| Pages: 1 2 :: [one page] |
| Author |
Thread Statistics | Show CCP posts - 7 post(s) |
|

CCP Wrangler

|
Posted - 2007.11.28 13:55:00 -
[1]
We have reason to believe that certain parties are asking players for their email address in order to send them files with embedded keyloggers. Not opening attachments only gets you so far, not giving strangers your email address is the best defense against this form of attack.
If someone you don't know and trust contacts you and asks for your email address, do not under any circumstances give it to them! This applies especially to players who are attempting to sell characters on the character sell forum as they seem to be the current target of choice.
Wrangler Community Manager CCP Games, EVE Online Email / Netfang
"The trouble with having an open mind, of course, is that people will insist on coming along and trying to put things in it." |
|

Moon Kitten
GoonFleet GoonSwarm
|
Posted - 2007.11.28 13:59:00 -
[2]
How does this affect the people who use the Linux or Mac client?
 Layla > i wont have anyone say we didnt fight for our space
Please resize image to a maximum of 400 x 120, not exceeding 24000 bytes, ty. If you would like further details please mail [email protected] - Cortes |
|

CCP Wrangler

|
Posted - 2007.11.28 14:04:00 -
[3]
Originally by: Moon Kitten How does this affect the people who use the Linux or Mac client?
It probably depends on what kind of keylogger it is, but you should be careful no matter what OS you use. There is no reason to use anything except forum threads, evemails and in game convos anyway, there is no reason at all to use emails to communicate.
Wrangler Community Manager CCP Games, EVE Online Email / Netfang
"The trouble with having an open mind, of course, is that people will insist on coming along and trying to put things in it." |
|

torswin
Silver Snake Enterprise Interstellar Starbase Syndicate
|
Posted - 2007.11.28 14:18:00 -
[4]
Originally by: Moon Kitten How does this affect the people who use the Linux or Mac client?
As long as you have an updated system and don't give them root access there shouldn't be any problem. --- Unless explicitly stated, this post does not represent my alliance, corporation, my own, or any other living organism's view. |

Barrick Stormsworn
Minmatar Re-Awakened Technologies Inc Electus Matari
|
Posted - 2007.11.28 14:21:00 -
[5]
Linux and Mac, though not as susceptible to viruses, rootkits, keyloggers and the like as Windows is, are still very vulnerable if not secured properly. A great many Linux servers have been adopted into botnets because their administrators thought "Oh, it's Linux, that means it's secure and I don't have to do anything!" The user ensures security, not the OS.
That being said, Novell's AppArmour and Red Hat's SELinux are two good GUI tools for securing their respective distros. If you are concerned about security, look for solutions for your distro and play around with it a bit. It's not too hard to secure a box enough to ward off the casual attacker.
This isn't to say that Windows is all that hard either; antivirus, spyware scanners, and hardware/software firewalls pretty much do the trick. It's just that the security of Linux/Mac(Unix) is built in, where it has to be bolted on to Windows.
Originally by: Tarminic OH MY GOD WHAT HAVE YOU DONE?!
|
|

GM Guard

|
Posted - 2007.11.28 14:21:00 -
[6]
Edited by: GM Guard on 28/11/2007 14:21:59
Originally by: torswin
Originally by: Moon Kitten How does this affect the people who use the Linux or Mac client?
As long as you have an updated system and don't give them root access there shouldn't be any problem.
An even simpler answer....
Don't give them your E mail address.
|
|

Pilk
Axiom Empire
|
Posted - 2007.11.28 15:03:00 -
[7]
Quote: Not opening attachments only gets you so far, not giving strangers your email address is the best defense against this form of attack.
Are we seriously worried that the ghostly gobblies are somehow going to attack? Or are we worried about a 0-day exploit against a mail client being inaugurated by a single-target, very traceable attack against an EVE player for their account?
Advise people to keep their Email software up-to-date, even advise them to use alternate mail client, like Thunderbird, Eudora, or GMail's web interface, but your hysteria seems a bit overblown here.
--P
Kosh: The avalanche has already started. It is too late for the pebbles to vote. |

