You are not logged in.

Applications: [GameMaster: OPEN] | [Volunteer Testers: OPEN]


This forum will be permanently shut down on Friday 13.07.2018
Please copy or save all important information from old forum before they will be deactivated
We have moved to new board. https://forum.runesofmagic.gameforge.com/Come join us.

Murkalael

Intermediate

  • "Murkalael" started this thread

Posts: 487

Location: Santo Andre - SP - Brazil

Occupation: Computer Fix Technician

  • Send private message

1

Sunday, July 8th 2012, 6:45pm

Warning to administration and players

Today as usual, I first gone to take a little glance on forum and when I tried to load the page, surprize!


I use opendns, and this is happening all over website, forum, even the latin made forum / site that I don't like. I have one other computer (where I'm writting this right now), without opendns and all is fine, but is worth to take a look in website security and people responsible for this to contact opendns to see what triggered their allarm. And players be aware that is a possible threat so be cautions with sensitive data. Ty for reading.

2

Sunday, July 8th 2012, 7:59pm

Could it be a false positive from the forum updates not too long ago? Granted with those people stealing EVERYONES Credit Card info a few years ago, this wouldn't surprise me a whole lot.
61/55/50 D/W/R

trav42073

Professional

Posts: 806

Location: Arizona

Occupation: welder/fabricator/antagonist

  • Send private message

3

Sunday, July 8th 2012, 8:15pm

i got similar warning but from mcaffee site advisor. just this morning.
95r/62m/63s/ Soultwist.
Ryaderr wrd/s/w erobos

Murkalael

Intermediate

  • "Murkalael" started this thread

Posts: 487

Location: Santo Andre - SP - Brazil

Occupation: Computer Fix Technician

  • Send private message

4

Sunday, July 8th 2012, 8:15pm

Not only foruns. Website, patcher as well, in the pc I use opendns even the patcher is showing this block because patcher loads an HTML file directly from website, so administration should contact opendns team and see what's going on. IDK if you are aware that tomorrow a few thousand pcs from US and Latin America could be offline because of a rootkit that redirect their dns servers for a zombie network, so it's a thing to be concerned. See the article bellow
http://www.dailymail.co.uk/sciencetech/a…d-machines.html

5

Sunday, July 8th 2012, 8:52pm

I suppose it wouldn't surprise too much to see website security compromised as well. Servers were held hostage a few years ago (The German ones i believe) because the classes desperately needed balancing (No joke, classes were THAT Bad) With all the blunders of the current overlords, I can't say it'd be shocking to find out that someone had hijacked the forums.
61/55/50 D/W/R

LadyMacV

Professional

Posts: 700

Location: Pennsylvania, USA

Occupation: Dental Hygienist

  • Send private message

6

Sunday, July 8th 2012, 8:58pm

Kaspersky Pure picked this up as well. In addition to the "Phishing" warning, I have an-in game guildie who has had his account attacked (someone attempting to log into it while he was online) twice within the last two days. He changed his passwords and managed to lock down both attempts on the account, but it seems someone has decided to be a bit more quiet about how to approach compromising both ROM's website and player accounts this time around.
In a world of black, white, and grey... I'd be bright friggin' purple. M/P on Reni.

7

Sunday, July 8th 2012, 9:13pm

Well, there are so many people who have their usernames either AS their account name on the forums or somewhere in their signature. I also hypothesize that most of these users also use the same password for the Forums as their in game account. This means that all someone would have to do is get access to Forum info and have plenty of info for in game characters.

i'd check to see if my characters are alright, but if they weren't I'd just rage about how support will likely say it was my fault and it was some addon i was using *COUGHCOUGH*

TBH it wouldn't come as a shock to see, "You access the forums at your own risk. Any loss of RoM items or currency in any form is not our fault."
61/55/50 D/W/R

Murkalael

Intermediate

  • "Murkalael" started this thread

Posts: 487

Location: Santo Andre - SP - Brazil

Occupation: Computer Fix Technician

  • Send private message

8

Sunday, July 8th 2012, 9:54pm

It's funny you mentioned that, because I have same username of game account but different passwords, and sometimes when I log in ingame I receive a warning that I entered wrong password once, but the case is that I log in just @night when I arrive from work.

paxm

Beginner

Posts: 16

Location: Artemis

  • Send private message

9

Monday, July 9th 2012, 11:29pm

I'm getting a phishing warning from McAfee too, on the main ROM page. Could we get a response from a CM or Froggy pls?

Nytefall

Unregistered

10

Monday, July 9th 2012, 11:52pm

This is a false positive - If you get messages like this, please report them to your DNS provider as a false positive so that they can review it.

Additionally, you may wish to switch to a new DNS provider if you find this annoying in the meantime.

Murkalael

Intermediate

  • "Murkalael" started this thread

Posts: 487

Location: Santo Andre - SP - Brazil

Occupation: Computer Fix Technician

  • Send private message

11

Tuesday, July 10th 2012, 1:54am

I just assumed that staff might wanna know about this, since opendns is an American company. I'm in Brazil and noticed this at first on Sunday, so I get concerned. I have 2 computers here, one that I use opendns for use with bank and other security stuff, and other with regulas DNS server from ISP, in this last one I can easily access all website / forum, etc. In my main computer even the patcher shows opendns blocking the load of main homepage. So I believe Frogster crew should contact opendns and find out what triggered this since I mentioned before, today (monday), FBI would pull the plug on that network with DNSchanger trojan, so it's all about be cautious.

12

Tuesday, July 10th 2012, 6:11am

Mine isn't my DNS. Mine is my AV. Kaspersky is now reading phishing on the loading client page (all that comes on that is the warning, but can still load game) FROM THE WEBSITE. Not the client itself.

paxm

Beginner

Posts: 16

Location: Artemis

  • Send private message

13

Tuesday, July 10th 2012, 2:32pm

Thanks Nytefall. I appreciate the response. :) I would have to agree with Keyshana, though. I do not believe this is a DNS issue for me.