| Pages: [1] 2 :: one page |
| Author |
Thread Statistics | Show CCP posts - 7 post(s) |
|

CCP Wrangler

|
Posted - 2007.11.28 13:55:00 -
[1]
We have reason to believe that certain parties are asking players for their email address in order to send them files with embedded keyloggers. Not opening attachments only gets you so far, not giving strangers your email address is the best defense against this form of attack.
If someone you don't know and trust contacts you and asks for your email address, do not under any circumstances give it to them! This applies especially to players who are attempting to sell characters on the character sell forum as they seem to be the current target of choice.
Wrangler Community Manager CCP Games, EVE Online Email / Netfang
"The trouble with having an open mind, of course, is that people will insist on coming along and trying to put things in it." |
|

Moon Kitten
GoonFleet GoonSwarm
|
Posted - 2007.11.28 13:59:00 -
[2]
How does this affect the people who use the Linux or Mac client?
 Layla > i wont have anyone say we didnt fight for our space
Please resize image to a maximum of 400 x 120, not exceeding 24000 bytes, ty. If you would like further details please mail [email protected] - Cortes |
|

CCP Wrangler

|
Posted - 2007.11.28 14:04:00 -
[3]
Originally by: Moon Kitten How does this affect the people who use the Linux or Mac client?
It probably depends on what kind of keylogger it is, but you should be careful no matter what OS you use. There is no reason to use anything except forum threads, evemails and in game convos anyway, there is no reason at all to use emails to communicate.
Wrangler Community Manager CCP Games, EVE Online Email / Netfang
"The trouble with having an open mind, of course, is that people will insist on coming along and trying to put things in it." |
|

torswin
Silver Snake Enterprise Interstellar Starbase Syndicate
|
Posted - 2007.11.28 14:18:00 -
[4]
Originally by: Moon Kitten How does this affect the people who use the Linux or Mac client?
As long as you have an updated system and don't give them root access there shouldn't be any problem. --- Unless explicitly stated, this post does not represent my alliance, corporation, my own, or any other living organism's view. |

Barrick Stormsworn
Minmatar Re-Awakened Technologies Inc Electus Matari
|
Posted - 2007.11.28 14:21:00 -
[5]
Linux and Mac, though not as susceptible to viruses, rootkits, keyloggers and the like as Windows is, are still very vulnerable if not secured properly. A great many Linux servers have been adopted into botnets because their administrators thought "Oh, it's Linux, that means it's secure and I don't have to do anything!" The user ensures security, not the OS.
That being said, Novell's AppArmour and Red Hat's SELinux are two good GUI tools for securing their respective distros. If you are concerned about security, look for solutions for your distro and play around with it a bit. It's not too hard to secure a box enough to ward off the casual attacker.
This isn't to say that Windows is all that hard either; antivirus, spyware scanners, and hardware/software firewalls pretty much do the trick. It's just that the security of Linux/Mac(Unix) is built in, where it has to be bolted on to Windows.
Originally by: Tarminic OH MY GOD WHAT HAVE YOU DONE?!
|
|

GM Guard

|
Posted - 2007.11.28 14:21:00 -
[6]
Edited by: GM Guard on 28/11/2007 14:21:59
Originally by: torswin
Originally by: Moon Kitten How does this affect the people who use the Linux or Mac client?
As long as you have an updated system and don't give them root access there shouldn't be any problem.
An even simpler answer....
Don't give them your E mail address.
|
|

Pilk
Axiom Empire
|
Posted - 2007.11.28 15:03:00 -
[7]
Quote: Not opening attachments only gets you so far, not giving strangers your email address is the best defense against this form of attack.
Are we seriously worried that the ghostly gobblies are somehow going to attack? Or are we worried about a 0-day exploit against a mail client being inaugurated by a single-target, very traceable attack against an EVE player for their account?
Advise people to keep their Email software up-to-date, even advise them to use alternate mail client, like Thunderbird, Eudora, or GMail's web interface, but your hysteria seems a bit overblown here.
--P
Kosh: The avalanche has already started. It is too late for the pebbles to vote. |

