not logged in.

Applications: [GameMaster: OPEN] | [Volunteer Testers: OPEN]


This forum will be permanently shut down on Friday 13.07.2018
Please copy or save all important information from old forum before they will be deactivated
We have moved to new board. https://forum.runesofmagic.gameforge.com/Come join us.

ray1981

Intermediate

Posts: 170

Location: Where ever the Army sends me

Occupation: US Army

  • Send private message

81

Thursday, March 22nd 2012, 9:22am

Quoted from "Kefkai;519113"

Lol.

People and their "Anti-viruses", most things go past undetected to the big anti-virus names.

Some even get past hijackthis nowadays, though I do still like hijackthis as a tool to remove things from the registry.



The one thing I have to ask about this is did you use your account password anywhere else? If you did your security is compromised.


I'm not on anyone's side here, but being 100% completely secure is hard.

It's why I have a 'secure' computer.

I don't use it for anything else but secure things, like if I wanted to change my password now, that's where I'd do it, you can't always ensure security on your end if you go to pretty much any website.


this is not a local issue with specific users, this is a situation of a compromised server. its only affecting the artemis server, whether its the authentication server or not is another question, but its not a local user issue, personal customer av software is whats not in question, this is dealing with the information security software/hardware on the servers side.
Ayawisgi 72K/S/P Ragequit | Govinda, Unb Stam 23.5k, Unb PA 37k
Lilfeather (Retired) 62K/P Realmguardian, Tribe | Govinda
Tanking Guide:http://forum.us.runesofmagic.com/showthread.php?t=75770

ray1981

Intermediate

Posts: 170

Location: Where ever the Army sends me

Occupation: US Army

  • Send private message

82

Thursday, March 22nd 2012, 9:36am

i bet its some looser on a wireless laptop gaining access via poor information security protocols, could be through hardware (ports, packets, storage devices, etc) or software (packet sniffer, network vulnerability software, etc), there never an absolute amount of information security you can have to prevent data compromise, even for enterprise networks.

i hope the firewall guys atleast have one, scanned the network with vulnerability software themsleves, maybe even an external honeypot (proxy) to atleast try to trick the loosers, and practice some sort of physical information security with access, eyes only, and authorization methods.

a network can have more than one firewall, firewall for external proxy, between that fake server and the actual network is an example. they could regularly scan the network themselves to prevent the network from being compromised, theres alot of practices and tools in place...i truly hope your net admin/IT security guys are atleast security+ certified...
Ayawisgi 72K/S/P Ragequit | Govinda, Unb Stam 23.5k, Unb PA 37k
Lilfeather (Retired) 62K/P Realmguardian, Tribe | Govinda
Tanking Guide:http://forum.us.runesofmagic.com/showthread.php?t=75770

83

Thursday, March 22nd 2012, 9:51am

Guildy is currently spamming world chat :( another one down
Mörder
75/55/50 P/S/K

84

Thursday, March 22nd 2012, 10:05am

Thers another level 70 spamming right now. Same website as the last couple of days.

Also, our biggest player has had his account suspended of which we/he can only assume is part of the same problem, which is worrying considering how many diamonds he buys and how much could have been lost as a result of this. Those of you who know me and what guild i am in will know who im talking about.

85

Thursday, March 22nd 2012, 12:38pm

Another possibility is that Aquila had a trojan on his system and whoever did all this was able to use his own computer making it almost untraceable. In security, having such remote access can be very damaging. If this were true, he most likely would have been able to have direct access to the Frogster database, the characters and so on.

Whats most important is we rule out every possibility we can though. I've run several security checks on my system, and am planning on changing all my passwords on all my sites as a precaution. As long as we do our part, and Frogster does theirs, we can hopefully minimise whatever is happening.

86

Thursday, March 22nd 2012, 2:12pm

Unless this is the person Morder was talking about, there is another one -- a lvl 67 P/K who has obviously been possessed and is now spamming outside of the auction house.
[img][/img]





87

Thursday, March 22nd 2012, 2:45pm

Quoted from "Zarli;519153"

Unless this is the person Morder was talking about, there is another one -- a lvl 67 P/K who has obviously been possessed and is now spamming outside of the auction house.


It isn't, its yet another person.