Pilk
Axiom Empire
|
Posted - 2007.11.28 15:10:00 -
[8]
Originally by: torswin
Originally by: Moon Kitten How does this affect the people who use the Linux or Mac client?
As long as you have an updated system and don't give them root access there shouldn't be any problem.
While you're certainly welcome to do as you wish, I try not to give attackers access of any sort to my machines, even non-root logins. I believe what you meant to say is, "Don't run applications, especially something as blatantly-stupid as an email client, as root." Which is very true, but doesn't really do a whole hell of a lot to protect you from a keylogger, as you're likely to run Eve as the same user as your mail client, which means a userspace keylogger can poll for the Eve client's pid and just tap into I/O for it once found, without ever needing to setuid() or be a kernel module (the most common *NIX keylogger approach).
In reality, you're mostly just protected by the fact that you're on a different OS; 99% of attackers won't bother to port their code to another OS, so unless you do something monumentally stupid, like explicitly running an application you've been forwarded, you're safe.
--P
Kosh: The avalanche has already started. It is too late for the pebbles to vote. |

Nisd
Metals Minerals Manufacturers
|
Posted - 2007.11.28 15:17:00 -
[9]
A good way to defende windows on is installing a anti-malware/spyware, Like Comodo Firewall Pro i got this feacture that is call IDefence, it monitors for hook's and dll injections. And it is just a good firewall.......
|

Snake Doctor
MacroIntel United Corporations Against Macros
|
Posted - 2007.11.28 16:03:00 -
[10]
If anyone in UCAM alliance ever asks you for any personal information, for any reason whatsoever (without being prompted by you), please contact me or Mongwen ingame.
There are a lot of keyloggers floating around right now. Any of the programs downloaded from t**lt are a risk, as well as the most* of the "macro" programs available on ebay.
Join MacroIntel! |
|

CCP Wrangler

|
Posted - 2007.11.28 16:21:00 -
[11]
Originally by: Pilk
Quote: Not opening attachments only gets you so far, not giving strangers your email address is the best defense against this form of attack.
Are we seriously worried that the ghostly gobblies are somehow going to attack? Or are we worried about a 0-day exploit against a mail client being inaugurated by a single-target, very traceable attack against an EVE player for their account?
Advise people to keep their Email software up-to-date, even advise them to use alternate mail client, like Thunderbird, Eudora, or GMail's web interface, but your hysteria seems a bit overblown here.
--P
You are always responsible for your account information and having someone steal your account will at minimum cost you time, but in some cases it can also cost you ISK, items etc. Considering we have started receiving cases where people gave out their email and got infected with a keylogger and got their account stolen, I don't see this as "hysteria". It's more about protecting our players.
Wrangler Community Manager CCP Games, EVE Online Email / Netfang
"The trouble with having an open mind, of course, is that people will insist on coming along and trying to put things in it." |
|

Darken Two
Gallente Cruororis Consors Conlegium Ivy League
|
Posted - 2007.11.28 16:59:00 -
[12]
Originally by: Pilk
Quote: Not opening attachments only gets you so far, not giving strangers your email address is the best defense against this form of attack.
Are we seriously worried that the ghostly gobblies are somehow going to attack? Or are we worried about a 0-day exploit against a mail client being inaugurated by a single-target, very traceable attack against an EVE player for their account?
Advise people to keep their Email software up-to-date, even advise them to use alternate mail client, like Thunderbird, Eudora, or GMail's web interface, but your hysteria seems a bit overblown here.
--P
They are protecting tehir players which is the right thing to do. Stop being a smartass.
Originally by: Blind Fear Generally, when trying to be a puppetmaster, it is considered good form not to wrap the strings around your neck and choke yourself.
|

Dan Grobag
Caldari Oyster Colors
|
Posted - 2007.11.28 17:06:00 -
[13]
would www.PLAYEVE.com be some sort of scam ?
|

Snake Doctor
MacroIntel United Corporations Against Macros
|
Posted - 2007.11.28 17:11:00 -
[14]
Edited by: Snake Doctor on 28/11/2007 17:11:34
Originally by: Dan Grobag would ---- be some sort of scam ?
Of course. And an ISK seller affiliate. And a mail spammer. Money launderer. Etc...
PS: You should remove that address before a mod gets to it 
Join MacroIntel! |

manasi
Caldari Valhalla Navy Technical Institute
|
Posted - 2007.11.28 17:32:00 -
[15]
Originally by: Nisd A good way to defend windows on is installing a anti-malware/spyware, Like Comodo Firewall Pro i got this feature that is call IDefence, it monitors for hook's and dll injections. And it is just a good firewall.......
I have not had any luck with that firewall...obviously the first line is to do as CCP wrangler said...no one should e-mail you about your EVE password.
As far as other firewalls not here to discuss... that just my 2 cents
I work in a testing lab and we see lots of personal firewalls..sadly, the Comodo one is one we do NOT recommend due to all the problems on our install base of 2K XP XPSP2 and Vista.
Manasi
|