Pilk
Axiom Empire
|
Posted - 2007.11.28 15:10:00 -
[8]
Originally by: torswin
Originally by: Moon Kitten How does this affect the people who use the Linux or Mac client?
As long as you have an updated system and don't give them root access there shouldn't be any problem.
While you're certainly welcome to do as you wish, I try not to give attackers access of any sort to my machines, even non-root logins. I believe what you meant to say is, "Don't run applications, especially something as blatantly-stupid as an email client, as root." Which is very true, but doesn't really do a whole hell of a lot to protect you from a keylogger, as you're likely to run Eve as the same user as your mail client, which means a userspace keylogger can poll for the Eve client's pid and just tap into I/O for it once found, without ever needing to setuid() or be a kernel module (the most common *NIX keylogger approach).
In reality, you're mostly just protected by the fact that you're on a different OS; 99% of attackers won't bother to port their code to another OS, so unless you do something monumentally stupid, like explicitly running an application you've been forwarded, you're safe.
--P
Kosh: The avalanche has already started. It is too late for the pebbles to vote. |

Nisd
Metals Minerals Manufacturers
|
Posted - 2007.11.28 15:17:00 -
[9]
A good way to defende windows on is installing a anti-malware/spyware, Like Comodo Firewall Pro i got this feacture that is call IDefence, it monitors for hook's and dll injections. And it is just a good firewall.......
|

Snake Doctor
MacroIntel United Corporations Against Macros
|
Posted - 2007.11.28 16:03:00 -
[10]
If anyone in UCAM alliance ever asks you for any personal information, for any reason whatsoever (without being prompted by you), please contact me or Mongwen ingame.
There are a lot of keyloggers floating around right now. Any of the programs downloaded from t**lt are a risk, as well as the most* of the "macro" programs available on ebay.
Join MacroIntel! |
|

CCP Wrangler

|
Posted - 2007.11.28 16:21:00 -
[11]
Originally by: Pilk
Quote: Not opening attachments only gets you so far, not giving strangers your email address is the best defense against this form of attack.
Are we seriously worried that the ghostly gobblies are somehow going to attack? Or are we worried about a 0-day exploit against a mail client being inaugurated by a single-target, very traceable attack against an EVE player for their account?
Advise people to keep their Email software up-to-date, even advise them to use alternate mail client, like Thunderbird, Eudora, or GMail's web interface, but your hysteria seems a bit overblown here.
--P
You are always responsible for your account information and having someone steal your account will at minimum cost you time, but in some cases it can also cost you ISK, items etc. Considering we have started receiving cases where people gave out their email and got infected with a keylogger and got their account stolen, I don't see this as "hysteria". It's more about protecting our players.
Wrangler Community Manager CCP Games, EVE Online Email / Netfang
"The trouble with having an open mind, of course, is that people will insist on coming along and trying to put things in it." |
|

Darken Two
Gallente Cruororis Consors Conlegium Ivy League
|
Posted - 2007.11.28 16:59:00 -
[12]
Originally by: Pilk
Quote: Not opening attachments only gets you so far, not giving strangers your email address is the best defense against this form of attack.
Are we seriously worried that the ghostly gobblies are somehow going to attack? Or are we worried about a 0-day exploit against a mail client being inaugurated by a single-target, very traceable attack against an EVE player for their account?
Advise people to keep their Email software up-to-date, even advise them to use alternate mail client, like Thunderbird, Eudora, or GMail's web interface, but your hysteria seems a bit overblown here.
--P
They are protecting tehir players which is the right thing to do. Stop being a smartass.
Originally by: Blind Fear Generally, when trying to be a puppetmaster, it is considered good form not to wrap the strings around your neck and choke yourself.
|