GarySandstorm

Professional

Posts: 656

Location: Cape Town: South Africa

Occupation: Engineering Technician

  • Send private message

88

Thursday, March 22nd 2012, 3:28pm

Is it me or is the forum layout been changed the main site links are gone, the logo at the top and some other minor things.

ruisen2000

not a wallet warrior

Posts: 4,052

Location: here

Mood: Blink

  • Send private message

89

Thursday, March 22nd 2012, 4:42pm

Quoted from "GarySandstorm;519162"

Is it me or is the forum layout been changed the main site links are gone, the logo at the top and some other minor things.


Notice that the CM/FM's chat are no longer in blue and green, but standard black like everyone else.
The hacker has come... :rolleyes:

And to Cm/FM's:
Its not that we're attacking you or purposely misunderstanding you or anything, but when such an upsetting thing has happened and continues to happen, your uncaring attitude is indeed very maddening. I'm not saying that you are uncaring about this issue, but reading your posts, it does deliver the feeling of "just check your computers, stop bothering us, thanks" when what available evidense points that the issue may be on Frogster's end.

If it is indeed the players computer's issue, the hacking should be on all servers at any time. It is quite coincidental that it is all on Artemis and all during this week.
Noblewarrior
lv 98/98/89/60 M/W/P/K
Kikosi 98/50/60 Wl/Ch/M
the fail clothie tank~

Inactive

Posts: 262

Location: The Ocean?

  • Send private message

90

Thursday, March 22nd 2012, 4:51pm

Quoted from "ruisen2000;519171"

Notice that the CM/FM's chat are no longer in blue and green, but standard black like everyone else.
The hacker has come... :rolleyes:

And to Cm/FM's:
Its not that we're attacking you or anything, but when such an upsetting thing has happened and continues to happen, your uncaring attitude is indeed very maddening. I'm not saying that you are uncaring about this issue, but reading your posts, it does deliver the feeling of "just check your computers, stop bothering us, thanks" when what available evidense points that the issue may be on Frogster's end.


The issue is that it isn't an uncaring attitude. As much as you would like us to help you fix the problems instantly... only the GM's can fix problems related to hacked accounts.

I have forwarded whatever information that comes up to the appropriate people.

I will repeat what I have previously stated in this thread and the other thread.

If you feel that you are at risk of a hacking attempt, the only thing you have in your control is the ability to change your password. If you see someone who was hacked, you have to submit a support ticket. (If you have seen someone is hacked at this very moment, please send the character name or the account name toto Roeksha ( http://forum.us.runesofmagic.com/member.php?u=106582 ) )

-TunaShake

91

Friday, March 23rd 2012, 1:02am

Quoted from "TunaShake;518958"

I would like a bit more clarification concerning this matter that (in my opinion) seems like a bunch of you are acting overly paranoid.


I would like a bit more clarification concerning this matter that (in my opinion) seems like a Mentor is acting overly dismissive.

Quoted

You guys need to relax and calm down. As far as I know there hasn't been a compromise otherwise we would have noticed a few days ago instead of now.


You need to read and understand. As far as I know there has been a massive compromise, otherwise a GM account wouldn't have been hacked.

Quoted

If you can change your password, go ahead and do so. If you cannot and come up with an error, make sure you are using the right password.


If you can say there isn't a malicious hacker, go ahead and say so. If you cannot see that this is a situation of epic proportions, make sure you are using your logic.

Quoted

If you cannot log into the game because you did not change your password. You need to submit a ticket.


If people cannot log into the game because they did not change their password. They need to uninstall RoM due to non-helpful/prolonged solution to a ticket.

Quoted

I see nothing wrong with my account.


Part of me wants to be snarky and say something like "Let's see if you say that when someone hacks you, burns your megas, steals your gear/gold, and leaves you without a paddle."



It's this kind of response from anyone affiliated with Frogster that makes me dislike the company. This is a serious issue. Massively serious. And to me, in my opinion, it's being downplayed and dismissed. I really hope this is bigger than I believe it to be; maybe when all of the paying players quit after a cataclysmic hack attack, Frogster will realize that paying customers don't like being ignored.

We need a US-based Frogster division again. Except, a Frogster division that actually gets things done. This seems to be a lot of the same old stuff from back in the day with FAI.

No offence.

Quoted from "UncleMart;518972"

Sorry, but I've been down this road before, see my previous post. Not being rude but I think trying to reason with you or convince you to look into this will be fruitless. Frogster should be looking into this. If they're not, then it really goes to show how little they care about the game and their customers. I'll wait for a CM to post in this thread so hopefully someone will actually listen.