Amerus
Eternal Industries
|
Posted - 2007.11.28 18:13:00 -
[16]
Thanks for the warning. Also a bit of comon sence. NO real need to give it out to strangers or open mails you are not expecting. Specialy not when ya got pm in game, eve mail and the forum boards. ______________________
Im Minmatar, i can't afford a sig! |
|

GM Retrofire
Game Masters

|
Posted - 2007.11.28 18:24:00 -
[17]
We have noticed that there is a trojan out there that's called ibm00002.dll, information on it can be found here
We suggest that everyone scan their computer thoroughly using their installed anti-virus program and/or spyware removal tool. If you don't have one installed you can do this using TrendMicro's Housecall utility which is an online scanner
|
|

Snake Doctor
MacroIntel United Corporations Against Macros
|
Posted - 2007.11.28 18:27:00 -
[18]
Originally by: GM Retrofire We have noticed that there is a trojan out there that's called ibm00002.dll, information on it can be found here
We suggest that everyone scan their computer thoroughly using their installed anti-virus program and/or spyware removal tool. If you don't have one installed you can do this using TrendMicro's Housecall utility which is an online scanner
I always suggest to clients that they use Avira Antivir for home use. It catches EVERYTHING I've ever thrown at it. And it's free. Like free-free for the personal edition.
www.free-av.com
Join MacroIntel! |

Verlaine Glariant
Knights of the Flame Knights Of the Southerncross
|
Posted - 2007.11.28 18:42:00 -
[19]
Thanks for the tip.
Sounds like a CCP's strategy to keep all character trading under control.
Verlaine Glariant. Tactical Weapons Specialist.
|

Lazuran
Gallente Time And ISK Sink Corporation
|
Posted - 2007.11.28 19:12:00 -
[20]
Originally by: torswin
Originally by: Moon Kitten How does this affect the people who use the Linux or Mac client?
As long as you have an updated system and don't give them root access there shouldn't be any problem.
Unfortunately, under Linux (and probably OSX as well) you do not need root to start a keylogger while you are using X11.
Also, once someone has access to the X display, there are plenty of holes in old (and possibly current) X clients with local privilege escalation. Not that privilege escalation is necessary to do a lot of nasty stuff to a user's data or to host malware (spam bots etc.).
So basically there are many opportunities for malware to infect a Linux/OSX box even if you are not using root. Making such broad statements as above is a bit reckless... In practice, the biggest contribution to Linux/OSX desktop security (i.e. safety from malware) is the small market share, then comes the system architecture (and exploit-friendly languages like C used) and quality of software (that may be a bit better than on Windows).
"...been designed for one purpose and one purpose only. Imagine a handful of repair drones pouring from the carebear's mouth. Now imagine they have um, nothing." -Unknown Hel redesigner (2007) |

Sister Impotentata
Caldari Elite Angels Of Death
|
Posted - 2007.11.28 22:52:00 -
[21]
Poor, poor Clementine. Don't let this happen to you. Please EVE safely. ----- TANSTAAFL
Originally by: Psycho John Petrucci If there's any point where you feel it's too difficult, then just stop. Because you just, you don't have it, you're just not good.
|

voogru
Gallente Massive Damage
|
Posted - 2007.11.28 23:48:00 -
[22]
Man, I wish CCP would give us the option of restricting our accounts to only be able to log on from specific IP addresses for us with static IP's.
Hate Farmers? Click Here |

ry ry
StateCorp Veritas Immortalis
|
Posted - 2007.11.28 23:49:00 -
[23]
Edited by: ry ry on 28/11/2007 23:49:59
CAUTION! THIS LINK CONTAINS A LOGGER.
Please resize image to a maximum of 400 x 120, not exceeding 24000 bytes, ty. If you would like further details please mail [email protected] - Cortes |

VicturusTeSaluto
|
Posted - 2007.11.29 03:26:00 -
[24]
Edited by: VicturusTeSaluto on 29/11/2007 03:27:19
Originally by: CCP Wrangler You are always responsible for your account information
From stories I have read I take this to mean that if your account is hijacked that you are on your own. This is not a good policy because the game client itself can not be assured to be secure. Not to mention that the OS that 99% of the players use is inherently insecure.
Really, the only good way to try and protect your own account security would be to only play eve on a seperate machine that is firewalled off from everything but eve, and to never- ever run any other apps- except perhaps in a virtual machine. Not to mention to have the machine secured again physical access.
In these times, people have gotten rootkits on their machines from simple acts like playing a commercial music cd, or viewing an image file posted to a forum such as this one.
I take a lot of precautions because I am fortunate enough to know a good deal about computers- many players do not know much.
|