Dan Grobag
Caldari Oyster Colors
|
Posted - 2007.11.28 17:06:00 -
[13]
would www.PLAYEVE.com be some sort of scam ?
|

Snake Doctor
MacroIntel United Corporations Against Macros
|
Posted - 2007.11.28 17:11:00 -
[14]
Edited by: Snake Doctor on 28/11/2007 17:11:34
Originally by: Dan Grobag would ---- be some sort of scam ?
Of course. And an ISK seller affiliate. And a mail spammer. Money launderer. Etc...
PS: You should remove that address before a mod gets to it 
Join MacroIntel! |

manasi
Caldari Valhalla Navy Technical Institute
|
Posted - 2007.11.28 17:32:00 -
[15]
Originally by: Nisd A good way to defend windows on is installing a anti-malware/spyware, Like Comodo Firewall Pro i got this feature that is call IDefence, it monitors for hook's and dll injections. And it is just a good firewall.......
I have not had any luck with that firewall...obviously the first line is to do as CCP wrangler said...no one should e-mail you about your EVE password.
As far as other firewalls not here to discuss... that just my 2 cents
I work in a testing lab and we see lots of personal firewalls..sadly, the Comodo one is one we do NOT recommend due to all the problems on our install base of 2K XP XPSP2 and Vista.
Manasi
|

Amerus
Eternal Industries
|
Posted - 2007.11.28 18:13:00 -
[16]
Thanks for the warning. Also a bit of comon sence. NO real need to give it out to strangers or open mails you are not expecting. Specialy not when ya got pm in game, eve mail and the forum boards. ______________________
Im Minmatar, i can't afford a sig! |
|

GM Retrofire
Game Masters

|
Posted - 2007.11.28 18:24:00 -
[17]
We have noticed that there is a trojan out there that's called ibm00002.dll, information on it can be found here
We suggest that everyone scan their computer thoroughly using their installed anti-virus program and/or spyware removal tool. If you don't have one installed you can do this using TrendMicro's Housecall utility which is an online scanner
|
|

Snake Doctor
MacroIntel United Corporations Against Macros
|
Posted - 2007.11.28 18:27:00 -
[18]
Originally by: GM Retrofire We have noticed that there is a trojan out there that's called ibm00002.dll, information on it can be found here
We suggest that everyone scan their computer thoroughly using their installed anti-virus program and/or spyware removal tool. If you don't have one installed you can do this using TrendMicro's Housecall utility which is an online scanner
I always suggest to clients that they use Avira Antivir for home use. It catches EVERYTHING I've ever thrown at it. And it's free. Like free-free for the personal edition.
www.free-av.com
Join MacroIntel! |

Verlaine Glariant
Knights of the Flame Knights Of the Southerncross
|
Posted - 2007.11.28 18:42:00 -
[19]
Thanks for the tip.
Sounds like a CCP's strategy to keep all character trading under control.
Verlaine Glariant. Tactical Weapons Specialist.
|

Lazuran
Gallente Time And ISK Sink Corporation
|
Posted - 2007.11.28 19:12:00 -
[20]
Originally by: torswin
Originally by: Moon Kitten How does this affect the people who use the Linux or Mac client?
As long as you have an updated system and don't give them root access there shouldn't be any problem.
Unfortunately, under Linux (and probably OSX as well) you do not need root to start a keylogger while you are using X11.
Also, once someone has access to the X display, there are plenty of holes in old (and possibly current) X clients with local privilege escalation. Not that privilege escalation is necessary to do a lot of nasty stuff to a user's data or to host malware (spam bots etc.).
So basically there are many opportunities for malware to infect a Linux/OSX box even if you are not using root. Making such broad statements as above is a bit reckless... In practice, the biggest contribution to Linux/OSX desktop security (i.e. safety from malware) is the small market share, then comes the system architecture (and exploit-friendly languages like C used) and quality of software (that may be a bit better than on Windows).
"...been designed for one purpose and one purpose only. Imagine a handful of repair drones pouring from the carebear's mouth. Now imagine they have um, nothing." -Unknown Hel redesigner (2007) |