Like I just posted, bro... more of the same. I'm starting to actually miss FAI. Seriously. I know I know, I sound like I just lost my mind, but it's true.
" ...either a service provider who fails to pass on customer feedback, or developers with the listening skills of Helen Keller..." - zaeltaeth
[img][/img]

Posts: 262

Location: The Ocean?

  • Send private message

92

Friday, March 23rd 2012, 1:33am

Quoted from "Myxril;519273"

I would like a bit more clarification concerning this matter that (in my opinion) seems like a Mentor is acting overly dismissive.



You need to read and understand. As far as I know there has been a massive compromise, otherwise a GM account wouldn't have been hacked.



If you can say there isn't a malicious hacker, go ahead and say so. If you cannot see that this is a situation of epic proportions, make sure you are using your logic.



If people cannot log into the game because they did not change their password. They need to uninstall RoM due to non-helpful/prolonged solution to a ticket.



Part of me wants to be snarky and say something like "Let's see if you say that when someone hacks you, burns your megas, steals your gear/gold, and leaves you without a paddle."



It's this kind of response from anyone affiliated with Frogster that makes me dislike the company. This is a serious issue. Massively serious. And to me, in my opinion, it's being downplayed and dismissed. I really hope this is bigger than I believe it to be; maybe when all of the paying players quit after a cataclysmic hack attack, Frogster will realize that paying customers don't like being ignored.

We need a US-based Frogster division again. Except, a Frogster division that actually gets things done. This seems to be a lot of the same old stuff from back in the day with FAI.

No offence.


I understand that you might feel a little frustrated at the moment.

You need to remember that we do care about this issue, however, we do know (as Dionaea has stated in this thread before) the servers have not been compromised. There is no hacker. It is just people who accidentally downloaded the wrong things, used the same usernames and passowrds on different websites or the most common one Account Sharing.

You also need to remember that this information has been forwarded to the appropriate department. You guys know everything that we do know.

A lot of people keep saying that "But a GM account got hacked", GM's are people too and they log onto the wrong websites, download the wrong programs and end-up compromising inactive accounts.

There isn't much you can do about it.

I understand your need to be overly aggressive but that is not necessary. We are doing everything (actually, we have done everything) in our power to help.

Now the only thing we ask you to do is to submit a support ticket if you feel that your account is at risk. For whatever reason...

Please let me know if you any further questions concerning this matter.

-TunaShake

93

Friday, March 23rd 2012, 1:39am

Quoted from "TunaShake;518958"

(in my opinion) seems like a bunch of you are acting overly paranoid.

You guys need to relax and calm down.
-TunaShake


these two tasty fragments where what i reacted to... but being called paranoid and then dismissed with a slightly demeaning "calm down" after being hacked and seeing a string of what now 15? people hacked in the last 3 days is a bit frustrating.

As of yet i have not received any communication from frogster/RW concerning the ticket I submitted about what was taken from me (other then auto confirm and my reply to that) so we will see how they decide to work this out. hopefully things are put right and they catch whoever is doing this =)
Berec [PPK]
Class: R/S/K 72/72/72
Server: Artemis

ruisen2000

not a wallet warrior

Posts: 4,052

Location: here

Mood: Blink

  • Send private message

94

Friday, March 23rd 2012, 1:46am

Quoted from "TunaShake;519284"

we do know (as Dionaea has stated in this thread before) the servers have not been compromised. There is no hacker. It is just people who accidentally downloaded the wrong things, used the same usernames and passowrds on different websites or the most common one Account Sharing.



What bugs me about this is - then why is it all happening now? This is an ongoing issue with everyone at any time. Why is it only happening now? And why is it only happening to players in that particular server?
Noblewarrior
lv 98/98/89/60 M/W/P/K
Kikosi 98/50/60 Wl/Ch/M
the fail clothie tank~

Inactive

Posts: 262

Location: The Ocean?

  • Send private message

95

Friday, March 23rd 2012, 1:49am

Quoted from "ruisen2000;519287"

What bugs me about this is - then why is it all happening now? This is an ongoing issue with everyone at any time. Why is it only happening now? And why is it only happening to players in that particular server?


The only thing I can suggest is that it was all a coincidence. I do not have any information and I most likely never will have that information to know.

The first thing that comes to mind is most likely a common forum all these people visit and used the same usernames and passwords for them and someone (in power) in that specific forum decided to abuse that information.