Topaz Skydiver
Minmatar Narrative Freshfood
|
Posted - 2007.11.29 04:05:00 -
[25]
Edited by: Topaz Skydiver on 29/11/2007 04:08:51
Originally by: Lazuran (and exploit-friendly languages like C used
Yes, actually the abundance of buffer-overflow errors is shocking me. Sometimes I wonder, if there was ever a longer C program written without buffer overflows. It's not explainable by programmers making random mistakes, but has a lot to do with bad coding habits and people not fully understanding, what they are doing. So they shoot themselves in the foot and C doesn't stop them, because C assumes you know exactly, what you are doing and gives you a lot of freedom.
Personally I prefer C++. You have the full power like in C combined with the tools that help you more easily to avoid stupid mistakes, at least if you invest effort to really understand the stuff that you plan to use. But I think technical anyway, like have a clear view how the objects, pointers etc are lying in memory, so it's quite clear that I like it. Agree that there are other languages though, that have other strength and more appropriate and they are often easier to learn and people can't write evil mistakes so easily with most of them. --------------------------------------------- *snip* |

Nobloodx
|
Posted - 2007.11.29 06:34:00 -
[26]
welp i may not agree with ur patches, but u do a dam good job in keeping our accounts secure, thanks ccp
|

Andrue
Amarr
|
Posted - 2007.11.29 08:31:00 -
[27]
Windows users would also do well not to log in as administrators. Most Windows applications run just fine as a limited user. It can be a minor nuisance when you have a genuine need to perform system maintennance but if you enable fast user switching it's not too bad.
How to change.
-- (Battle hardened industrialist)
[Brackley, UK]
My budgie can say "ploppy bottom". You have been warned. |

Arcticblue2
Gallente Nordic Freelancers inc
|
Posted - 2007.11.29 09:24:00 -
[28]
While I played WoW I became targeted by probably goldfarmers or something like that, and while I use both a Anti-virus program and firewall and from time to time use ad-aware to check for spyware I did not find that keylogger that made it possible to clean out one of the servers I played on.
So right now there is one server there where all my characters are naked... (mostly female characters so I don't mind really).
I did read on their forums that it was suggested to install a program called Hitman that use several anti-spyware programs (free to use aparently), and while it does take a while to search the computer it did infact find several malware/spyware including one keylogger used spesific towards WoW.
While I did not find out where I did get that logger from, I do suspect it came from sites that gives clues to quests and ****, there is quite possible that goes towards EVE as well.
---------------------------------------------- "When I was a child, I spoke as a child, I felt as a child, I thought as a child: now that I am become a man, I have put away childish things." 1 cor. |

Pilk
Axiom Empire
|
Posted - 2007.11.29 10:13:00 -
[29]
Originally by: CCP Wrangler
Originally by: Pilk
Quote: Not opening attachments only gets you so far, not giving strangers your email address is the best defense against this form of attack.
Are we seriously worried that the ghostly gobblies are somehow going to attack? Or are we worried about a 0-day exploit against a mail client being inaugurated by a single-target, very traceable attack against an EVE player for their account?
Advise people to keep their Email software up-to-date, even advise them to use an alternate mail client, like Thunderbird, Eudora, or GMail's web interface, but your hysteria seems a bit overblown here.
--P
You are always responsible for your account information and having someone steal your account will at minimum cost you time, but in some cases it can also cost you ISK, items etc. Considering we have started receiving cases where people gave out their email and got infected with a keylogger and got their account stolen, I don't see this as "hysteria". It's more about protecting our players.
I agree with your aims, to be certain, but being the boy who cried, "Wolf!" is not the solution. Overstating the dangers, and overcorrecting for the perceived risks, leads to user disenchantment with security in general. Witness the number of Vista users calling the helpdesk, wanting to turn off all of the new warnings. Not some. All.
search:Vista Disable Warnings (841,000 results) (and probably far more by the time you click the link)
Again, my issue was not with your warning, which was timely and, doubtless, well-founded. My issue was with your recommendations. With the reduced space now available in EVEMails, and the need to transfer around large dumps of data, spreadsheets, applications, etc., that I often generate in the course of my Eve business, operating without the benefit of being able to communicate with other players out-of-band would render me blind, dumb--and broke. Were I a less-security-aware user, I might therefore read your warning with interest, then note that the suggested resolution steps are unacceptable and resolve to cross my fingers and trust in the GM's ability to reverse all fraudulent transactions.
At any rate, thank you for the warning about the sudden surge in keyloggers being sent via this method. Speaking as both an Eve player and a network security professional, I'd simply ask that you avoid overreaching in any one area of the security trifecta of cheap, useable, and effective when issuing direct calls to action to your users.
--P
Kosh: The avalanche has already started. It is too late for the pebbles to vote. |