Sister Impotentata
Caldari Elite Angels Of Death
|
Posted - 2007.11.28 22:52:00 -
[21]
Poor, poor Clementine. Don't let this happen to you. Please EVE safely. ----- TANSTAAFL
Originally by: Psycho John Petrucci If there's any point where you feel it's too difficult, then just stop. Because you just, you don't have it, you're just not good.
|

voogru
Gallente Massive Damage
|
Posted - 2007.11.28 23:48:00 -
[22]
Man, I wish CCP would give us the option of restricting our accounts to only be able to log on from specific IP addresses for us with static IP's.
Hate Farmers? Click Here |

ry ry
StateCorp Veritas Immortalis
|
Posted - 2007.11.28 23:49:00 -
[23]
Edited by: ry ry on 28/11/2007 23:49:59
CAUTION! THIS LINK CONTAINS A LOGGER.
Please resize image to a maximum of 400 x 120, not exceeding 24000 bytes, ty. If you would like further details please mail [email protected] - Cortes |

VicturusTeSaluto
|
Posted - 2007.11.29 03:26:00 -
[24]
Edited by: VicturusTeSaluto on 29/11/2007 03:27:19
Originally by: CCP Wrangler You are always responsible for your account information
From stories I have read I take this to mean that if your account is hijacked that you are on your own. This is not a good policy because the game client itself can not be assured to be secure. Not to mention that the OS that 99% of the players use is inherently insecure.
Really, the only good way to try and protect your own account security would be to only play eve on a seperate machine that is firewalled off from everything but eve, and to never- ever run any other apps- except perhaps in a virtual machine. Not to mention to have the machine secured again physical access.
In these times, people have gotten rootkits on their machines from simple acts like playing a commercial music cd, or viewing an image file posted to a forum such as this one.
I take a lot of precautions because I am fortunate enough to know a good deal about computers- many players do not know much.
|

Topaz Skydiver
Minmatar Narrative Freshfood
|
Posted - 2007.11.29 04:05:00 -
[25]
Edited by: Topaz Skydiver on 29/11/2007 04:08:51
Originally by: Lazuran (and exploit-friendly languages like C used
Yes, actually the abundance of buffer-overflow errors is shocking me. Sometimes I wonder, if there was ever a longer C program written without buffer overflows. It's not explainable by programmers making random mistakes, but has a lot to do with bad coding habits and people not fully understanding, what they are doing. So they shoot themselves in the foot and C doesn't stop them, because C assumes you know exactly, what you are doing and gives you a lot of freedom.
Personally I prefer C++. You have the full power like in C combined with the tools that help you more easily to avoid stupid mistakes, at least if you invest effort to really understand the stuff that you plan to use. But I think technical anyway, like have a clear view how the objects, pointers etc are lying in memory, so it's quite clear that I like it. Agree that there are other languages though, that have other strength and more appropriate and they are often easier to learn and people can't write evil mistakes so easily with most of them. --------------------------------------------- *snip* |

Nobloodx
|
Posted - 2007.11.29 06:34:00 -
[26]
welp i may not agree with ur patches, but u do a dam good job in keeping our accounts secure, thanks ccp
|

Andrue
Amarr
|
Posted - 2007.11.29 08:31:00 -
[27]
Windows users would also do well not to log in as administrators. Most Windows applications run just fine as a limited user. It can be a minor nuisance when you have a genuine need to perform system maintennance but if you enable fast user switching it's not too bad.
How to change.
-- (Battle hardened industrialist)
[Brackley, UK]
My budgie can say "ploppy bottom". You have been warned. |

