Page 1 of 2

Ugh, hacked >.<

Posted: Fri Jan 21, 2011 8:20 am
by Tudyk
Got an awesome phone call from my BF at 4 this morning along the lines of "Hi! Sorry to wake you up, but you'd tell me if you decided to sell everything in the guild bank, right?"

I'm already running Kaspersky, but was told anti-malware programs don't actually ... exist ... for Macs. So if by any chance the person that told me that was wrong and y'all know of one it'd be greatly appreciated. =D

Re: Ugh, hacked >.<

Posted: Fri Jan 21, 2011 9:11 am
by fatman
http://download.cnet.com/mac/antivirus- ... col;narrow

That list seems to say that McAfee and Norton does have security software for Macs. Maybe you should go to their official sites to check.

I think I'm going to change the passwords on my Battle.Net account now. This is getting scary.

Re: Ugh, hacked >.<

Posted: Fri Jan 21, 2011 9:29 am
by Tudyk
Have (and was running) an antivirus program, it was the other little bugs I was worried about. It's lookin' like somebody from China got into my email and used it to change my account info and got in from there. No idea how they got into my email in the first place, but apparently I got in like 4 mins after they did (they hadn't changed my email PW) and I booted 'em out before Blizzards "locked your account password for suspicious activity" email got deleted. Used that to regain access to my bnet account and was at least able to start the recovery process without spending the morning talking to robots on the phone.

Still don't know the extent of the damages, and while I know how to go about making my WoW account secure I have no idea what to do about the rest of the machine. Virus scan DID find 2 little buggers when I ran it with my launcher open ... but yeah, pretty sure they got to my Gmail first.

*sigh*

Re: Ugh, hacked >.<

Posted: Fri Jan 21, 2011 1:27 pm
by erwil
Glad you're getting it sorted out. :3
My fiancée got hacked in a similar way. He runs a mac, but he couldn't find any malware on it. By the looks of it, the hackers got into his email, which he was using for our old guild website (guildomatic) AND his wow account. We both ended up getting authenticators after the incident and changing our WoW emails to one that we don't use for anything else but battlenet.

Re: Ugh, hacked >.<

Posted: Fri Jan 21, 2011 1:29 pm
by Lisaara
Seems hackers are targeting mac users more than windows now cause Macs have less stuff than Windows.

Re: Ugh, hacked >.<

Posted: Fri Jan 21, 2011 1:32 pm
by erwil
I don't think they care if you're a mac user or a windows user, if they get your account details through your email. We had to change our guild website address because we learned that guildomatic shares their user information (not sure how to explain this the best) and several of our other guild members using their battlenet emails got hacked as well.

Re: Ugh, hacked >.<

Posted: Fri Jan 21, 2011 1:42 pm
by Lisaara
erwil wrote:I don't think they care if you're a mac user or a windows user, if they get your account details through your email. We had to change our guild website address because we learned that guildomatic shares their user information (not sure how to explain this the best) and several of our other guild members using their battlenet emails got hacked as well.
Well the trend is awfully coincidental cause this is like the 10th person I've seen in a row within the last few weeks that was hacked and was a mac user. I'm pretty sure they don't care but it seems Mac users are much more vulnerable.

Re: Ugh, hacked >.<

Posted: Fri Jan 21, 2011 1:56 pm
by erwil
Aye, there seems to still be a general misconception that macs are safe from viruses, when in truth there are just a whole lot less of those that can actually affect them.

Re: Ugh, hacked >.<

Posted: Fri Jan 21, 2011 2:48 pm
by Lisaara
erwil wrote:Aye, there seems to still be a general misconception that macs are safe from viruses, when in truth there are just a whole lot less of those that can actually affect them.
Well the hackers now should set that story straight, I think. I've always thought Macs were more vulnerable because a lot of antivirus programs arent that compatable with Macs.

Re: Ugh, hacked >.<

Posted: Sat Jan 22, 2011 2:20 pm
by Ognian
Add me to the hacked list. Happened last night/this morning. I DID happen to install the MyRolePlay addon off curse last night. Maybe coincidence, but I don't believe in those, so maybe a warning to all to not trust that particular download at the moment!

Re: Ugh, hacked >.<

Posted: Sat Jan 22, 2011 2:44 pm
by Raederle
Get thee to an authenticator!!