Andrue
Amarr
|
Posted - 2007.11.29 10:19:00 -
[30]
Pilk, I think you are overreacting. The warning was timely (as you say) but also brief and to the point. It contains useful advice that every computer user should follow all the time.
The fact that so many people are asking MS how to hide the warnings and how to turn off UAC and run as administrator is a sad reflection on the users. I bet those people don't whine and moan to the builder for putting security locks on doors and windows. Then again a fair number do moan about seatbelts in vehicles so perhaps we just have to accept that a large minority of the population are fools.
The rest of us need to be sympathetic, try to educate them and if all else fails put them in a locked room and throw away the key. Er.. Sorry. That last bit may have sounded a litle harsh  -- (Battle hardened industrialist)
[Brackley, UK]
My budgie can say "ploppy bottom". You have been warned. |

Pilk
Axiom Empire
|
Posted - 2007.11.29 10:41:00 -
[31]
Originally by: Andrue Pilk, I think you are overreacting. The warning was timely (as you say) but also brief and to the point. It contains useful advice that every computer user should follow all the time.
The fact that so many people are asking MS how to hide the warnings and how to turn off UAC and run as administrator is a sad reflection on the users. I bet those people don't whine and moan to the builder for putting security locks on doors and windows. Then again a fair number do moan about seatbelts in vehicles so perhaps we just have to accept that a large minority of the population are fools.
The rest of us need to be sympathetic, try to educate them and if all else fails put them in a locked room and throw away the key. Er.. Sorry. That last bit may have sounded a litle harsh 
True, I probably am overreacting, but I think not without some jusification. I have become sick of the UI designers who have forgotten the hard-won lessons of dancing pigs, and of self-proclaimed "security experts" who know nothing more than how to install their favored suite of protective software, proclaiming how they are under constant attack by the eeeeeebil hackers, as evidenced by the log showing over THREE HUNDRED cookie deletions. The reality is, computer security is complex, and security software and advice should be designed to insulate the user from that complexity, while silently allowing them to go about their business.
Really, even an "if possible" prepended to the recommendation to avoid use of email to communicate with fellow players would have placated me. As it stands, the recommendation combines the worst elements of security communication:
- It doesn't help; the attacker(s) will just send their victim to a website, which is a far easier attack vector than an email, anyway.
- It's opaque; for instance, users may think that by following it, they may safely open emails purporting to be from CCP because nobody but CCP has their address, when the malicious party in fact just happened to guess correctly.
- And last but not least, it is draconian in the extreme. This attribute guarantees that the average user won't follow it, and studies show that once users dismiss any part of a security scheme, product or process, they are very likely to bypass the offending element as a whole.
--P
Kosh: The avalanche has already started. It is too late for the pebbles to vote. |

Purlon
|
Posted - 2007.11.29 11:17:00 -
[32]
You know it might be time for online game companies to start offering extra layers of security themselves.
A simple floating keypad would almost eliminate keyloggers, might be a pain to use but at least you would be using your mouse to type in your password. Many banks are rolling this stuff out now.
What about one time passwords? Could CCP send a one time password via sms or some other out of band authentication? Hmmmm
Customers (in my field of work) are now starting to understand the value of their identity and how easily it can be stolen and on sold (to hackers or whoever) from the internet channel. And now they are demanding extra layers of security to keep using products (like internet banking for example).
Also, a floating keyboard would eliminate macro's that login to eve online automatically as the keyboard would be in a differnet position everytime.
Anyways, my 2 cents.
|

Snowcrash Winterheart2
Gallente Vanguard Venture
|
Posted - 2007.11.29 12:20:00 -
[33]
Worth keeping in mind that your system is as secure as a 50p Mars bar. That's the going rate to get your average commuter to cough up their username/password (at least 49% if I remember the story).
----- Four paws... four sets of claws. |
|

CCP Wrangler

|
Posted - 2007.11.29 12:22:00 -
[34]
If someone asks for your email, please petition it in the harrassment category. This will help us find the people who are trying to steal your accounts!
Wrangler Community Manager CCP Games, EVE Online Email / Netfang
"The trouble with having an open mind, of course, is that people will insist on coming along and trying to put things in it." |
|

ry ry
StateCorp Veritas Immortalis
|
Posted - 2007.11.29 13:40:00 -
[35]
Edited by: ry ry on 29/11/2007 13:40:20
Originally by: CCP Wrangler If someone asks for your email, please petition it in the harrassment category. This will help us find the people who are trying to steal your accounts!
cool, i'll email you. what's your email address?
Please resize image to a maximum of 400 x 120, not exceeding 24000 bytes, ty. If you would like further details please mail [email protected] - Cortes |