-TunaShake

96

Friday, March 23rd 2012, 1:56am

Can someone spare a hand? I need more to facepalm

Quoted from "TunaShake;519284"

You need to remember that we do care about this issue, however, we do know (as Dionaea has stated in this thread before) the servers have not been compromised. There is no hacker. It is just people who accidentally downloaded the wrong things, used the same usernames and passowrds on different websites or the most common one Account Sharing.


You sound so certain that this is the players' fault and not Frogster's. For as long as it takes you guys to do anything for us here in the US, I'm utterly amazed that ALL OF THE DATA has been reviewed and reported as not compromised. Only, what, about 3 days or so after this happened?

Remember what you typed here. I'm going to rake you over the coals with it in the future.

Quoted

I understand your need to be overly aggressive but that is not necessary. We are doing everything (actually, we have done everything) in our power to help.


I wasn't being aggressive. I like how I made pointedly ridiculous comments like you did (/trollface), followed by my opinion about Frogster's negative reputation for being the non-caring entity it is. OH BUT THAT'S AGGRESSIVE. No, clueless sir, it is called voicing my opinion. Don't slander me. Thank you.

Quoted

Now the only thing we ask you to do is to submit a support ticket if you feel that your account is at risk. For whatever reason...


You do realize that a lot of people have been neglected by support too many times to even care to waste their time to send a ticket, right?

Quoted

Please let me know if you any further questions concerning this matter.


Here's a question; when will the hacker be indentified/stopped, and how soon will the hacked people get their accounts restored to pre-hacked condition?


PS: Don't tell me there isn't a hacker while telling me that there is (remember the part about going to the wrong webpage or downloading the wrong thing? Guess who uses those methods; HACKERS).

I feel like randomly defenestrating something. Your words of dismissive neglect invoke rage, sir, and NOW inspire me to be aggressive. You should have some of your fellow Mentors or CMs read the stuff you're posting. Peer Review. Seriously.
" ...either a service provider who fails to pass on customer feedback, or developers with the listening skills of Helen Keller..." - zaeltaeth
[img][/img]

97

Friday, March 23rd 2012, 2:47am

Another update for the thread:

Both my accounts have been suspended/blocked.

I submitted a ticket, I received automated responses for both accounts and one direct response from Frogster Support stating they set up a temporary account asking me to reset my password for primary account (link lasts for 24 hours).

I will wait patiently for them to fix my accounts.

Here's the weird part:

1. Primary account is run on a brand new system with specs previously explained.

2. Secondary account is run on separate system, stand-alone, only purpose is to run my alt account.

I see replies stating that accounts can be compromised because people downloaded the wrong thing, visited a website, shared their information, etc.

My primary system is pristine, brand new system as of 2 months ago, i don't go to any unknown links, torrents, porn, or hidden links.

I do the same thing everyday like clockwork - Check ESPN, ROM forums, MSN, Gamespot, and Oakland Tribune site.

My Secondary system does one thing only, runs a ROM client, no web client ever opened.

So why were both of my accounts knocked out on the same day, same time?

The explanation to players that this problem can stem from end user accessing or downloading harmful or malicious items from the web simply does not apply to my situation.

Maybe visiting the sites i outlined above constitutes harmful or dangerous sites, if so, then i throw my hands up.

Started in 03/2009, never had any problems with accounts being compromised or suspended.

Again i am just trying to understand how this happened and how i can get both my accounts restored to active duty.


Roth
P/M 70/70
Artemis

98

Friday, March 23rd 2012, 3:01am

10pm EST. Reni account hacked and spamming gold messages. Looks like Artemis is not the only target.

Character is level 67, and as far as I know not an active player. Guildless too. So, chances of recent activity causing the problem are fairly small.
-- Rustyx --- 92R / 92S / 92M on Reni (Guild KnightShift). Yes, running the new FOTM R/M, cause I am not elf enough to be WD/S.

Oh, and people who have more than 3 classes are clinically insane.


99

Friday, March 23rd 2012, 3:02am

This has just hit Reni 5 minutes before SW began today. An inactive player was hacked and started spamming a gold seller website with all his world shouts. This player has been quit for quite a while so I'm not sure if this is a virus on a player's computer...
Firetruck W/Wdn/S 72/72/72- Retired as well now...
Bangsalot K/S/R 70/70/68 - Retired
Heretic- Reni

smid1401

Intermediate

Posts: 284

Location: Right here cant you see me ??

Occupation: Bin there dun that

  • Send private message

100

Friday, March 23rd 2012, 3:05am

Just seen a 67/62 spam world on Reni : ( Sad day