I got hacked

General discussion and socializing.

Re: I got hacked

Postby jock » Sat May 27, 2023 4:05 pm

For people that did get hacked can you comment and share what client you were using, to try to help people avoid this?

This also allows us to see correlations if a specific client is to blame or if there is another reason this occurred.
jock
 
Posts: 583
Joined: Thu Mar 08, 2012 7:27 am

Re: I got hacked

Postby loftar » Sat May 27, 2023 4:06 pm

jock wrote:For people that did get hack can you comment and share what client you where using, to try help people avoid this.

I want to be clear about the fact that I don't know that it's a malicious client. If anything, I've noticed among the hacked accounts some that haven't even logged in since like 2013, so I'm not sure the client theory is even satisfactory at all.

To be sure, though, it's not just a brute-force hack. The attacker just logged straight into the accounts without trying different passwords, so he clearly has some sort of list of credentials.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 8926
Joined: Fri Apr 03, 2009 7:05 am

Re: I got hacked

Postby jock » Sat May 27, 2023 4:07 pm

loftar wrote:
jock wrote:For people that did get hack can you comment and share what client you where using, to try help people avoid this.

I want to be clear about the fact that I don't know that it's a malicious client. If anything, I've noticed among the hacked accounts some that haven't even logged in since like 2013, so I'm not sure the clien theory is even satisfactory at all.


I edit my post just before you replied :D
jock
 
Posts: 583
Joined: Thu Mar 08, 2012 7:27 am

Re: I got hacked

Postby jock » Sat May 27, 2023 4:07 pm

jock wrote:For people that did get hacked can you comment and share what client you were using, to try to help people avoid this?

This also allows us to see correlations if a specific client is to blame or if there is another reason this occurred.
<edit
jock
 
Posts: 583
Joined: Thu Mar 08, 2012 7:27 am

Re: I got hacked

Postby vatas » Sat May 27, 2023 4:13 pm

No idea if this is connected and this is basically hearsay, but someone said they lost 4 top-quality treepots and suspected a bug. While Occam's Razor still says "he accidentally dropped them, did not notice, they despawned" there still could be a connection. It would make sense that the attacker would perform surgical strikes like this. In WoW you could make decent in-game gold from compromised accounts by vendoring everything soulbound (trade restricted) then simply mailing all money and all non-soulbound items to an expendable mule account. In Haven you can't really liquidate large amount of items, part of the reason why, after a successful siege, it is common to simply bash most containers and only cherry-pick the few especially valuable items.
The most actively maintained Haven and Hearth Wiki (Not guaranteed to be up-to-date with all w14 changes.)

Basic Claim Safety (And what you’re doing wrong) (I recommend you read it in it's entirety, but TL:;DR: Build a Palisade.)

Combat Guide (Overview, PVE, PVP) (Tells you how to try and escape, and make it less likely to die when caught.)
User avatar
vatas
 
Posts: 4511
Joined: Fri Apr 05, 2013 8:34 am
Location: Suomi Finland Perkele

Re: I got hacked

Postby Kyrex » Sat May 27, 2023 4:32 pm

vatas wrote:No idea if this is connected and this is basically hearsay, but someone said they lost 4 top-quality treepots and suspected a bug.



How long ago?

It seems not enough people know about the (awesome) security logs that you can check.
On this website, the person can go to:
Code: Select all
Account -> Account Security -> View Security Log
ImageImageImage
User avatar
Kyrex
 
Posts: 42
Joined: Wed Jan 04, 2023 2:26 pm

Re: I got hacked

Postby Kyrex » Sat May 27, 2023 4:33 pm

menillos wrote:i got hacked and my name is not on the list i feel scammed xD

Re: this
Checked in with Menillos and looks like e probably didn't get hacked.
ImageImageImage
User avatar
Kyrex
 
Posts: 42
Joined: Wed Jan 04, 2023 2:26 pm

Re: I got hacked

Postby dor » Sat May 27, 2023 4:39 pm

loftar wrote:To be sure, though, it's not just a brute-force hack. The attacker just logged straight into the accounts without trying different passwords, so he clearly has some sort of list of credentials.


IMHO, it's not related to malicious client. Initially I thought it was just dict-based bruteforce attack, but if there was no failed attempts, it seems that hacker had login:pass pair. I think he got it from one of the widely available leaked bases. So he just had to try these pairs in hope that user used same password everywhere.

@Loftar, if it's possible, please, check two things:
- are there any spike in amount of failed attempts with non-existent login
- are there any spike in amount of failed attempts overall

First could give some insight regarding where from attacker got logins. Second one will shed some light on my hypothesis about "same password everywhere" attack.

If both are "no" then it would mean that attacker had very accurate info about user accounts.
dor
 
Posts: 16
Joined: Sat Jan 21, 2023 7:24 am

Re: I got hacked

Postby dagrimreefah » Sat May 27, 2023 4:45 pm

dor wrote:IMHO, it's not related to malicious client. Initially I thought it was just dict-based bruteforce attack, but if there was no failed attempts, it seems that hacker had login:pass pair. I think he got it from one of the widely available leaked bases. So he just had to try these pairs in hope that user used same password everywhere.

@Loftar, if it's possible, please, check two things:
- are there any spike in amount of failed attempts with non-existent login
- are there any spike in amount of failed attempts overall

First could give some insight regarding where from attacker got logins. Second one will shed some light on my hypothesis about "same password everywhere" attack.

If both are "no" then it would mean that attacker had very accurate info about user accounts.

Image
User avatar
dagrimreefah
 
Posts: 2631
Joined: Wed May 25, 2011 3:01 am

Re: I got hacked

Postby Kyrex » Sat May 27, 2023 4:47 pm

dor wrote:
loftar wrote:To be sure, though, it's not just a brute-force hack. The attacker just logged straight into the accounts without trying different passwords, so he clearly has some sort of list of credentials.


IMHO, it's not related to malicious client. Initially I thought it was just dict-based bruteforce attack, but if there was no failed attempts, it seems that hacker had login:pass pair. I think he got it from one of the widely available leaked bases. So he just had to try these pairs in hope that user used same password everywhere.

@Loftar, if it's possible, please, check two things:
- are there any spike in amount of failed attempts with non-existent login
- are there any spike in amount of failed attempts overall


From discord:
loftar (via discord) wrote:To be sure, it's not just a random brute-force bot, the site does have protections against that. The attacker just logged straight into the accounts without any password misses.
Or well, there were some accounts where he used the wrong passwords, but on the ones where they did successfully log in, they logged right in.


Suggesting that the credentials that failed had changed passwords since their compromise.

This is generally suggestive of some kind of phishing/scraping.
ImageImageImage
User avatar
Kyrex
 
Posts: 42
Joined: Wed Jan 04, 2023 2:26 pm

PreviousNext

Return to The Inn of Brodgar

Who is online

Users browsing this forum: No registered users and 6 guests