Jupiter Sun
|
Posted - 2007.11.29 17:17:00 -
[36]
Originally by: Purlon You know it might be time for online game companies to start offering extra layers of security themselves.
A simple floating keypad would almost eliminate keyloggers, might be a pain to use but at least you would be using your mouse to type in your password. Many banks are rolling this stuff out now.
What about one time passwords? Could CCP send a one time password via sms or some other out of band authentication? Hmmmm
Customers (in my field of work) are now starting to understand the value of their identity and how easily it can be stolen and on sold (to hackers or whoever) from the internet channel. And now they are demanding extra layers of security to keep using products (like internet banking for example).
Also, a floating keyboard would eliminate macro's that login to eve online automatically as the keyboard would be in a differnet position everytime.
Anyways, my 2 cents.
runescape offers this.
yes, runescape, that much derided mmo.
|

Xaroth Brook
Minmatar BIG Ka-Tet
|
Posted - 2007.12.01 02:26:00 -
[37]
95% of staying virus-free comes from your own grey cells.. in the now 5 years i've had this rig setup i've not have a single virus -_-
some tips:
never, EVER, install stuff from the internet unless you're ABSOLUTELY sure it's a valid program. ALWAYS check the site you're actually browsing on, this goes for internet banking as well.. your local bank is rich enough to make sure you're on the www.yourbankname .com domain name, so if you're on some dodgy ip, it's NOT YOUR BANK. never give out more personal information than needed.. remember your mother telling you not to talk to strangers? well, the internet is full of em, so a random person in a random system is NOT a good person to give your email address to (nor your account password, for that matter) use STRONG passwords for all your accounts ( http://en.wikipedia.org/wiki/Strong_password#strong_passwords ).. stuff like 't3wahSetyeT4' might take 50 times longer to memorize, but it sure beats 'password' as a password (and yes i ripped that password from wikipedia...) as pointed out before, limited user accounts are less prone to crude backdoor bandit hacks, and for the common user they will save a lot of hassle (especially since you have to relog to install an app, giving you enough time to re-think the validity of said app)
if you value your performance, don't use stuff like norton or mcaffee (no offence), they are bloated and decrease your system performance by a LOT.. free ('open source' and alike) antivirus scanners perform just as well and generally don't mess your pc up that much after uninstalling.
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Xaroth Brook -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Look ma, my sig is too good to be highjacked by the mods |
|

CCP Wrangler

|
Posted - 2007.12.03 11:21:00 -
[38]
Originally by: ry ry Edited by: ry ry on 29/11/2007 13:40:20
Originally by: CCP Wrangler If someone asks for your email, please petition it in the harrassment category. This will help us find the people who are trying to steal your accounts!
cool, i'll email you. what's your email address?
Create a petition. 
And I'm gonna create one to report you!!!  
Wrangler Community Manager CCP Games, EVE Online Email / Netfang
"The trouble with having an open mind, of course, is that people will insist on coming along and trying to put things in it." |
|

Pitt Bull
Caldari
|
Posted - 2007.12.03 15:23:00 -
[39]
Originally by: Nisd A good way to defende windows on is installing a anti-malware/spyware, Like Comodo Firewall Pro i got this feacture that is call IDefence, it monitors for hook's and dll injections. And it is just a good firewall.......
Agreed.
|

Lucas Avignon
|
Posted - 2007.12.03 16:16:00 -
[40]
I'd just like to ask about key loggers, isn't it the case if you don't open attachments then a key logger can't get on your puter. Also don't web clients like hotmail and yahoo scan attachments for viruses/keyloggers if you do decide to download it. Also is in only if you open the attachment not download it that a key logger can get installed.
Thanks in advance for this info.
|

ry ry
StateCorp Veritas Immortalis
|
Posted - 2007.12.03 16:45:00 -
[41]
Originally by: Lucas Avignon I'd just like to ask about key loggers, isn't it the case if you don't open attachments then a key logger can't get on your puter. Also don't web clients like hotmail and yahoo scan attachments for viruses/keyloggers if you do decide to download it. Also is in only if you open the attachment not download it that a key logger can get installed.
Thanks in advance for this info.
ideally, yeah. but if you're using an un-patched copy of.. say.. outlook express there are a few ways of forcing the app to execute code without opening the attachment.
although just never using outlook express is half the battle.
Please resize image to a maximum of 400 x 120, not exceeding 24000 bytes, ty. If you would like further details please mail [email protected] - Cortes |