Re: Ugh, hacked >.<

Posted: Sat Jan 22, 2011 3:45 pm
by Kalliope
Indeed, you're not the first Mac user to be hacked recently. It's possible that hackers are just reaching that part of their lists or something.

Re: Ugh, hacked >.<

Posted: Sat Jan 22, 2011 5:04 pm
by Tudyk
At least recovery/restoration was (mostly) painless, once I figured out to just pick up the phone instead of constantly worrying about strange Chinese people deleting my emails before I could read them.

My big concern is I have no idea how they got in in the first place. From the little I know of tech, it really looks like all they did was have control of my email account and use that to change my bnet account's password. But yeah ... virus scan's drawing a blank and I really don't use this computer for anything other than WoW and the warcraft/petopia/elitistjerks forums. I've got an ancient 13" Mac that's still my email/banking workhorse, and a larger compy for anything that involves video or trying to use multiple browser tabs at once.

I do use addons (and update them manually from Curse), but even those I haven't touched since Wrath launched and nobody dicked with my gmail until about half an hour before my BF's panic-inducing phone call.

Re: Ugh, hacked >.<

Posted: Sat Jan 22, 2011 5:53 pm
by Ognian
my restoration is mostly done now. They reacted quickly, I have since run all the appropriate scans, changed all passwords....and added an authenticator (<3 my EVO)

moral of the story is, it only takes one small slip-up.

I redownloaded the addon i installed last night, and thoroughly scanned it....it doesn't appear to have anything malicious in the folders. It is baffling to me how this happened.

Re: Ugh, hacked >.<

Posted: Sat Jan 22, 2011 7:58 pm
by Sarayana
That really sucks, though it's good to hear you got it back. What worried me is that a lot of people seem to get compromised through gmail accounts of late.

Re: Ugh, hacked >.<

Posted: Sun Jan 23, 2011 4:43 pm
by Lisaara
Ognian wrote:Add me to the hacked list. Happened last night/this morning. I DID happen to install the MyRolePlay addon off curse last night. Maybe coincidence, but I don't believe in those, so maybe a warning to all to not trust that particular download at the moment!
I use MRP....infact majority of Moon Guard does. I highly doubt MRP had anything to do with it. Mere coincidence.

Re: Ugh, hacked >.<

Posted: Sun Jan 23, 2011 4:58 pm
by cajunspices
Key-logged likely.

I had my account hacked just before the new release. Blizz was very nice about it and fixed the account and even sent me a free authenticator.

One item you should know, They noted that the only way to stop having your e-mail or any other password logged was to start using my on-screen keyboard for login's with my authenticator. The Screen keyboard uses mouse clicks and is outside the loop used for key logging systems.

I simply added it to my tool bar and use it for all log-ins now.


Cajun

Re: Ugh, hacked >.<

Posted: Sun Jan 23, 2011 11:19 pm
by Celi
On using the on screen keyboard, I have Windows 7 and use the post it notes for lots of things, including keeping my wow password so I can just copy paste rather than type it out. Does that help avoid keylogging systems or is it just a pointless timesaver? Even though I now have an authenticator, I'm still pretty paranoid.

Re: Ugh, hacked >.<

Posted: Sun Jan 23, 2011 11:43 pm
by fatman
Google seems to have had a security problem in China a few months back so .... but that was mostly about espionage, so they say.

Personally, I think the hackers ARE targeting Macs specifically. The question is how.

Other than that, I think they have been harvesting WoW fansite forums for e-mails. I've gotten a few legitimate looking fake e-mails from "Blizzard" about being suspected of doing illegal stuff but they sent it to the wrong e-mail address. I forwarded them immediately to Blizzard's customer support.

Re: Ugh, hacked >.<

Posted: Sun Jan 23, 2011 11:47 pm
by Lisaara
Celi wrote:On using the on screen keyboard, I have Windows 7 and use the post it notes for lots of things, including keeping my wow password so I can just copy paste rather than type it out. Does that help avoid keylogging systems or is it just a pointless timesaver? Even though I now have an authenticator, I'm still pretty paranoid.
the copy/paste is your error. They could easily snatch that right up. I'd never recommend using copy/paste. You're much safer typing it out.