Arcticblue2
Gallente Nordic Freelancers inc
|
Posted - 2007.11.29 09:24:00 -
[28]
While I played WoW I became targeted by probably goldfarmers or something like that, and while I use both a Anti-virus program and firewall and from time to time use ad-aware to check for spyware I did not find that keylogger that made it possible to clean out one of the servers I played on.
So right now there is one server there where all my characters are naked... (mostly female characters so I don't mind really).
I did read on their forums that it was suggested to install a program called Hitman that use several anti-spyware programs (free to use aparently), and while it does take a while to search the computer it did infact find several malware/spyware including one keylogger used spesific towards WoW.
While I did not find out where I did get that logger from, I do suspect it came from sites that gives clues to quests and ****, there is quite possible that goes towards EVE as well.
---------------------------------------------- "When I was a child, I spoke as a child, I felt as a child, I thought as a child: now that I am become a man, I have put away childish things." 1 cor. |

Pilk
Axiom Empire
|
Posted - 2007.11.29 10:13:00 -
[29]
Originally by: CCP Wrangler
Originally by: Pilk
Quote: Not opening attachments only gets you so far, not giving strangers your email address is the best defense against this form of attack.
Are we seriously worried that the ghostly gobblies are somehow going to attack? Or are we worried about a 0-day exploit against a mail client being inaugurated by a single-target, very traceable attack against an EVE player for their account?
Advise people to keep their Email software up-to-date, even advise them to use an alternate mail client, like Thunderbird, Eudora, or GMail's web interface, but your hysteria seems a bit overblown here.
--P
You are always responsible for your account information and having someone steal your account will at minimum cost you time, but in some cases it can also cost you ISK, items etc. Considering we have started receiving cases where people gave out their email and got infected with a keylogger and got their account stolen, I don't see this as "hysteria". It's more about protecting our players.
I agree with your aims, to be certain, but being the boy who cried, "Wolf!" is not the solution. Overstating the dangers, and overcorrecting for the perceived risks, leads to user disenchantment with security in general. Witness the number of Vista users calling the helpdesk, wanting to turn off all of the new warnings. Not some. All.
search:Vista Disable Warnings (841,000 results) (and probably far more by the time you click the link)
Again, my issue was not with your warning, which was timely and, doubtless, well-founded. My issue was with your recommendations. With the reduced space now available in EVEMails, and the need to transfer around large dumps of data, spreadsheets, applications, etc., that I often generate in the course of my Eve business, operating without the benefit of being able to communicate with other players out-of-band would render me blind, dumb--and broke. Were I a less-security-aware user, I might therefore read your warning with interest, then note that the suggested resolution steps are unacceptable and resolve to cross my fingers and trust in the GM's ability to reverse all fraudulent transactions.
At any rate, thank you for the warning about the sudden surge in keyloggers being sent via this method. Speaking as both an Eve player and a network security professional, I'd simply ask that you avoid overreaching in any one area of the security trifecta of cheap, useable, and effective when issuing direct calls to action to your users.
--P
Kosh: The avalanche has already started. It is too late for the pebbles to vote. |

Andrue
Amarr
|
Posted - 2007.11.29 10:19:00 -
[30]
Pilk, I think you are overreacting. The warning was timely (as you say) but also brief and to the point. It contains useful advice that every computer user should follow all the time.
The fact that so many people are asking MS how to hide the warnings and how to turn off UAC and run as administrator is a sad reflection on the users. I bet those people don't whine and moan to the builder for putting security locks on doors and windows. Then again a fair number do moan about seatbelts in vehicles so perhaps we just have to accept that a large minority of the population are fools.
The rest of us need to be sympathetic, try to educate them and if all else fails put them in a locked room and throw away the key. Er.. Sorry. That last bit may have sounded a litle harsh  -- (Battle hardened industrialist)
[Brackley, UK]
My budgie can say "ploppy bottom". You have been warned. |
| |
|
| Pages: [1] 2 :: one page |
| First page | Previous page | Next page | Last page |