Jolliejoe
Caldari
|
Posted - 2007.12.04 14:06:00 -
[42]
CCP Wrangler,
Why do you post this??? Since when is CCP serious about preventing ISK buying, account stealing and such? A friend om mine has waited for more than a month with a -5 bil debt on his account because you refused to correct the issue and punish the previous owner of his account.
If you are serious about all of this, why not actively monitor and moderate the timecode/bazar subforum and demand that people include the necessary information when selling a character?? There are rules for it as posted by CCP but nobody with CCP gives one **** about enforcing those rules other than punished innocent people.
There are a couple of very simple steps CCP can take to prevent a lot of problems but you don't..
Ludricous I find this..
|

Lisento Slaven
Amarr Capitalism Amuck
|
Posted - 2007.12.04 15:13:00 -
[43]
Does this mean I should petition everyone (that I can recall) I have given my private e-mail address to on EVE as a precaution? ---
Put in space whales!
|

RaTTuS
BIG Ka-Tet
|
Posted - 2007.12.04 15:31:00 -
[44]
Originally by: Jolliejoe CCP Wrangler,
Why do you post this??? Since when is CCP serious about preventing ISK buying, account stealing and such? A friend om mine has waited for more than a month with a -5 bil debt on his account because you refused to correct the issue and punish the previous owner of his account.
If you are serious about all of this, why not actively monitor and moderate the timecode/bazar subforum and demand that people include the necessary information when selling a character?? There are rules for it as posted by CCP but nobody with CCP gives one **** about enforcing those rules other than punished innocent people.
There are a couple of very simple steps CCP can take to prevent a lot of problems but you don't..
Ludricous I find this..
here we go again ,,, what friend ? and you cannot transfer accounts - only characters - -- BIG Lottery, BIG Deal, InEve [Now Verified] & Recruiting
|

Jolliejoe
Caldari
|
Posted - 2007.12.06 09:13:00 -
[45]
Originally by: RaTTuS
Originally by: Jolliejoe CCP Wrangler,
Why do you post this??? Since when is CCP serious about preventing ISK buying, account stealing and such? A friend om mine has waited for more than a month with a -5 bil debt on his account because you refused to correct the issue and punish the previous owner of his account.
If you are serious about all of this, why not actively monitor and moderate the timecode/bazar subforum and demand that people include the necessary information when selling a character?? There are rules for it as posted by CCP but nobody with CCP gives one **** about enforcing those rules other than punished innocent people.
There are a couple of very simple steps CCP can take to prevent a lot of problems but you don't..
Ludricous I find this..
here we go again ,,, what friend ? and you cannot transfer accounts - only characters -
I meant player dude and you seriously think I'm going to name him here in public... LOL... But hey, I expected to not get a responde from CCP while a CCP rep responded to a number of other replies here.
|

Xurx
Wreckless Abandon Triumvirate.
|
Posted - 2007.12.06 13:24:00 -
[46]
Originally by: ry ry Edited by: ry ry on 29/11/2007 13:40:20
Originally by: CCP Wrangler If someone asks for your email, please petition it in the harrassment category. This will help us find the people who are trying to steal your accounts!
cool, i'll email you. what's your email address?

|

Aramis Rosicrux
Gallente Canadia Security Institute PROBABLE CAUSE
|
Posted - 2007.12.06 17:50:00 -
[47]
Let's take a moment to actually educate the readers of this thread.
Security is a good thing. It protects you and your Eve charaacters.
Security means several things you have to do, not just one.
Guard your Infos Giving out personal details invites identity theft, a smart person will not give out personal details to strangers. Just because someone has been a buddy to you in the game does not mean they are your friend in real life. Real hackers use "social engineering" to rob you. The "social" part is they do things to gain your trust.
Guard your E-mail Opening an E-mail sometimes allows programs and scripts to be run on your computer automatically. Outlook Express, and other e-mail programs have functions that can be used to launnch programss. Picture files can have code embedded in them that can, under the right circumstances, run a script. Hackers can use programs and scripts to install nasty code on your computer.
Guard your Web Use Opening a web page means you let that web page give instructions to your web browser. Some web browsers can be tricked into following instructions to install nasty code. Also, multimedia content, including pictures, music and even videos can be altered so that they can install nasty code.
Now these attacks do not work every time. They may only work one time out of a hundred. But if you are that hundredeth user, you have the problem.
What is nasty code??? There are several varieties, and hackers have been cross-breeding them to make stronger versionss.
Virus- Code that replicates the instructions to install the virus into other programs. It makes a safe file become infected and then the infected file is now also spreading thwe virus.
Trojan Horse- A one-time program that drops a nasty onto your system. These can be from web sites, mails or even a program installed from a CD-ROM, diskette or a flash memory chip.
Keylogger- A program that gets between the stream of data coming from your keyboard that goes to the operating system, and usually records every key you press and writes it to a secret location. Periodically, the keylogger sends the data it collects to a secret location on the internet, where the hacker(s) can save a copy and study what you typed... this can be a password, your credit card number, or even your secret loveletters... if you type it, the logger gets a copy!
Rootkits- A program designed to install nasties and also includes a "backdoor" that allows the hacker(s) to remotely use your computer. Many thousands of computers have been converted into a veritable army of computers and used to attack other web sites (Denial of Service cloud attacks). Usually the hackers use them to send spam, but they can also read, write and delete your files. They can place data on your computer for safe keeping, access your microphone and even your video camera!
Malware- Semi-professiobnally written code installed as part of some "freebie" gimmick, like a free screen saver, a free program or (often) free p0rn players. The software "watches" your web surfing and alters web pages with the goal of selling you something. So you look at car ads, they put fake links to car sales on the page you are on.
Anyway, please, if you think you want to give away your e-mail address, go to a free e-mail service and create a single-use account for the purpose. Do not ever use the e-mail for any other purpose.
Even if you have a special e-mail account to use to send mail to your alliance mates, you still want to keep some details to your self. Last name, employer, street address, personal phone number, it is a good idea to not share these.
So, play smart, play safe, and assume everyone in the world is reading your e-mail, watching your web browsing and maybe even peeking in your room using your camera!
Just cuz' I am paranoid does not mean thar are NOT out to get me!
- Aramis Rosicrux
Humility is the hallmark of honorable character. Aramis Rosicrux
|

ry ry
StateCorp Veritas Immortalis
|
Posted - 2007.12.09 18:59:00 -
[48]
just a small point, but most malware is professionally wrote, rather than 'semi-professional', which suggests some kind of bedroom coders.
*again. |

DEFF DSP
|
Posted - 2007.12.10 11:43:00 -
[49]
now those guys are sending links in game to corp mates using already stolen accounts. file: First_Screensaver_Attempt.rar contains: Awsome Ships and Stations -- no name yet though.scr
did not work on my test pc, but worked on my friends pc who dont have an eve client :D
so theres key logger named klog AFAIK. its making directory C:\WINDOWS\system32\Ms32 with files klog.dat, win32.exe etc. its impossible to rename or delete it - only using some process killers.
that crap can't be detected by anti viruses /o\ i guess its making a connection to host (bad guy who made this thing) so firewall should block it but i'm not sure about that.
|

Loyal Servant
Caldari Viper Intel Squad Pure.
|
Posted - 2007.12.23 07:38:00 -
[50]
Some of you are killing me.
Don't give out your email address!
Is it really that friggin hard? It is not hysteria, you want your account stolen by a fracking isk farmer... so he can launder your isk and items?
DO WHAT THEY SAY and DO NOT GIVE OUT YOUR EMAIL ADDRESS.

|

Mother Inlaw
|
Posted - 2008.03.01 08:55:00 -
[51]
Edited by: Mother Inlaw on 01/03/2008 08:56:44 If you have a keylogger just send the email address of the person who sent it to your freindly mother inlaw and let her sort them out.
But seriously for a second - can anyone recommend some good software to check and remove these? IS it worth using specific programmes for this apart from the preffered antivirus / firewall packages bundles we all use?
I'm sure many of us have been in the position where we have previously given out the email address many times. Not me of course 
Capital Sales You're worth it! |

AndrewRyan
|
Posted - 2008.03.01 09:00:00 -
[52]
Grab the holy water and the stakes its alive! ========================================= A Man chooses, a slave obeys. |

Mother Inlaw
|
Posted - 2008.03.01 09:08:00 -
[53]
Edited by: Mother Inlaw on 01/03/2008 09:08:12
Originally by: AndrewRyan Grab the holy water and the stakes its alive!
/me waves to AndrewRyan
Capital Sales You're worth it! |

Drahcir Nasom
Independent Manufacturers
|
Posted - 2008.04.29 20:51:00 -
[54]
The account of one of our corp members has been hacked through the use of a keylogger today and we have lost about 40Bn worth of stuff from our corp hangars.
Drahcir
|
| |
|
| Pages: 1 2 :: [one page] |